COVID-19 in the UK: the Public Health Wales announces a data breach among Welsh residents tested positive
With an official statement, the Public Health Wales announced tonight that they registered a data breach among the personal data of Welsh residents who tested positive for COVID-19.
COVID-19 in the UK- The official statement of the Public Health Wales
According to what issued by the Public Health Wales, the data breach may put at risk all the registered residents and violates the law. “A risk assessment has been conducted and legal advice has been sought, both of which advise that the risk of identification of the individuals affected by this data breach appears low.”
According to Public Health Wales, this incident is probably the result of human error. Apparently it occurred on the afternoon of 30 August 2020 when the personal data of 18,105 Welsh residents who have tested positive for COVID-19 was uploaded by mistake to a public server where it was searchable by anyone using the site.
The statement reports: “After being alerted to the breach we removed the data on the morning of 31 August. In the 20 hours it was online it had been viewed 56 times. In the majority of cases (16,179 people) the information consisted of their initials, date of birth, geographical area and sex meaning that the risk they could be identified is low. However, for 1,926 people living in nursing homes or other enclosed settings such as supported housing, or residents who share the same postcode as these settings, the information also included the name of the setting. The risk of identification for these individuals therefore is higher but is still considered low.”
COVID-19 in the UK: what to do now?
The Public Health Wales declared that there is no evidence at this stage that the data has been misused. However, “we recognise the concern and anxiety this will cause and deeply regret that on this occasion we have failed to protect Welsh residents’ confidential information. Anyone concerned that their data or that of a close family member may have been breached and wanting advice should firstly read the FAQs at www.phw.nhs.wales then email us at PHW.data@wales.nhs.uk if they have any additional questions. People can also call Public Health Wales on 0300 003 0032 to discuss their concerns.”
The Public Health Wales assures that the Information Commissioner’s Office and Welsh Government have been informed and that they have commissioned an external investigation into the full circumstances surrounding the data breach and any lessons to be learned. “The investigation is being led by the Head of Information Governance at the NHS Wales Informatics Service.”
The public organization assured also that they have taken immediate steps to prevent a similar incident from happening again. Tracey Cooper, Chief Executive of Public Health Wales declared, “We take our obligations to protect people’s data extremely seriously and I am sorry that on this occasion we failed. I would like to reassure the public that we have in place very clear processes and policies on data protection. We have commenced a swift and thorough external investigation into how this specific incident occurred and the lessons to be learned. I would like to reassure our public that we have taken immediate steps to strengthen our procedures and sincerely apologise again for any anxiety this may cause people.”