Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
October 2, 2025
No Result
View All Result
Concur News

Home » NHS software provider fined £3m over data breach

NHS software provider fined £3m over data breach

March 27, 2025
in News, Privacy
Reading Time: 2 mins read
NHS software provider fined £3m over data breach
Share on LinkedinShare on Whatsapp

The Information Commissioner’s Office (ICO) has fined an NHS software provider £3m due to security lapses that caused a ransomware attack on the NHS.

Data Breach Affects Thousands

The Advanced Computer Software Group, a company that provides IT and software services to various organizations, including the NHS, has faced a penalty for a data breach that exposed the personal information of 79,404 individuals. The breach occurred in August 2022, when hackers gained access to sensitive data, including patients’ phone numbers, medical records, and home entry details for 890 people receiving home care.

Lack of Security Measures Leads to Cyberattack

The attackers exploited a customer’s account that lacked sufficient security, particularly multi-factor authentication (MFA). The ICO’s investigation revealed that Advanced had failed to implement adequate security protocols at the time of the attack.

Consent Foundation

Disruption to NHS Services

The breach disrupted critical services, including NHS 111, and prevented healthcare staff from accessing patient records. Additionally, software used for patient check-ins faced issues, further increasing the strain on an already overburdened healthcare sector.

ICO’s Findings and Proactive Engagement

Initially, the ICO announced a provisional £6m fine for the incident. However, the watchdog reduced the fine to £3m after Advanced proactively engaged with police, cybersecurity services, and the NHS following the attack. The ICO’s investigation noted that although Advanced implemented MFA across many of its systems, the company had not applied it comprehensively to all accounts.

A Stark Reminder for Organizations

Information Commissioner John Edwards stated that the breach exposed significant security weaknesses in the company’s systems. He added, “There is no excuse for leaving any part of your system vulnerable.” The fine acts as a reminder for all organizations to ensure they implement robust security measures to protect sensitive data.

Tags: Data breachData privacy

Related Posts

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns
India

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

September 8, 2025
Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025

RECOMMENDED NEWS

IT Ministry Receives Nearly 7,000 Comments on Draft Data Protection Rules

IT Ministry Receives Nearly 7,000 Comments on Draft Data Protection Rules

2 months ago
Concur-CDPSE-Training

Elevate Your Career with Multisoft Systems’ Certified Data Privacy Solutions Engineer (CDPSE) Training

6 months ago
PRIKTZER

Pritzker Acts to Protect Privacy Rights of People with Autism

5 months ago
Naval Group Probes Alleged Military Data Leak Posted Online

Naval Group Probes Alleged Military Data Leak Posted Online

2 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager