The ICO has issued Northumbria Healthcare NHS Foundation Trust, (‘the Trust’) with an undertaking committing the trust to improving the way it handles patients’ information.
The action comes after the trust mistakenly sent five faxes containing information relating to the care of several patients to a member of the public. The faxes should have been sent to a social care team working at the trust but the wrong number was dialled.
After the first incident occurred in March 2014, the trust took action to make sure its fax machines were only able to send information to pre-programmed numbers belonging to organisations working in the health service. However, these measures were not adopted across all wards and four further faxes were sent to the same member of the public again two months later.
The ICO’s investigation found that the trust failed to inform all wards about the original data breach and the actions that they should take to stop this mistake occurring again. The trust also initially made no effort to recover the documents once they were alerted to the problem.
ICO Head of Enforcement, Stephen Eckersley, said:
“ If an organisation decides that a document must be sent [by fax] then they should have adequate measures in place to make sure the information is actually sent to the correct person. These measures must be adopted across all areas of the organisation.
The undertaking commits the Trust to introducing clear procedures so that any data breaches reported to the trust are acted upon promptly and remedial measures are introduced across the organisation. Fax procedures, including the use of pre-programmed numbers to avoid mistakes, must be adopted across all wards to ensure adequate security standards are maintained across all wards. The trust must make these improvements by 30 October 2015.