NHS software provider fined £3m over data breach

Deal Score0
Deal Score0

An NHS software program supplier has been fined £3m by the Info Commissioner’s Workplace (ICO) over safety failings that led to a ransomware assault on the NHS.

The Superior Pc Software program Group was fined for a breach that put private info of 79,404 individuals in danger, the UK’s knowledge safety watchdog mentioned.

The agency supplies IT and software program providers to organisations across the nation, together with the NHS and different well being suppliers, dealing with info in its position as an information processor.

The breach occurred in August 2022, when hackers gained entry to sufferers’ cellphone numbers and medical data in addition to particulars of find out how to acquire entry to the properties of 890 individuals receiving care at residence.

The unidentified hackers have been capable of acquire entry to the data by utilizing a buyer’s account that didn’t have ample safety within the type of multi-factor authentication.

The regulator’s investigation concluded that Superior didn’t have acceptable safety measures in place previous to the incident.

The cyberattack led to the disruption of vital providers together with NHS 111, and left some healthcare employees unable to entry affected person data.

Software program used to facilitate affected person check-ins was additionally impacted.

Final 12 months, the regulator criticised Superior over the incident, which positioned “additional pressure” on a “sector already below stress”.

Whereas the corporate had put in multi-factor authentication throughout a lot of its techniques, “the dearth of full protection” was criticised by Info Commissioner John Edwards.

“The safety measures of Superior’s subsidiary fell significantly wanting what we’d count on from an organisation processing such a big quantity of delicate info,” Mr Edwards mentioned.

He added the nice ought to function a “stark reminder” to organisations to make sure they’ve “strong safety measures in place”.

“There isn’t any excuse for leaving any a part of your system weak,” Mr Edwards added.

Final 12 months, the ICO introduced it meant to impose a provisional £6m nice on Superior for the breach.

Nevertheless, the watchdog mentioned the sum had been halved due to the proactive engagement of Superior with police, cyber safety providers and the NHS following the assault.

See also  How many of us will end up being diagnosed?

Kurt
Besthealthplace
Logo
Shopping cart