£3 million fine for healthcare MSP with sloppy security after it was hit by ransomware attack
A UK firm has been hit by a £3.07 million fine after being hit by a ransomware attack that exposed sensitive data related to almost 80,000 people, and disrupted NHS services.
The fine imposed by the Information Commissioner's Office (ICO) confirms that managed service provider Advanced Computer Software Group failed to fully implement security measures such as multi-factor authentication (MFA) coverage prior to a cyber-attack in August 2022.
As the ICO explains, hackers launched a ransomware attack on systems at Advanced health and care subsidiary via an account that was not protected with MFA.
The successful hack of Advanced, which provides digital services to the National Health Service, impacted products including Adastra (which is used by the NHS 111 service), and Caresys and Carenotes, which are essential elements for care home services like patient notes and visitor booking.
BBC News reported at the time that doctors believed it could take months to process the mounting paperwork caused by the disruption to services.
The attack not only saw hackers steal the personal details of 79,404 individuals, but also details of how to gain entry into the homes of 890 people who were receiving care at home.
Aside from the failure to universally adopt MFA, Advanced was also criticised by the ICO for its failure to regularly check for vulnerabilities and keep systems up to date with the latest security patches.
This incident shows just how important it is to prioritise information security. Losing control of sensitive personal information will have been distressing for people who had no choice but to put their trust in health and care organisations," said UK Information Commissioner John Edwards. "Not only was personal information compromised, but we have also seen reports that this incident caused disruption to some health services, disrupting their ability to deliver patient care. A sector already under pressure was put under further strain due to this incident.
The ICO
The healthcare sector is a major target for cybercriminals because of the high value of the patient data it stores, and its highly sensitive and confidential nature.
Protecting this data from unauthorised access, disclosure, or manipulation is paramount to maintaining patient privacy and confidentiality. Not only does a cyber-attack erode the trust of patients and cause financial losses, it can also - in the worst cases - endanger lives too.
That's why it is so important for healthcare organisations to strengthen the security of their network, and implement strong defences.
Make sure to read more about how Exponential-e works in partnership with the healthcare sector to keep it secure.
Securing Healthcare's Digital Future
This brochure explores how Exponential-e empowers NHS and private care providers with secure, compliant digital infrastructure - driving innovation, protecting patient data, and supporting resilient, future-ready services. Trusted by 3,000+ organisations and backed by a 96% satisfaction rating.
When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.