Lampeter Medical Practice loses unencrypted memory stick

The Information Commissioner’s Office (ICO) has found Lampeter Medical Practice to be in breach of the Data Protection Act, after an unencrypted memory stick containing the personal details of 8,000 patients was reported lost to the privacy watchdog.

In March 2010, a member of staff downloaded a database containing patient details in contravention of practice policy. The staff member downloaded the information on to an unencrypted and non password protected computer memory stick which was then posted by recorded delivery to the Health Boards Business Service Centre. The memory stick did not arrive at its intended destination and is now accepted to be lost.

Sally-anne Poole, Enforcement Group Manager, said: “It is unnecessarily risky to download 8,000 personal details on to a memory stick. It is imperative that staff are made fully aware of an organisation’s policy for securing personal data and any portable device containing personal information should always be encrypted to prevent it being accessed in the event of loss or theft…”

If your business is at risk of this happening, give us a call and let’s get your data sorted!