NHS Birmingham East and North

What

Sensitive personal information kept insufficiently secure.

How much

“Thousands” of records.

Why

The data controller realised that its own employees could access restricted information relating to patients.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that technical security measures are adequate to ensure the security of data.

Reason for action

The data controller brought the matter to the attention of the Data Commissioner. Although this data was only accessible internally it was felt that this displayed inadequate security.

When

20 April 2011.

Links

View PDF of the NHS Birmingham East and North Undertaking (Via ICO Website)

View PDF of the NHS Birmingham East and North Undertaking (Breach Watch Archive)

Norwich City College of Further and Higher Education

What

Loss of sensitive personal information on two occasions.

How much

80 records.

Why

Hard copy records were disposed of inappropriately and insecurely.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that a formal policy for the disposal of confidential waste be written and implemented.

Reason for action

The records were disposed of in standard black bin liners and were thrown into a skip on college grounds by cleaning staff, the same as any other waste.

When

19 April 2011.

Links

View PDF of the Norwich City College of Further and Higher Education Undertaking (Via ICO Website)

View PDF of the Norwich City College of Further and Higher Education Undertaking (Breach Watch Archive)

Borough of Poole

What

Loss on sensitive personal information on three occasions.

How much

Three records

Why

Faxes containing  personal information were erroneously sent to the wrong number.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff are sufficiently training in both the usage of and policies relating to the transmission of data via, fax machines.

Reason for action

Insufficiently clear instructions and training was provided to staff.

When

19 April 2011.

Links

View PDF of the Borough of Poole Undertaking (Via ICO Website)

View PDF of the Borough of Poole Undertaking (Breach Watch Archive)

University College London Hospitals NHS Foundation Trust

What

Loss of sensitive personal data.

How much

750 records.

Why

Loss of an unencrypted memory stick.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that portable media devices are sufficiently encrypted and that staff are trained in the transportation of such data.

Reason for action

Sensitive personal information should never have been transported off site in an unencrypted media device.

When

15 April 2011.

Links

View PDF of the University College London Hospitals NHS Foundation Trust Undertaking (Via ICO Website)

View PDF of the University College London Hospitals NHS Foundation Trust Undertaking (Breach Watch Archive)

Council for Healthcare Regulatory Excellence

What

Possible loss of sensitive personal information.

How much

Three records

Why

Discovery that some hard copy files relating to cases could not be accounted for.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that all correspondence regarding personal data is adequately protected and a permanent system for the logging of data is put into place.

Reason for action

It was impossible, due to insufficient data tracking, to be sure if the data had ever been received by the data controller, let alone lost.

When

15 April 2011.

Links

View PDF of the Council for Healthcare Regulatory Excellence Undertaking (Via ICO Website)

View PDF of the Council for Healthcare Regulatory Excellence Undertaking (Breach Watch Archive)

NHS Liverpool Community Health

What

Loss of sensitive personal information.

How much

31 records

Why

Files were transported in uncollected crates by a removal company which the data controller did not have a contract with.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that written contracts are used whenever third parties might have access to sensitive data and that clear and precise policies will be put into place for how to transport data while moving offices .

Reason for action

Contradictory instructions given to staff members by the removal company lead to confusion as to how the data could be transported, leading to errors made due to short notice.

When

11 April 2011.

Links

View PDF of the NHS Liverpool Community Health Undertaking (Via ICO Undertaking)

View PDF of the NHS Liverpool Community Health Undertaking (Breach Watch Archive)

City of York Council

What

Loss of sensitive personal information.

How much

One record.

Why

The information was erroneously included with documentation sent to an unrelated third party.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that documentation containing personal data is not printed when there is no need to do so.

Reason for action

The information was mistakenly collected from a shared printer by an employee who failed to check that the documentation was only for their case. A lack of quality control prevented this error from being discovered until it was too late.

When

05 April 2011.

Links

View PDF of the City of York Council Undertaking (Via ICO Website)

View PDF of the City of York Council Undertaking (Breach Watch Archive)

Royal Cornwall Hospitals NHS Trust.

What

Inappropriate disclosure of personal information on two separate occasions.

How much

Two records.

Why

The information was sent out in response to a third party Subject Access Request, inappropriately.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff are made familiar with procedures and policies relating to Subject Access Requests.

Reason for action

Insufficient training combined with a large volume of subject access requests lead to the error.

When

04 April 2011.

Links

View PDF of the Royal Cornwall Hospitals NHS Trust Undertaking (Via ICO Website)

View PDF of the Royal Cornwall Hospitals NHS Trust Undertaking (Breach Watch Archive)

Warrington and Halton Hospitals NHS Trust

What

Loss of sensitive data.

How much

110 records

Why

Theft of an unencrypted laptop from premises.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that policies relating to the encryption of portable media devices are checked and upheld.

Reason for action

Despite the data controller having a policy in place to ensure that all such devices were encrypted, this laptop had not been, nor had it been identified as a security risk, despite having no other form of protection.

When

01 April 2011.

Links

View PDF of the Warrington and Halton Hospitals NHS Trust Undertaking (Via ICO Website)

View PDF of the Warrington and Halton Hospitals NHS Trust Undertaking (Breach Watch Archive)

Wolverhampton City Council

What

Loss of sensitive personal data.

How much

Unknown.

Why

Personal data belonged to the data controller was dumped in a skip, which was later stolen.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff are made aware of the data controller’s policy on the disposal of confidential waste

Reason for action

The data should never have been disposed of in a skip. The data controller had a written contract with a third party for the disposal of confidential waste, but on this occasion there was confusion as to the confidential nature of the waste.

When

15 March 2011.

Links

View PDF of the Wolverhampton City Council Undertaking (Via ICO Website)

View PDF of the Wolverhampton City Council Undertaking (Breach Watch Archive)