The “concentration” of electronic patient record systems under a relatively small number of suppliers has increased the risk of highly damaging cyber attack, a government review has concluded.
The Department of Health and Social Care’s Gateway review of NHS England’s Frontline Productivity programme reported “EPRs and their hosting/supplier dependencies present concentration and cyber risks”, and this “may warrant” their designation as “critical national infrastructure”.
The review, which has been seen by HSJ, says responsibility for the cyber risks posed by EPR concentration was “fragmented” and that there was “material uncertainty” over how an attack might be prevented and responded to.
The gateway review said it was “essential” that NHSE “publish minimum cyber security requirements for EPRs and clarify cyber risk ownership”.
Read full story (paywalled)
Source: HSJ, 5 October 2026
Recommended Comments
Create an account or sign in to comment