Skip to content

Government alert sounded over EPR cyber security risk

The  “concentration” of electronic patient record systems under a relatively small number of suppliers has increased the risk of highly damaging cyber attack, a government review has concluded.

The Department of Health and Social Care’s Gateway review of NHS England’s Frontline Productivity programme reported “EPRs and their hosting/supplier dependencies present concentration and cyber risks”, and this “may warrant” their designation as “critical national infrastructure”.

The review, which has been seen by HSJ, says responsibility for the cyber risks posed by EPR concentration was “fragmented” and that there was “material uncertainty” over how an attack might be prevented and responded to. 

The gateway review said it was “essential” that NHSE “publish minimum cyber security requirements for EPRs and clarify cyber risk ownership”.

Read full story (paywalled)

Source: HSJ, 5 October 2026

User Feedback

Recommended Comments

There are no comments to display.

Create an account or sign in to comment

Registered address: Patient Safety Learning, China Works SB203, 100 Black Prince Road Vauxhall, London, SE1 7SJ

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.