Doctor and patient
Doctors are breaking data protection rules by carrying unencrypted data on USB devices
R E L A T E D   C O N T E N T
ADVERTISEMENT

NHS clinicians risking patient data

Doctors carrying unprotected USB sticks with confidential patient information

Phil Muncaster, Computing 04 Sep 2008
ADVERTISEMENT

UK clinicians are putting patient data at risk by carrying information on unprotected USB sticks, according to a new report.

Research by two clinicians at a London teaching hospital published in Health Service Journal found that 92 out of 105 doctors carried memory sticks with them.

But only five out of the 79 USB devices which held confidential patient information were password protected.

This contravenes data protection rules and exposes the NHS to the kind of data loss scandal that has affected several central government departments in recent months.

Matthew Brown, vice president of products at data loss prevention firm Workshare, said that the first step towards correcting the problem should be an "information audit" to gain insight into how data flows in and out of the organisation.

This should be complemented by technologies such as encryption and access controls, he added.

"Implementing policies is not enough. You cannot simply stop employees from downloading information onto USB devices as they will just find a way around it to do their job," said Brown.

"The NHS must proactively look at how its information is being used, and take steps to ensure that risks are stopped before they have a chance to happen."

Neil Yeomans, partner in the IT security practice at consultancy firm Deloitte, explained that the Department of Health has already issued information governance standards and guidelines, and warned that unintended breaches can be as damaging as criminal acts.

"It is clear that the solution to managing such a risk requires flexibility and is as much about people and culture and changing behaviour as it is about process and technology," he added.

See also:

Inside a prisonA Home Office contractor has lost a memory stick containing data on all UK prisoners  22 Aug 2008
WhitehallTories critical over government waste  18 Jul 2008
Cabinet Office signData will be encrypted, staff trained and privacy impact assessments carried out on all projects  25 Jun 2008
Picture of a gavelA third of the country's legal firms are reliant on onsite archiving methods  04 Jun 2008
Picture of Symantec logoDeal will help boost buyer's data loss prevention business  03 Dec 2007

All IT Careers and skills
Tags: Nhs, Government, Legislation-and-regulation, Security-technology, Management, Public-sector, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities