Feeds

ICO slaps NHSBT for wrong organ donor data

Ten years, thousands of cockups

Internet Security Threat Report 2014

The Information Commissioner's Office has reprimanded NHS Blood and Transplant for wrongly recording organ donation preferences over a decade.

The ICO said that in March 2010 NHSBT, which manages the Organ Donation Register (ODR), found irregularities between donation preferences stated on Driver and Vehicle Licensing Agency (DVLA) application forms and the data recorded on the register.

Further investigation showed that there was an ODR software error dating back to 1999, which affected the recording of specific organ preferences from the DVLA. Once the error was discovered, NHSBT halted use of DVLA data files and an independent investigation was commissioned by NHSBT, carried out by Professor Sir Gordon Duff. It informed the ICO and the public in April 2010.

In October last year, Duff's review said that the donations of 25 people had been affected by the error. He concluded that the error had been avoidable if systematic data verification procedures had been in place in 1999. Duff explained in his report that the fault was able to go undetected for so long because for many years the ODR was not consulted as part of the process of establishing consent for organ transplantation.

"Until consultation with the ODR started to become more routine it appears not to have been seen as a business critical system and consequently it seems that resources and scrutiny were concentrated on other priorities," he said.

In a written ministerial statement, published last October, health secretary Andrew Lansley said he was happy with Duff's independent review and the recommendations he offered.

The information watchdog acknowledged that the vast majority of the data during the error period was accurate, and that a number of patients were contacted directly in order to ensure that their original preferences were accurate.

NHSBT has now signed an undertaking, which commits the organisation to being "more robust in checking information is accurate".

Mick Gorrill, head of enforcement at the ICO, said: "The decision to donate an organ is a significant one and it is important that the preferences of the donors are recorded accurately. In this case errors were made in the recording of the donor's wishes.

"I welcome the NHSBT's commitment to correcting the inaccurate data and their willingness to make sure this type of incident does not happen again by introducing a variety of new security measures."

NHSBT will also continue to write to all new registered entrants to give them a chance to report any errors, as well as inviting an external organisation with experience of running large databases to conduct a review of its proposed new control systems.

This article was originally published at Kable.

Kable's GC weekly is a free email newsletter covering the latest news and analysis of public sector technology. To register click here.

Choosing a cloud hosting partner with confidence

More from The Register

next story
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Big Content outs piracy hotbeds: São Paulo, Beijing ... TORONTO?
MPAA calls Canadians a bunch of bootlegging movie thieves
Google Glassholes are UNDATEABLE – HP exec
You need an emotional connection, says touchy-feely MD... We can do that
Just don't blame Bono! Apple iTunes music sales PLUMMET
Cupertino revenue hit by cheapo downloads, says report
US court SHUTS DOWN 'scammers posing as Microsoft, Facebook support staff'
Netizens allegedly duped into paying for bogus tech advice
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Verizon bankrolls tech news site, bans tech's biggest stories
No agenda here. Just don't ever mention Net neutrality or spying, ok?
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.