NHS Data Security Incidents Top List Again

NHS Data Security Incidents Top List Again

The UK’s healthcare sector once again accounted for the largest number of data security incidents in Q3 2016, although the charity, education and finance sectors revealed a bigger jump in incidents from the previous quarter, according to the ICO.

The UK’s privacy watchdog claimed in its quarterly review for the period July-September 2016 that reported incidents for healthcare jumped over 3% from the previous quarter.

So-called “cyber incidents” stood at 74 for the period, while loss or theft of unencrypted devices was 65. Other reported incidents listed included failure to redact data (11), and failure to use BCC when emailing sensitive data (18).

In total, the ICO reported 239 incidents for the period, significantly higher than the next most affected sectors – local government (62) and “general business” (56).

However, it had the following by way of explanation:

“The health sector once again accounted for the most data security incidents. This is due to incident reporting being mandatory, the size of the health sector and the sensitivity of the data processed.”

It’s likely that we’ll get a clearer picture of how well or badly the NHS is doing on data security versus other sectors when the European GDPR comes into force, bringing with it mandatory 72-hour data breach notifications.

It’s notable that, despite lower overall numbers, the volume of incidents in the education (18%), finance (18%) and charity (21%) sectors all grew by more than healthcare.

The ICO advised organizations looking for quick wins to prevent such incidents occurring to disable autocomplete on users’ email address bars – reducing the likelihood of sending emails in error – and to clarify policy so that staff better understand when and when not to use encryption.

Ransomware was a major scourge for the UK’s healthcare organizations in 2016.

Nearly half (47%) of NHS Trusts in England claimed to have fallen victim over the past 12 months, according to an FoI request from NCC Group in August.

In one of the most high profile cases, North Lincolnshire and Goole NHS Foundation Trust’s IT systems were taken offline for several days in autumn 2016 after an infection, forcing some patients to be moved elsewhere.

Source: Information Security Magazine