The Information Commissioner’s Office fined Brighton and Sussex University Hospitals NHS Trust £325,000, the largest penalty it had issued at the time. Hard drives containing highly sensitive patient and staff data had been sold on eBay instead of being destroyed.
What happened
- The trust had arranged, through its IT service provider, for around 1,000 hard drives to be destroyed in 2010.
- An individual working on the job over several days took at least 252 drives, some of which were sold online.
- The drives held data including patient medical information and staff records containing National Insurance numbers.
- The breach came to light when a data recovery company bought drives and alerted the trust, and later when a student reported another purchase.
Why it mattered
The case became a landmark example of supplier and asset-disposal failures, showing that outsourcing a task does not outsource accountability for personal data. The trust contested the fine, but the penalty was upheld.
Lessons for organisations
Use accredited disposal providers, obtain certificates of destruction, and supervise or audit disposal of data-bearing equipment. Encrypting drives means data remains protected even if devices go astray.
Sources: Digital Health, The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.