We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Dáil
‹ Leaders’ Questions.

Stolen laptop containing blood donor data

Summary

A laptop stolen in New York held encrypted personal data on more than 170,000 blood donors. The Taoiseach outlines the IBTS’s data-sharing arrangement, its notification of the Data Protection Commissioner and plans to contact affected donors, while acknowledging the importance of data security and public confidence.

It emerged yesterday that a laptop containing personal information on over 170,000 people who have donated blood to the Irish Blood Transfusion Service was stolen on a street in New York earlier this month. I have concerns about the security of personal information supplied by people to Government bodies and State agencies. This is not the first time personal information of this nature has been lost. We discovered recently, in response to parliamentary questions tabled by my colleague, Deputy Quinn, that more than 80 laptops, desktops or blackberries have been stolen from, or lost by, Departments over the past five years. There was considerable controversy in the United Kingdom late last year when a computer disk, on which personal information about 25 million people was stored, was lost. At that time, the Office of the Data Protection Commissioner stated that there was no guarantee that something similar could not happen here. When people supply personal information to a State agency, it is reasonable for them to have confidence that it will be kept securely. The information supplied to the Irish Blood Transfusion Service can be quite sensitive.

I would like to ask the Taoiseach a couple of questions. What was the extent of the information on the laptop that was stolen in New York? I understand that the Irish Blood Transfusion Service has written to the people concerned. We should be given details about the extent of the information stored on the laptop. Will the Taoiseach ask the Office of the Data Protection Commissioner to undertake a full audit of the security procedures and measures which are in place to govern the protection of personal information that is supplied to Departments? We need to have a full overview of the security in place so that when information is supplied by people to Departments, which they believe is supplied on a confidential basis, it is not open to theft or being accessed by criminals for the purpose of identity theft or even by the staff of the agencies concerned in an unauthorised way.

Comment on this

That is why the Government wants e-voting.

Comment on this

The Irish Blood Transfusion Service, IBTS, has given me a report on the incident. The IBTS entered into an agreement with the New York Blood Centre, NYBC, for the provision of a data query tool last October. The purpose of the data warehousing reporting tool is to improve the existing IBTS blood banking system computer, which is called Progresa. The issue the IBTS was trying to deal with was improving its own security and service, which is why it had set up the New York agreement. Under the terms of the agreement, the IBTS exported data on a CD from its Progresa system for the period 2 July 2007 to 11 October 2007. The data were encrypted using a 256-bit key encryption prior to export on the CD. The data contained details of 171,324 donor records, including name, address, date of birth, gender, blood group and contact telephone number. The CD holding the records was handed over to personnel of the NYBC in Ireland during the week beginning 3 December last and it is retained by the NYBC in a physically secure environment. No data stored on the encryption volume can be read or decrypted without using the correct password, key files or encryption keys.

The IBTS and the NYBC consider that the risk of any person being in a position to bypass the password controls and decrypt the data is extremely remote.

Comment on this
Sean Sherlock Deputy Seán Sherlock Labour Party

A hacker would sort that out in a few minutes.

Comment on this

On the evening of 7 February, an NYBC staff member was mugged outside his home in New York and the laptop issued to him by the centre containing these encrypted files was stolen. While the police have been notified and an investigation into the robbery is ongoing, the laptop has not been recovered. The IBTS and the NYBC are very concerned about the theft and the IBTS informed the Data Protection Commissioner on 11 February about the matter. The IBTS is writing to each donor affected on 22 February to reassure them and to advise them of the possibility, however remote, that personal data might be accessed. It is also writing to general practitioners and hospitals who will, in turn, contact the patients concerned. I am also informed that an information line has been set up for anyone with concerns. The number is 1850731137. The IBTS also advises it would be glad of the opportunity to brief interested Deputies and representatives will make themselves available today at a suitable time to be arranged with the Minister for Health and Children. They will brief any Member with questions or concerns.

Comment on this

I thank the Taoiseach for his reply. One of our concerns must be to ensure continuing confidence in the blood bank so that people do not withhold donating blood as a result of this. It is ironic that the IBTS set out to seek help in securing the information only to end up with somebody walking around with it on a laptop on a street in New York where it ended up being stolen. There is something incredibly sloppy about that.

I refer to the second part of my question. Unfortunately, this incident is not a one off, as there have been other thefts of computer equipment, disks and so on from Departments. Deputy Shortall tabled questions to the Department of Social and Family Affairs about the unauthorised accessing of personal information by staff. One prominent case occurred in recent times. Will the Taoiseach ask the Data Protection Commissioner to undertake a full review of the security arrangements surrounding personal information supplied to Departments, which is held electronically? There is a necessity to restore people's confidence that the information they are supplying to Departments will not be accessed, lost or carried around on a disk or a laptop by staff of an agency on the streets of Dublin or New York and that the dangers of personal information getting into the hands of criminals or others and the dangers associated with identity theft will be minimised. Serious attention needs to be given to this issue and the way to proceed is to ask the Data Protection Commissioner, in the first instance, to conduct a full audit of security measures, make a report and for the Government to take whatever necessary action needs to be taken to increase security and to protect people's identities.

Comment on this

In fairness to the staff of the IBTS, they were conscious that the service's blood banking computer system required improvement and they set out to do that. They went to where they had been advised were the best records in the world. What happened was unfortunate but these things happen. Everyone will say one can hack into anything nowadays——

Comment on this

Even e-voting machines.

Comment on this

——but the IBTS and the NYBC strongly believe this is an extremely remote possibility. However, they will take all the necessary precautions. I agree with Deputy Gilmore that the credibility of the system and the security of the data of people who give blood are important.

Public service bodies, as well as other organisations or individuals who hold personal data, are subject to the requirements of the Data Protection Acts, 1998 and 2003, which provide for the appropriate compilation, storage and use of such data. Among the requirements placed on organisations and individuals regarding the management of personal data is the need to keep it secure against unauthorised access. The specific statute provision is as follows:

A data controller shall, as respects personal data kept by him or her, comply with the following provisions:. . .(d) appropriate security measures shall be taken against unauthorised access to, or unauthorised alteration, disclosure or destruction of, the data, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.

Organisations and individuals that hold personal data have to register with the Data Protection Commissioner. This registration gives the details of the type of personal data held. That applies to all organisations, which must designate a data controller who will have statutory responsibility and ensure compliance by the organisations with the Acts. Many laws and regulations cover unauthorised disclosure and fines on indictment are set out in the legislation.

The Deputy referred to individual Departments. I have seen parliamentary questions and replies over the past two weeks from all Departments about security and data. Those replies should be on the record of the House. The Deputy also asked for the Data Protection Commissioner to examine this issue and I will bring that to his attention.

Comment on this