Imperial College Healthcare NHS Trust

What
Loss of sensitive personal data.

How much
6,000 records.

Why
Six laptops were stolen from a secure area within the hospital on two separate occasions. In a separate incident a small number of paper records were lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Measures must be taken to ensure the physical security of all such devices containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
One of laptops was unencrypted despite containing sensitive personal data.

When
29 July 2009

Links
View PDF of the Imperial College Healthcare NHS Trust Undertaking (Breach Watch Archive)

East Cheshire NHS Trust

What
Loss of sensitive personal data.

How much
About 60 records.

Why
Personal data relating to over 60 patients were found in a garden in Newcastle-under-Lyme. This followed an office move during which an external company was retained to clear out scrap and rubbish from vacated premises.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that in all cases where third party supplies of goods or services will have access to personal data, a written contract must be entered into prior to work beginning which covers data security requirements. Staff must be made aware of the data controller’s policy for the storage and use of personal data and be appropriately trained to follow that policy.

Reason for action
The data controller did not enter into any written contract with the external company, nor where its actions appropriately supervised. It was noted during the clearance operations that boxes of data were being disposed of in open skips, but the data controller failed to react to this in time to prevent loss of some records.

When
27 July 2009

Links
View PDF of the East Cheshire NHS Trust Undertaking (Breach Watch Archive)

NHS Lothian

What
Loss of personal data.

How much
162 records.

Why
A document wallet containing 25 paper files was temporarily left in a shop. In a second incident an unencrypted USB memory stick was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Network systems are to be introduced to prevent the use of unauthorised personal memory devices to download personal data being processed by NHS Lothian. Measures must be taken to ensure the physical security of all paper files containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it. Compliance with these policies must be monitored.

Reason for action
The USB memory stick was unencrypted and was the personal property of an employee. In both cases the employees failed to comply with NHS Lothian security requirements.

When
21 July 2009

Links
View PDF of the NHS Lothian Undertaking (Breach Watch Archive)

Repair Management Services Ltd

What
Loss of sensitive personal data.

How much
36,800 records.

Why
A unencrypted laptop was stolen from a secure, but unattended, motor vehicle in a public car park.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Measures must be taken to ensure the physical security of all such devices containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The laptop was unencrypted despite containing details relating to criminal convictions.

When
17 July 2009

Links
View PDF of the Repair Management Services Ltd Undertaking (Breach Watch Archive)

London Borough of Sutton

What
Loss of sensitive personal data.

How much
About 119 records.

Why
Numerous Incidents:

  • A paper file containing personal data relating to 73 individuals receiving social care went missing from an office.
  • A document package relating to childcare proceedings was left with the neighbour of an intended recipient and subsequently went missing.
  • An unencrypted laptop containing personal data to 9 children was stolen from a locked cupboard on a children’s hospital ward.
  • An unencrypted laptop containg social care data relating to 39 individuals was stolen from the home of an employee of the data controller.
  • 9 administration computers used to access dara in the data controller’s network were stolen, but some files may have been downloaded onto the computer’s hard drives in breach of policy.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. Measures must be taken to ensure the physical security of all such devices containing personal information. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The various breaches demonstration a lack of security, both physical and technical. The sheer amount of breaches betrayed an overall organisational weakness.

When
29 July 2009

Links
View PDF of the London Borough of Sutton Undertaking (Breach Watch Archive)

Counted4 CIC

What
Loss sensitive of personal data.

How much
84 records.

Why
A filing cabinet containing paper records referring to the personal details of 84 individuals undergoing Drug Rehabilitation Requirements was lost during an office move.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that the physical security of personal data be ensured, especially during transit. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
A building contractor was employed to transport a number of cabinets to the new sit and insufficient organisational measures were made to prevent cabinets containing data for transfer from being mixed with obsolete cabinets to be disposed of.

When
9 July 2009

Links
View PDF of the Counted4 CIC Undertaking (Breach Watch Archive)

Neath Port Talbot County Borough Council

What
Loss of personal data.

How much
65 records.

Why
An unencrypted USB memory stick containing the personal data of children looked after the data controller was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
The memory stick was not encrypted or password protected.

When
9 July 2009

Links
View PDF of the Neath Port Talbot County Borough Council Undertaking (Breach Watch Archive)

Oldham Council

What
Loss of sensitive personal data.

How much
220 records.

Why
13 unencrypted laptops were stolen during a burglary at secure council offices, with the exception of one stolen from a staff members car and another that was stolen during the course of a youth activity evening.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it.

Reason for action
Three of these unencrypted laptops held sensitive personal data and the council did not take adequate steps to safeguard the data, either through encryption, or better physical security in respect of the two laptops stolen outside of council property.

When
7 July 2009

Links
View PDF of the Oldham Council Undertaking (Breach Watch Archive)

Sandwell Metropolitan Borough Council

What
Loss of sensitive personal data.

How much
About four records.

Why
An unencrypted memory stick containing data relating to children in care was lost.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all portable media devices are encrypted to a suitable standard. Staff must be made aware of the data controller’s policy for the storage and use of personal data and be appropriately trained to follow that policy.

Reason for action
Sensitive data was transferred to the memory stick in breach of Council procedure and was not password protected. The employee intended to use the data to work at home, but lost it during his commute.

When
29 July 2009

Links
View PDF of the Sandwell Metropolitan Borough Council Undertaking (Breach Watch Archive)

Hampshire Partnership NHS Trust

What
Loss of personal data.

How much
607 records.

Why
An unencrypted laptop containing personal data relating to staff and patients was stolen from an employee’s hotel room.

Regulator
ICO

Regulatory action
Undertaking issued to ensure that all mobile data storage devices are sufficiently encrypted. All staff must be made aware of the data controller’s policy for the storage of personal data and be trained to follow it. Compliance with these policies must be monitored.

Reason for action
The laptop was unencrypted and stolen from the employee while he was attending a conference.

When
26 June 2009

Links
View PDF of the Hampshire Partnership NHS Trust Undertaking (Breach Watch Archive)