Health Service Focus


Tackling old and new threats to data security

Source: NHE Nov/Dec 16

Andrew Rose, senior policy officer at the Information Commissioner’s Office (ICO), discusses what actions NHS organisations can do to improve their data security compliance.

Cyber-attacks are a growing concern in the NHS, but the majority of data security breaches are still down to manual issues, according to the ICO. 

Recently the regulator released its data security incident and trends statistics for Q1 in 2016-17, which, once again, showed that the health sector continued to account for the most data security incidents. 

Andrew Rose, senior policy officer at the ICO, noted that this is due to the combination of the NHS making it mandatory to report incidents, the size of the health sector, and the sensitivity of the data processed. 

However, the latest data saw a 26% increase in the number of data security incidents in the health sector compared to the previous quarter (from 184 in Q4 2015-16 to 232 in Q1 2016-17). 

Asked what the main incidents were, Rose explained that the top three included data being posted or faxed to the wrong recipient; loss or theft of paperwork; and data being sent by email to the incorrect recipient. 

“A lot of these incidents could be avoided,” he said, adding that improving training is one of the big issues that have come out of a number of its enforcements. 

“I think that organisations need to make sure it [training] is happening and is relevant to the job role if they can,” explained Rose. “It doesn’t mean designing a course for every department, but it should be something that is a little bit more nuanced than e-learning once a year. It also shouldn’t be done once and forgotten.” 

Earlier this year, Dame Fiona Caldicott’s review recommended that the CQC should integrate measures for compliance with updated data security standards into their ‘Well-Led Inspections’ regime. This is a move that the regulator is taking forward.

Rose added that the CQC picking up on information governance in its inspection regime “should help enforce the fact that this stuff needs to happen. You need to record that the training is happening”. 

The ICO policy officer added that NHS organisations must also look at the policies and procedures they have in place. If you think about things being sent to the wrong recipient, Rose said, is that the fact that someone has not been trained or isn’t there a procedure in place for them to follow.Although the regulator produces a lot of advice and guidance, which helps NHS organisations understand what the issues are in terms of data and helps them with the questions to ask, Rose noted that it won’t help them with what solutions need to be put in place. 

“That is where CareCERT comes in, and they have the link with the National Cyber Security Centre,” he said. “That should be a key route to support. 

“I think that is where NHS organisations should get the expert advice from CareCERT, because they are set up and geared-up to provide that.” 

Despite there being an increased threat of cyber-attacks, especially Ransomware attacks against the NHS, which should not be neglected, Rose told NHE that as well as putting measures in place to mitigate these threats, the NHS must address the issue that the “majority of incidents still come down to manual errors”.

Tell us what you think – have your say below or email


There are no comments. Why not be the first?

Add your comment


national health executive tv

more videos >

latest healthcare news

Stop intervening to speed up birth unless real risks involved, says WHO

16/02/2018Stop intervening to speed up birth unless real risks involved, says WHO

Medical staff and midwives should not intervene to speed up a woman’s labour unless there are real risks of complications, says the World&n... more >
RCN launches member survey on decriminalisation of abortions

16/02/2018RCN launches member survey on decriminalisation of abortions

The Royal College of Nursing (RCN) has launched a UK-wide survey, quizzing its members for their views on decriminalising abortions. The onl... more >
CQC finds improvements at troubled Somerset hospital

16/02/2018CQC finds improvements at troubled Somerset hospital

The Care Quality Commission (CQC) has found improvements at a troubled hospital in Weston-super-Mare following an inspection last year that rated... more >

editor's comment

25/09/2017A hotbed of innovation

This edition of NHE comes hot on the heels of this year’s NHS Expo which, once again, proved to be a huge success at Manchester Central. A number of announcements were made during the event, with the health secretary naming the second wave of NHS digital pioneers, or ‘fast followers’, which follow the initial global digital e... read more >

last word

Hard to be optimistic

Hard to be optimistic

Rachel Power, chief executive of the Patients Association, warns that we must be realistic about the very real effects of continued underfunding across the health service. It’s now bey... more > more last word articles >
681 149x260 NHE Subscribe button

the scalpel's daily blog

Trusts recognise the value of the GIRFT programme – but it must remain ‘quality first’

09/02/2018Trusts recognise the value of the GIRFT programme – but it must remain ‘quality first’

Cassandra Cameron, policy advisor at NHS Providers, says trusts must be given constructive support – without fear of failure – in order for the Getting It Right First Time (GIRFT) programme to succeed. The NHS GIRFT programme aims for better value in acute hospital and mental health care by using trusts’ clinical, operational and financial data for benchmarking and scrutiny of local performance. Along with efficiency, ... more >
read more blog posts from 'the scalpel' >


Celebrating 75 years of healthcare

14/02/2018Celebrating 75 years of healthcare

Julian Amey, chief executive of the Institute of Healthcare Engineering & Estate Management (IHEEM), outlines what the coming year holds for ... more >
The HSIB approach to maternity investigations

14/02/2018The HSIB approach to maternity investigations

Jane Rintoul, director of strategy and policy and programme director for maternity investigations at the Healthcare Safety Investigation Branch (... more >
Data saves lives

14/02/2018Data saves lives

Kuldeep Sohal, programme manager at Connected Yorkshire, part of Connected Health Cities, discusses how data sharing across the north is improvin... more >
Our work can help ease A&E pressures

09/02/2018Our work can help ease A&E pressures

Last year, NICE guidelines recommended that the NHS should provide more advanced paramedic practitioners (APPs) to relieve pressure on emergency ... more >
Training the next generation

07/02/2018Training the next generation

Professor Wendy Reid, national medical director and executive director of education and quality at Health Education England (HEE), outlines the w... more >


Duncan Selbie: A step on the journey to population health

24/01/2018Duncan Selbie: A step on the journey to population health

The NHS plays a part in the country’s wellness – but it’s far from being all that matters. Duncan Selbie, chief executive of Pu... more >
Cutting through the fake news

22/11/2017Cutting through the fake news

In an era of so-called ‘fake news’ growing alongside a renewed focus on reducing stigma around mental health, Paul Farmer, chief exec... more >
Tackling infection prevention locally

04/10/2017Tackling infection prevention locally

Dr Emma Burnett, a lecturer and researcher in infection prevention at the University of Dundee’s School of Nursing and Midwifery and a boar... more >
Scan4Safety: benefits across the whole supply chain

02/10/2017Scan4Safety: benefits across the whole supply chain

NHE interviews Gillian Fox, head of eProcurement (Scan4Safety) programme at NHS Supply Chain. How has the Scan4Safety initiative evolved sin... more >
Simon Stevens: A hunger for innovation

25/09/2017Simon Stevens: A hunger for innovation

Simon Stevens, chief executive of NHS England, knows that the health service is already a world leader when it comes to medical advances – ... more >