Feeds

Devon NHS trust left data of 1,373 staff online for MONTHS

Must cough £175k for opening employees to ID fraud, ICO sniffs

The essential guide to IT transformation

A painful £175,000 fine has been slapped on a health trust in Torquay, Devon, after it published sensitive details of nearly 1,400 employees on its website.

The Information Commissioner's Office issued the penalty, following the embarrassing incident that took place in April 2011.

A spreadsheet containing the information was mistakenly published by staff at Torbay Care Trust for 19 weeks before a member of the public alerted it of the data protection cockup.

"The data covered the equality and diversity responses of 1,373 staff and included individuals’ names, dates of birth and National Insurance numbers, along with sensitive information about the person’s religion and sexuality," the ICO said.

The data watchdog noted that the trust had no safeguards in place to prevent such information being published online. It said staff hadn't been offered any guidance on handling such information and added that there were inadequate checks in place to spot potential problems.

ICO head of enforcement Stephen Eckersley said:

We regular [sic] speak with organisations across the health service to remind them of the need to look after people’s data. The fact that this breach was caused by Torbay Care Trust publishing sensitive information about their staff is extremely troubling and was entirely avoidable. Not only were they giving sensitive information out about their employees but they were also leaving them exposed to the threat of identity fraud.

The ICO added that the trust had now introduced a web management policy to prevent such data protection cockups in the future. ®

Next gen security for virtualised datacentres

More from The Register

next story
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Think crypto hides you from spooks on Facebook? THINK AGAIN
Traffic fingerprints reveal all, say boffins
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.