Dr Neil Paul

Data security is again a hot topic

· Originally published in GP magazine, Jul 2009

Originally published in GP magazine .

Written for GP magazine around 2009. This is the version I submitted - the published article may have been edited.

Data security is again a hot topic. Previously there was a big outcry when several public servants left laptops and data sticks in public places, giving away private information on members of the public. A senior police officer was criticised for carrying secret plans about an anti-terrorist operation on top of a pile of papers in full view of telephoto lenses. This last week there has been a lot of fuss about minor and major celebrities’ phones being hacked into for sordid details of their private lives. Not only has this brought it back into the news but it has shown that not all data loss is accidental - some of it is done on purpose, through foul means, by clever individuals.

What’s any of this got to do with GPs, you might ask? Well, on the Guardian online an ex-private investigator revealed some people specialised in getting medical information about targets and their favourite method was to pose as an A&E nurse ringing for information about a critically ill patient and ask for the medical summary to be faxed over asap.

You might think you would recognise the name and think twice, but would you the name of someone who had just won an award for charity that they were trying to dig the dirt on, or someone who the police had just arrested for serious crimes?

A really determined hacker can use all sorts of kit to listen in to signals, break encryption and clone phones, but most books on hacking agree that the most successful ways of gaining information are by exploiting people’s laziness and by bluffing your way into being given the information or password.

So, some tips:

  • Don’t give out information on the phone to received calls - always ring back on a number you have independently verified.
  • Do have a list of the most common safe haven faxes you can fax information to securely by your fax machine, and make sure the number you are using is one of them.
  • Do make everyone read and sign your security and confidentiality policy.
  • Do ask visitors to sign in and use badges.
  • Do lock rooms and computer terminals when not in use.
  • Do use security levels where available to restrict access to parts of the system that people don’t need to get into.
  • Do ask people you don’t know for ID, even if they look official or have an NHS badge around their necks.
  • Do teach people to use strong passwords or passphrases.
  • Don’t write down passwords in insecure locations.

From a clinician’s point of view, particularly with laptops and mobile phones, it is important to use passwords and PIN numbers to lock them. Although it can be a pain when unlocking them ten times a day, just think of the trouble if it is stolen.

Most mobile operators have a number that you can ring from a landline to check your voicemail. This was exploited by hackers who rang them when they thought the person wouldn’t know and tried several default PIN numbers, e.g. 0000 or 1234, or inspired guesses, e.g. dates of birth or anniversaries, and managed to get into a lot of people’s accounts to listen to their messages. To get round this, make sure you activate a PIN on voicemail and change it from the default to a non-obvious one.

A new feature on my favourite device, the iPhone, is that if lost you can now wipe all data on it remotely, and no doubt this function will spread to other devices and laptops.