Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Thursday 27 March 2025 12:42 pm  |  Updated:  Thursday 27 March 2025 12:43 pm

NHS software firm fined over highly sensitive data breach

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Vallance calls for US-UK health tech collaboration

A major NHS software provider has been fined £3m after a cyber attack exposed the personal data of nearly 80,000 people – including home entry details and medical records for vulnerable patients.

had “seriously inadequate” security measures, allowing hackers to infiltrate its systems in August 2023.

The breach disrupted vital NHS 111 services, stripped staff from being able to access patient records, overall adding pressure to an already strained healthcare system.

The ransomware attack was made possible because the software provider failed to implement multi-factor authentication (MFA) across all of its systems, allowing cyber criminals to exploit a customer account with weak security.

The ICO reported that the company’s failures left a critical system that processes highly sensitive data, “dangerously exposed”.

Real-world consequences

The breach compromised patients’ phone numbers, their medical records, and even instructions on how to access the homes of 890 vulnerable individuals receiving care.

The impact rippled through the NHS services, delaying emergency responses and patient treatment.

Last year, the ICO provisionally set the fine to £6m, but proceeded to halve it due to the firm’s cooperation with police, cyber experts and the NHS in the aftermath of the attack.

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

The penalty should, however, serve as a trenchant reminder to all firms handling highly sensitive data.

“There is no excuse for leaving any part of your system vulnerable”, said information commissioner John Edwards.

The provider’s failure to fully roll out MFA also garnered critique.

Edwards dubbed it an unacceptable security lapse for a firm entrusted with such critical information.

The fine has been revealed amid growing regulatory pressure on companies to prioritise cyber security, especially in sectors handling sensitive data sets.

Meanwhile, a growing pay gap between public and private sector cyber roles has led some firms to warn the UK‘s national security is at risk, because it is harder for government to attract and retain top talent.

“The risks to UK national security from cyber crime are real, and the potential costs and damage to critical national infrastructure are staggering”, said Naoris Protocol chief executive David Carvalho.

Read more

Regulator wins decade-long pricing tussle with Pfizer

Hikma reported a jump in profit for 2024

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Cyber
  • cyber attack
  • data breach
  • ICO
  • National security
  • NHS

Trending Articles

  • Reeves’ new tax charge on cash ISAs faces fierce industry backlash

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • As it happened: Stocks recover after markets rocked by tech-sell off; US claims ‘good foundations’ of Iran deal

  • As it happened: FTSE 100 scrapes into green after Segro’s surge; Oil at pre-war levels after Trump snaps at industry

More from City PM

  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • Regulator wins decade-long pricing tussle with Pfizer

    Legal
    Hikma reported a jump in profit for 2024
  • Forget Palantir, Microsoft is the government’s real tech problem

    Opinion
    At the centre of Microsoft’s pitch is the idea of agents - small, specialised AI systems trained to take on specific security tasks.
  • Neo4j Acquires GraphAware to Launch Intelligence Analysis Alternative to Palantir Gotham

    Business Wire
  • Starmer scrambles to make savings in bid to boost defence spending

    Politics
    Keir Starmer discussing UKs defense strategy with BAE Systems executives in a formal meeting setting
  • Palantir to sue Khan over blocked Met police contract

    Legal
    The Mayor of London says he stands ready to help form a bid for the 2040 Olympic Games after City PM polling revealed widespread support for the plans.
  • Jaguar Land Rover eyes cost-cutting and wealthy buyers in cyber attack recovery

    Retail
    JLR logo prominently displayed in an automotive business setting, highlighting the companys brand presence and identity
  • IBM’s consulting chief warns AI will ‘implode’ unprepared rivals

    Consulting
    All eyes on IBM v Lzlabs as the tech giant kicks off legal battle

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM. All rights reserved.
About · Contact · Terms · Privacy