Skip to content

Official UK records confirm cyberattacks put NHS patients at risk of clinical harm

Two cyberattacks affecting the NHS last year put patients at risk of clinical harm, according to official data obtained by Recorded Future News.

The data, recorded by the government under the Network and Information Systems (NIS) Regulations and obtained under the Freedom of Information Act, does not identify specific incidents but highlights the growing threat that financially motivated cyber incidents pose to public safety.

It follows the head of the National Cyber Security Centre, Richard Horne, telling cybersecurity practitioners earlier this month that their work was “not just about protecting systems, it’s about protecting our people, our economy, our society, from harm.”

One of the two incidents is likely to be the ransomware attack on pathology services provider Synnovis, which severely disrupted care at a large number of National Health Service (NHS) hospitals and care providers in London by delaying and cancelling operations and appointments. 

Criminals similarly disrupted care in an attack on Wirral University Teaching Hospital NHS Foundation Trust, causing delays to cancer treatments as reported by The Register.

The government data records no incidents that led to excess fatalities or excess casualties, the two highest categories for NIS incidents.  Two incidents, however, passed the threshold of the third category of causing potential clinical harm to more than 50 patients, with clinical harm defined as harm resulting from medical care or the lack of it.

Patient safety concerns in England and Wales, potentially including concerns resulting from cyberattacks, are investigated by the Health Services Safety Investigations Body (HSSIB).

HSSIB’s chief executive Dr Rosie Benneyworth told Recorded Future News that while the board hadn’t “carried out specific investigation work examining the impact of cyberattacks […] as expert independent investigators, we understand the impact of emerging risks, and we can see that there is potential with a cyber attack to make patient safety incidents more likely.”

Read full story

Source: The Record, 19 May 2025

 

User Feedback

Recommended Comments

There are no comments to display.

Create an account or sign in to comment

Registered address: Patient Safety Learning, China Works SB203, 100 Black Prince Road Vauxhall, London, SE1 7SJ

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.