TOTAL: {[ getCartTotalCost() | currencyFilter ]} Update cart for total shopping_basket Checkout

The Privacy Advisor | UK—Scottish Health Board Ordered To Improve After Personal Details Left Abandoned Related reading: UK—ICO identifies its priorities for 2012

rss_feed

""

""

The Information Commissioner's Office (ICO) has ordered Grampian Health Board (NHS Grampian) to improve its data-handling practices following six data breaches within a 13-month period where papers containing sensitive personal data were left abandoned in public areas of the hospital and one case where the details were found at a local supermarket. All papers were returned to staff, with the final incident occurring on 28 March.

ICO investigations found that the same mistakes continued to occur because NHS Grampian failed to have an information register identifying the personal information held and the department responsible for looking after it. This gap in its procedures resulted in the organisation failing to take sufficient remedial action.

The ICO previously alerted NHS Grampian to this oversight during an audit carried out in December 2011; however, the organisation failed to act.

The ICO’s enforcement notice requires the organisation to produce a high-level information asset register by 22 June 2015. The register must explain which areas of the organisation are responsible for keeping the personal information it handles secure. NHS Grampian must provide a progress report showing how these improvements are being made by 31 March 2015 and confirm completion by 29 June 2015.

The enforcement notice is available here.

Comments

If you want to comment on this post, you need to login.