NHS Software Provider Fined £3m Over Breach

NHS software services provider Advanced Computer Software Group has been fined £3.07 million by the Information Commissioner’s Office over security lapses that led to a ransomware attack on the NHS and placed the personal data of 79,404 people at risk.

The company provides software services to the NHS and other healthcare providers and processes personal data on behalf of its customers.

The fine relates to an August 2022 ransomware attack in which hackers gained access to Advanced’s health and care subsidiary.

The headquarters of the UK Information Commissioner's Office (ICO)
Image credit: Information Commissioner’s Office

Data access

The hackers were able to penetrate the company’s defences via a customer account that did not have multi-factor authentication, the ICO said.

At the time critical services were disrupted, including NHS 111, and other healthcare staff were left unable to access patient records.

The breach gave hackers access to patients’ phone numbers and medical records and details of how to gain entry to the homes of 890 people who were receiving care at home.

The ICO’s investigation concluded Advanced did not have sufficient security measures in place.

It criticised the “lack of complete coverage” of multi-factor authentication.

“The security measures of Advanced’s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information,” said information commissioner John Edwards at the time.

Security failures

“There is no excuse for leaving any part of your system vulnerable,” he added.

The ICO initially announced a provisional £6.09m fine, but halved it because of Advanced’s strong engagement with police, cybersecurity services and the NHS following the attack.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Amazon Joins Bidders To Acquire TikTok In US

But will Beijing or ByteDance allow sale? Amazon joins potential bidders for TikTok in US,…

8 hours ago

Elon Musk Dismisses Reports Of Imminent Departure From DOGE

Elon Musk dismisses report that Trump told cabinet that he expects Musk to leave his…

9 hours ago

Mark Zuckerberg Lobbies Trump To Avoid Antitrust Trial – Report

Mark Zuckerberg is reportedly lobbying President Donald Trump for a settlement to avoid antitrust trial…

11 hours ago

Bitcoin Slides To $81,000 In Trump Tariff Shock

As global markets reel from Trump's tariffs, the price of Bitcoin slides as investors seek…

11 hours ago

Amazon’s First Project Kuiper Satellites Slated For 9 April Launch

Rival for Starlink and OneWeb. United Launch Alliance slated to send 27 Kuiper satellites into…

14 hours ago

Trump’s Tariffs: Implications For Tech Sector

Semiconductor imports are free of Trump's tariff war, but concerns remain over imports of smartphones…

14 hours ago