ICO hits London NHS Trust with £60,000 fine
Data protection watchdog describes latest breach as "clearly preventable".
The Information Commissioner's Office (ICO) has fined St George's Healthcare NHS Trust 60,000 for sending a patient's medical details to the wrong person.
The Trust sent out two letters in May 2011 to the patient's former address, despite having the person's up to date contact details already on file.
The patient's correct address had been logged on the national care records service, NHS Spine, in June 2006.
Stephen Eckersley, the ICO's head of enforcement, said the breach was "clearly preventable".
"This is the fourth monetary penalty we have issued to the NHS in the past two months," he said.
"It is vital that these organisations make sure they have the necessary measures in place to keep patients' details secure."
In a statement to IT Pro, a Trust spokesperson said the breach had been reported to the ICO as soon as it was discovered.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We launched an immediate investigation and have introduced a number of measures to prevent similar incidents in the future, including clearer documentation and additional training for staff," said the statement.
"We have also made improvements to our information systems to ensure that staff always have access to the most up to date patient contact details."
-
AI layoffs could spark a new wave of offshoringNews Analysts expect a wave of rehiring next year in the wake of AI layoffs. That may sound like good news for workers, but it'll probably involve offshoring or outsourcing.
-
Hackers are using these malicious npm packages to target developers Windows, macOS, and Linux systemsNews Security experts have issued a warning to developers after ten malicious npm packages were found to deliver infostealer malware across Windows, Linux, and macOS systems.
-
23andMe 'failed to take basic steps' to safeguard customer dataNews The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so farNews A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practicesNews Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attackNews Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
Cyber attack delayed cancer treatment at NHS hospitalNews A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway serviceNews Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service
-
Major incident declared as Merseyside hospitals hit by cyber attackNews The incident, which has led to cancelled appointments, is just the latest in a series of attacks on healthcare organizations
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuseNews The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data