DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

UK: NHS Grampian out of compliance with Data Protection Act – again.

Posted on November 19, 2014 by Dissent

From the Information Commissioner’s Office:

The Information Commissioner’s Office (ICO) has ordered Grampian Health Board (NHS Grampian) to take action to make sure patients’ information is better protected.

The warning comes after six data breaches within a thirteen month period where papers containing sensitive personal data were left abandoned in public areas of the hospital and one case where the information was found at a local supermarket. All of the papers were returned to staff, with the final incident occurring on 28 March 2014.

The ICO’s investigation found the same mistakes continued to occur because NHS Grampian didn’t have an information register identifying the personal information held and the department responsible for looking after it. This gap in their procedures resulted in the organisation failing to take sufficient remedial action. The ICO previously alerted NHS Grampian to this oversight during an audit carried out in December 2011, but the organisation failed to act.

This is not the first time Grampian NHS has been required to sign an undertaking. In September 2009, PHIprivacy.net reported that Grampian had signed an undertaking following three separate incidents: a nursing manager had inappropriately emailed 50 staff with sensitive personal details relating to a patient, lack of secure storage on the labor ward enabled someone to remove the personal details of 200 patients from a confidential waste sack, and a laptop with unencrypted details of 1,500 patients in the gastroenterology clinic was stolen from a locked office.

In 2012, this site noted a report that 50 patient records had gone missing or were lost in the previous year. At that time, the public did not know about the consensual audit Grampian had undergone or its findings.

The ICO’s current enforcement notice requires Grampian to produce an overarching high level information asset register assigning owners in line with best practice, by 22 June 2015. The register must explain which areas of the organization are responsible for keeping the personal information they handle secure. Grampian must provide a progress report showing how these improvements are being made by 31 March 2015, and confirm completion by 29 June 2015.

Given its past history, Grampian should consider itself fortunate that there was no monetary penalty.


Related:

  • The "reincarnation" of BreachForums: A cyberdrama in three acts
  • It's been a strange week, Part 2. An open letter to Twitter.
  • Fraudster's fake data breach claims should remind media to be careful what we report
  • DHS Cyber Safety Review Board to Conduct Second Review on Lapsus$
  • Established dark web market disappears suddenly, leaving vendors and customers scrambling
Category: Uncategorized

Post navigation

← Identity thieves hit 2 Metro Detroit hospitals
Staples Confirms POS Malware Attack →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges
  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.