A Scots health board has been reprimanded by a watchdog after staff members shared patients’ personal data on WhatsApp hundreds of times.
The Information Commissioner’s Office (ICO) has issued a reprimand to NHS Lanarkshire after they found 26 staff sent sensitive data to each other via the messaging app on more than 500 occasions.
The data was leaked between April 2020 and April 2022.
The data included patients’ names, phone numbers, addresses, images, videos, screenshots and clinical information.
While WhatsApp is approved for NHS staff for basic communication, it is not approved by the NHS for sharing sensitive data.
READ MORE: Scottish NHS data breaches up by a third in five years
A non-staff member was also added to the WhatsApp group in error, meaning they could have viewed the sensitive information.
NHS Lanarkshire was made aware of the issue and reported the incident to the ICO, which conducted an investigation and concluded the organisation did not have the appropriate policies, clear guidance or processes in place when WhatsApp was made available to download.
This meant that NHS Lanarkshire had no assessment of the potential risks relating to sharing patient data.
UK Information Commissioner John Edwards said: “Patient data is highly sensitive information that must be handled carefully and securely.
“When accessing healthcare and other vital services, people need to trust that their data is in safe hands.
“We appreciate that NHS Lanarkshire, like all healthcare providers, was under huge pressure during the pandemic but there is no excuse for letting data protection standards slip.
“Every healthcare organisation should look at this case as a lesson learned and consider their own policies when it comes to both messaging apps and processing information about patients.
“We will be following up with NHS Lanarkshire to ensure that patient data is not compromised again.”
The ICO has since recommended that NHS Lanarkshire should take action to prevent future data breaches.
The ICO suggested the health board should implement a secure clinical image transfer system for the storage of images and videos within a care setting.
READ MORE: Mental health care waiting times branded 'intolerable' as one patient waits 9 years
The watchdog said NHS Lanarkshire should “consider the risks” in relation to personal data and ensure that staff are “aware of their responsibilities to report personal data breaches internally without delay to the relevant team”.
The ICO asked NHS Lanarkshire to provide an update of action taken within six months of the reprimand being issued.
NHS Lanarkshire acknowledged the issue and apologised for the leaked information.
Trudi Marshall, nurse director health and social care North Lanarkshire, said: “We have received a formal reprimand from the ICO for the use of WhatsApp by one of our community teams to exchange personal patient data during the pandemic.
“We recognise that the team took this approach as a substitute for communications that would have normally taken place in either a clinical or office setting, but was not possible at that time due to Covid restrictions.
“However, the use of WhatsApp was never intended for processing patient data.
“We offer our sincere apologies to anyone whose personal details were shared through this group.
“We have already taken a number of steps including looking at alternative apps that can be introduced for the transfer and storage of images and videos within a care setting.
“This is being taken forward while considering the risks relating to the storage of any personal data.”
Why are you making commenting on The Herald only available to subscribers?
It should have been a safe space for informed debate, somewhere for readers to discuss issues around the biggest stories of the day, but all too often the below the line comments on most websites have become bogged down by off-topic discussions and abuse.
heraldscotland.com is tackling this problem by allowing only subscribers to comment.
We are doing this to improve the experience for our loyal readers and we believe it will reduce the ability of trolls and troublemakers, who occasionally find their way onto our site, to abuse our journalists and readers. We also hope it will help the comments section fulfil its promise as a part of Scotland's conversation with itself.
We are lucky at The Herald. We are read by an informed, educated readership who can add their knowledge and insights to our stories.
That is invaluable.
We are making the subscriber-only change to support our valued readers, who tell us they don't want the site cluttered up with irrelevant comments, untruths and abuse.
In the past, the journalist’s job was to collect and distribute information to the audience. Technology means that readers can shape a discussion. We look forward to hearing from you on heraldscotland.com
Comments & Moderation
Readers’ comments: You are personally liable for the content of any comments you upload to this website, so please act responsibly. We do not pre-moderate or monitor readers’ comments appearing on our websites, but we do post-moderate in response to complaints we receive or otherwise when a potential problem comes to our attention. You can make a complaint by using the ‘report this post’ link . We may then apply our discretion under the user terms to amend or delete comments.
Post moderation is undertaken full-time 9am-6pm on weekdays, and on a part-time basis outwith those hours.
Read the rules hereLast Updated:
Report this comment Cancel