Close Menu
    Trending
    • Schengen anniversary overshadowed by returning border checks
    • BREAKING: Texas Capitol Evacuated After ‘Credible’ Threat Against Politicians Attending ‘No Kings’ Protest Following Assassin’s Deadly Attack on Minnesota Lawmakers | The Gateway Pundit
    • Dakota Johnson Blasts Hollywood’s Creative Collapse
    • Tens of thousands of Americans join protest rallies ahead of Trump’s military parade
    • UK announces national inquiry into ‘grooming gangs’ after pressure | Sexual Assault News
    • Education: Teacher training | The Seattle Times
    • The Middle East War Escalating Into European Civil Unrest
    • BREAKING: Suspect in Lawmaker Assassination Was a Tim Walz Appointee, Leads International Security Firm | The Gateway Pundit
    Ironside News
    • Home
    • World News
    • Latest News
    • Politics
    • Opinions
    • Tech News
    • World Economy
    Ironside News
    Home»Tech News»Software bug at firm left NHS data ‘vulnerable to hackers’
    Tech News

    Software bug at firm left NHS data ‘vulnerable to hackers’

    Ironside NewsBy Ironside NewsMarch 12, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ben Morris

    Editor, Know-how of Enterprise

    Getty Images A nurse fills in a form in front of screensGetty Photos

    Medefer handles round 1,500 referrals a month

    The NHS is “trying into” allegations that affected person knowledge was left susceptible to hacking on account of a software program flaw at a non-public medical companies firm.

    The flaw was discovered final November at Medefer, which handles 1,500 NHS affected person referrals a month in England.

    The software program engineer who found the flaw believes the issue had existed for at the least six years.

    Medefer says there isn’t any proof the flaw had been in place that lengthy and pressured that affected person knowledge has not been compromised.

    The flaw was mounted just a few days after being found.

    In late February the corporate commissioned an exterior safety company to undertake a evaluation of its knowledge administration methods.

    An NHS spokesperson stated: “We’re trying into the considerations raised about Medefer and can take additional motion if acceptable.”

    Medefer’s system permits sufferers to e book digital appointments with medical doctors, and offers these clinicians entry to the suitable affected person knowledge.

    Nevertheless, the software program bug, found in November, made Medefer’s inside affected person document system susceptible to hackers, the engineer stated.

    The software program engineer, who doesn’t need to be named, was shocked by what he uncovered.

    “When I discovered it, I simply thought ‘no, it could’t be’.”

    The issue was in bits of software program known as APIs (utility programming interfaces), which permit completely different pc methods to speak to one another.

    The engineer says that at Medefer these APIs weren’t correctly secured, and will doubtlessly have been accessed by outsiders, who would have been capable of see affected person data.

    He stated it was unlikely that affected person data was taken from Medefer, however that with no full investigation, the corporate couldn’t have recognized for certain.

    “I’ve labored in organisations the place, if one thing like this occurred, the entire system could be taken down instantly,” he stated.

    On discovering the flaw the engineer instructed the corporate that an exterior cybersecurity skilled needs to be introduced in to research the issue, which he says the corporate didn’t do.

    Medefer says the exterior safety company has confirmed that it has discovered no proof of any breach of information and that every one the corporate’s knowledge methods had been at present safe.

    It says the method of investigating and fixing the API flaw was “extraordinarily open”.

    Medefer stated it had reported the difficulty to the ICO (Data Commissioner’s Workplace) and the CQC (Care High quality Fee), “within the pursuits of transparency”, and that the ICO had confirmed there isn’t any additional motion to be taken as there isn’t any proof of a breach.

    The engineer, who had been contracted in October to check for flaws within the firm’s software program, left the corporate in January.

    In an announcement Dr Bahman Nedjat-Shokouhi, founder and CEO of Medefer, stated: “There is no such thing as a proof of any affected person knowledge breach from our methods.”

    He confirmed that the flaw had been found in November and a repair was developed in 48 hours.

    “The exterior safety company has asserted that the allegation that this flaw might have offered entry to giant quantities of sufferers’ knowledge is categorically false.”

