Cambridge hospital trust apologises after data breaches affect thousands

Cambridge University Hospitals NHS Foundation Trust has issued an unreserved apology for two significant data breaches involving the personal information of nearly 22,500 patients. The incidents occurred when sensitive maternity and cancer patient data was inadvertently included in spreadsheets released in response to Freedom of Information requests. Although the data did not contain home addresses or dates of birth, it exposed names, hospital numbers, and specific medical details, highlighting critical vulnerabilities in how public sector organizations handle information transparency. The trust’s response demonstrates the complex ethical considerations inherent in modern data governance. While immediate steps were taken to contain the breaches and review past records, the decision regarding patient notification was nuanced. For maternity patients, direct contact was withheld to protect privacy regarding undisclosed pregnancies, whereas cancer patients were notified individually. This distinction underscores that effective data protection requires balancing statutory transparency obligations with the duty to minimize harm and respect patient dignity, rather than applying a one-size-fits-all approach to breach mitigation. This article is highly relevant to the open data community because it illustrates the severe risks associated with poorly sanitized datasets. It serves as a cautionary tale that the principle of openness must not compromise confidentiality, particularly when dealing with vulnerable populations. The incident emphasizes the urgent need for rigorous data sanitization protocols and automated checks before any information is released publicly. Ultimately, it reinforces that true open data practices require robust administrative controls to prevent human error from eroding public trust in institutional data stewardship.

Source: cambridge-news.co.uk
Published on 2023-12-07