Feeds

ICO: NHS data security breaches are just 'plain daft'

As bad as gossiping about patients down the pub, says watchdog

High performance access to file storage

NHS staff should be more aware of data security risks as patient confidentiality "is at the heart of what they do", Jonathan Bamford, head of strategic liaison at the Information Commissioner's Office has said.

Speaking at an event on healthcare efficiency, he said that he was confounded by the disconnect between staff awareness on the subject and the number of breaches that occur in the health service.

"The conundrum for me is that those very same people who wouldn't dream of chatting about patient information at Costa Coffee or down the curry house on a Friday evening, or down the Coach and Horses, are the very same people who are losing memory sticks with lots of information on it, who are doing daft things with people's personal information," Bamford, to the Healthcare Efficiency Through Technology event in London.

"Why is there that disconnect there? Why have things fallen down in that way?" he asked. "Because I don't believe that any of those people who are involved in those security blunders are ill informed in terms of the need to look after people's information, or information that is entrusted to them."

He used the Dartford and Gravesham trust's data security issues as an example of lax data security awareness within the NHS. The ICO recently took action against the trust after it mistakenly destroyed 10,000 health records that were left in a destruction room, because the archiving room was full. He said that these kind of breaches occur because people find "work-arounds" such as someone logging into a computer and then allowing colleagues to use the same access.

Bamford explained that it was important for the NHS to realise that security was not all about technical measures, but about organisational changes as well. "It's about standards that are set by organisations, it's about what people are told. You have to ensure the reliability of staff that have access to information and data," he added.

He said that there are lots of issues that need to be addressed, but stressed that the situation could be improved.

"Information governance is at the heart of this and there are lots of lessons we can learn from the data losses over the years. We're really great supporters of the information governance (IG) toolkit and the fact there is a lot of effort put into that, but there has to be something which is meaningful that people embrace in their daily lives, in their professional lives when they go around and use personal information, that's very very important," said Bamford.

Fiona Caldicott, chair of the National Information Governance Board for Health and Social Care, also spoke at the event, acknowledging that some within the NHS had experienced problems with the IG toolkit due to its complexity.

She said that the board plans to support and train people who are having difficulties with understanding the system. She also disclosed that the organisation, which is set to become part of the Care Quality Commission (CQC) in 2013 under proposals in the health and social care bill, was working on transitional guidance to help healthcare professionals with the changes to the NHS.

Caldicott said that NIGB will place ideas online in the next few weeks. "What we would like to do is publish it and then be very open to responses from the readership and those that wish to use it for more amendments," she said.

She also spoke of an emerging contradiction between health secretary Andrew Lansley's "mantra" of 'no decision about me, without me' and the delivery of good quality information governance.

"That is not a simple concept, and I think one of the things we have to think about is how the issues of information governance fit with that statement and how members of the public understand what we're doing with their data," said Caldicott, adding that it was important with information to give them patients "the assurance that this is fully safeguarded within the services with which they present".

This article was originally published at Guardian Government Computing.

Guardian Government Computing is a business division of Guardian Professional, and covers the latest news and analysis of public sector technology. For updates on public sector IT, join the Government Computing Network here.

High performance access to file storage

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Did a date calculation bug just cost hard-up Co-op Bank £110m?
And just when Brit banking org needs £400m to stay afloat
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Big Content goes after Kim Dotcom
Six studios sling sueballs at dead download destination
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Alphadex fires back at British Gas with overcharging allegation
Brit colo outfit says it paid for 347KVA, has been charged for 1940KVA
Jack the RIPA: Blighty cops ignore law, retain innocents' comms data
Prime minister: Nothing to see here, go about your business
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.