Related Stories

  • Competition will drive down NHS IT costs, say Conservatives
    The Conservative party is to reveal plans to cut NHS IT spending by scrapping the government's planned central database for medical records.
  • A breach a day will keep the patients away - information security in the health sector
    The NHS web is made up of different management structures, different information security needs, and different budgets. Cath Everett looks for a medicine that will cure information security worries across the healthcare board
  • Healthcare IT professionals mistrustful of cloud security
    Confirming the outlook of NHS IT professionals at the Mobile and Wireless Healthcare conference in Birmingham late last month, a survey due to be published next week will show that health professionals are highly sceptical about migrating to the cloud, owing to serious security worries.
  • Keynote Theatre Agenda
    The 2010 Keynote programme will address the security issues and pressures that organisations face in an increasingly mobile and global working environment. Leading security experts, industry innovators and speakers from the end-user community who will provide expert analysis, real-life case studies, strategic advice and predictions.
  • Real life security in the NHS revealed
    For Tracy Andrew, his military background stands him in good stead for dealing with the real-world IT security issues he and his team encounter when dealing with the sharp end of technology problems that staff in three health trusts experience.

News

Doctors encourage patients to opt-out after NHS data losses

04 January 2008

A letter for patients to use to opt-out of the English NHS’s nascent central database of medical records, written by doctors and medical privacy campaigners, has reached more than 200 000 downloads. Meanwhile, nine NHS trusts have admitted data breaches, in the wake of HM Revenue and Customs’ loss of 25 million people’s data.

The standard letter points out that the government is asking GPs to transfer medical data without patients’ individual consent, against BMA policy. “I do not believe that such a large database, with so many staff users, can be regarded as secure,” it continues, and quotes 93C3, a special code which records the patient’s refusal to consent to the national shared electronic record.

Helen Wilkinson, founder of TheBigOptOut.org campaign which hosts the letter, says interest has picked up since the HM Revenue and Customs disaster, although the letter was first uploaded in November 2006. Following that, the Department of Health told NHS trusts to send personal data encrypted and by courier. “In the past, we can assume it was sent unencrypted and by normal post,” she said.

Wilkinson added that 400 000 people working with the health service, including staff at chemists, already have access to the existing NHS Personal Demographic Service, which includes names and addresses in addition to ex-directory numbers and next of kin. As the system is not publicised, she believes this puts at risk victims of domestic violence and others with a need for privacy. People can opt-out only if police or social services request it.

During the Christmas holidays, nine English NHS trusts admitted they had lost personal data on patients. The Department of Health said it did not have figures on how many patients were affected, but the Sunday Mirror newspaper reported that London’s City and Hackney primary care trust lost a CD holding the names and addresses of 160 000 children.

The other trusts reporting breaches were Bolton Royal Hospital, Sutton and Merton, Sefton Merseyside, Mid-Essex Care Trust, Norfolk and Norwich, Gloucester Partnership Foundation Trust, Maidstone and Tunbridge Wells – which suffered two such incidents – and East and North Hertfordshire.

 

This article is featured in:
Data Loss

 

Comment on this article

You must be registered and logged in to leave a comment about this article.