Guidance

ICO reminds healthcare organisations about keeping patient data secure

Following reports of a data breach at the London Clinic, the Information Commissioner’s Office (ICO) would like to remind all healthcare organisations about the importance of keeping patient data secure.

Patient data is highly sensitive information that must be handled with care. When accessing healthcare and other vital services, people need to trust that their medical information is safe and only available to authorised employees.

Healthcare organisations should ensure:

  • Staff are thoroughly trained: Organisations should have data protection training in place that is role-specific, tailored and relevant to the tasks being completed. Staff should feel confident in handling people’s personal data safely and securely. It must be clear to staff about what records they are allowed to access.
  • Appropriate technical measures are in place: Appropriate measures, such as passwords and access controls, should be in place to ensure personal information can only be seen by people who need to use it.
  • Staff are clear on the data breach reporting process: An organisation must report misuse of personal data to the ICO if there is a risk to people’s rights and freedoms, which is often the case with sensitive medical information. This must be reported within 72 hours of becoming aware of the breach. More information on breach reporting here.

Find out more here.

First Published
24 April 2024
Updated On
24 April 2024
Due to be Reviewed
24 April 2026
Not signed in.

Please Login or Register an account to access the ability to favourite this.
Share this article

You might also find this useful...

Expansion of Shingles Vaccination
Expansion of Shingles Vaccination
31 July 2025
A letter has been published detailing the planned expansion of the Shingles vaccination programme to include all those who are severely immunosuppressed and aged 18-49 years old from 1 September…
Cont. Reading
OpenSAFELY Expansion – Action Required
OpenSAFELY Expansion – Action Required
30 July 2025
The Data Provision Notice (DPN) for OpenSAFELY now permits expansion beyond COVID-19-related analyses. The opt-in functionality for EMIS was rolled out this week.  SystmOne already has this functionality in place.…
Cont. Reading
MMR vaccinations for practice staff 
MMR vaccinations for practice staff 
26 July 2025
Due to the recent measles outbreaks, GP practices are permitted to administer MMR vaccines to their eligible staff who are registered with another practice under INT (immediately necessary treatment).  This…
Cont. Reading