Hackers threaten to publish more stolen patient data

Related news

How data insights will help deliver NHS reform

NHS IT ready to take ’transformative’ step

Health Secretary commits to kidney action

Scotland’s GP workforce rises

Government to act on A&E failures

Charting Scotland’s future health and hospital demand

Insight: Early childhood development inequalities

Cancer trials ‘back on track’

New health & social care governance initiative

EU staff qualifications & registrations confirmed

Health Secretary to give evidence on rural GPs

Retired doctors to address rural recruitment gaps

Image Credit: © BillionPhotos.com

by Frankie Macpherson

Wednesday 27th March 2024

NHS Dumfries and Galloway has confirmed that a ransomware group have accessed clinical data relating to at least a “small number of patients” after the hackers today have threatened to publish the sensitive documents.

Reports emerged across social media this morning that a group called Inc Ransom was holding three terabytes of NHS Scotland data, including patients’ genetic reports and treatment letters.

The group had posted on its darknet blog stating that it was in possession of the data, including a “proof pack” which NHS Dumfries and Galloway has now confirmed.

No specific deadline or price has been set by the ransomware group, but it has threatened to release the stolen patient and staff data “soon” if its demands are not met.

Updating its website for the first time in a week this afternoon, NHS Dumfries and Galloway it is aware of the clinical data that has been published thus far by Inc Ransom as proof of its breach.

NHS Dumfries and Galloway Chief Executive, Jeff Ace said:

“We absolutely deplore the release of confidential patient data as part of this criminal act.

“This information has been released by hackers to evidence that this is in their possession.

“Patient-facing services continue to function effectively as normal.

“As part of this response, we will be making contact with any patients whose data has been leaked at this point, and continue working to limit any sharing of this information.”

It comes after a cyber-attack hit the health board earlier this month, placing a “significant” amount of data – including patient and staff information – at risk.

Police Scotland has confirmed that it is investigating the attack.

NHS Dumfries and Galloway has today shared that it is working with the police, the Scottish government, and the National Cyber Security Centre.

The health board’s Chief Executive, Jeff Ace, said:

“NHS Dumfries and Galloway is very acutely aware of the potential impact of this development on the patients whose data has been published, and the general anxiety which might result within our patient population.”

A Scottish government spokesperson told healthandcare.scot that the incident is contained to NHS Dumfries and Galloway and work is ongoing to address the situation:

“We are aware of some data published on the web that is linked to the recent cyber-attack on NHS Dumfries and Galloway.

“This incident remains contained to NHS Dumfries and Galloway and there have been no further incidents across NHS Scotland as a whole.

“The Scottish government is working with the health board, Police Scotland and other agencies including the National Crime Agency and National Cyber Security Centre to assess the level of this breach and the possible implications for individuals concerned.

“The Scottish government is continuing to provide support to NHS Dumfries and Galloway as they deal with this ongoing situation. This remains an on-going police investigation.”

Read more: NHS staff say data vital to improving careBig data: closing the endometriosis knowledge gapRADAR system to spot drug death risks  

Sign up to our bulletin for key health & social care updates straight to your inbox and you can follow healthandcare.scot on Google News.