The Information Commissioner’s Office (ICO) has provisionally imposed a £6m fine on an NHS software program supplier over a knowledge breach which affected greater than 80,000 individuals.
The breach happened in 2022 and included delicate private data together with medical records and “how to acquire entry to the houses of 890 individuals”.
But the ICO careworn it was a provisional fine, and it will wait to hear from Advanced Computer Software Group earlier than making a ultimate determination.
It mentioned its preliminary findings had been that private data belonging to 82,946 individuals had been “exfiltrated” by hackers.
“Not solely was private data compromised, however we’ve got additionally seen studies that this incident brought about disruption to some well being companies, disrupting their potential to ship affected person care,” mentioned John Edwards, the Information Commissioner.
“A sector already below stress was put below additional pressure due to this incident.”
The ICO mentioned individuals who had been affected by the hack had been notified, and Advanced had not been in a position to discover proof that data had been leaked on the darkish net.
Criminal hackers took offline seven of Advanced’s well being methods, together with software program used for affected person check-ins, medical notes and the NHS 111 service.
Doctors instructed the BBC on the time it might take months to course of mounting piles of medical paperwork attributable to the cyber-attack.
It left some GP companies compelled to take notes utilizing pen and paper somewhat than utilizing digital methods.
The hackers had been in a position to acquire entry to the knowledge by utilizing a buyer’s account which didn’t have ample safety.
But the ICO says it believed Advanced ought to have carried out measures to defend in opposition to this vulnerability.
“I’m selecting to publicise this provisional determination right this moment as it’s my responsibility to guarantee different organisations have data that may assist them to safe their methods and keep away from comparable incidents sooner or later,” mentioned Mr Edwards.
“I urge all organisations, particularly these dealing with delicate well being information, to urgently safe exterior connections with multi-factor authentication.”


