Data Loss Incidents

The request was successful.

Dear University Hospitals of Morecambe Bay NHS Foundation Trust,

would like to know to what extent you have implemented data loss prevention strategies and losses that you have incurred specifically covering the following;

a) How many data losses have you incurred in the last 24 months relating to the following

USB loss (to include data theft by employees as well as just lost USB devices)
Email leakage (accidental and also malicious)
Laptop theft

To each of the above please provide an indication of what data was lost or stolen and the estimated cost associated with that loss

b) What policies do you have in place surrounding

Encryption of data on Laptops, devices and email
Data transfer between departments and organisations under your control/guidance
The use of removable storage devices

c) What tools have you implemented to help meet data protection requirements to ensure that data is stored and transferred securely and not kept longer than necessary?

d) What was the cost of these tools - initial licence cost and ongoing support/maintenance contracts?

I look forward to receiving your response

Yours faithfully,

Belinda Perrin

University Hospitals of Morecambe Bay NHS Foundation Trust

University Hospitals of Morecambe Bay NHS Foundation Trust
Trust Headquarters
Westmorland General Hospital
Burton Road
Kendal
LA9 7RG

Tel: 01539 716666
Fax: 01539 795313
Web: www.uhmb.nhs.uk
Reference Number: 817

31 March 2011

Belinda Perrin
[FOI #67017 email]

Dear Belinda
RE: REQUEST FOR INFORMATION UNDER THE FREEDOM OF INFORMATION ACT (FOI Act)
I am writing to acknowledge receipt of your written request of 31 March 2011 regarding data loss. This was received in this office on 31 March 2011 via our electronic mailing system. The FOI Act provides for up to 20 working days to respond to written requests from date of receipt. You can therefore expect to receive a written response by 3 May 2011.

Your request is currently being processed. Should we require further clarification of your information needs, we will contact you again within the timeframe indicated above.

There are certain categories of information that are exempt from the general right of access provided by the FOI Act. These include, for example, personal information protected by the Data Protection Act 1998 and where the release of information would not be in the public interest as defined by the Act. Should your request be deemed to relate to any exempt information, you will be advised accordingly and a full explanation given.

Public authorities may charge a fee for the information requested. The fees are worked out in accordance with the regulations issued under the Act. Should your request generate fee payment, you will be informed at the earliest opportunity with an estimation of costs provided.
The officer handling your request can be contacted by telephone on 01539 716698 should you have any questions or concerns.

Yours sincerely

TONY HALSALL
CHIEF EXECUTIVE

DISCLAIMER: This e-mail may be confidential and privileged. If you are not the intended recipient please accept our apologies; please do not disclose, copy or distribute information in this e-mail or take any action in reliance on its contents: to do so is strictly prohibited and may be unlawful. Please forward the message to [email address] before deleting it. Comments or opinions expressed in this email are those of their respective contributors only. The views expressed do not represent the views of the Trust, its management or employees.
University Hospitals of Morecambe Bay NHS Foundation Trust is not responsible and disclaims any and all liability for the content of comments written within. Thank you for your co-operation

University Hospitals of Morecambe Bay NHS Foundation Trust

1 Attachment

Dear Belinda,

Please see attached response to your recent FoI.

Kind regards,

Louise Fleming

DISCLAIMER: This e-mail may be confidential and privileged. If you are not
the intended recipient please accept our apologies; please do not
disclose, copy or distribute information in this e-mail or take any action
in reliance on its contents: to do so is strictly prohibited and may be
unlawful. Please forward the message to [1][email address] before
deleting it. Comments or opinions expressed in this email are those of
their respective contributors only. The views expressed do not represent
the views of the Trust, its management or employees.
University Hospitals of Morecambe Bay NHS Foundation Trust is not
responsible and disclaims any and all liability for the content of
comments written within. Thank you for your co-operation

References

Visible links
1. mailto:[email address]

James Titcombe left an annotation ()

Dear Belinda,

On Monday 10th of August 2009, a draft report meant for the NMC, which contained confidential information relating to the death of my son, was sent by a midwife at FGH to an incorrect (but active) email account.

The email containing the report about Joshua’s death was titled “NMC shit”.

I guess this would constitute a ‘data loss’ incident. Perhaps you could ask the trust why they have not reported this to you?

Kind Regards,
James