web analytics

£3 million fine for healthcare MSP with sloppy security after it was hit by ransomware attack – Source: www.exponential-e.com

Rate this post

Source: www.exponential-e.com – Author: Graham Cluley

A UK firm has been hit by a £3.07 million fine after being hit by a ransomware attack that exposed sensitive data related to almost 80,000 people, and disrupted NHS services.

The fine imposed by the Information Commissioner’s Office (ICO) confirms that managed service provider Advanced Computer Software Group failed to fully implement security measures such as multi-factor authentication (MFA) coverage prior to a cyber-attack in August 2022.

As the ICO explains, hackers launched a ransomware attack on systems at Advanced health and care subsidiary via an account that was not protected with MFA.

The successful hack of Advanced, which provides digital services to the National Health Service, impacted products including Adastra (which is used by the NHS 111 service), and Caresys and Carenotes, which are essential elements for care home services like patient notes and visitor booking.

BBC News reported at the time that doctors believed it could take months to process the mounting paperwork caused by the disruption to services.

The attack not only saw hackers steal the personal details of 79,404 individuals, but also details of how to gain entry into the homes of 890 people who were receiving care at home.

Aside from the failure to universally adopt MFA, Advanced was also criticised by the ICO for its failure to regularly check for vulnerabilities and keep systems up to date with the latest security patches.

This incident shows just how important it is to prioritise information security. Losing control of sensitive personal information will have been distressing for people who had no choice but to put their trust in health and care organisations,” said UK Information Commissioner John Edwards. “Not only was personal information compromised, but we have also seen reports that this incident caused disruption to some health services, disrupting their ability to deliver patient care. A sector already under pressure was put under further strain due to this incident.

The ICO

Under GDPR, a data controller (which decides what personal data is collected, and controls its purpose and usage) has more obligations than a data processor (which is a third-party which processes the data based on the instructions of a data controller). The notorious LockBit ransomware gang later claimed responsibility for the attack.

The healthcare sector is a major target for cybercriminals because of the high value of the patient data it stores, and its highly sensitive and confidential nature.

Protecting this data from unauthorised access, disclosure, or manipulation is paramount to maintaining patient privacy and confidentiality. Not only does a cyber-attack erode the trust of patients and cause financial losses, it can also – in the worst cases – endanger lives too.

That’s why it is so important for healthcare organisations to strengthen the security of their network, and implement strong defences. 

Make sure to read more about how Exponential-e works in partnership with the healthcare sector to keep it secure.

Securing Healthcare’s Digital Future

This brochure explores how Exponential-e empowers NHS and private care providers with secure, compliant digital infrastructure – driving innovation, protecting patient data, and supporting resilient, future-ready services. Trusted by 3,000+ organisations and backed by a 96% satisfaction rating.

Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn’t miss them.

About the author

Graham Cluley is an award-winning cybersecurity public speaker, podcaster, blogger, and analyst. He has been a well-known figure in the cybersecurity industry since the early 1990s when he worked as a programmer, writing the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows.

Since then he has been employed in senior roles by computer security companies such as Sophos and McAfee.

Graham Cluley has given talks about cybersecurity for some of the world’s largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats.

Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the “10 Greatest Britons in IT History” for his contribution as a leading authority in internet security.

Original Post URL: https://www.exponential-e.com/blog/3-million-fine-for-healthcare-msp-with-sloppy-security-after-it-was-hit-by-ransomware-attack

Category & Tags: Data loss,Guest blog,Ransomware,data breach,healthcare,NHS,ransomware – Data loss,Guest blog,Ransomware,data breach,healthcare,NHS,ransomware

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post