Skip to main content

HCA International fined 200k for Data loss #ITSecurity #DataSecurity #unencrypted


HCA International Ltd, private health firm are the latest to be fined by the ICO. They have been fined £200,000 for failing to keep data secure after it was found that conversations had by IVF patients were online.
Audio recordings of interviews with patients were being sent to a company unencrypted in India for transcription. The Indian company was unable to maintain secure access due to an unsecure server.
By failing to ensure its subcontractor had acted responsibly, HCA International failed to comply with the seventh data protection principle.
More details on the monetary penalty notice click here
Supplier Risk is a huge concern for most companies - You may have all the bells and whistles when it comes to security your infrastructure but your partners may not. Failing to ensure due diligence in the Supply chain costs - with HCA it was £200,000 - next year it would of been much more!! #EUGDPR

Comments

Post a Comment

Popular posts from this blog

Microsoft Azure faults knock websites offline

Faults with Microsoft's cloud computing platform have knocked many third-party sites offline, as well as disrupting the US firm's own products. Microsoft Azure's status page  says problems began at 00:52 GMT across the globe. Its European operations are taking the longest to fix. Access to Microsoft's Office 365 on-line suite of apps and its Xbox Live gaming facility are among services affected. The faults could set back the company's efforts to sell Azure. Microsoft is attempting to make gains on the market leader, Amazon Web Services, as well as IBM, Google and others offering rival products. Their pitch is that it is more efficient for companies to rent computing power from a large tech firm than owning and managing their own computer servers or going to a smaller provider. "Microsoft is investigating an issue affecting access to some Microsoft services," said Adrienne Hall, general manager at the company. "We are working to restore ...

Top 5 Considerations for Effective Security Awareness #ITSecurity #SecurityAwareness #PeopleIssue

"If you want to change attitudes, start with a change in behaviour"  This quote was taken by William Glasser, an American psychiatrist. I think it's really relative to this subject, as a user, you may be fully aware of IT/Cyber Security and how your actions can reflect on the company you work for...However it doesn't mean it is going to change the way you work. As a company you need to start to change users   behaviours ... The below is taken from the company I work for ZeroDayLab  blog, which I feel, are the key components to Security Awareness/Behaviour Training. Top 5 are below (part 2 to follow) Interested in the datasheet? please let me know... Security, The Risk of Human Error...& a Tricky Thing Called Motivation… Top 10 Considerations for Truly Effective Security Awareness Training Even though 52% of breaches are attributed to human error, security awareness is still quite a new thing for many companies....