Will Your Patient Forms Cost You Thousands £££?

The last thing any practice or business wants is to be fined over £250,000 by the Information Commissioner’s Office (ICO) in the United Kingdom for not storing sensitive special category data securely. Personal health data is one of many special categories of data under UK GDPR and the Data Protection Act of 2018 (DPA) that need to be treated with great care due to sensitivity. While these data protection regulations are relatively new, we are starting to see how the government expects practices and businesses to treat health related information. Many businesses don’t understand the gravity of their current processes and that this type of penalty is completely avoidable.

Penalties are in Effect NOW

The most significant fine in the health care sector thus far was levied in late 2019 against a London based pharmacy that did not handle health data in a proper manner. This pharmacy was fined £275,000 for failure to ensure the security of special category data and ordered to improve its data protection processes within three months or face additional consequences. You can read the citation in its entirety, although what stands out is how the citation directly references Article 32 of GDPR titled “Security of Processing.”

Article 32 states in relevant part (emphasis added in bold):

1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

  • (a) the pseudonymisation and encryption of personal data;
  • (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  • (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

2. In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

Health data is a special category of data under UK law, meaning that anything with personal or protected health information needs to have the highest levels of security. Article 32 lists a number of areas where health businesses and practices can improve their data security, including “appropriate technical and organisational measures,” “encryption of personal data,” the ability to ensure security, and protections against “unauthorised disclosure of, or access to personal data.”

Time to Review Your Processes

Practices are still learning and adjusting to UK GDPR and DPA 2018, though there are 5 questions that you should start asking yourself today to reduce your chance of being fined:

  1. Does your practice still email documents and forms with patient health information back and forth?
  2. Is your patient information encrypted?
  3. Do you have a system in place to ensure the security of patient information?
  4. If you still use paper files, are they securely stored and maintained?
  5. Do you receive any identifiable health information into an email inbox?

These questions are just a starting point, but your answers can help determine next steps for you to ensure the highest levels of data security. FormDr allows you to send and receive online forms that are encrypted and secure. All data is stored in our secure portal so you do not need to worry about sensitive data in your inbox. We take the security of patient data seriously so that you have one less item to stress about. Schedule a free consultation and demo today!