DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: Scandal of computer snooping by public servants includes medical information

Posted on January 5, 2011 by Dissent

Jack Blanchard reports the results of a freedom of information request on police in Yorkshire, UK. Revelations concerning non-medical incidents are posted to PogoWasRight, but here are the medically related incidents:

The cases include… a doctor in Doncaster caught looking at a colleague’s medical records.

At one hospital, in Rotherham, a cleaner was caught only last month accessing the private medical files of a friend to determine that she had recently had an abortion. That disciplinary case is still proceeding.

A cleaner was able to access medical files? Who are they disciplining? I hope it’s not just the cleaner but whomever is responsible for securing the files.

At another hospital, in Sheffield, a receptionist gathered patients’ personal contact records and used them for a second job as a market researcher.

[…]

Meanwhile nine NHS trusts across Yorkshire have revealed mostly isolated cases of staff being reprimanded for similar offences, including primary care trusts in Wakefield and Barnsley, and hospitals trusts in Barnsley, Goole, Mid-Yorkshire, South Tees and Rotherham.

The highest number of cases was at Doncaster and Bassetlaw Hospitals NHS Trust, where six members of staff have been reprimanded over the past three years. However, the trust insisted only three of the cases should be classed as formal disciplinary matters.

In one such case, a nurse accessed the private medical test results of her daughter’s father. She was dismissed but reinstated on appeal. In another, a clerk received a written warning after looking up her brother’s test results.

A spokeswoman for the trust said: “We take data security very seriously and have a number of means of ensuring that patients’ personal data is not accessed inappropriately. All six cases of inappropriate access to medical records related to an individual’s colleague, partner, or relative – and while this is inexcusable, it does not indicate misuse of the millions of patient records we hold.”

There were five cases at Sheffield Teaching Hospitals Trust, ranging from the relatively innocent – a staff member wanting to send a birthday card to a sick relative, and checking which hospital ward they were on – to the sinister, as in the case of staff member accessing the medical records of an ex-partner’s new partner. Three of the staff members involved received final warnings, and two were dismissed.

Read more in the Yorkshire Post.

In a related news report in the Gazette & Herald by Julie Hayes on data protection breaches by North Yorkshire police, there was also this intriguing statement:

North Yorkshire and York NHS Trust, who had a similar FOI request, said it had not disciplined any of its staff for illegally or inappropriately accessing the personal data of a member of the public over the past three years.

Does that mean that they had no incidents, detected no incidents, or that they had detected incidents but just didn’t discipline anyone? And what about incidents where staff may have accessed personal data of a fellow member of the staff? I’ve emailed the reporter to request clarification.


Related:

  • Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • Massachusetts hospitals Heywood, Athol say outage was a cybersecurity incident
Category: Health Data

Post navigation

← Data Stewardship: Managing Personally Identifiable Information in Electronic Student Education Records
Experts Forecast Top Seven Trends in Healthcare Information Privacy for 2011 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Once a Patient’s in Custody, ICE Can Be at Hospital Bedsides — But Detainees Have Rights
  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.