Advertisement
Promo

Security threats Toolkit

NHS trust loses 18,000 staff details

Tom Espiner ZDNet.co.uk

Published: 17 Sep 2008 12:41 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A London NHS hospital trust has admitted to losing almost 18,000 staff details on four CDs.

The payroll details were lost on 22 July while in transit between the salaries and wages department of Whittington Hospital NHS Trust and payroll company McKesson, where they were to be stored.

David Sloman, chief executive of the Whittington Hospital NHS Trust, said on Tuesday that a staff member had been suspended over the incident, as the discs had been placed in an out-tray in the post room marked 'recorded delivery', instead of being sent by courier.

"It is trust policy to send any such information by courier," said Sloman. "An investigation is underway, with an inquiry panel taking place shortly. In the meantime, a member of staff has been suspended."

The details lost on the 17,990 NHS staff included the names, dates of birth, national insurance numbers, start dates, pay details and sickness dates of all staff who have worked at Whittington Hospital NHS Trust, Camden Primary Care Trust (PCT), Islington PCT, and Camden and Islington NHS Foundation Trust since April 2001. Included in the lost data relating to the financial year 2007–08 were the addresses of 587 Whittington Hospital NHS Trust staff, 2,303 Camden and Islington NHS Foundation Trust, 1,458 Camden PCT staff, and 1,050 Islington PCT staff.

A hospital spokesperson told ZDNet.co.uk on Wednesday that personal bank-account details had not been lost, and that police had said the discs were "highly unlikely" to have been stolen. The trust said it did not know whether the discs had gone into the Royal Mail postal system.

Read this

Feature
Protect your mobile devices in any location

Forget the recent hype about about Chinese hackers — users and organisations should be securing mobile systems as a matter of course, so follow these tips to find out how

Read more +

The discs were not encrypted but were protected by alphanumeric passwords, which the trust insisted could only be broken by "expert hackers".

However, encryption companies questioned the trust's claims. Passwords are easy to crack, according to CryptoCard UK chief executive Jason Hart, even if they do contain a mixture of letters and numbers.

"There are a very large number of utilities that can brute-force passwords in a matter of seconds," Hart told ZDNet.co.uk on Tuesday. "Alphanumeric passwords do not make a difference. You do not need to be an expert to crack passwords; anyone who's IT literate can go onto the web, type 'password cracker' into a search program, and download a number of utilities and tools," said Hart.

Nick Lowe, Check Point's regional director for Northern Europe, said that passwords are "only a very basic step that can be overcome fairly easily by anyone with a little determination".

"With this type of data, in a high-risk environment, strong automated encryption is the minimum protection that should be applied," said Lowe.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
7 out of 8 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters