- Security TWENTY
- Women in Security
The data protection watchdog the Information Commissioner’s Office (ICO) issued Northumbria Healthcare NHS Foundation Trust with an undertaking committing the trust to improving the way it handles patients’ information. This comes after the trust mistakenly sent five faxes containing information relating to the care of several patients to a member of the public. The faxes should have been sent to a social care team working at the trust but the wrong number was dialled.
After the first incident in March 2014, the trust took action to make sure its fax machines were only able to send information to pre-programmed numbers belonging to health service bodies. However, these measures were not adopted across all wards and four further faxes were sent to the same member of the public again, two months later. The ICO found that the trust failed to inform all wards about the original data breach and the actions that they should take to stop this mistake occurring again. The trust also initially made no effort to recover the documents once they were alerted to the problem.
ICO Head of Enforcement, Stephen Eckersley, said: “Many people will be surprised that we are still having to warn organisations about their use of fax machines. There are certainly more secure ways to send information, but if an organisation decides that a document must be sent in this way then they should have adequate measures in place to make sure the information is actually sent to the correct person. These measures must be adopted across all areas of the organisation. We are pleased that Northumbria Healthcare NHS Foundation Trust are now going to take effective action to make sure that a secure process is in place to keep information sent by fax secure.”
The undertaking commits Northumbria Healthcare NHS Foundation Trust to introducing clear procedures so that any data breaches reported to the trust are acted upon promptly and remedial measures are introduced across the organisation. Fax procedures, including the use of pre-programmed numbers to avoid mistakes, must be adopted across all wards to ensure adequate security standards are maintained across all wards. The trust must make these improvements by October 30.