Connect with us

Health

Manx Care Fined for Failure to Protect Patient Info

Manx Care has acknowledged the significant failures and outlined how it is reforming its procedures.

Published

on

The Information Commissioner has imposed a penalty of £170,500 on Manx Care for infringements of the data protection legislation. 

This comes after Manx Care emailed an insecure attachment containing one patient’s confidential health data to more than 1,870 recipients in October last year.

Manx Care was subject to an enforcement notice at that time and a further enforcement notice was issued in February 2022.  

The Info Commissioner said that Manx Care has failed to comply with those notices which has led to the penalty notice.

The Information Commissioner said: ‘It is unacceptable for such a significant personal data breach to occur. The data protection legislation, along with the Caldicott Principles and medical professionals’ codes of practice, require patient data to be confidential, with access to that data restricted to those with a ‘need to know’.  

‘Previous enforcement notices attempted to get Manx Care to appropriately protect the patient data with which it is entrusted. The continued failure of Manx Care to implement a secure means of communicating patient data has ultimately led to the imposition of this penalty.

The exercise of the power to impose a penalty is one of last resort and I am conscious that there will inevitably be public opinion against, and in favour of, this penalty. The decision to stay the payment of the penalty provides another opportunity for Manx Care to take the necessary action; public funds will only be diverted if it fails to do so.  It is now up to Manx Care.’

In response to this, Manx Care has said that it would ‘acknowledge the significant failures outlined in the Enforcement Notice, which make for uncomfortable reading, and would like to offer our sincere and unreserved apologies to those individuals whose data was breached through no fault of their own’.

It added: ‘In the short term, Manx Care is actively progressing a number of technical and organisational measures in order to mitigate further risk by addressing the most immediate risks quickly whilst a longer term programme is implemented, which will result in the organisation becoming a compliant one where information governance is at the forefront of our corporate agenda, supported by the policies, procedures and training required to achieve this.

‘This will result in our ability to deal with data protection and information governance matters robustly, fully investigate and determine the root cause of any compliance issues, ensure appropriate steps are taken to further mitigate any risk, and effect a culture change across the organisation with regard to the secure management and processing of patient information.’

In early July, 3FM’s Jason Roberts reported that the health and care provider had been fined £170,000, with Manx Care saying this was inaccurate. This report was released by Jason before the fine was imposed, but was otherwise accurate.