Summary

The UK data watchdog is set to fine NHS vendor Advanced for security failures that occurred before the LockBit ransomware attack. These security lapses contributed to the vulnerability exploited during the attack.

The cyber attack had extensive repercussions, impacting the systems for dispatching ambulances, booking out-of-hours appointments, and issuing emergency prescriptions.

In a provisional ruling, the ICO stated that the software provider violated data protection laws by failing to secure personal information for 82,946 individuals.

These records were stolen in a ransomware attack by hackers who accessed Advanced's computer systems through an account that lacked multi-factor authentication (MFA).

Typically, MFA would have prevented cyber criminals from using stolen passwords to gain access.

The stolen data included sensitive information such as phone numbers, medical records, and details on how to access the properties of 890 people receiving home care.

Read more

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Home

Discover our latest articles

View All Blog Posts
February 9, 2026
AI
Biotech & Healthtech
Regulations & Guidelines
Healthcare

EU AI Act for Healthcare: What Life Sciences Companies Need to Know before August 2026

EU AI Act 2026 healthcare enforcement requires immediate compliance to avoid penalties.

February 2, 2026
Healthtech
US Privacy Law
USA

Navigating US Regulatory Requirements for AI-Powered Medical Devices: A Comprehensive Guide to FDA, HIPAA, and IRB Compliance

US AI medical device compliance requires navigating FDA, HIPAA, IRBs, and consent waivers strategically.

February 2, 2026
Clinical Trials
Clinical Trial Sponsor
Biotech & Healthtech

VERBIS Registration and Standard Contractual Clauses in Turkey: A Complete Guide for Life Sciences Companies Conducting Clinical Trials

Turkey's VERBIS registration and SCC requirements demand apostilles, tight deadlines, and experienced local guidance.

FAQs

Our frequently questions

No items found.