{"id":204,"date":"2007-04-26T11:57:39","date_gmt":"2007-04-26T10:57:39","guid":{"rendered":"http:\/\/resource.bmj.com\/bmj\/2007\/04\/26\/candidates-details-were-freely-available-in-mtas-security-breach\/"},"modified":"2007-04-26T11:57:39","modified_gmt":"2007-04-26T10:57:39","slug":"candidates-details-were-freely-available-in-mtas-security-breach","status":"publish","type":"post","link":"https:\/\/stg-blogs.bmj.com\/bmj\/2007\/04\/26\/candidates-details-were-freely-available-in-mtas-security-breach\/","title":{"rendered":"Candidates&#8217; details were freely available in MTAS security breach"},"content":{"rendered":"<p>Personal details of applicants involved in the already discredited MTAS system were available for all to see yesterday &#8212; until the Department of Health stepped in and closed the loophole which had allowed anyone to view the page without the need for a password.<!--more--><\/p>\n<p>Channel 4 News ran with the story yesterday, after discovering that the\u00a0URL of the page containing all this information was not password protected.<\/p>\n<p>Although this address should only have been known to those who were authorised to access the site &#8212; primarily those interviewing candidates &#8212; the\u00a0URL was leaked. This made it possible for anyone who had been given that address to go straight to the page, bypassing the initial home page.<\/p>\n<p>As soon as the Department of Health became aware of the\u00a0security breach, early yesterday evening, they put a password on the page. But in the meantime confidential information about junior doctors &#8212; including their religion and\u00a0sexual orientation &#8212; could have been viewed by anyone who knew the\u00a0URL.\u00a0<\/p>\n<p>Dr Jo Hilborne, chairman of the BMA Junior Doctors Committee, said it was a breach of security &#8220;on an appalling scale&#8221;.<\/p>\n<p>\u201cWhat little faith anyone had left in this shambolic system has just evaporated,&#8221; she said. &#8220;The ease with which anyone could have accessed highly sensitive information about thousands of people is frankly shocking.\u00a0 The BMA has raised concerns about the security of the MTAS website on more than one occasion.\u00a0 The Department of Health had months to put it right and failed.\u00a0 There can be no excuse for this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Personal details of applicants involved in the already discredited MTAS system were available for all to see yesterday &#8212; until the Department of Health stepped in and closed the loophole which had allowed anyone to view the page without the need for a password. [&#8230;]<\/p>\n<p><a class=\"btn btn-secondary understrap-read-more-link\" href=\"https:\/\/stg-blogs.bmj.com\/bmj\/2007\/04\/26\/candidates-details-were-freely-available-in-mtas-security-breach\/\">Read More&#8230;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-204","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/posts\/204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/comments?post=204"}],"version-history":[{"count":0,"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/posts\/204\/revisions"}],"wp:attachment":[{"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/media?parent=204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/categories?post=204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stg-blogs.bmj.com\/bmj\/wp-json\/wp\/v2\/tags?post=204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}