UK private health records available to buy for £4
blogs.computerworlduk.com
blogs.computerworlduk.com
Er, right.
I should note that this is not something against Indians, most of the time it was due to the problems with working across two security boundaries and the lack of acceptance of the problems and realities of doing so, combined with what were effectively unrealistic promises and a complete lack of understanding of the two cultures, gaps and overlaps.
To put it another way, any system where data is held in trusted environment A, but accessed from partially trusted environment B is dependent on the security of both A and B. However, while environment A is fully trusted, environment B isn't, and for (sometimes) good reason. The problem arises when instead of proper controls what happens is a bizarre form of security theatre starts to arise, and subsequently gaps start popping up all over environment B that would be otherwise considered acceptable in environment A.
It is not realistic to securely manage information with a strong trust requirement in an untrusted environment on a permanent basis. It is even less realistic to do so on the basis of contractual obligation as an alternative to routine checks and balances.
The digital age is good for a lot of things, but it was a lot harder to carry a filing cabinet, and thus harder to steal records.
No.
http://www.theregister.co.uk/2009/01/21/work_pensions_it_bud...
http://www.theregister.co.uk/2008/03/03/doh_it_budget_oversh...
I could post all the examples but I would get banned for flooding.
(No that is not fishing for job offers.)