{"id":29145,"date":"2025-03-27T05:41:42","date_gmt":"2025-03-27T09:41:42","guid":{"rendered":"https:\/\/worldjusticenews.com\/news\/?p=29145"},"modified":"2025-03-27T05:41:42","modified_gmt":"2025-03-27T09:41:42","slug":"nhs-software-provider-fined-3m-over-data-breach-after-ransomware-attack","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2025\/03\/27\/nhs-software-provider-fined-3m-over-data-breach-after-ransomware-attack\/","title":{"rendered":"NHS software provider fined \u00a33m over data breach after ransomware attack"},"content":{"rendered":"<div class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\"><b class=\"ssrcss-1xjjfut-BoldText e5tfeyi3\">An NHS software provider has been fined \u00a33m by the Information Commissioner&#8217;s Office (ICO) over security failings that led to a ransomware attack on the NHS.<\/b><\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The Advanced Computer Software Group was fined for a breach that put personal information of 79,404 people at risk, the UK&#8217;s data protection watchdog said.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The firm provides IT and software services to organisations around the country, including the NHS and other health providers, handling information in its role as a data processor.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The breach<a class=\"ssrcss-f6h2dj-InlineLink e1kn3p7n0\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-62506039\" target=\"_blank\" rel=\"noopener\">\u00a0took place in August 2022<\/a>, when hackers gained access to patients&#8217; phone numbers and medical records as well as details of how to gain entry to the homes of 890 people receiving care at home.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The unidentified hackers were able to gain access to the information by using a customer&#8217;s account that did not have sufficient protection in the form of multi-factor authentication.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The regulator&#8217;s investigation concluded that Advanced did not have appropriate security measures in place prior to the incident.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">The cyberattack led to the disruption of critical services including NHS 111, and left some healthcare staff unable to access patient records.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Software used to facilitate patient check-ins was also impacted.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Last year, the regulator criticised Advanced over the incident, which placed &#8220;further strain&#8221; on a &#8220;sector already under pressure&#8221;.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">While the company had installed multi-factor authentication across many of its systems, &#8220;the lack of complete coverage&#8221; was criticised by Information Commissioner John Edwards.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;The security measures of Advanced&#8217;s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information,&#8221; Mr Edwards said.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">He added the fine should serve as a &#8220;stark reminder&#8221; to organisations to ensure they have &#8220;robust security measures in place&#8221;.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">&#8220;There is no excuse for leaving any part of your system vulnerable,&#8221; Mr Edwards added.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">Last year, the ICO announced it intended to impose a\u00a0<a class=\"ssrcss-f6h2dj-InlineLink e1kn3p7n0\" href=\"https:\/\/www.bbc.co.uk\/news\/articles\/c78llg7n5d5o\" target=\"_blank\" rel=\"noopener\">provisional \u00a36m fine<\/a>\u00a0on Advanced for the breach.<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph e1jhz7w10\">However, the watchdog said the sum had been halved because of the proactive engagement of Advanced with police, cyber security services and the NHS following the attack.<\/p>\n<p>Source: <a href=\"https:\/\/www.bbc.co.uk\/news\/articles\/cp3yv1zxn94o\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">An NHS software provider has been fined \u00a33m by the Information Commissioner&#8217;s Office (ICO) over security failings that led to a ransomware attack on the NHS. The Advanced Computer Software Group was fined for a <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2025\/03\/27\/nhs-software-provider-fined-3m-over-data-breach-after-ransomware-attack\/\" title=\"NHS software provider fined \u00a33m over data breach after ransomware attack\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":29146,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[109,2,4],"tags":[11140,5056,7120,2134,1009,4324,6270],"class_list":{"0":"post-29145","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-headline","8":"category-news","9":"category-uk","10":"tag-advanced-computer-software-group","11":"tag-cyber-attack","12":"tag-cyber-security","13":"tag-data-breach","14":"tag-hackers","15":"tag-nhs","16":"tag-ransomware","17":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=29145"}],"version-history":[{"count":1,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29145\/revisions"}],"predecessor-version":[{"id":29147,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/29145\/revisions\/29147"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/29146"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=29145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=29145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=29145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}