Medical practice loses 8,000 patient details on unencrypted USB
Data security within the NHS has been highlighted again today as the Information Commissioner’s Office revealed yet another incident of data loss.


A Welsh medical practice has been named and shamed by the Information Commissioner's Office (ICO) for breaching the Data Protection Act.
Back in March, a staff member from Lampeter Medical Practice downloaded a database containing 8,000 patient details onto an unencrypted USB stick before sticking it in the post.
It may have been sent recorded delivery but the USB stick never made it to its final destination the Health Board's Business Service Centre and has now been accepted as lost.
"It is unnecessarily risky to download 8,000 personal details on to a memory stick," said Sally-Anne Poole, enforcement group manager at the ICO, in a statement.
"It is imperative that staff are made fully aware of an organisation's policy for securing personal data and any portable device containing personal information should always be encrypted to prevent it being accessed in the event of loss or theft."
The head of the practice, Dr Rowena Mathew, has admitted the fault and signed a declaration to the ICO saying from now on she will ensure all portable devices are encrypted, take all physical precautions to keep data protected on such devices and train all staff to know what security policies are in place.
This latest incident has again highlighted the issues within the NHS when it comes to data breaches.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
During the InfoSecurity conference back in April, the deputy commissioner of the ICO, David Smith, claimed the NHS was the worst offender when it came to data security and was responsible for a third of all reported data breaches in the UK over the past two years.
In his keynote speech, Smith said: "[Many] would say 'this is confidential health information, surely they should be better than this?' but this is the largest employer outside of the red army and this is hardly a command and conquer structure."
"There is a real, real, real challenge there but it is worrying that still we see these losses," he said.
Jennifer Scott is a former freelance journalist and currently political reporter for Sky News. She has a varied writing history, having started her career at Dennis Publishing, working in various roles across its business technology titles, including ITPro. Jennifer has specialised in a number of areas over the years and has produced a wealth of content for ITPro, focusing largely on data storage, networking, cloud computing, and telecommunications.
Most recently Jennifer has turned her skills to the political sphere and broadcast journalism, where she has worked for the BBC as a political reporter, before moving to Sky News.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
TikTok to open first European data centre in Ireland
News The move could signify a desire to shift its operations away from the US as well as secure its position in the European market
By Sabina Weston
-
MPs in a muddle over GDPR and storing voters' personal data
News Labour MP Chris Bryant says his staff were told to delete constituents' data
By Bobby Hellard
-
Trump resort will not be charged for breaching data laws
News Presidential hopeful's Scottish golf course failed to register under the Data Protection Act for four years
By Adam Shepherd
-
Banks urged to share data but warned over security
News Experts voice concern over security of open API recommendations
By Rene Millman
-
EU centralises European open data through one portal
News Open Data Portal will enable public sector bodies to share information
By Rene Millman
-
Experts question sheer scale of data storage required by Snooper's Charter
News Who will foot bill for physical infrastructure to house UK's browsing histories?
By Jane McCallion
-
Snapchat's T&Cs update could put user data at risk
News Kaspersky said giving the service permission to share pictures with third parties could lead to a serious breach of privacy
By Clare Hopping
-
Transport Systems Catapult launches data sources catalogue
News Intelligent Mobility Data Index could push forward smart transport innovation in the UK
By Caroline Preece