The process of developing patient records through handwritten notes may be convenient, but it inevitably leads to errors through misinterpretation and potential security issues. The use of paper files also exposes documents to the risk of loss or damage, something highly likely to occur in a busy hospital environment.
And yet in 2018 patient information is not only at risk from cyber attacks through outdated software and operating systems, but also from the most basic forms of security – losing pieces of paper.
An NHS Under Siege From Cyber Attacks
The Care Quality Commission earlier this year subjected the NHS’s cyber security defences to on-site assessments, which all trusts failed to pass. It was found that inadequate patching on IT systems, a core vulnerability targeted by the WannaCry ransomware, had not been carried out sufficiently.
On top of this, 11 of Scotland’s 14 NHS Trusts still rely on Windows XP – An operating service that Microsoft ended support for some four years ago and hasn’t had a major security update since 2008. In fact, the only significant recent activity for Windows XP came last year when Microsoft released a one-off patch to prevent the spread of ransomware material.
Across NHS Lothian in particular, it was revealed that 3,000 out of 19,000+ computers still run XP. That’s 15% of all of NHS Lothian devices left vulnerable to cyber attacks.
But a damning report by Parliament Street suggests that the NHS has failed to move forward with digital transformation plans due to the over-reliance on paper-based systems.
Missing Patient Records
The Parliament Street research team liaised with 68 NHS Trusts for the report, asking for information on patient records which were reported ‘missing’ over the last financial year. When asked whether the trust still used handwritten notes, the research team discovered 94 per cent of trusts incredibly still used this method of documentation.
The report also discovered that overall, 9,132 patient records from the 68 hospitals had been reported missing or lost in the last financial year.
Royal Devon and Exeter NHS Foundation Trust, which uses only paper-based case notes, reported 425 documents lost or stolen, while the Wigan and Leigh NHS Foundation Trust reported 426 lost or stolen documents despite using an electronic health record system.
The University Hospital Birmingham reported the largest amount of records ‘unavailable’ for out patient clinic appointments at a staggering 3,179 documents, despite using electronic clinical systems such as iCARE and Concerto.
With nearly 10,000 patient records reported as missing in the last year, it’s clear that much more needs to be done to protect the identity and integrity of patient documents. Many have called for the implementation of Blockchain solutions to ensure the security, transparency and integrity of patient files but one could argue that the bigger issue is getting the basics right – move away from paper filing systems first.






