DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: Scandal of computer snooping by public servants includes medical information

Posted on January 5, 2011 by Dissent

Jack Blanchard reports the results of a freedom of information request on police in Yorkshire, UK. Revelations concerning non-medical incidents are posted to PogoWasRight, but here are the medically related incidents:

The cases include… a doctor in Doncaster caught looking at a colleague’s medical records.

At one hospital, in Rotherham, a cleaner was caught only last month accessing the private medical files of a friend to determine that she had recently had an abortion. That disciplinary case is still proceeding.

A cleaner was able to access medical files? Who are they disciplining? I hope it’s not just the cleaner but whomever is responsible for securing the files.

At another hospital, in Sheffield, a receptionist gathered patients’ personal contact records and used them for a second job as a market researcher.

[…]

Meanwhile nine NHS trusts across Yorkshire have revealed mostly isolated cases of staff being reprimanded for similar offences, including primary care trusts in Wakefield and Barnsley, and hospitals trusts in Barnsley, Goole, Mid-Yorkshire, South Tees and Rotherham.

The highest number of cases was at Doncaster and Bassetlaw Hospitals NHS Trust, where six members of staff have been reprimanded over the past three years. However, the trust insisted only three of the cases should be classed as formal disciplinary matters.

In one such case, a nurse accessed the private medical test results of her daughter’s father. She was dismissed but reinstated on appeal. In another, a clerk received a written warning after looking up her brother’s test results.

A spokeswoman for the trust said: “We take data security very seriously and have a number of means of ensuring that patients’ personal data is not accessed inappropriately. All six cases of inappropriate access to medical records related to an individual’s colleague, partner, or relative – and while this is inexcusable, it does not indicate misuse of the millions of patient records we hold.”

There were five cases at Sheffield Teaching Hospitals Trust, ranging from the relatively innocent – a staff member wanting to send a birthday card to a sick relative, and checking which hospital ward they were on – to the sinister, as in the case of staff member accessing the medical records of an ex-partner’s new partner. Three of the staff members involved received final warnings, and two were dismissed.

Read more in the Yorkshire Post.

In a related news report in the Gazette & Herald by Julie Hayes on data protection breaches by North Yorkshire police, there was also this intriguing statement:

North Yorkshire and York NHS Trust, who had a similar FOI request, said it had not disciplined any of its staff for illegally or inappropriately accessing the personal data of a member of the public over the past three years.

Does that mean that they had no incidents, detected no incidents, or that they had detected incidents but just didn’t discipline anyone? And what about incidents where staff may have accessed personal data of a fellow member of the staff? I’ve emailed the reporter to request clarification.

No related posts.

Category: Health Data

Post navigation

← Data Stewardship: Managing Personally Identifiable Information in Electronic Student Education Records
Experts Forecast Top Seven Trends in Healthcare Information Privacy for 2011 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)
  • Nigerian National Pleads Guilty to International Fraud Scheme that Defrauded Elderly U.S. Victims
  • Nova Scotia Power Data Breach Exposed Information of 280,000 Customers
  • No need to hack when it’s leaking: Brandt Kettwick Defense edition
  • SK Telecom to be fined for late data breach report, ordered to waive cancellation fees, criminal investigation into them launched
  • Louis Vuitton Korea suffers cyberattack as customer data leaked
  • Hunters International to provide free decryptors for all victims as they shut down (2)
  • SEC and SolarWinds Seek Settlement in Securities Fraud Case

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t
  • Oregon Amends Its Comprehensive Privacy Statute

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.