View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

UK ICO fines NHS Surrey for loss of patients’ records

Claimed to be one of the most serious breaches witnesed by the ICO.

By CBR Staff Writer

The UK Information Commissioner’s Office (ICO) has fined NHS Surrey £200,000 over loss of secret data of more than 3,000 patients.

According to the watchdog, thousands of children’s patient records were discovered on a second-hand NHS computer that was auctioned on an online auction site.

Regulators reported that the NHS Surrey failed to ensure that a data destruction firm had correctly disposed of the records.

ICO head of enforcement Stephen Eckersley said the facts of the breach are truly shocking.

"NHS Surrey chose to leave an approved provider and handed over thousands of patients’ details to a company without checking that the information had been securely deleted," Eckersley said.

"The result was that patients’ information was effectively being sold online.

"This breach is one of the most serious the ICO has witnessed and the penalty reflects the disturbing circumstances of the case," he said.

Content from our partners
An evolving cybersecurity landscape calls for multi-layered defence strategies
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways

During the course of investigation, ICO found that the data destruction firm had offered free disposal of the computers in return for the sale of salvageable stuffs.

Investigation also involved recovering 39 computers that were sold by the data destruction firm, which had sensitive records on three of the hard disks.

ICO also ruled that the firm assured to crush the computer hard disks through an industrial guillotine, while NHS Surrey failed to observe the destruction process and did not have a contract ready with their new provider that explained the legal requirements of the data destruction.

NHS Surrey was decommissioned in March 2013 after some of their legal responsibilities were transferred to the NHS Commissioning Board.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU