The Register® — Biting the hand that feeds IT

Feeds

Hospital gopher fined for prying into ex's family records

Court dishes out £1,500 bill for data breach

Agentless Backup is Not a Myth

A former healthcare assistant at Royal Liverpool university hospital has been fined £500 and been ordered to pay £1,000 towards prosecution costs after she unlawfully accessed the medical records of five members of her ex-husband's family.

Juliah Kechil accessed the records of the five individuals between July and November 2009 in an effort to obtain their new telephone numbers.

The hospital launched an investigation in November 2009 when the defendant's former father-in-law contacted the hospital after receiving nuisance calls which he suspected had been made by Kechil. He told the hospital that he was concerned that there had been a breach of the Data Protection Act.

Checks by the hospital revealed that all of the patients whose details had been compromised were not at any time under the medical care of Ms Kechil and that she had no work related reasons to access their records. The breaches were traced through audit trails linked to the defendant's smartcard ID. Kechil was also ordered to pay a £15 victim surcharge by Liverpool city magistrates court.

Steve Eckersley, head of enforcement at the Information Commissioner's Office, said: "Unlawfully obtaining other people's information for personal gain is a serious offence which can have potentially devastating effects. Ms Kechil accessed medical records for entirely personal reasons. The breach of their privacy would obviously have been very distressing for the individuals involved.

"People should be able to feel confident that their personal details will be stored securely and only accessed when there is a legitimate business need. We will always push for the toughest penalties against individuals who abuse this trust."

This article was originally published at Guardian Government Computing.

Guardian Government Computing is a business division of Guardian Professional, and covers the latest news and analysis of public sector technology. For updates on public sector IT, join the Government Computing Network here.

What you need to know about cloud backup

So they *can* trace who accessed your data.

And (unlike say the Police) they actually *do* so on occasion.

Here's a little suggestion for *all* govt and public service organisations.

Lets say once a month run a report that cross checks case file access versus staff *assigned* to those cases. Only print staff *not* assigned to case but who have accessed the files.

Should be a 1 page report saying "There is nothing to report"

Bet it's not.

Thumbs up as the hospital did the right thing and should be *encouraged* to do it again.

10
0

Even if you trust the government...

Even if you trust the government, and believe the "nothing to hide" arguments, this sort of thing shows why centralized data-gathering is dangerous.

7
0

£15 victim surcharge

It's just not worth being a victim these days...

6
0

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
 breaking news
NSA whistleblower to tech firms, Obama: 'Grow a pair!'
Ed Snowden: Email tracking grabs 'IPs, raw data, content, headers, attachments, everything'
 breaking news
Ecuador: All right, Julian, you CAN stay on our sofa - it's your human right
Minister and Wikileaker share cosy chat in tiny London flat
Google flings another £1m at online child sex abuse vid CRACKDOWN
See, see, we're trying, ad giant tells Daily Mail UK.gov
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
NSA: We COULD track you by your phone ... if we WANTED to
Honestly, too much work, can't be bothered