Royal Liverpool and Broadgreen University Hospitals NHS Trust

What

Loss of sensitive personal data on two occasions.

How much

22 records and 27 records.

Why

  • Ward handover sheets were discovered in a street near the hospital.
  • A clinic bag containing paper documents was stolen from a staff members’ car.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff are made aware of the requirements for keeping data secure.

Reason for action

Both occasions seem to have been caused by staff failing to take the proper precautions.

When

15 September 2011.

Links

View PDF of the Royal Liverpool and Broadgreen University Hospitals NHS Trust Undertaking (Via ICO Website)

View PDF of the Royal Liverpool and Broadgreen University Hospitals NHS Trust Undertaking (Breach Watch Archive)

Eastern and Coastal Kent Primary Care Trust

What

Loss of personal data.

How much

1.6 million records.

Why

A filling cabinet containing records was sent to a landfill during a move, however it also contained a CD holding data on 1.6 million patients.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff receive the necessary Information Governance training and are made aware of retention and storage policies.

Reason for action

A failure of internal communication meant that the presence of the CD in the filing cabinet was not known to those disposing of it.

When

14 September 2011.

Links

View PDF of the Eastern and Coastal Kent Primary Care Trust Undertaking (Via ICO Website)

View PDF of the Eastern and Coastal Kent Primary Care Trust Undertaking (Breach Watch Archive)

Walsall Council

What

Accidental disposal of personal data.

How much

951 records.

Why

The appointed data processor accidentally disposed of postal vote statements in a skip.

Regulator

ICO

Regulatory action

Undertaking issued to insure that in the future a written contract exists between data processors and the controller.

Reason for action

There was no written contract between the data controller and the data processor..

When

09 September 2011.

Links

View PDF of the Walsall Council Undertaking (Via ICO Website)

View PDF of the Walsall Council Undertaking (Breach Watch Archive)

London Ambulance Service NHS Trust

What

Loss of sensitive personal data.

How much

Unknown.

Why

Theft of unencrypted laptop from a staff member’s home.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff members are made aware sensitive personal data is not to be forwarded to personal email accounts under any circumstances.

Reason for action

Data was emailed by a staff member to a personal account and downloaded onto a personal, unencrypted, laptop.

When

07 September 2011.

Links

View PDF of the London Ambulance Service NHS Trust Undertaking (Via ICO Website)

View PDF of the London Ambulance Service NHS Trust Undertaking (Breach Watch Archive)

University Hospital of South Manchester NHS Foundation Trust

What

Loss of sensitive personal data.

How much

87 records.

Why

Loss of an unencrypted memory stick by a medical student.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that students are provided with sufficient training and that the security of personal data is sufficiently monitored.

Reason for action

It was assumed that the medical student had already received sufficient data protection training. Sensitive data was copied from an encrypted memory stick provided by the hospital to an unencrypted personal memory stick.

When

07 September 2011.

Links

View PDF of the University Hospital of South Manchester NHS Foundation Trust Undertaking (Via ICO Website)

View PDF of the University Hospital of South Manchester NHS Foundation Trust Undertaking (Breach Watch Archive)

The Scottish Children’s Reporter Administration

What

Loss of sensitive personal data.

How much

10 records.

Why

An email containing sensitive information was sent to an unknown 3rd party and nine case files were temporarily lost during a move.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that staff are made aware that they may not send data to personal email accounts.

Reason for action

Information was emailed despite a policy being in place that stated this could only be done if sent to an equally secure recipient. A filing cabinet was not checked for case files during a move.

When

02 September 2011.

Links

View PDF of the Scottish Children’s Reporter Administration Undertaking (Via ICO Website)

View PDF of the Scottish Children’s Reporter Administration Undertaking (Breach Watch Archive)

Luton Borough Council

What

Discovery of flawed encryption.

How much

None

Why

A flaw in the encryption of memory sticks allowed them to be reformatted, removing the encryption.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that all encryption is up to a sufficient standard.

Reason for action

Encryption was of an insufficient standard and this was only discovered during a recall of old devices.

When

02 September 2011.

Links

View PDF of the Luton Borough Council Undertaking (Via ICO Website)

View PDF of the Luton Borough Council Undertaking (Breach Watch Archive)

London Borough of Greenwich

What

Two incidents of disclosure of sensitive personal information.

How much

Two records.

Why

Information sent to incorrect email addresses.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that the Council’s IT policy specifically makes it clear that data is not to be sent to personal emails.

Reason for action

Both incidents saw staff fail to adhere to the Council’s IT policy, regarding the encryption of data. However the policy did not explicitly prevent the sending to data to personal emails.

When

10 August 2011.

Links

View PDF of the London Borough of Greenwich Undertaking (Via ICO Website)

View PDF of the London Borough of Greenwich Undertaking (Breach Watch Archive)

Bay House School

What

Loss of sensitive personal data.

How much

20,000 records.

Why

Malicious website intrusion.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that encryption is used, annual penetration tests are performed and password policies are updated to ensure security.

Reason for action

A member of staff was using the same password for the school’s website and management systems, allowing the attackers, including at least one pupil, with the system administration information required to attack the system.

When

08 August 2011.

Links

View PDF of the Bay House School Undertaking (Via ICO Website)

View PDF of the Bay House School Undertaking (Breach Watch Archive)

Lewisham Council and Wandle Housing Association

What

Loss of personal data.

How much

20,000 records.

Why

Loss of an unencrypted memory stick in a London pub.

Regulator

ICO

Regulatory action

Undertaking issued to ensure that data is not transferred onto unencrypted personal media devices.

Reason for action

Staff were insufficiently trained and unaware of the dangers of copying sensitive information to personal, unsecure, devices.

When

04 August 2011.

Links

View PDF of the Lewisham Council Undertaking (Via ICO Website)

View PDF of the Lewisham Council Undertaking (Breach Watch Archive)

View PDF of the Wandle Housing Association Undertaking (Via ICO Website)

View PDF of the Wandle Housing Association Undertaking (Breach Watch Archive)