DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: Patients’ details found in public bins, University Hospitals Coventry & Warwickshire signs undertaking

Posted on October 27, 2011 by Dissent

University Hospitals Coventry & Warwickshire NHS Trust breached the Data Protection Act by losing patients’ medical information on two separate occasions, the Information Commissioner’s Office (ICO) said today. The ICO’s action and press release was intended to make the point that even “small” breaches in terms of numbers are important and can indicate a pattern or problem that requires remedial action.

In February, records relating to the treatment of 18 patients were found in a communal waste bin at a residential apartment block. The information had been taken home by a member of staff and accidentally disposed of in a public bin along with other rubbish.

In a second incident – which took place in May – a member of the public discovered details relating to a patient’s sensitive medical procedures and test results which were allegedly found in a bin outside Coventry University Hospital. That incident was reported in the media and was previously mentioned on this blog.

The ICO’s investigation found that the trust’s policies and procedures on the use of personal information were not sufficient. During the Commissioner’s investigation, concerns were also raised about the delivery and collection point for patient notes at one of the Trust’s hospitals.

Sally Anne Poole, Acting Head of Enforcement said:

“The fact that the trust lost sensitive personal information on two separate occasions within the space of two months is clearly not acceptable. Organisations across the health service must recognise that they hold some of the most sensitive personal data available and that it must never be disposed of in the same way as routine household waste.”

The ICO has now ordered the trust to review its policies to make sure that personal information is adequately protected and disposed of. Staff will be trained to follow the trust’s updated guidelines and new procedures governing the handling of clinical data. The hospital will also carry out routine monitoring to ensure that procedures are being followed.


Related:

  • Large medical lab in South Africa suffers multiple data breaches
  • From bad to worse: Doctor Alliance hacked again by same threat actor (1)
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • NHS providers reviewing stolen Synnovis data published by cyber criminals
  • HIPAA, but for non-Covered Entities?
Category: Health Data

Post navigation

← Dump of accounts from nationmultimedia.com by @_V4ND
Survey says: Data Breaches Can Cause Lasting and Costly Damage to the Reputation of Affected Organizations →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Leavenworth, Kansas cyberattack disrupts city services
  • They’ve escaped a lot of media attention, but Anubis RaaS is a threat to the medical sector
  • “In the most expedient time possible…”
  • Portugal updates cybercrime law to exempt security researchers
  • LockBit 5’s “new secure blog domain” infra leaked already
  • NL: Nuenen accidentally leaks addresses of 1,000 asylum center opponents
  • Ex-teen hackers warn parents are clueless as children steal ‘millions’
  • UK Government Considers Computer Misuse Act Revision
  • Japan issues arrest warrant against teen suspected of cyberattack using AI
  • How old is the average hacker? What does a new research report suggest? (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.