NHS to face compulsory data protection audits
Government minister sets out plans for more pro-active approach to NHS data protection.

The NHS could soon face compulsory data protection audits, as the Government pushes ahead with plans to improve the health service's handling of patient data.
The plans were outlined by Simon Hughes, minister of state for justice and civil liberties, during an address earlier this week at the Information Commissioner's Office's (ICO) Data Protection Practitioner Conference.
Hughes, who only took up his current Government role two months ago, said the NHS is being targeted because of the large amounts of sensitive data it regularly handles.
"We have recently conducted a consultation on extending the ICO's powers of compulsory audit to NHS bodies. This requires secondary legislation which we plan to introduce before the summer recess so that the power can come into effect by the autumn," said Hughes.
"We have chosen the NHS as it is one of the largest data controllers in the UK, processing huge amounts of sensitive personal data on a daily basis."
The practice could also be extended to other industries, added Hughes, depending on how its work with the NHS goes.
"We will work closely with the ICO to monitor the effectiveness of these powers before considering whether we might extend them to other sectors that process large amounts of personal data in their day-to-day business," he continued.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The news will be music to the ears of data protection and privacy experts who have regularly rounded on the NHS for its haphazard approach to information security.
In recent years, this has resulted in various NHS Trusts being subjected to massive fines from the ICO for data protection breaches, with Brighton and Sussex University Hospitals NHS Trust receiving a record 325,000 penalty in June 2012.
At present, the onus is on organisations that suffer data breaches to report them to the ICO, so the introduction of compulsory audits could result in a marked uptick in the number uncovered.
Hughes also used his presentation to outline other changes to data protection enforcement the Government is mulling over, including the introduction of tougher sanctions against organisations that breach the Data Protection Act.
Companies that infringe on the Data Protection Act can find themselves subjected to fines of up to 500,000.
However, the introduction of custodial sentences for Data Protection Act rule breakers has also recently been mooted.
"Serious misuse of personal data by any sector causes significant distress and damage to ordinary citizens and undermines public trust in public institutions and business which in turn can undermine economic growth," said Hughes.
"That is why in the last few weeks we have begun to review the sanctions available for breaches of the Act so we can decide whether to increase the penalties as the law permits."
-
CyberOne appoints Microsoft’s Tracey Pretorius to its advisory board
News The threat intelligence leader will provide strategic guidance to CyberOne’s executive team
By Daniel Todd
-
CISA issues warning in wake of Oracle cloud credentials leak
News The security agency has published guidance for enterprises at risk
By Ross Kelly
-
NHS supplier hit with £3m fine for security failings that led to attack
News Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
By Emma Woollacott
-
The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles
Analysis A new report released by the DSIT revealed the UK’s cybersecurity sector generated £13.2 billion over the last year
By Solomon Klappholz
-
Cyber attack delayed cancer treatment at NHS hospital
News A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
By Nicole Kobie
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag
By George Fitzmaurice
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway service
News Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service
By Solomon Klappholz
-
Major incident declared as Merseyside hospitals hit by cyber attack
News The incident, which has led to cancelled appointments, is just the latest in a series of attacks on healthcare organizations
By Emma Woollacott
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott