Hospital breaks law but avoids pain
15th March 2023
Hospital breaks law but avoids pain
Did complying with the Accountability Principle save this hospital from receiving serious penalties?
Today’s blog is a very interesting demonstration of the GDPR Accountability Principle – and how repercussions could potentially be far less damaging if you have the relevant controls in place and if you respond adequately when an incident occurs.
The story relates to a data breach that occurred at Liverpool University Hospital Foundation Trust (LUHFT) when an email was sent out to hundreds of managers which contained the personal details of almost 14,000 members of staff.
The personal information that was shared was significant and included:
- Names
- Addresses
- National Insurance numbers
- Salaries
- Gender
- Ethnicity
The incident occurred in December 2022 when a spreadsheet containing a ‘hidden tab’ was sent out to the managers. Whilst apparently, the tab would not have been visible to those receiving the email, it was a data breach that it was sent out at all.
According to an article appearing online in the Liverpool Echo on 9 March 2023, at a recent meeting of the Trust’s board, James Sumner, CEO of the Trust, confirmed that the Information Commissioner’s office had determined that ‘no further action’ would be taken following the breach.
Considering the apparent seriousness of the breach, we can only assume that this has come down to the GDPR Accountability principle.
What controls did they have in place in advance of the incident, and how did they respond to it when it occurred? It is likely they did well on both counts.
The response from the Trust appears to have been fast and thorough.
- The offending email and data were immediately deleted from IT systems, with preventative measures put in place to stop this from happening again.
- Trust Chief Executive James Sumner sent an email to the people affected, apologising for the error.
- He provided them with full details regarding the occurrence and offered them support.
- He commissioned an independent expert to carry out a review and provide learnings on the experience.
- The incident was reported to the Information Commissioners’ Office.
What is the GDPR Accountability Principle?
The Accountability Principle is one of the seven key principles that govern the UK GDPR. The Information Commissioner’s website states that:
“The accountability principle requires you to take responsibility for what you do with personal data and how you comply with the other principles.
You must have appropriate measures and records in place to be able to demonstrate your compliance.”
The graphic attached to this blog is from the ICO and gives you an excellent checklist to help you comply with Accountability Principle.
Did you know that here at The Griffin House Consultancy, we not only provide training but also carry out external audits that will
- a) Help to ensure you are compliant (or create a roadmap to get there); and
b) Demonstrate your due diligence, which goes a long way towards the accountability principle.
PS TEST YOURSELF. What are the other 6 Principles of the UK GDPR? If you can’t remember, you might want to book some refresher training!
Take a peek here at the 7 Principles of the UK GDPR
As always, please get in touch or book your complimentary thirty-minute zoom consultation if we can be of any assistance.
Source: Liverpool Echo
Source: Digitalhealth.net