Feeds

GP surgeries MUST DO BETTER on data handling, says ICO

Watchdog warning comes as NHS prepares to unlock medical records

Combat fraud and increase customer satisfaction

A number of GP surgeries in England allowed their employees to have unrestricted internet access - thereby increasing the risk of data being leaked, hacked and targeted by viruses, Britain's information watchdog warned today.

Officials from the Information Commissioner's Office visited 24 GP practices between April and November 2013 to inspect how well those NHS doctors' surgeries were handling sensitive patient data.

It found (PDF) that several of the sites agreed that staff could access personal email accounts via the surgery's computer system, and added that local polices on acceptable internet and email usage were "not always reflected in the software/tools that enforced them".

The ICO said:

The visits helped to highlight the pressures faced by GPs as data controllers for their patient records in a time of massive change to the structure and practices within the NHS and the corresponding information flows.

NHS England is currently posting leaflets out in among junk mail to 26.5m households highlighting that patients have a right to opt out of its plans to share their medical records, even though it failed to provide a simple form that individuals could then submit to their GPs.

Under the so-called care.data scheme, the Health and Social Care Information Centre (HSCIC) will shortly begin laboriously collecting patient info from GP practices, which will then be linked with hospital data it already stores.

However, controversially, GP surgeries are ultimately saddled with any issues that arise while the records are being transferred to the HSCIC.

But the ICO found shortcomings during its visits to the GP practices.

It said improvements could be made when it comes to reporting data breaches and of informing patients about how their information will be shared with the NHS, private companies and "approved" researchers.

The regulator warned that more needed to be done with the "risks posed by unrestricted internet access."

Paper records containing sensitive medical information took up considerable space, the ICO noted. It said the volumes of paperwork needed to be carefully managed.

“The NHS processes some of the most sensitive personal information available and data breaches at GP surgeries can have significant repercussions for the individuals affected," said the ICO's Lee Taylor.

"But we were broadly pleased with what we saw during the advisory visits. Having the right policies and procedures in place is the backbone to good data protection and the GP practices we visited tended to have these."

On Monday, the regulator explained in a blog post how the UK's Data Protection Act applied to the care.data scheme.

The ICO's Dawn Monaghan said:

GPs holding personal information about patients is nothing new and is covered squarely by the DPA. Generally everyone understands what’s happening: you give personal information to your GP who then records that information as your medical history. This record may include information from other health services and allows your GP to track your health throughout your lifetime.

The changes begin with some of the personal information included in that record going from GPs to the HSCIC. This happens under the direction of NHS England, which is allowed due to a new law, the Health and Social Care Act 2012.

This law gives NHS England the right to direct the HSCIC to collect certain sorts of data from the medical records. The law is a statutory enactment which requires the disclosure of the data, which means the data becomes exempt from the main parts of the DPA.

In other words, there is no legal opt out under the UK's data protection law, which in turn means that care.data is not regulated by the ICO - nor does the watchdog set the rules on how the system works.

"That responsibility for letting patients know what is happening falls to GPs, as the data controllers," said Monaghan.

"It might seem unfair that this responsibility doesn’t fall on NHS England, who are instructing the data collection, or on the HSCIC who will collect and use it, but the DPA focuses squarely on the whoever originally collected, holds and is going to disclose the data (the data controller) - in this case the GPs."

She added that the ICO had initially concluded that NHS England - with its much-criticised leaflet drop that was addressed to households rather than individuals - had met the fair processing requirements under the DPA.

Beyond that, patients objecting to the medical records data grab are expected to burden GPs with their concerns.

NHS patients and information director Tim Kelsey attempted to shrug off critics who are worried about who might have access to the data-sharing system earlier this week.

He said on his Twitter account: "care.data only for NHS patient care purposes; no insurance or other applications permitted. NHS guarantees privacy."

The HSCIC will start receiving the data from GP surgeries in England in the next few months. Once collected, the ICO will be able to police how that information is shared because at that point the HSCIC will be the data controller.

It will be interesting to see at that stage if Kelsey's promises hold tight. ®

SANS - Survey on application security programs

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Did a date calculation bug just cost hard-up Co-op Bank £110m?
And just when Brit banking org needs £400m to stay afloat
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Alphadex fires back at British Gas with overcharging allegation
Brit colo outfit says it paid for 347KVA, has been charged for 1940KVA
Jack the RIPA: Blighty cops ignore law, retain innocents' comms data
Prime minister: Nothing to see here, go about your business
Banks slap Olympus with £160 MEEELLION lawsuit
Scandal hit camera maker just can't shake off its past
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.