NHS software program supplier fined £3m over information breach

NHS software program supplier fined £3m over information breach

An NHS software program supplier has been fined £3m by the Data Commissioner’s Workplace (ICO) over safety failings that led to a ransomware assault on the NHS.

The Superior Laptop Software program Group was fined for a breach that put private data of 79,404 individuals in danger, the UK’s information safety watchdog stated.

The agency offers IT and software program companies to organisations across the nation, together with the NHS and different well being suppliers, dealing with data in its function as an information processor.

The breach passed off in August 2022, when hackers gained entry to sufferers’ telephone numbers and medical data in addition to particulars of the way to achieve entry to the houses of 890 individuals receiving care at house.

The unidentified hackers have been capable of achieve entry to the knowledge through the use of a buyer’s account that didn’t have ample safety within the type of multi-factor authentication.

The regulator’s investigation concluded that Superior didn’t have applicable safety measures in place previous to the incident.

The cyberattack led to the disruption of essential companies together with NHS 111, and left some healthcare workers unable to entry affected person data.

Software program used to facilitate affected person check-ins was additionally impacted.

Final yr, the regulator criticised Superior over the incident, which positioned “additional pressure” on a “sector already below strain”.

Whereas the corporate had put in multi-factor authentication throughout lots of its methods, “the dearth of full protection” was criticised by Data Commissioner John Edwards.

“The safety measures of Superior’s subsidiary fell severely wanting what we’d anticipate from an organisation processing such a big quantity of delicate data,” Mr Edwards stated.

He added the advantageous ought to function a “stark reminder” to organisations to make sure they’ve “sturdy safety measures in place”.

“There isn’t a excuse for leaving any a part of your system susceptible,” Mr Edwards added.

Final yr, the ICO introduced it meant to impose a provisional £6m advantageous on Superior for the breach.

Nevertheless, the watchdog stated the sum had been halved due to the proactive engagement of Superior with police, cyber safety companies and the NHS following the assault.

Leave a Reply

Your email address will not be published. Required fields are marked *