Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Expert opinion: NHS reveals data leak

by Guru Writer
February 24, 2022
in Editor's News, Featured
Expert opinion: NHS reveals data leak
Share on FacebookShare on Twitter

This week, the NHS reported a data leak incident to the Information Commissioner’s Office, which puts third-party contractor cybersecurity risks in the spotlight.

 

What happened?

A former employee of PSL Print Management, a consultancy used by the NHS, requested all emails and text messages regarding his employment at the company. PSL obliged, but sent him a USB stick that seemingly contained the company’s entire email server contents, including thousands of patient letters that contained the PII of these patients.

 

According to sources, the confidential files included hospital appointment letters for women who had suffered miscarriages, test results of cervical screening exams and letters to parents of children needing urgent surgery at Alder Hey Children’s Hospital in Liverpool.

 

Some of the information dated back to 2015. This is despite data protection laws requiring that medical data be deleted as soon as it is no longer needed.

 

The ICO announced this week that it has launched an investigation.

 

The IT Security Guru asked a selection of experts for their opinions on the matter:

 

Roger A. Grimes, data-driven security evangelist at KnowBe4:

“It appears [the contractors] were sending out too much information in addition to the requested information… it was possibly all emails from an email server. It’s a pretty bad mistake. With that said, it isn’t known if this is a one-time mistake or was it done more times? Mistakes happen. Or was it a procedural error that was accidentally done over and over. Was it ever sent to someone who then took unauthorised advantage of the information? Not all data breaches are equal. You have to look at the intent of the parties involved with the breach. If all involved parties had good faith and didn’t spread the information beyond the initial incident, then the overall harm was very low. This isn’t a classical breach in the sense that a malicious actor broke into a network and stole information to do bad things. This was a well-intentioned person accidentally sent too much information. And instead of using the information in an unauthorised way, they reported the breach. All things considered, if this is a one-time event, it’s not the worst thing I’ve read about. Even if it happened more than once…as long as the information was not used in an unauthorised manner beyond the unintentional data leak. The vendor should absolutely investigate how it was allowed to happen and put in policy, tools, and education to make sure it doesn’t happen again.”

 

Robert Byrne, field strategist at One Identity:

“There was a failure of Data Governance and oversight procedures here. Encryption for mail and attachments is common, so the main issue here seems to have been a failure to separate operational level access and data level access. In other words, a privileged operations user was able to export mail and content in clear and export it to a USB stick, all without appropriate oversight.  Normal procedure would be to separate those privileges or at least ensure that the relevant data owner approved the data transfer.  Clear separation of duties, especially for privileged administrative staff, combined with periodic data access reviews have been shown to significantly reduce the risk of data leaks such as this.”

 

Martin Jartelius, CSO at Outpost24:

“We have several problems to address that contributed to the massive NHS leak. Firstly, evidentially patient data is sent unencrypted via email between employees. This is not an acceptable practice. Secondly, those emails are then retained on the personal accounts for a very long duration even though they contain this sensitive data. Thirdly, the emails are clearly retained beyond the end of employment in an accessible format, otherwise it would not have been possible to accidentally include other individuals emails. Fourthly, when extracting those emails on the former employee’s request, the information retained in the emails has not been reviewed for patient confidentiality. There are likely more issues here, but those are the most apparent ones, taking the available information at face value.”

 

Felix Rosbach, product manager at comforte AG:

“The shocking data breach affecting the tens of thousands of NHS patients might make you question whether healthcare providers are serious about data privacy and security. This report should trigger alarm bells within the healthcare sector. After all, it is difficult to grasp a situation in which thousands of subjects have had their most personal and sensitive health information compromised.

 

“The more these types of data breaches occur, the more the general public understands that protecting borders and perimeters around sensitive data isn’t enough—effective data security needs to be applied directly to sensitive information in the form of data-centric security, including methods such as tokenisation or format-preserving encryption. By tokenizing patient information as soon as it enters the data ecosystem, these organisations can continue to work with sensitive data in its protected state due to data format preservation. Better yet, if (or when) threat actors gain access to tokenised data, they cannot comprehend it or leverage it for personal gain or other nefarious purposes. If a healthcare organisation isn’t actively assuming the worst and exploring data-centric security to protect patient data, the long-term prognosis doesn’t look good.”

 

ShareTweet
Previous Post

The Inside Man Season 4: The Future of Cybersecurity Awareness Training

Next Post

Construction companies receive cybersecurity guidance

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol