ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Leicester City Council facing ICO investigation

The local authority loses home security and medical data of 4,000 elderly and vulnerable people.

By Tom Brewster, 22 Mar 2011 at 11:41

USB

Leicester City Council could be hit by an Information Commissioner’s Office (ICO) fine after losing data on 4,000 elderly and vulnerable people.

LeicesterCare, the council's service which supports vulnerable city residents, lost a USB stick containing medical information and home security codes, according to a report from the Leicester Mercury.

The ICO, which has the power to fine organisations up to £500,000, confirmed to IT PRO it was looking into the case and would be making inquiries.

A spokesperson for the council said it was investigating the “possible loss of a data device,” adding there was no reason to suspect the information had been removed deliberately.

“However, whilst we have been assured by our supplier that the information on the device is not accessible to anyone who may find it, we are taking every precaution to maintain the security of our LeicesterCare users,” the spokesperson added.

“So, as a precaution, we are urgently carrying out changes to the keysafe codes of around 2,000 users. We began this programme last week and will have completed all of the code changes by Friday.”

The memory stick was not supposed to leave the council’s premises, and the local authority believed the device could be missing within the building.

Terry Greer-King, Check Point UK managing director, said it was positive the council had taken steps to ensure the sensitive data was not accessible to outside parties.

However, many councils have been guilty of not adding such layers of security, leaving the Leicester body in "the minority,” Greer-King said.

“There’s still a big security gap to be bridged, even though automated data encryption is easily deployed so that employees cannot work around or disable the protection,” he added.

Last week, the ICO confirmed it would be investigating a security breach at the University of York, when 148 individual student records were accessed.

Email to a friend

Print this page

< Previous   Public Sector : News Next >

1 comments

You need to Login or Register to comment.

Outdated Security Process

This news once again stands as testament to the fact that current storage security solutions for removable storage are not adequate or do not fit the way that users and organisations need to operate in order to remain efficient and productive. Complex endpoint security solutions that only allow specific USB devices or approved removable media to be used are extremely expensive and cumbersome, which almost certainly led to Leicester City Council relying on the rather out-dated need to lock up the memory stick in a safe every night. By using a solution that could remotely self destruct the data the moment they realised the memory stick had been misplaced would have afforded them an extra level of security and protection.

Tom Colvin, CTO, Conseal Security

By Conseal_Security on Tuesday Mar 22

0 people out of 0 found this comment useful.

Did you find it useful?

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement