{"id":24778,"date":"2025-03-27T00:25:34","date_gmt":"2025-03-27T01:25:34","guid":{"rendered":"http:\/\/medexperts.pro\/?p=24778"},"modified":"2025-03-27T01:30:05","modified_gmt":"2025-03-27T01:30:05","slug":"nhs-software-provider-fined-3m-over-data-breach-after-ransomware-attack","status":"publish","type":"post","link":"https:\/\/medexperts.pro\/?p=24778","title":{"rendered":"NHS software provider fined \u00a33m over data breach after ransomware attack"},"content":{"rendered":"<div><\/div>\n<div data-component=\"text-block\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">An NHS software provider has been fined \u00a33m by the Information Commissioner&#8217;s Office (ICO) over security failings that led to a ransomware attack on the NHS.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The Advanced Computer Software Group was fined for a breach that put personal information of 79,404 people at risk, the UK&#8217;s data protection watchdog said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The firm provides IT and software services to organisations around the country, including the NHS and other health providers, handling information in its role as a data processor.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The breach<!-- --><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-62506039\" class=\"sc-c9299ecf-0 beIoQm\"> took place in August 2022<!-- --><\/a>, when hackers gained access to patients&#8217; phone numbers and medical records as well as details of how to gain entry to the homes of 890 people receiving care at home.<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The unidentified hackers were able to gain access to the information by using a customer&#8217;s account that did not have sufficient protection in the form of multi-factor authentication.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The regulator&#8217;s investigation concluded that Advanced did not have appropriate security measures in place prior to the incident.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The cyberattack led to the disruption of critical services including NHS 111, and left some healthcare staff unable to access patient records.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Software used to facilitate patient check-ins was also impacted.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Last year, the regulator criticised Advanced over the incident, which placed &#8220;further strain&#8221; on a &#8220;sector already under pressure&#8221;.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">While the company had installed multi-factor authentication across many of its systems, &#8220;the lack of complete coverage&#8221; was criticised by Information Commissioner John Edwards.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;The security measures of Advanced&#8217;s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information,&#8221; Mr Edwards said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">He added the fine should serve as a &#8220;stark reminder&#8221; to organisations to ensure they have &#8220;robust security measures in place&#8221;.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;There is no excuse for leaving any part of your system vulnerable,&#8221; Mr Edwards added.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Last year, the ICO announced it intended to impose a <!-- --><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c78llg7n5d5o\" class=\"sc-c9299ecf-0 beIoQm\">provisional \u00a36m fine<!-- --><\/a> on Advanced for the breach.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">However, the watchdog said the sum had been halved because of the proactive engagement of Advanced with police, cyber security services and the NHS following the attack.<!-- --><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An NHS software provider has been fined \u00a33m by the Information Commissioner&#8217;s Office (ICO) over security failings that led to a ransomware attack on the NHS.<\/p>\n","protected":false},"author":1,"featured_media":24780,"comment_status":"close","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-24778","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-health"],"_links":{"self":[{"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/posts\/24778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/medexperts.pro\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24778"}],"version-history":[{"count":2,"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/posts\/24778\/revisions"}],"predecessor-version":[{"id":24781,"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/posts\/24778\/revisions\/24781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/medexperts.pro\/index.php?rest_route=\/wp\/v2\/media\/24780"}],"wp:attachment":[{"href":"https:\/\/medexperts.pro\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/medexperts.pro\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/medexperts.pro\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}