Hastings and Rother Primary Care Trust

What
Loss of sensitive personal data.

How much
70 records.

Why
A desktop computer containing health data relating to a number of patients was stolen.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the data controller take all reasonable measures to ensure the physical security of equipment used to process personal data, whether on the data controller’s premises or those of another organisation. All staff must receive adequate data protection training.

Reason for action
It is believed that the computer was stolen by an opportunistic thief who entered the building via scaffolding that was not normally in place. The data controller did not own this building, but had not taken measures to safeguard the personal data held on the premises.

When
23 January 2009

Links
View PDF of the Hastings and Rother Primary Care Trust Undertaking (Breach Watch Archive)

Brent Teaching Primary Care Trust

What
Loss of sensitive personal data.

How much
70 records.

Why
Two unencrypted laptops containing sensitive personal data relating to 389 patients were stolen from a locked office.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the data controller take all reasonable measures to ensure the physical security of equipment used to process personal data. All such mobile devices must be encrypted, Staff must be adequately trained on the data controller’s information security policies.

Reason for action
The laptops were unencrypted and although the office was locked they were left out on a desk with no further physical security measures taken, contrary to the Trust’s own security policy.

When
19 January 2009

Links
View PDF of the Brent Teaching Primary Care Trust Undertaking (Breach Watch Archive)

Abertawe Bro Morgannwg University NHS Trust

What
Loss of personal data.

How much
5,000 records.

Why
An unencrypted laptop containing sensitive personal data relating to approximately 5,000 patients was stolen from an unlocked office.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the portable and mobile devices are encrypted to a suitable standard.

Reason for action
The Laptop was unencrypted and the office was not locked as it usually would have been.

When
14 January 2009

Links
View PDF of the Abertawe Bro Morgannwg University NHS Trust Undertaking (Breach Watch Archive)

Tees, Esk and Wear Valleys NHS Foundation Trust

What
Loss of personal data.

How much
Unknown.

Why
An unencrypted data stick holding personal data and sensitive personal data relating to health patients and trust staff was found by a member of the public and handed in to the press.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that only data sticks with suitable encryption are used by Trust staff and that an adequate encryption policy and procedures are put in place. All staff must be given appropriate data protection training.

Reason for action
The lost data stick was unencrypted and there was no encryption policy in place.

When
2 January 2009

Links
View PDF of the Tees, Esk and Wear Valleys NHS Foundation Trust Undertaking (Breach Watch Archive)

Hampshire Partnership NHS Trust

What
Loss of personal data.

How much
1,161 records.

Why
1,161 Trust payslips containing employee personal data were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the transporting of all personal data should be risk assessed, and where appropriate, tracked. A review of all internal post procedures should be conducted for security purposes. All staff must receive adequate data protection training.

Reason for action
It could not be explained where or how the payslips had gone missing.

When
19 December 2008

Links
View PDF of the Hampshire Partnership NHS Trust Undertaking (Breach Watch Archive)

Virgin Media Limited

What
Loss of personal data.

How much
3,383 records.

Why
An unencrypted compact disc containing the personal data of 3,383 customers passed on to the data controller by Carphone Warhouse was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that media devices used to transport and store personal data are encrypted and that any contracts between the data controller and any data processors require this.

Reason for action
The lost CD was unencrypted and the arrangement between the data controller and data processor was insufficient.

When
17 September 2008

Links
View PDF of the Virgin Media Limited Undertaking (Breach Watch Archive)

Shirley (Warwickshire) Royal British Legion Club Ltd

What
Unspecified breach of the Seventh Data Protection Principle.

How much
Unknown.

Why
Unknown.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that personal data is processed in accordance with the Seventh Data Protection Principle in Schedule 1 Part 1 of the Act.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
20 March 2008

Links
View PDF of the Shirley (Warwickshire) Royal British Legion Club Ltd Undertaking (Breach Watch Archive)

Skipton Financial Services Limited

What
Inappropriate processing of personal data

How much
Unknown.

Why
An unencrypted laptop computer was stolen from Moore Stephens Consulting, who had been engaged to provide professional consultancy services to SFS in relationship to a software development project.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that sensitive personal data must be encrypted. Risk assessments must be carried out to confirm the adequacy and effectiveness of technical and organisational security measures, including those taken by third parties.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
18 February 2008

Links
View PDF of the Skipton Financial Services Limited Undertaking (Breach Watch Archive)

Southampton City Primary Care Trust

What
Loss of personal data.

How much
168 records.

Why
168 Trust payslips containing employee personal data were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the transporting of all personal data should be risk assessed, and where appropriate, tracked. A review of all internal post procedures should be conducted for security purposes. All staff must receive adequate data protection training.

Reason for action
It could not be explained where or how the payslips had gone missing.

When
13 January 2008

Links
View PDF of the Southampton City Primary Care Trust Undertaking (Breach Watch Archive)

The Department of Health

What
Inappropriate processing of personal data

How much
Unknown.

Why
The personal details of junior doctors held on the Medical Training Application Service (MTAS) website was readily accessible to any person accessing the website.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that sensitive personal data held on the website must be encrypted. Instructions and advice as to the use of passwords and PIN numbers be given to the data controller to those entitled to access the site. Staff will be given appropriate training and regular penetration and vulnerability testing of developing applications and systems to minimise unauthorised access.

Reason for action
The ICO had received a complaint about the data controller’s breach of the Seventh Data Protection Principle.

When
4 December 2007

Links
View PDF of the Department of Health Undertaking (Breach Watch Archive)