Nigel Harper, 14 September 2009
The ICO has found Grampian NHS in breach of the Data Protection Act after receiving reports of three separate incidents involving data security. A senior nursing manager inappropriately emailed 50 staff with sensitive personal details relating to a patient. Lack of secure storage on the labour ward enabled someone to remove the personal details of 200 patients from a confidential waste sack. Finally, a laptop containing details of patients in the gastroenterology clinic was stolen from a locked office. The laptop was not encrypted and contained personal data on 1500 patients with a particular disease.
Source: Information Commissioner's Office (pdf)