Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

UK government apologizes for breaching doctors' personal info

Posted data on physicians included home addresses, sexual orientations

April 26, 2007 12:00 PM ET

Computerworld UK - The U.K. Department of Health has been forced to apologize after the personal details of hundreds of doctors -- including home addresses, phone numbers, sexual orientation and previous convictions -- were made available online.

The security breach is the latest disaster to hit a troubled NHS online application system for specialist medical training posts. Doctors' leaders said there was "no excuse" for the "appalling" breach -- particularly after security concerns had been raised with the DoH.

Last month the government had to offer interviews to junior doctors who appeared to have been wrongly disqualified after the Medical Training Application Service (MTAS) spiralled into chaos.

The online application system crashed under the pressure of thousands of junior doctors trying to submit applications simultaneously. British Medical Association representatives called for the scheme to be scrapped and the DoH was forced to call a snap review of the scheme.

Now it has emerged that doctors' personal details were available online for several hours from 9am Wednesday. The security breach was reported by Channel 4 News, which said: "It appears that the information was downloaded onto Excel files and placed on an unsecured website that could be accessed by anyone through the Internet."

Wednesday the DoH told Channel 4 that the team administering MTAS did not know how long the data had been available nor how many people had accessed the files.

The problem has now been fixed, the DoH has confirmed. A spokesperson said: "We apologize to any applicants whose details have been improperly accessed. This is a very serious matter and is under investigation.

"This URL was made available to a strictly limited number of people making checks as part of the employment process. This information was never publicly available through the MTAS website and was only accessible for only a short period of time after details of the URL were leaked."

He added: "The MTAS team fixed the problem as soon as it was brought to their attention."

But doctors' representatives were furious. Dr Jo Hilborne, chair of the BMA's junior doctors committee, said: "What little faith anyone had left in this shambolic system has just evaporated. It is a breach of security on an appalling scale. The ease with which anyone could have accessed highly sensitive information about thousands of people is frankly shocking."

The BMA had raised concerns about the security of the MTAS website "on more than one occasion," she said. "The Department of Health had months to put it right and failed. There can be no excuse for this."

Emily Rigby, chair of the BMA's medical students committee, said: "We raised concerns about online security for medical students' applications last year after the system was hacked into. We were given explicit assurances it wouldn't happen again."


This article is reprinted by permission from ComputerworldUK.com, Copyright (c) 2007 Computerworld UK All rights reserved.

Jump to comments

U.K. Department of Health

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs