Grampian NHS to improve security after breaching the Data Protection Act

Nigel Harper, 14 September 2009

The ICO has found Grampian NHS in breach of the Data Protection Act after receiving reports of three separate incidents involving data security. A senior nursing manager inappropriately emailed 50 staff with sensitive personal details relating to a patient. Lack of secure storage on the labour ward enabled someone to remove the personal details of 200 patients from a confidential waste sack. Finally, a laptop containing details of patients in the gastroenterology clinic was stolen from a locked office. The laptop was not encrypted and contained personal data on 1500 patients with a particular disease.

Source: Information Commissioner's Office (pdf)