Vyta

  • Why Vyta
    • The Vyta Team
    • Certifications
    • Sustainability
    • Awards
    • Vision, Mission & Values
    • Charity & CSR
  • Our Services
    • IT Asset Disposal Services
    • IT Equipment Resale and Revenue Return
    • Onsite Shredding Services
    • WEEE Recycling
    • Secure Data Destruction
    • Secure Collection
    • IT Asset Relocation and Deployment
    • IT Reseller Solutions
    • IT Services
  • DiskShred
  • Clients
  • Careers
  • News
  • Glossary
  • Contact

June 1, 2012

NHS Trust fined £325,000 following major data breach

Brighton and Sussex University Hospitals NHS Trust has been served with a Civil Monetary Penalty (CMP) of £325,000 following a serious breach of the Data Protection Act (DPA), the Information Commissioner’s Office (ICO) said today.

It comes after the discovery of highly sensitive personal data belonging to tens of thousands of patients and staff – found on hard drives sold on an Internet auction site in October and November 2010.

The data included

  • Patients’ medical conditions and treatments
  • Disability living allowance forms and children’s reports.
  • Documents containing staff details such as National Insurance numbers, home addresses, ward and hospital IDs, and information referring to criminal convictions and suspected offenses.

The data breach occurred when an individual engaged by the Trust’s IT service provider, Sussex Health Informatics Service (HIS), was tasked to destroy approximately 1000 hard drives held in a room accessed by key code at Brighton General Hospital in September and October 2010. A data recovery company bought four hard drives from a seller on an Internet auction site in December 2010, who had purchased them from the individual.

Although the ICO was assured that only these four hard drives were affected, in April 2011 a university contacted them and advise that one of their students had purchased hard drives via an Internet auction site. An examination of the drives established that they contained data which belonged to the Trust.

The ICO’s Deputy Commissioner and Director of Data Protection David Smith said:

“The amount of the CMP issued in this case reflects the gravity and scale of the data breach. It sets an example for all organisations – both public and private – of the importance of keeping personal information secure. That said, patients of the NHS in particular rely on the service to keep their sensitive personal details secure. In this case, the Trust failed significantly in its duty to its patients, and also to its staff.”

The Trust has now committed to providing a secure central store for hard drives and other media, reviewing the process for vetting potential IT suppliers, obtaining the services of a fully accredited ISO 27001 IT waste disposal company, and making progress towards central network access.

Link to article on the ICO webpage: http://www.ico.gov.uk/news/latest_news/2012/nhs-trust-fined-325000-following-data-breach-affecting-thousands-of-patients-and-staff-01062012.aspx

 

 

Filed Under: News

Search

Latest News

Vyta wins Sustainable Services Company of the Year

Vyta were awarded Sustainable Services Company of the Year at the Business Eye Sustainability Awards 2023.    … More...

Shortlist unveiled for NI Dealmaker Awards

Insider has revealed the companies, individuals and deals that have been shortlisted for the forthcoming Northern Ireland Dealmakers Awards. The awards reward the best-performing professional advisory firms based in Northern Ireland … More...

Vyta receives government approved top data security certification across UK and Ireland

We are delighted to announce that Vyta has been awarded the new ADISA ICT Asset Recovery Standard 8.0 and has been certified to distinction across all three sites in Great Britain, Republic of Ireland and Northern Ireland. This makes us the … More...

BUSINESS SECTORS

  • Data Centre Disposal
  • Financial Organisations
  • IT Service Companies

COMPUTER RECYCLING

  • Computer Recycling
  • Server Recycling
  • Laptop Recycling
  • Monitor Recycling
  • Printer Recycling

DATA DESTRUCTION

  • Secure IT Disposal Service
  • Blancco Wiping
  • Hard Drive Shredding
  • Tape Shredding
  • On Site Data Shredding
  • Detailed Asset Tracking and Reporting

IT SERVICES

  • Secure IT Disposal
  • IT Recycling
  • Secure Collection Services
  • IT Buyback Service
  • On Site IT Audit
  • Deployment Support

Get in touch with our team today

Vyta provide sustainable, secure and cost-effective solutions for the disposal of your end of life tech. Our solutions are key to protecting your data, controlling your IT assets, maximising value, managing corporate risk and meeting sustainability goals.

CONTACT US

info@vyta.com
+44 (0) 28 9084 7913

Vyta Great Britain
Vyta
Unit 28 Little Boyton Hall,
Roxwell, Chelmsford CM1 4LN, United Kingdom
Tel +44 (0) 33 0551 9983

Vyta Republic of Ireland
Vyta
Unit 66 Block 503, Greenogue Business Park
Rathcoole, Dublin D24 F300, Ireland
Tel +353 (0) 1257 3232

Vyta Northern Ireland
Vyta
Unit 1 Mallusk View, Central Park
Newtownabbey BT36 4FR, Northern Ireland
Tel +44 (0) 33 0551 9983

Privacy Policy | Cookie Policy | Modern Slavery Policy |
PAS2060 Qualifying Explanatory Statement
  • LinkedIn
  • Twitter

Copyright Vyta Ltd © 2023