DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: Scandal of computer snooping by public servants includes medical information

Posted on January 5, 2011 by Dissent

Jack Blanchard reports the results of a freedom of information request on police in Yorkshire, UK. Revelations concerning non-medical incidents are posted to PogoWasRight, but here are the medically related incidents:

The cases include… a doctor in Doncaster caught looking at a colleague’s medical records.

At one hospital, in Rotherham, a cleaner was caught only last month accessing the private medical files of a friend to determine that she had recently had an abortion. That disciplinary case is still proceeding.

A cleaner was able to access medical files? Who are they disciplining? I hope it’s not just the cleaner but whomever is responsible for securing the files.

At another hospital, in Sheffield, a receptionist gathered patients’ personal contact records and used them for a second job as a market researcher.

[…]

Meanwhile nine NHS trusts across Yorkshire have revealed mostly isolated cases of staff being reprimanded for similar offences, including primary care trusts in Wakefield and Barnsley, and hospitals trusts in Barnsley, Goole, Mid-Yorkshire, South Tees and Rotherham.

The highest number of cases was at Doncaster and Bassetlaw Hospitals NHS Trust, where six members of staff have been reprimanded over the past three years. However, the trust insisted only three of the cases should be classed as formal disciplinary matters.

In one such case, a nurse accessed the private medical test results of her daughter’s father. She was dismissed but reinstated on appeal. In another, a clerk received a written warning after looking up her brother’s test results.

A spokeswoman for the trust said: “We take data security very seriously and have a number of means of ensuring that patients’ personal data is not accessed inappropriately. All six cases of inappropriate access to medical records related to an individual’s colleague, partner, or relative – and while this is inexcusable, it does not indicate misuse of the millions of patient records we hold.”

There were five cases at Sheffield Teaching Hospitals Trust, ranging from the relatively innocent – a staff member wanting to send a birthday card to a sick relative, and checking which hospital ward they were on – to the sinister, as in the case of staff member accessing the medical records of an ex-partner’s new partner. Three of the staff members involved received final warnings, and two were dismissed.

Read more in the Yorkshire Post.

In a related news report in the Gazette & Herald by Julie Hayes on data protection breaches by North Yorkshire police, there was also this intriguing statement:

North Yorkshire and York NHS Trust, who had a similar FOI request, said it had not disciplined any of its staff for illegally or inappropriately accessing the personal data of a member of the public over the past three years.

Does that mean that they had no incidents, detected no incidents, or that they had detected incidents but just didn’t discipline anyone? And what about incidents where staff may have accessed personal data of a fellow member of the staff? I’ve emailed the reporter to request clarification.

Related posts:

  • UK: ICO issues stark reminder to NHS bodies on patient records
  • NHS Management, LLC issues updated statement about cyberattack in 2021
Category: Health Data

Post navigation

← Data Stewardship: Managing Personally Identifiable Information in Electronic Student Education Records
Experts Forecast Top Seven Trends in Healthcare Information Privacy for 2011 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-student charged with wave of cyber attacks on Sydney uni
  • Detaining Hackers Before the Crime? Tamil Nadu’s Supreme Court Approves Preventive Custody for Cyber Offenders
  • Potential Cyberattack Scrambles Columbia University Computer Systems
  • 222,000 customer records allegedly from Manhattan Parking Group leaked
  • Breaches have consequences (sometimes) (1)
  • Kansas City Man Pleads Guilty for Hacking a Non-Profit
  • British national “IntelBroker” charged with causing $25 million in damages; U.S. seeks his extradition from France
  • France issues press statement about arrest of ShinyHunters members
  • Patients Allege Home Delivery Pharmacy Failed to Timely Notify Them of Data Breach
  • Hackers breach Norwegian dam, open valve at full capacity

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Microsoft’s Departing Privacy Chief Calls for Regulator Outreach
  • Nestle USA Settles Suit Over Job-Application Medical Questions
  • NY Attorney General James Affirms Hospitals Must Provide Access to Emergency Abortion Care
  • How Internet of Things devices affect your privacy – even when they’re not yours
  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.