Advanced fined £6m over stolen patient data in 2022 cyber attack


The Information Commissioner’s Office (ICO) has imposed a £6.09 million fine on software provider Advanced following an initial finding that it failed to implement measures to protect the personal information of almost 83,000 people.

A number of health and care systems delivered by Advanced first experienced major outages on 4 August 2022, disrupting several critical services such as NHS 111, with other healthcare staff unable to access patient records.

Read more…
Source: DigitalHealth News


Sign up for our Newsletter


Related:

  • 9 months after the largest healthcare breach in history, UnitedHealth subsidiary back online

    November 22, 2024

    Change Healthcare—a subsidiary of the global health company UnitedHealth Group — has restored its medical billing services nine months after suffering an unprecedented ransomware attack that left providers with serious cashflow problems, threatened access to care, and leaked sensitive information onto the dark web. Change Healthcare, one of the largest health payment processing companies in the ...

  • 100 million people hit in largest healthcare data breach in history – medical info, SSNs and more

    October 26, 2024

    More than 100 million people had their personal information and healthcare data stolen in the massive UnitedHealth ransomware attack earlier this year, making it the largest healthcare data breach in the country. After completing its investigation into February’s data breach, the US Department of Health and Human Services said this week that roughly a third of ...

  • Microsoft Threat Intelligence healthcare ransomware report highlights need for collective industry action

    October 22, 2024

    Healthcare organizations are an increasingly attractive target for threat actors. In a new Microsoft Threat Intelligence report, US healthcare at risk: strengthening resiliency against ransomware attacks, our researchers identified that ransomware continues to be among the most common and impactful cyberthreats targeting organizations. The report offers a holistic view of the healthcare threat landscape with a ...

  • EU Network and Information Security (NIS) Directive: Parliament adopts new law to strengthen EU-wide resilience

    October 11, 2024

    Rules requiring EU countries to meet stricter supervisory and enforcement measures and harmonise their sanctions were approved by MEPs on Thursday. The legislation, already agreed between MEPs and the Council in May, will set tighter cybersecurity obligations for risk management, reporting obligations and information sharing. The requirements cover incident response, supply chain security, encryption and vulnerability disclosure, ...

  • British Columbia: Clients of Indigenous health authority react to ransomware attack

    October 9, 2024

    The First Nations Health Authority (FNHA) in British Columbia says it has concluded its investigation into a ransomware attack in May, but some clients remain concerned about the theft of their medical and personal information. The FNHA said it “uncovered evidence that health insurance plan billing data, procurement contracts, business contracts, FNHA budgets, cheques, information on ...

  • Awareness of Cyber Risks to Healthcare Organizations is not Always Translating to Adequate Protections

    October 8, 2024

    Despite growing awareness and widespread acknowledgment of the impact of cyber threats facing the healthcare industry, many within it are still struggling to keep them at bay. The third annual Ponemon Institute Report, commissioned by Proofpoint, found that 92% of US healthcare organizations surveyed experienced at least one cyber attack in the past 12 month, with ...