About RSS
Search for: in 

Windows Watch - an XP & Vista blog

image: Notebook
Notebooks containing confidential data stolen
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Organisations lose confidential data

Experts warn that password security is not sufficient

Andrea-Marie Vassou, Computeract!ve 25 Sep 2007
ADVERTISEMENT

Two notebooks containing confidential information about NHS patients and council staff have been stolen.

One was owned by the Dunstan Medical Centre in Bolton, and contained medical details of patients.

The other belonged to St Edmundsbury Borough Council, and contained bank and national insurance details for 1,380 people on the council's payroll. Both were stolen in residential burglaries.

When Computeractive contacted the two organisations both said they had informed the people whose data was stolen, and that the notebooks had multiple password security systems in place.

A representative for Bolton Primary Care Trust EHI Primary Care, which oversees Dunstan medical centre, told Computeractive: "Our policies were already up to date but we have learnt our lessons and will continue to revise them."

Following the breach it sent out a reminder to staff and GP practices about security and confidentiality when using notebook computers. This included providing users with appropriate access protection such as passwords. It also said that notebooks should not be left unattended in public places or in cars.

However, according to the security company PGP Corporation, these security measures are not enough.

Jamie Cowper, a representative for PGP, said: "It is disturbing that two organisations handling such sensitive information on a daily basis still rely on simple passwords for data security."

He also said that locking away laptops when not in use is ineffective when dealing with today's threats.

"Locks can be broken and passwords can be hacked. If Bolton Primary Care Trust and St Edmundsbury BC had implemented an enterprise-wide encryption policy, employees could take laptops off-site with the assurance that, even if their device was lost or stolen, the data would remain inaccessible."

The Information Commissioners Office (ICO) would not comment on the two cases individually, but agreed that encryption was a key part of the security process. It said that any lost or stolen notebooks that were reported to be unencrypted could be subject to enforcement powers. The ICO's powers allow it to issue organisations with a warning and, if it conducts an inspection and finds that data is not being adequately protected, take the organisation to court.

A representative for the ICO told Computeractive: "Organisations that process personal information have an obligation to handle that information in line with the eight data protection principles, one of which is that it must be kept securely.

"Customers, clients and employees should be able to feel confident that their personal information is protected," she added.

Neither organisation would comment on why they did not use encryption to secure their notebooks.

See also:

shoppingDetails of 26,000 M & S employees could be at risk  11 May 2007

All Peripheral Devices
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | MI5 Security Service
Forensic Analysts Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis and capability ... more >
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
  The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
United Kingdom | London School of Economics and Political Science
  London School of Economics and Political Science The Library Analyst Programmer (fixed term 24 months) Salary: £30,201 - £36,563 pa incl The Library is at the heart of LSE, one of the world's greatest ... more >
Leeds, United Kingdom | NHS Connecting Health
  Project Manager, Leeds, up to £53k  NHS Connecting for Health is an agency of the Department of Health supporting the NHS to deliver better, safer care to patients, by bringing in new computer systems ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT