Simple clear advice in plain English

Welsh medical practice loses details of 8,000 patients

The data was put on an unencyrpted memory stick that was lost in the post

image of USB memory key
hardware/siemens/siemens-gigaset-m34-usb

A medical practice in Wales has reported to the Information Commissioner’s Office (ICO) that it has lost the personal details of 8,000 patients.

In March this year, a member of staff at the Lampeter Medical Practice downloaded the data onto an unencrypted memory stick.

The memory stick was posted via recorded delivery to the Health Boards Business Service Centre but never arrived.

This is a clear breach of the Data Protection Act, which states data must be processed and kept securely.

Sally-Anne Poole, ICO enforcement group manager said: “It is unnecessarily risky to download 8,000 personal details on to a memory stick.

“It is imperative that staff are made fully aware of an organisation’s policy for securing personal data and any portable device containing personal information should always be encrypted to prevent it being accessed in the event of loss or theft.”

Dr Rowena Mathew, head of the Lampeter practice, has agreed to take remedial action by ensuring sufficient steps are taken to stop another security breach occurring.

This includes ensuring all mobile devices including laptops and memory sticks are encrypted, ensuring physical security measures are sufficient and making staff fully aware of the organisations’ data security policy.

“I am pleased Lampeter Medical Practice has agreed to take action to prevent a similar security breach happening again,” said Ms Poole.

Article tags

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Personal information data breaches top 1,000

Privacy watchdog, the Information Commissioner's Office, warns companies to be vigilant

ICO to fine companies for DPA breaches

Offending organisations could be fined up to £500,000 for breaching Data Protection Act

Data protection appeals body merges with tribunals service

The Information Tribunal, which dealt with appeals over data protection and freedom of information rulings, has been merged into a unified body

Question & Answer

Q.Why are some of the keys on my keyboard doing strange...

> Read the answer

Q.Is my phone’s Bluetooth any use?

> Read the answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Best deals on the web

img

Samsung RV520-A07

£359.98- Buy it now

img

Acer Aspire 5750G (LX.RXP02.019)

£399.99- Buy it now

img

Apple MacBook Pro (MD313B/A)

£904.37- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

CAD

Computer Aided Design. Software used to create 3D models.

Great shopping deals from Computeractive