Skip to content
Tuesday 11 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,844.19
-0.17%
DAX
26,391.42
+0.26%
CAC 40
8,714.94
-0.13%
STOXX 50
6,551.22
+0.24%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Thursday 27 March 2025 12:42 pm  |  Updated:  Thursday 27 March 2025 12:43 pm

NHS software firm fined over highly sensitive data breach

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
Vallance calls for US-UK health tech collaboration

A major NHS software provider has been fined £3m after a cyber attack exposed the personal data of nearly 80,000 people – including home entry details and medical records for vulnerable patients.

had “seriously inadequate” security measures, allowing hackers to infiltrate its systems in August 2023.

The breach disrupted vital NHS 111 services, stripped staff from being able to access patient records, overall adding pressure to an already strained healthcare system.

The ransomware attack was made possible because the software provider failed to implement multi-factor authentication (MFA) across all of its systems, allowing cyber criminals to exploit a customer account with weak security.

The ICO reported that the company’s failures left a critical system that processes highly sensitive data, “dangerously exposed”.

Real-world consequences

The breach compromised patients’ phone numbers, their medical records, and even instructions on how to access the homes of 890 vulnerable individuals receiving care.

The impact rippled through the NHS services, delaying emergency responses and patient treatment.

Last year, the ICO provisionally set the fine to £6m, but proceeded to halve it due to the firm’s cooperation with police, cyber experts and the NHS in the aftermath of the attack.

Read more

London-listed healthcare services firm hit by cyberattack

Assura has been the subject of a ferocious bidding war for nearly six months

The penalty should, however, serve as a trenchant reminder to all firms handling highly sensitive data.

“There is no excuse for leaving any part of your system vulnerable”, said information commissioner John Edwards.

The provider’s failure to fully roll out MFA also garnered critique.

Edwards dubbed it an unacceptable security lapse for a firm entrusted with such critical information.

The fine has been revealed amid growing regulatory pressure on companies to prioritise cyber security, especially in sectors handling sensitive data sets.

Meanwhile, a growing pay gap between public and private sector cyber roles has led some firms to warn the UK‘s national security is at risk, because it is harder for government to attract and retain top talent.

“The risks to UK national security from cyber crime are real, and the potential costs and damage to critical national infrastructure are staggering”, said Naoris Protocol chief executive David Carvalho.

Read more

Champions Cup rugby team hacked in ransom attack with player data at risk

Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Cyber
  • cyber attack
  • data breach
  • ICO
  • National security
  • NHS

Trending Articles

  • Five-star Mayfair hotel hit with HMRC winding-up petition

  • Nottingham Forest owner Marinakis sues Crystal Palace for defamation

  • Back to basics: Sainsbury’s gradual retreat from the British high street

  • Hargreaves Lansdown orders staff back to office

  • As it happened: Intel, Arm shares slide; Oil climbs higher

More from Morning Wire

  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • NHS data counters claims that £330m Palantir deal has led to ‘no improvement’

    Tech
    Brit are seeking financial support from the ‘Bank of Mum and Dad’ to afford private healthcare.
  • UK’s AI watchdog flags new OpenAI and Anthropic cyber alarms

    AI
    Smartphone displaying the Claude by Anthropic AI assistant app, showing the app icon and interface.
  • Ignore Palantir’s political opponents and look at the data: this technology helps patients

    Opinion
    NHS logo on a white surface with visible water droplets, blue and white branding
  • Wasabi and Megaport Partner to Advance the Next Generation of AI and Cloud Infrastructure

    Business Wire
  • London AI car firm records surge in revenue on demand for driver-tracking software

    Tech
    Seeing Machines Guardian device mounted on a desk, with a computer monitor in the background.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook