Site navigation

ICO Reprimands NHS Lanarkshire Staff for WhatsApp Data Sharing

Thom Carter

,

NHS Lanarkshire Reprimanded by ICO Over Sharing Patient Data via WhatsApp
The Information Commissioner’s Office (ICO) has issued a reprimand to NHS Lanarkshire after finding that the health board’s staff had shared the information of patients via an unauthorised WhatsApp group.

From April 2020 to April 2022, 26 members of staff at NHS Lanarkshire had access to a WhatsApp group where patient data — such as names, phone numbers, and addresses — was shared on over 500 occasions. Screenshots, images, and videos which included clinical information were also shared.

On one occasion, a non-staff member was added to the group by mistake, resulting in the disclosure of patient data to an unauthorised individual.

After becoming aware of the incident, NHS Lanarkshire reported themselves to the ICO. The body’s investigation then concluded that NHS Lanarkshire did not have the appropriate policies, guidance, or processes in place.

As an emergency measure at the beginning of the Covid-19 pandemic, the health board enabled WhatsApp to be downloaded for specific administrative purposes and crisis planning.

On this, Information Commissioner John Edwards, said on BBC’s Good Morning Scotland radio programme: “They did that at pace and we can’t particularly criticise them for that. But what they did not do is follow up with rules about the way in which WhatsApp could be used, and the use of it drifted with the members sharing very sensitive information for which the app was not authorised.”

Edwards mentioned that while there was “no suggestion that the data was misused, [or] that anybody acted unprofessionally with it,” it “did expose the data to risk,” and that the message for other health boards is to “really consider a risk assessment when deploying new technologies and new communications platforms.”

The Information Commissioner went on to say that “One of the other things that this case shows us is that staff were being innovative themselves: they were in some cases sharing images that could be used for clinical purposes. That tells us that there’s a demand for secure image sharing services and we’ve recommended that the Lanarkshire board look at that.”

The ICO has provided NHS Lanarkshire with a set of actions to undertake to ensure their compliance with data protection law. The ICO has asked NHS Lanarkshire to provide an update of the actions taken within six months of the reprimand being issued.

No financial penalty was made against NHS Lanarkshire.


Recommended


NHS Lanarkshire isn’t the only Scottish NHS board to have received a warning from the ICO this year.

For instance, in March, DIGIT reported on the news that NHS Highland had been given a reprimand after a data breach involving those likely to be accessing HIV services.

After sending an email to 37 recipients likely to be accessing HIV services, an email error — inadvertently using CC (carbon copy) instead of BCC (blind carbon copy) — had meant that the recipients could see other peoples’ personal email addresses.

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data