{"id":28173,"date":"2024-08-07T05:23:07","date_gmt":"2024-08-07T09:23:07","guid":{"rendered":"https:\/\/worldjusticenews.com\/news\/?p=28173"},"modified":"2024-08-07T05:23:07","modified_gmt":"2024-08-07T09:23:07","slug":"nhs-software-provider-faces-6m-fine-after-hackers-steal-tens-of-thousands-of-medical-records","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2024\/08\/07\/nhs-software-provider-faces-6m-fine-after-hackers-steal-tens-of-thousands-of-medical-records\/","title":{"rendered":"NHS software provider faces \u00a36m fine after hackers steal tens of thousands of medical records"},"content":{"rendered":"<p>A major NHS IT provider faces a penalty of just over \u00a36m for failures which led to a cyber attack and the theft of nearly 83,000 medical records.<\/p>\n<p>The Information Commissioner&#8217;s Office (ICO) has been investigating Advanced, which supplies vital systems for the health service,\u00a0<strong><a href=\"https:\/\/news.sky.com\/story\/ransomware-attack-on-nhs-systems-could-take-weeks-to-fix-major-it-provider-warns-12670649\" target=\"_blank\" rel=\"noopener\">since the breach<\/a><\/strong>\u00a0on 4 August 2022.<\/p>\n<p>The\u00a0<strong><a href=\"https:\/\/news.sky.com\/topic\/cyberattacks-6250\" target=\"_blank\" rel=\"noopener\">cyber attack<\/a><\/strong>\u00a0had wide-ranging implications, affecting the system used to dispatch ambulances, book out-of-hours appointments and issue emergency prescriptions.<\/p>\n<p>In a provisional ruling, the ICO says the software provider breached data protection law by failing to secure personal information belonging to 82,946 people.<\/p>\n<p>Their records were stolen in a ransomware attack by hackers who gained entry to Advanced&#8217;s computer systems using an account which did not have multi-factor authentication (MFA).<\/p>\n<p>Typically MFA would prevent cyber criminals from using stolen passwords to secure access.<\/p>\n<p>The data included sensitive information, phone numbers, medical records and information about how to gain entry to the properties of 890 people receiving care at home.<\/p>\n<p><strong>Read more from Sky News:<\/strong><br \/>\n<a href=\"https:\/\/news.sky.com\/story\/electoral-commission-reprimanded-over-cyber-security-failings-after-major-hack-13187307\" target=\"_blank\" rel=\"noopener\"><strong>Electoral Commission criticised for cyber security failings<\/strong><\/a><br \/>\n<strong><a href=\"https:\/\/news.sky.com\/video\/nhs-cyber-attack-data-stolen-from-blood-test-provider-by-criminal-group-published-online-13156897\" target=\"_blank\" rel=\"noopener\">Stolen NHS data &#8216;published online&#8217; by hackers<\/a><\/strong><\/p>\n<p>The disruption affected critical services such as\u00a0<strong><a href=\"http:\/\/news.sky.com\/topic\/nhs-5893\" target=\"_blank\" rel=\"noopener\">NHS<\/a><\/strong>\u00a0111 and meant other healthcare staff were unable to access patient records.<\/p>\n<p>People affected by the breach have been notified, and there is no evidence any data was published on the dark web.<\/p>\n<p>The ICO has provisionally decided to impose a fine of \u00a36.09m but the final ruling, and any penalty, will depend on the response from Advanced.<\/p>\n<p>John Edwards, UK Information Commissioner, said: &#8220;Not only was personal information compromised, but we have also seen reports that this incident caused disruption to some health services.<\/p>\n<p>&#8220;For an organisation trusted to handle a significant volume of sensitive and special category data, we have provisionally found serious failings in its approach to information security.&#8221;<\/p>\n<p>Advanced released an update following the data breach confirming patient information was copied from their systems before being encrypted.<\/p>\n<p>Typically ransomware attacks involve scrambling victims&#8217; data and making it inaccessible unless they pay up.<\/p>\n<p>The ransomware attack in 2022 led the Welsh Ambulance Service to declare a &#8220;major outage&#8221; of the system used to refer patients from 111 to out-of-hours GP providers.<\/p>\n<p>It said the issue had affected all four nations in the UK.<\/p>\n<p>In 2018, the NHS was severely affected by the\u00a0<strong><a href=\"https:\/\/news.sky.com\/story\/cost-of-wannacry-cyber-attack-to-the-nhs-revealed-11523784\" target=\"_blank\" rel=\"noopener\">WannaCry cyber attack<\/a><\/strong>, leading to thousands of cancelled appointments at a cost of nearly \u00a3100m.<\/p>\n<blockquote>\n<h4>What is ransomware?<\/h4>\n<p>Ransom malware &#8211; or ransomware &#8211; is malware that locks users out of their system and demands a ransom payment in order to get back in.<\/p>\n<p>The malware dates back to the late 1980s and has been the subject of several high profile incidents in recent years.<\/p>\n<p>Nowadays ransomware authors order that payment be sent via cryptocurrency or credit card, and attackers target individuals, businesses, and organisations of all kinds.<\/p>\n<p>The targets can be individual users or &#8211; as it seems is the case this time &#8211; larger organisations relied upon by millions of people.<\/p>\n<p>So how does ransomware lock up people&#8217;s systems?<\/p>\n<p>First the hacker or threat actor needs to gain access to a device or network.<\/p>\n<p>Having this access means they can use the malware to encrypt your device and data so they cannot be accessed.<\/p>\n<p>Once that&#8217;s done, the user will see a message demanding a payment in return for restoring access to their files or system.<\/p><\/blockquote>\n<p>Source: \u00a0<a href=\"http:\/\/worldjusticenews.com\/news\/wp-content\/uploads\/2016\/11\/sky-news-logo-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/worldjusticenews.com\/news\/wp-content\/uploads\/2016\/11\/sky-news-logo-1.png\" alt=\"Sky News\" width=\"100\" height=\"20\" \/><\/a> <a href=\"https:\/\/news.sky.com\/story\/nhs-software-provider-faces-6m-fine-after-hackers-steal-tens-of-thousands-of-medical-records-13192012\" target=\"_blank\" rel=\"noopener\">news.sky.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">A major NHS IT provider faces a penalty of just over \u00a36m for failures which led to a cyber attack and the theft of nearly 83,000 medical records. The Information Commissioner&#8217;s Office (ICO) has been <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2024\/08\/07\/nhs-software-provider-faces-6m-fine-after-hackers-steal-tens-of-thousands-of-medical-records\/\" title=\"NHS software provider faces \u00a36m fine after hackers steal tens of thousands of medical records\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":28174,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[2,4],"tags":[10578,5056,3911,10580,10579,4324,6270,6167,10581],"class_list":{"0":"post-28173","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-uk","9":"tag-advanced","10":"tag-cyber-attack","11":"tag-dark-web","12":"tag-ico","13":"tag-information-commissioners-office","14":"tag-nhs","15":"tag-ransomware","16":"tag-wannacry","17":"tag-welsh-ambulance-service","18":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/28173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=28173"}],"version-history":[{"count":1,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/28173\/revisions"}],"predecessor-version":[{"id":28175,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/28173\/revisions\/28175"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/28174"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=28173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=28173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=28173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}