NHS Trust hit with £175,000 data breach fine
The Information Commissioner's Office claims latest breach was entirely avoidable.

A Torquay-based NHS health Trust has been fined 175,000 by the Information Commissioner's Office (ICO) after sensitive details of more than 1,000 staff were posted on its website.
Information about employees working at Torbay Care Trust was posted online in a spreadsheet in April 2011.
The leaked information included National Insurance numbers, dates of birth, as well as the equality and diversity responses of 1,373 of the Trust's employees.
There will be no effect on budgets for staff, or health and social care services.
The document remained online for 19 weeks until it was discovered by a member of the public,
In a statement to IT Pro, Torbay Care Trust blamed the breach on an "organisational issue", insisting there was no evidence the data was accessed by anyone other than the person who reported it.
The NHS Trust said it was disappointed by the ICO's decision to issue a fine, but confirmed it plans to pay up.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Andrew Farnsworth, chief executive of Torbay Care Trust, told IT Pro in a statement: "We accept the findings and will be taking advantage of the early payments discount to minimise the financial impact of the fine.
"Provision was made to potentially pay such a fine, so there is no effect on budgets for staff, or health and social care services," he said.
The trust has also introduced measures to prevent similar breaches happening in future, added Farnsworth.
"It is important to clarify this information did not contain any clinical or patient data. Neither have we received any evidence to suggest the information has been used inappropriately," he added.
In a further statement, Stephen Eckersley, head of enforcement at the ICO, said the data could have been used by identity fraudsters.
"The fact this breach was caused by Torbay Care Trust publishing sensitive information about their staff is extremely troubling and was entirely avoidable," he said.
"While organisations can publish equality and diversity information about staff in an aggregated form, there is no justification for unnecessarily releasing their personal information."
-
The Era of Hybrid Cloud Storage
Whitepaper
By ITPro
-
Women show more team spirit when it comes to cybersecurity, yet they're still missing out on opportunities
News While they're more likely to believe that responsibility should be shared, women are less likely to get the necessary training
By Emma Woollacott
-
NHS supplier hit with £3m fine for security failings that led to attack
News Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
By Emma Woollacott
-
Cyber attack delayed cancer treatment at NHS hospital
News A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
By Nicole Kobie
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway service
News Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service
By Solomon Klappholz
-
Major incident declared as Merseyside hospitals hit by cyber attack
News The incident, which has led to cancelled appointments, is just the latest in a series of attacks on healthcare organizations
By Emma Woollacott
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott