The University College London Hospitals NHS Foundation Trust (UCLH) has signed an undertaking with the Information Commissioner’s Office after an unencrypted flash drive with patients’ sensitive personal information was discovered in a training room. Robert Naylor, Chief Executive of University College London Hospitals NHS Foundation Trust (UCLH) indicated that the ICO was notified by Brighton and Sussex…
Category: Health Data
UK: Borough of Poole agrees to strengthen data protection following a series of misdirected faxes
The Borough of Poole has signed an undertaking with the Information Commissioner’s Office as a result of faxing errors. According to the undertaking, signed by John McBride, Chief Executive of the Borough of Poole, faxes containing personal data had been sent to the same incorrect fax number on three separate occasions in 2010. On the first…
Southwest Ambulance reports data breach
Ken Alltucker reports: A former Southwest Ambulance employee took 581 patient records that included the names, financial and medical information from those customers. Southwest Ambulance recovered the records and notified affected customers about the breach of their private medical records. The Mesa-based company said it recently learned the employee took the records after a property…
Ca: Security breach of kids' info raises alarm
Jennifer O’Brien reports: A memory stick containing records of 4,500 kids has gone missing from a speech and hearing clinic at UWO, a thumb-sized example of how ever-smaller digital technology is heightening security risks. Included among the records on the tiny storage device are 11 years worth of names, addresses, phone numbers, birthdates, doctor information,…
MA: Computer access breach exposed UMass Memorial pay stub data
Lee Hammel reports: Personal pay stub information of some UMass Memorial Healthcare employees was subject to unauthorized access for five months. The organization learned March 10 that at 10 kiosks where employees could view their pay stub information, and also at shared workstations, subsequent users were able to access the information of previous users, according…
GSK involved in Epsilon breach; context raises concerns
The Epsilon breach, covered extensively on DataBreaches.net, just got worse. Yesterday, 12 days after they were notified of the breach by Epsilon, GlaxoSmithKline sent out notifications. Emphasis added by me, below: From: “[email protected]” <[email protected]> Date: April 16, 2011 1:30:36 PM EDT To: [redacted] Subject: An Important Message from GSK Consumer Healthcare Reply-To: “[email protected]” Dear GlaxoSmithKline…