    The safety company will full its evaluation later this week.

    Dr Nedjat-Shokouhi added: “We take our duties to sufferers and the NHS very significantly. We maintain common exterior safety audits of our methods by impartial exterior safety businesses, undertaken on a number of events yearly.”

    Getty Images A vial of blood in front of a some medical scansGetty Photos

    Big quantities of medical knowledge needs to be shared amongst medical doctors and hospitals

    Cybersecurity consultants, who’ve checked out data provided by the software program engineer, have expressed their concern.

    “There’s the likelihood that Medefer saved knowledge derived from the NHS not as securely as one would hope it will be,” stated Prof Alan Woodward, a cybersecurity skilled on the College of Surrey.

    “The database could be encrypted and all the opposite precautions taken, but when there’s a means of glitching the API authorisation, anybody who is aware of how might doubtlessly achieve entry,” he added.

    One other skilled identified that as Medefer offers with highly-sensitive, medical knowledge, the corporate ought to have introduced in cybersecurity consultants as quickly as the issue was recognized.

    “Even when the corporate suspected that no knowledge was stolen, when dealing with a problem that would have resulted in an information breach, particularly with knowledge of the character in query, an investigation and affirmation from a suitably certified cybersecurity skilled could be advisable,” says Scott Helme, a safety researcher.

    Medefer was based in 2013 by Dr Nedjat-Shokouhi, with a aim to enhance outpatient care. Since then its know-how has been utilized by NHS trusts throughout England.

    In an announcement the NHS spokesperson stated these trusts are accountable for their contracts with the personal sector.

    “Particular person NHS organisations should guarantee they meet their authorized obligations and nationwide knowledge safety requirements to guard affected person knowledge when appointing suppliers, and we provide them assist and coaching nationally on how this needs to be achieved.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleUkraine Cuts Off Energy To Hungary & Slovakia
    Next Article Trump’s Tariffs on Steel and Aluminum Take Effect
    Ironside News
    • Website

    Related Posts

    Tech News

    ESA’s Nuclear Rocket: Faster Mars Missions

    June 14, 2025
    Tech News

    Robot Videos: Neo Humanoid Robot, NASA Rover, and More

    June 14, 2025
    Tech News

    Meta AI searches made public

    June 13, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    US Justice Department ends post-George Floyd police reform settlements | Donald Trump News

    May 22, 2025

    Shameless Hack Chuck Todd Insists Cover-Up of Biden’s Decline Isn’t the Media’s Fault: ‘This is a Failure of the Democratic Party’ (VIDEO) | The Gateway Pundit

    April 30, 2025

    ‘A Minecraft Movie’ Is Already Mining For A Sequel

    April 9, 2025

    WAYNE ROOT: How President Trump is Making America Prosperous Again…Safe Again…and Best of All…Revoking Taxpayer-Funded Security For Dr. Fauci (VIDEO) | The Gateway Pundit

    January 27, 2025

    US president set to reveal ‘liberation day’ trade levies

    April 2, 2025
    Categories
    • Entertainment News
    • Latest News
    • Opinions
    • Politics
    • Tech News
    • Trending News
    • World Economy
    • World News
    Most Popular

    Intuitive Machines Athena Moon Lander Dies After Toppling Over

    March 10, 2025

    China vows countermeasures against US tariffs linked to fentanyl

    March 4, 2025

    At least 33 people killed in suspected RSF attacks in Sudan | Sudan war News

    May 10, 2025
    Our Picks

    Schengen anniversary overshadowed by returning border checks

    June 14, 2025

    BREAKING: Texas Capitol Evacuated After ‘Credible’ Threat Against Politicians Attending ‘No Kings’ Protest Following Assassin’s Deadly Attack on Minnesota Lawmakers | The Gateway Pundit

    June 14, 2025

    Dakota Johnson Blasts Hollywood’s Creative Collapse

    June 14, 2025
    Categories
    • Entertainment News
    • Latest News
    • Opinions
    • Politics
    • Tech News
    • Trending News
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright Ironsidenews.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.