<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: freephone]]></title>
    <link>http://securityratty.com/tag/freephone</link>
    <description></description>
    <pubDate>Fri, 11 Jan 2008 14:15:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Oldham Primary Care Trust NHS loses two data sticks]]></title>
      <link>http://securityratty.com/article/1fa6887ba7491f504446d387e63807fc</link>
      <guid>http://securityratty.com/article/1fa6887ba7491f504446d387e63807fc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/11/08

Organization
Oldham Primary Care Trust NHS (PCT

Contractor/Consultant/Branch
None

Victims
PCT &quot;clients

Number Affected
148

Types of Data
The...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/oldham.jpg" align="right" height="50" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.oldham.nhs.uk/" target="_blank"> Oldham Primary Care Trust NHS (PCT)</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>PCT "clients"<br><br><span style="font-weight: bold;">Number Affected:</span><br>148<br><br><span style="font-weight: bold;">Types of Data:</span><br>"The information lost related to copies of assessments about future healthcare needs held in a secure central file. It included people’s names, addresses and dates of birth."*<br><br><font size="1"><span style="font-style: italic;">*I'm not sure if this means that copies of assessments AND names, addresses and dates of birth OR just names, addresses and dates of birth.</span></font><br><br><span style="font-weight: bold;">Breach Description:</span><br>The Oldham Primary Care Trust NHS has issued a press release announcing the loss of two "data sticks" containing personal information belonging to clients that had contact with the organization's continuing care service.&nbsp; A total of 148 clients were affected by the breach.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oldham.nhs.uk/temp_docs/PRESSNOTICE110108.pdf" target="_blank"> The Oldham Primary Care Trust NHS Press Release</a> <br><a href="http://www.manchestereveningnews.co.uk/news/s/1031694_personal_info_lost_in_oldham" target="_blank"> Manchester Evening News Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Oldham Primary Care Trust NHS<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A breach of information security has taken place. Two data sticks containing information relating to 148 clients who have been in contact with the PCT’s continuing care service have been reported missing.<br><br>This should never have happened.<br><span style="font-style: italic;">[Evan] Got that right.</span><br><br>All the individuals affected have been identified. Our first priority has been to try to contact all 148 individuals, or their representatives, personally. We have made personal contact with 145, and offered to visit them. We are waiting for three to get back to us after several attempts to contact them.<br><br>We have followed up the contacts in writing with our sincere apologies, and have set up a<br>dedicated freephone information line for those who may have further questions.<br><br>The information lost related to copies of assessments about future healthcare needs held in a secure central file. It included people’s names, addresses and dates of birth. It did not contain financial information.<br><span style="font-style: italic;">[Evan] It's a little unclear to me what this means exactly.</span><br><br>There is no risk at all to anyone’s future care.<br><br>A formal internal investigation has been launched.<br><br>The PCT takes patient confidentiality extremely seriously and has taken immediate action to prevent any further similar incidents.&nbsp; All data sticks containing ‘personal’ information have been recalled, and a full and thorough review of current processes and procedures is now underway.<br><br>Gail Richards, Oldham PCT chief executive, said: “We are deeply sorry – this should never have happened. We have launched a full and thorough investigation, and are reviewing our current policies relating to data storage.<br><span style="font-style: italic;">[Evan] It's always a good sign when a "chief executive" comments on security.&nbsp; I have said this before, but it shows that they understand their information security role and that the buck stops with them.</span><br><br>“While we believe the data sticks have been lost, we have reported the incident to the police in order to get the best advice possible. We have no reason at all to believe the information has been accessed by anyone else.”<br><br>To make sure this cannot happen again, the PCT:<br></font><ul><li><font size="2">Is undertaking a full audit of how removable media is used across the PCT</font></li><li>Has recalled all data sticks and pen drives which contain ‘personal’ data</li><li>Nearly completed recalling all data sticks and pen drives in order to reissue encrypted devices to staff alongside a new procedure for their use</li><li>Has reminded all staff formally of existing policies and procedures</li><li>Is urgently developing updated guidance for staff around information security<br></li></ul><font size="2"><span style="font-style: italic;">[Evan] These steps will go a long way towards preventing an similar occurrence.&nbsp; This is sound information security judgment, in my opinion.</span><br><br>Anyone with concerns should contact the PCT’s information line on freephone 0800 144 4304.&nbsp; The line is open from 8.30am8pm MonFri and 10am4pm SatSun.<br><br><span style="font-weight: bold;">Commentary:</span><br>Overall, this has to be one of the best responses I have seen in some time from an organization that experienced a breach of personal information.&nbsp; The response is open, thorough and honest.&nbsp; After reading the press release, I am clear about what happened and what Oldham Primary Care Trust ("PCT") plans to do about it.&nbsp; Too many times, organizations attempt to keep a breach under wraps.&nbsp; PCT prominently displays the information on their web site home page.<br><br><img style="border-color: rgb(0, 0, 0); width: 400px; height: 288px;" src="http://images.quickblogcast.com/95781-88451/oldhamhome.jpg" border="1" width="400"><br><br>The breach happens.&nbsp; The organization comes to terms with the fact that a breach occurred.&nbsp; The organization reaches out to everyone affected with an honest explanation and sincere apology.&nbsp; The organization issues a press release to announce what took place and what it intends to do about it.&nbsp; The organization saves face and keeps a certain amount of trust in the process.&nbsp; I am impressed with how PCT has responded to this breach. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>January, 2008 - <a href="http://breachblog.com/2008/01/10/kingstonnhs.aspx" target="_blank"> Medical information found in the road</a> <br>December, 2007 - <a href="http://breachblog.com/2007/12/19/bolton.aspx" target="_blank"> Laptop stolen from Royal Bolton Hospital NHS</a> <br>September, 2007 - <a href="http://breachblog.com/2007/09/16/nhs.aspx" target="_blank"> Dudley Group of Hospitals NHS hard drives for sale on eBay</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/11/oldham.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 11 Jan 2008 14:15:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information lost">information lost</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/medical information">medical information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/freephone information line">freephone information line</category>
      <category domain="http://securityratty.com/tag/data sticks">data sticks</category>
      <source url="http://breachblog.com/2008/01/11/oldham.aspx">Oldham Primary Care Trust NHS loses two data sticks</source>
    </item>
  </channel>
</rss>
