|
NHS Fife reprimanded over data breach |
Related newsNHS is working to address “unacceptable” abuse NHS board savings push could see AI replace staff Less than full-time – behind the NHS trend Drug harms on the rise in Scotland Government to merge two national NHS boards Probe into future of NHS Scotlands doctors underway New health & social care governance initiative EU staff qualifications & registrations confirmed Retired doctors to address rural recruitment gaps Westminster committee launches drug misuse inquiry |
|
|
Image Credit: © VILevi
|
||
|
||
|
The Information Commissioner’s Office has issued a formal reprimand to NHS Fife after an unauthorised person accessed patient information from a hospital ward – with security protocols failing to prevent the person from leaving with the documents.
The independent body upholding information rights across Scotland has warned the health board after personal information of 14 patients was obtained by member of the public.
In February 2023, an unauthorised person obtained secure documents and assisted in administering care to one patient due to a lack of identification checks.
The ICO says formal processes were lacking or not followed, with CCTV being accidentally turned off by staff prior to the incident meaning the documents have been unable to be recovered.
The ICO’s investigation concluded that NHS Fife had both low staff training rates and inappropriate security measures for personal information.
Natasha Longson, ICO Head of Investigations, said:
“Patient data is highly sensitive information and must be handled with the appropriate security. When accessing healthcare and other vital services, people need to trust that their data is secure and only available to authorised individuals.
“Every healthcare organisation should look at this case as a lesson learned and consider their own policies when it comes to security checks and authorised access. We are pleased to see NHS Fife has introduced new measures to prevent similar incidents from occurring in the future.”
This comes months after NHS Lanarkshire received a formal reprimand for staff’s unauthorised use WhatsApp to share patient data resulting in a non-staff member having access to patients’ personal information.
Now, NHS Fife faces similar warnings from the body around its patient data-handling.
Following its incident, NHS Fife introduced new measures including a system for documents containing patient data to be signed in and out, as well as updated identification processes.
Beyond this, the ICO recommended that NHS Fife improve its data protection by delivering refresher training for all staff more frequently and providing written security guidance.
Additionally, the body said it should develop a formal policy in relation for ID verification which should be reviewed regularly to ensure they are up-to-date and accurate.
It added that relevant data breaches must be reported within 72 hours and this process should be revisitied to ensure the health board is meeting that standard.
The ICO is expecting an update from NHS Fife of the actions it has taken within six months.
It adds that – in light of this incident – all organisations should review their procedures and ensure they have appropriate identification processes and training in place.
Read more: Staff shortage concerns in latest MWC reviews; Doctors ‘deeply concerned' for care homes over winter; Auditor General: Difficult choices for Scotland's NHS; Urgent workforce reforms needed for Scotland's NHS
Sign up to our bulletin for key health & social care updates straight to your inbox and you can follow healthandcare.scot on Google News |
