NHS has lost thousands of smartcards
By Nicole Kobie,
Over four thousand smartcards used to access NHS computer systems have gone missing, according to reports in a medical publication.
Pulse, a magazine for GPs, requested the statistics under the Freedom of Information Act. The information it received from National Health Service's (NHS) IT group Connecting for Health (CfH) showed 4,147 smartcards had gone missing since the systems were implemented. Some 1,240 disappeared in the last year alone.
Not all were misplaced, either. At least 142 were stolen, with 17 appropriated from Hammersmith and Fulham Primary Care Trust. Pulse said one trust in ten had no idea how many cards had gone missing.
So far, such cards have been issued to just under half a million NHS staff, but Pulse said that number will eventually pass 1.2 million.
The missing smartcards could not necessarily be used to access any NHS computers, however. Like most smartcard systems, the card is just one part of the two-factor authentication required to access computers. CfH said their cards require a six-digit pin code.
A CfH spokesman told the BBC: "There is no evidence that any security breaches have ever arisen from lost of stolen cards."
CfH also said any cards reported stolen or missing had been disabled. But Pulse claimed: "In almost every case, lost or stolen smartcards were reissued automatically without investigation, and no disciplinary action has been taken against any staff member."
The smartcard system is part of the National Programme for IT - one aspect of which is a UK-wide records system. Such a records system was recently panned by doctors as insecure in a recent survey by the British Medical Association.
Pulse's deputy editor Richard Hoey told the BBC: "The real message here isn't how many smartcards are being lost, but how many trusts are failing to keep proper records or gear themselves up to deal with security breaches."
This latest security problem is just the latest in a line of UK data breaches. With that in mind, security analysts came down hard on the NHS and its processes.
"It seems to me that there's a lot of best practise, which is well understood by industry, and supposedly mandated by government... but nearly every breach clearly would have been prevented if people had followed best practise," said Mike Small, director of security management for CA.
Small said the key to this latest trouble is how the technical objects are controlled, suggesting process is the most important. "If you have smartcards, how do you manage them?" he asked.
"My concern about this is that organisations can be lulled into a sense of security by what seems to be very strong technology," Small said. "But the weakest point is still the weakest point... and that's often the human aspect."
Despite the lost cards, such a system is necessary, said Paul Malcolm, UK general manager Sentillion, a healthcare identity management firm.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Networking Analysis & Insight
Q&A: Cisco on servers, storage and strategy
We chat with Laurent Blanchard, Cisco's vice president of enterprise, to ask why IT should get excited about what the networking giant can offer.
- It's not about the browser, stupid!
- The Great British network squeeze
- New year: new suppliers
- Top 10 tech winners and losers of 2011
- 2011: The year in news
- UK rural broadband: too little, and too late
- HP PCs back on the menu with Dellish plans
- Top 10 social networking tips for enterprise - part one
- Q&A: Why go via telecoms to the cloud?
Latest Networking Reviews
Swyx SwyxExpress X20 review
Rating: ![]()
- Ipswitch WhatsUp Gold Premium 15
- ForeScout Technologies CounterACT 6.3.4
- ThinPrint Printer Dashboard review: First Look
- TITUS Aware for Microsoft Outlook review
- Windows Phone 7 Mango review: First Look
- Dartware InterMapper review
- Kemp Technologies LoadMaster 3600 review
- Sangfor WANACC M5500 review
- Office 365 review: First look
advertisement
Most popular
- Will someone rid me of these troublesome Macs?
- BT considering Ofcom price cap appeal
- Google sends in Bouncer to sort out malicious apps
- Anonymous publishes FBI hacking call
- ACTA: the basics, the controversies, and the future
- Virgin 100Mbps rollout 'ahead of schedule'
- Who to trust after the VeriSign hack?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- VeriSign admits 2010 hack
- What should RIM do to recapture the attention of businesses?
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





