Docs store unsecured patient data on memory sticks
Information on the sticks include patient names, diagnoses, treatment details
Computerworld UK - Doctors are carrying around unencrypted patient data on USB memory sticks, according to stinging research carried out in a London hospital.
But the National Health Service (NHS) maintained it is taking the right steps to protect data, and that clinicians have to follow guidelines that insist on the encryption of identifiable patient data.
In a study conducted in one London hospital, clinicians Sven Putnis and Andrew Bircher found that 92 of 105 doctors surveyed carried memory sticks, Health Service Journal reported. Some 79 of these memory sticks held confidential patient information, but only five doctors had followed NHS rules and encrypted their data.
The authors said the information included patient names and birth dates, alongside X-ray results, diagnoses and treatment details, HSJ reported.
Calling the results "worrying," the researchers said there was "no reason why this lack of security would not be mirrored in surveys across every hospital in the U.K. and beyond."
They said data collection and processing had made patient care "more efficient," but that it was important the technology was monitored "to ensure we uphold patients' rights to privacy."
But the NHS hit back at the findings, saying it had issued clear instructions to local trusts that all identifiable patient data on portable devices has to be encrypted.
Dr. Simon Eccles, medical director at Connecting for Health, told Computerworld U.K. that typically patients were assigned codes that meant such records would be unidentifiable to anyone but staff.
"[NHS chief executive] David Nicholson quite rightly said that any portable device that contains identifiable information must be encrypted," he said, adding that the NHS is rolling out McAfee SafeBoot software across all hospitals to protect the data.
But he added: "At the end of the day, the responsibility for data must rest with the individual clinician." Ideally, data should be both unidentifiable and encrypted, he said.
A spokesperson at the Department of Health added: "The NHS locally has legal responsibility to comply with data protection rules."
NHS patients have suffered data losses in recent months. In June, two NHS trusts lost unencrypted laptops containing 31,000 patient records.
Reports of data losses in the NHS have raised concerns over the $22.1 billion National Programme for IT, which is building a central spine of patient data accessible by NHS staff with a smart card and passcode. In the summer, analysts said the NHS should urgently reconsider the program, and weigh up the benefits of patients carrying their own data instead.
In August, it emerged that across the public sector, the data of one in every 15 people in the country had been lost in one year alone.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Forrester Total Economic Impact (TEI) Case Study - Oracle
- In this paper, Forrester Consulting examines the total economic impact and potential return on investment (ROI) realized by three Enterprise organizations as they...
- The Hidden Truth About Virtualizing Business-Critical Applications
- This IDG whitepaper highlights key findings based on the Quickpoll Survey conducted with more than 300 Enterprise and Commercial IT decision makers worldwide...
- Top 10 Myths About Virtualizing Business-Critical Applications
- Even though virtualization has brought positive change to enterprise IT over the last decade, some skepticism remains about how valuable virtualization can be...
- Enterprise Java Applications on VMware: Unix to Linux Migration Guide
- This guide focuses on key considerations for IT Architects who are in the process of migrating Java applications from UNIX to Linux as...
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
- This IDC white paper explains how much of the Enterprise IT community is at a crossroads in extending their journey to the private... All Applications White Papers
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
- Discover the Benefits of Virtualization for Federal Applications
- Want to say goodbye to missed SLAs? VMware can help you virtualize mission-critical applications such as Oracle, MS Exchange and SharePoint to achieve...
- Reduce Application Lifecycle Management Costs with VMware ThinApp
- Traditional desktop application deployment and management is a time-consuming and costly endeavor for IT. From development to deployment, including help desk support, the... All Applications Webcasts