Department of Health broke the Data Protection Act through security failings on its Medical Training Application Service (MTAS) website. The site exposed doctors personal details, including religious beliefs and sexual orientation which were accessible to anyone using the site. The DoH has been required to encrypt any personal data on its websites. Regular penetration and vulnerability testing must also be carried out on developing applications and systems to minimize unauthorized access. The information commissioner Richard Thomas has ruled that staff are trained on compliance with the data protection Act.”]
Source: https://www.csoonline.com/article/2122150/department-of-health-broke-data-protection-act.html

