image: Notebook
Notebooks containing confidential data stolen

Organisations lose confidential data

Experts warn that password security is not sufficient

Written by Andrea-Marie Vassou

Two notebooks containing confidential information about NHS patients and council staff have been stolen.

One was owned by the Dunstan Medical Centre in Bolton, and contained medical details of patients.

The other belonged to St Edmundsbury Borough Council, and contained bank and national insurance details for 1,380 people on the council's payroll. Both were stolen in residential burglaries.

When Computeractive contacted the two organisations both said they had informed the people whose data was stolen, and that the notebooks had multiple password security systems in place.

A representative for Bolton Primary Care Trust EHI Primary Care, which oversees Dunstan medical centre, told Computeractive: "Our policies were already up to date but we have learnt our lessons and will continue to revise them."

Following the breach it sent out a reminder to staff and GP practices about security and confidentiality when using notebook computers. This included providing users with appropriate access protection such as passwords. It also said that notebooks should not be left unattended in public places or in cars.

However, according to the security company PGP Corporation, these security measures are not enough.

Jamie Cowper, a representative for PGP, said: "It is disturbing that two organisations handling such sensitive information on a daily basis still rely on simple passwords for data security."

He also said that locking away laptops when not in use is ineffective when dealing with today's threats.

"Locks can be broken and passwords can be hacked. If Bolton Primary Care Trust and St Edmundsbury BC had implemented an enterprise-wide encryption policy, employees could take laptops off-site with the assurance that, even if their device was lost or stolen, the data would remain inaccessible."

The Information Commissioners Office (ICO) would not comment on the two cases individually, but agreed that encryption was a key part of the security process. It said that any lost or stolen notebooks that were reported to be unencrypted could be subject to enforcement powers. The ICO's powers allow it to issue organisations with a warning and, if it conducts an inspection and finds that data is not being adequately protected, take the organisation to court.

A representative for the ICO told Computeractive: "Organisations that process personal information have an obligation to handle that information in line with the eight data protection principles, one of which is that it must be kept securely.

"Customers, clients and employees should be able to feel confident that their personal information is protected," she added.

Neither organisation would comment on why they did not use encryption to secure their notebooks.

Tags:

Further reading

Information Commissioner’s Office to investigate Marks and Spencer’s security procedures

Details of 26,000 M & S employees could be at risk   More...

Related articles

Information Commissioner gets tough on data security

Losing a laptop is 'gross negligence', Thomas tells Lords committee   More...

vnunet.com analysis: Information Commissioner slams UK privacy practices

Chief executives urged to raise their game   More...

FSA issues first fine for lax security

Organisation cracks down on data protection   More...

M&S rapped for Data Protection breach

This is not just data loss – this is your data loss   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

08 Jul 2008

3.67 MBSafe browsing, voice recognition and cyber-criminals More...

07 Jul 2008

2.76 MBLaptops on holiday, gaming in Vietnam and 'unbreakable' encryption More...

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Firefox

Firefox users shown to be safer

Internet Explorer users the worst of the bunch   More...

Internet Corporation for Assigned Names and Numbers

Icann downplays recent site hacks

Redirects were 'limited', says organisation   More...

Advertisement

DNA

Boffins build artificial DNA

Could be used in the ultimate computer   More...

Microsoft

Microsoft outlines appeal against EU fine

Two sides back in court   More...

Advertisement