Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Government departments will look at cutting budgets to fund defence, minister says

      Getty Images collection showcasing diverse business professionals in a collaborative office environment, emphasizing teamw...

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Can football conquer the US? Why culture is key this World Cup

      GettyImages 2281127577 featuring a significant news event or business setting, capturing key moments and interactions

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      The best places to eat sandwiches in Lisbon, from bifanas to pregos

      Bifana do Afonsos famous bifana sandwich showcasing tender pork in a freshly baked roll with savory sauce.

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Thursday 27 March 2025 12:42 pm  |  Updated:  Thursday 27 March 2025 12:43 pm

NHS software firm fined over highly sensitive data breach

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Vallance calls for US-UK health tech collaboration

A major NHS software provider has been fined £3m after a cyber attack exposed the personal data of nearly 80,000 people – including home entry details and medical records for vulnerable patients.

had “seriously inadequate” security measures, allowing hackers to infiltrate its systems in August 2023.

The breach disrupted vital NHS 111 services, stripped staff from being able to access patient records, overall adding pressure to an already strained healthcare system.

The ransomware attack was made possible because the software provider failed to implement multi-factor authentication (MFA) across all of its systems, allowing cyber criminals to exploit a customer account with weak security.

The ICO reported that the company’s failures left a critical system that processes highly sensitive data, “dangerously exposed”.

Real-world consequences

The breach compromised patients’ phone numbers, their medical records, and even instructions on how to access the homes of 890 vulnerable individuals receiving care.

The impact rippled through the NHS services, delaying emergency responses and patient treatment.

Last year, the ICO provisionally set the fine to £6m, but proceeded to halve it due to the firm’s cooperation with police, cyber experts and the NHS in the aftermath of the attack.

Read more

NHS gives Palantir wider access to patient data amid growing backlash

NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...

The penalty should, however, serve as a trenchant reminder to all firms handling highly sensitive data.

“There is no excuse for leaving any part of your system vulnerable”, said information commissioner John Edwards.

The provider’s failure to fully roll out MFA also garnered critique.

Edwards dubbed it an unacceptable security lapse for a firm entrusted with such critical information.

The fine has been revealed amid growing regulatory pressure on companies to prioritise cyber security, especially in sectors handling sensitive data sets.

Meanwhile, a growing pay gap between public and private sector cyber roles has led some firms to warn the UK‘s national security is at risk, because it is harder for government to attract and retain top talent.

“The risks to UK national security from cyber crime are real, and the potential costs and damage to critical national infrastructure are staggering”, said Naoris Protocol chief executive David Carvalho.

Read more

Palantir revenue rockets past forecasts

Roman Polanski and Kristen Spencer discuss film collaboration at press conference, seated at table with microphones and ca...

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Cyber
  • cyber attack
  • data breach
  • ICO
  • National security
  • NHS

Trending Articles

  • KPMG’s Summer Friday half-day rollback signals deeper woes for Big Four giants

  • Inflation expectations at record high in interest rates signal

  • London Tech Week sums up everything wrong with UK tech

  • KPMG report on AI found riddled with AI hallucinations

  • UK economy falters as deeper damage to growth to come

More from CityAM

  • NHS gives Palantir wider access to patient data amid growing backlash

    Tech
    NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...
  • Palantir revenue rockets past forecasts

    Tech
    Roman Polanski and Kristen Spencer discuss film collaboration at press conference, seated at table with microphones and ca...
  • Kainos shares lift as revenue surges on bumper NHS contract wins

    Tech
    Without the specific content and context from the article, its challenging to generate an accurate alt text. Please provid...
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • IMF warns AI cyberattacks could trigger global financial crisis

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Top spook says Russia ‘relentlessly targeting’ UK infrastructure 

    Tech
    GCHQ headquarters at dusk with illuminated windows, showcasing the iconic circular building amidst a vibrant evening sky.
  • Deutsche Bank hit with six-figure fine in UK for breaching Russia sanctions

    Banking
    Deutsche Bank is Germany's biggest lender.
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • News
  • Markets & Economics
  • Politics
  • Opinion
  • Life&Style
  • Personal Finance

Follow us for breaking news and latest updates

  • Facebook
  • X
  • Instagram
  • LinkedIn
Copyright 2026 CityAM Limited