From April 2020 to April 2022, 26 members of staff at NHS Lanarkshire had access to a WhatsApp group where patient data — such as names, phone numbers, and addresses — was shared on over 500 occasions. Screenshots, images, and videos which included clinical information were also shared.
On one occasion, a non-staff member was added to the group by mistake, resulting in the disclosure of patient data to an unauthorised individual.
After becoming aware of the incident, NHS Lanarkshire reported themselves to the ICO. The body’s investigation then concluded that NHS Lanarkshire did not have the appropriate policies, guidance, or processes in place.
As an emergency measure at the beginning of the Covid-19 pandemic, the health board enabled WhatsApp to be downloaded for specific administrative purposes and crisis planning.
On this, Information Commissioner John Edwards, said on BBC’s Good Morning Scotland radio programme: “They did that at pace and we can’t particularly criticise them for that. But what they did not do is follow up with rules about the way in which WhatsApp could be used, and the use of it drifted with the members sharing very sensitive information for which the app was not authorised.”
Edwards mentioned that while there was “no suggestion that the data was misused, [or] that anybody acted unprofessionally with it,” it “did expose the data to risk,” and that the message for other health boards is to “really consider a risk assessment when deploying new technologies and new communications platforms.”
The Information Commissioner went on to say that “One of the other things that this case shows us is that staff were being innovative themselves: they were in some cases sharing images that could be used for clinical purposes. That tells us that there’s a demand for secure image sharing services and we’ve recommended that the Lanarkshire board look at that.”
The ICO has provided NHS Lanarkshire with a set of actions to undertake to ensure their compliance with data protection law. The ICO has asked NHS Lanarkshire to provide an update of the actions taken within six months of the reprimand being issued.
No financial penalty was made against NHS Lanarkshire.
Recommended
- South Lanarkshire Council Publishes Staff Salaries in Data Leak
- ICO Finds Privacy Failings in Scottish Covid App
- Déjà Vu: NHS Lanarkshire Suffers Another Cyber-Security Breach
NHS Lanarkshire isn’t the only Scottish NHS board to have received a warning from the ICO this year.
For instance, in March, DIGIT reported on the news that NHS Highland had been given a reprimand after a data breach involving those likely to be accessing HIV services.
After sending an email to 37 recipients likely to be accessing HIV services, an email error — inadvertently using CC (carbon copy) instead of BCC (blind carbon copy) — had meant that the recipients could see other peoples’ personal email addresses.





