Around 14,000 employees at an NHS hospital trust in Liverpool have had their personal data leaked via email due to an incident of human error.
The Data Leak
The data is believed to have been leaked through an excel file sent to hundreds of NHS managers and 24 external accounts. The excel document contained personal and sensitive payroll information.
The Liverpool University Hospital Foundation Trust (LUHFT), comprises the Royal and Aintree hospitals in Liverpool.
An apology letter has been sent by trust chief executive, James Sumner, to all the victims of the data leak.
Part of the letter reads:
“The spreadsheet file included a hidden tab which contained staff personal information. Whilst it was not visible to those receiving the email, it should not have been included in this spreadsheet. The information in this hidden tab included names, addresses, DOBs, NI numbers, gender, ethnicity, salary, it did not include bank account details.“
Sumner also confirmed that each of the 24 external recipients have been notified of the sensitivity of the file, and they have also confirmed deletion of the file.
“The data was emailed to managers within the organisation, we set about deleting the email and the data file from our systems within an hour of the error being identified and action has been taken to prevent this from happening again.“
“We have also commissioned an independent, external review to assist in how we establish shared learning from the experience.“
The incident has also been reported to the Information Commissioner’s Office.
The letter closes with James Sumner stating:
“We have apologised to our colleagues for this error and are providing them with the full information and support they need. I want to reassure our patients and the communities we serve that we follow all the rules to protect their information and we take data security extremely seriously.“
Human Error
Human error is one of the biggest contributors to cybersecurity incidents and data leaks. According to a recent study by IBM, around 95% of cybersecurity incidents involve a factor of human error, making it a major concern for all cybersecurity professionals.
Human error includes a wide range of incidents, including clicking on phishing links, using weak passwords, or failing to update software.
Accidental direct data leaks such as this one suffered by the NHS rarer, but remain a significant threat to any organisation’s data security.
Human error is not always related to individual actions, and often they are encouraged by systemic issues and poor management. For example, in this recent incident it seems likely that the LUHFT has ineffective policies and procedures relating to handling sensitive data. While the Trust has been able to respond effectively to this leak, they did not have effective policies in place to prevent the leak occurring in the first place.







