NHS Trust reacts angrily to record £325,000 ICO fine

02.06.2012
Brighton and Sussex University Hospitals NHS Trust has reacted furiously after being handed a record £325,000 fine by the Information Commissioner for failing to correctly dispose of hundreds of unencrypted hard drives containing patient and staff records.

The ICO sent a letter of intent to the trust regarding the drive loss in January and has now followed up with the largest Civil Monetary Penalty (CMP) it has ever levied.

At the time on the basis that the issue was caused by a sub-contractor tasked with disposing of 1,000 hard drives in September and October 2010.

Up to 252 of these drives later turned up for sale on eBay, where some of them were later purchased in an unwiped, compromised state by third parties who alerted the trust to the issue.

"The Information Commissioner has ignored our extensive representations," said Brighton and Sussex University Hospitals chief executive, Duncan Selbie in an official statement.

"It is a matter of frank surprise that we still do not know why they have imposed such an extraordinary fine despite repeated attempts to find out, including a freedom of information request which they interestingly refused on the basis that it would 'prejudice the monetary penalty process'," he said.