Oh no! and another one

That-paper-which-now-looks-really-heavyweight-in-comparison-to-all -the-freebie-showbiz-gossip-rags reports tonight that the personal details of 160,000 children have been lost at a London hospital in a fresh blunder over confidential information.

A computer disc containing the data was sent to St Leonard’s Hospital in Hackney but failed to reach the right department - even though it was signed for by hospital staff. The disc contained the names, dates of birth and addresses of 160,000 children and there were fears the information could be enough for criminals to create fake identities. The blunder occurred when the disc was sent by courier to the Hackney hospital by BT, which operates the NHS’s IT system, on 14 November. It is believed the courier company used by BT did not check that it was signed for by the correct person and the disc never reached its intended destination in the IT department.

A spokeswoman for City and Hackney Primary Care Trust, which runs St Leonard’s Hospital, said “BT couriered a fully encrypted disc containing patient information to City and Hackney PCT. “It was not received by the named recipient, and attempts by the PCT to find the disc have so far failed. All deliveries of personal information have been suspended in light of the breach.” BT today called for parents to remain calm over the latest incident. A spokesman said: “Patients should not be concerned because BT uses the highest levels of security to safeguard the data in its care.

[Er… short of making sure that it or its representatives only hands over the data to the person who is supposed to receive it?]

“All NHS data sent by disc is fully encrypted to industry standards. We apply stringent controls in managing the complex encryption pass phrases necessary for unlocking the data. In this instance the encryption pass phrase would only have been released after one of two named individuals confirmed receipt. This was not confirmed so the encryption pass phrase has not been issued.

Ah… we can relax then. (Though the Standard worries that even 256-bit encryption has recently been shown by researchers to be crackable in two weeks...)

All this attention on missing data is not unhelpful in drawing ordinary people’s attention to a) the volume and frequency of personal data transfers and b) the potential value of their personal data. That’s not a bad thing - probably more effective than a fancy public service advertising campaign.  Ruth Carnall, chief executive of NHS London, has asked for an independent review of all NHS data transfer in London. WIBBI all these emergency reviews encompassed a really citizen-centric cost-benefit analysis of centralised data systems. 

Published by Ruth Kennedy on 13/12/07 at 5:48pm

Comments

  1. Ahem. Yes, yet another “isolated incident”. They seem to be about as isolated as copies of free newspapers on the evening tube.

    Reply by  on  12/14/07  at  12:17 am

Name:

Email:

Location:

URL:

Smileys

Remember my personal information

Notify me of follow-up comments?

Submit the word you see below:


This comment section is moderated in the interests of a civil, relevant and productive brainstorm. Divergence, disagreement and passion is welcome. We'll try to exclude flaming or spam and reserve the right to edit or delete anything we consider offensive, actionable or inappropriate to the subject.

Ideal Government

Let's say what we want from e-enabled government. Let's observe government first-hand. Let's say "Wouldn't It Be Better If" (WIBBI). Become an ethnographer of bureaucracy today! It beats getting frustrated with public services.

Categories

Comment

Anyone is free to comment. Or mail with an article if you want to be an author. I'll post it up and send you a password. This whole thing is supported by Kable.

Sponsor

Authors with password: click here to post

BLOGS etc
Bruce Schneier
Jeff Jonas, IBM
Jerry Fishenden
Headshift
Ian Brown
Kim Cameron, MS
Matthew Somerville
Public strategist
Richard Allan
Robin Wilton, Sun
Sam Smith
Stefan Brands, Credentica
Toby Stevens, EPG
Whitehall Webby
Will Davies

CRITICAL FRIENDS
Action on Rights for Children
Big Opt-Out
FIPR
Light blue touchpaper
NHS23
No2ID
Perfect e-democracy
Spy blog
Verified Voting

PERTINENT ART
ACLU privacy pizza
Very model of a notional identity
Swizz of the cards
Handelsman: NSA wiretaps
Handelsman: US spying
Wearcam
Googlezon
Three dead trolls
Stefanos Pantagis

ESSENTIALS

Cluetrain Manifesto
RAE Dilemmas of Privacy
NCC Playlist for public services
Sousveillance
Stefan Brands' book summary
Ross Anderson book

Engelbart Mother of all demos
OTHER ID/SECURITY
ID theft spy
Planet Identity
Pledgebank for refuseniks
Home Office ID cards
Credentica
Ann Cavoukian, Ontario


MYSOCIETY & SAM'S STUFF
MySociety/
They work for you
Fax your MP
DirectionlessGov
Comment on This

...and the original
Stand ID card campaign
PUBLIC SERVANT BLOGS
David Milliband
Read my day
Lynne Featherstone MP
David Copperfield - police
Roy Taylor, Kingston
ReadmyDay
Bill Sticker - parking
Ealing Magistrate
Cllr Andrew Brown
Reynolds/Ambulance

MAPS MASHUPS WE LIKED...
Plymouth Schools
Ben's UK speed cameras
5-day weather forecast
House sale prices
g-Traffic info
Place-O-Pedia

For Google maps mashups see
Googlemapsmania blog

ADVISERS, NGOs
Advice now
Advice Services Alliance
Advice UK
Citizens' Advice


Old stuff
RSS in government blog

Authors

Member List

Sign up for new articles

Locations of visitors to this page

Copyright

Creative Commons License - Some Rights Reserved Protect your Bits. Support ORG. Open Rights Group

Designed by...

visit ScoreCommunications Ltd

Statistics

This page has been viewed 388026 times

Entries: 1523 | Comments: 2374 | Trackbacks: 206
Most Recent Entry: 05/16/2008 10:36 pm
Most Recent Comment: 05/16/2008 11:49 am

Members: 185 | Logged in: 0 | Guests: 38
Most recent visitor: 05/17/2008 03:27 am
Most visitors ever: 443 on 10/12/2005 02:21 pm