Close Menu
    Trending
    • How This Man Grew His Beverage Side Hustle From $1k a Month to 7 Figures
    • Finding the right tool for the job: Visual Search for 1 Million+ Products | by Elliot Ford | Kingfisher-Technology | Jul, 2025
    • How Smart Entrepreneurs Turn Mid-Year Tax Reviews Into Long-Term Financial Wins
    • Become a Better Data Scientist with These Prompt Engineering Tips and Tricks
    • Meanwhile in Europe: How We Learned to Stop Worrying and Love the AI Angst | by Andreas Maier | Jul, 2025
    • Transform Complexity into Opportunity with Digital Engineering
    • OpenAI Is Fighting Back Against Meta Poaching AI Talent
    • Lessons Learned After 6.5 Years Of Machine Learning
    AIBS News
    • Home
    • Artificial Intelligence
    • Machine Learning
    • AI Technology
    • Data Science
    • More
      • Technology
      • Business
    AIBS News
    Home»Technology»Software bug at firm left NHS data ‘vulnerable to hackers’
    Technology

    Software bug at firm left NHS data ‘vulnerable to hackers’

    Team_AIBS NewsBy Team_AIBS NewsMarch 10, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ben Morris

    Editor, Expertise of Enterprise

    Getty Images A nurse fills in a form in front of screensGetty Pictures

    Medefer handles round 1,500 referrals a month

    The NHS is “trying into” allegations that affected person knowledge was left weak to hacking attributable to a software program flaw at a personal medical companies firm.

    The flaw was discovered final November at Medefer, which handles 1,500 NHS affected person referrals a month.

    The software program engineer who found the flaw believes the issue had existed for a minimum of six years.

    Medefer says there isn’t a proof the flaw had been in place that lengthy and harassed that affected person knowledge has not been compromised.

    The flaw was mounted a number of days after being found.

    In late February the corporate commissioned an exterior safety company to undertake a overview of its knowledge administration techniques.

    An NHS spokesperson mentioned: “We’re trying into the issues raised about Medefer and can take additional motion if applicable.”

    Medefer’s system permits sufferers to ebook digital appointments with docs, and offers these clinicians entry to the suitable affected person knowledge.

    Nevertheless, the software program bug, found in November, made Medefer’s inner affected person document system weak to hackers, the engineer mentioned.

    The software program engineer, who doesn’t need to be named, was shocked by what he uncovered.

    “When I discovered it, I simply thought ‘no, it might’t be’.”

    The issue was in bits of software program referred to as APIs (utility programming interfaces), which permit totally different laptop techniques to speak to one another.

    The engineer says that at Medefer these APIs weren’t correctly secured, and will doubtlessly have been accessed by outsiders, who would have been in a position to see affected person info.

    He mentioned it was unlikely that affected person info was taken from Medefer, however that with no full investigation, the corporate couldn’t have identified for positive.

    “I’ve labored in organisations the place, if one thing like this occurred, the entire system could be taken down instantly,” he mentioned.

    On discovering the flaw the engineer advised the corporate that an exterior cybersecurity skilled needs to be purchased in to analyze the issue, which he says the corporate didn’t do.

    Medefer says the exterior safety company has confirmed that it has discovered no proof of any breach of information and that each one the corporate’s knowledge techniques had been at present safe.

    It says the method of investigating and fixing the API flaw was “extraordinarily open”.

    Medefer mentioned it had reported the difficulty to the ICO (Info Commissioner’s Workplace) and the CQC (Care High quality Fee), “within the pursuits of transparency”, and that the ICO had confirmed there isn’t a additional motion to be taken as there isn’t a proof of a breach.

    The engineer, who had been contracted in October to check for flaws within the firm’s software program, left the corporate in January.

    In an announcement Dr Bahman Nedjat-Shokouhi, founder and CEO of Medefer, mentioned: “There is no such thing as a proof of any affected person knowledge breach from our techniques.”

    He confirmed that the flaw had been found in November and a repair was developed in 48 hours.

    “The exterior safety company has asserted that the allegation that this flaw might have offered entry to massive quantities of sufferers’ knowledge is categorically false.”

    The safety company will full its overview later this week.

    Dr Nedjat-Shokouhi added: “We take our duties to sufferers and the NHS very critically. We maintain common exterior safety audits of our techniques by unbiased exterior safety businesses, undertaken on a number of events yearly.”

    Getty Images A vial of blood in front of a some medical scansGetty Pictures

    Enormous quantities of medical knowledge needs to be shared amongst docs and hospitals

    Cybersecurity consultants, who’ve checked out info provided by the software program engineer, have expressed their concern.

    “There’s the chance that Medefer saved knowledge derived from the NHS not as securely as one would hope it might be,” mentioned Prof Alan Woodward, a cybersecurity skilled on the College of Surrey.

    “The database is likely to be encrypted and all the opposite precautions taken, but when there’s a means of glitching the API authorisation, anybody who is aware of how might doubtlessly acquire entry,” he added.

    One other skilled identified that as Medefer offers with highly-sensitive, medical knowledge, the corporate ought to have purchased in cybersecurity consultants as quickly as the issue was recognized.

    “Even when the corporate suspected that no knowledge was stolen, when dealing with a problem that would have resulted in a knowledge breach, particularly with knowledge of the character in query, an investigation and affirmation from a suitably certified cybersecurity skilled could be advisable,” says Scott Helme, a safety researcher.

    Medefer was based in 2013 by Dr Nedjat-Shokouhi, with a aim to enhance outpatient care. Since then its know-how has been utilized by NHS trusts throughout the nation.

    In an announcement the NHS spokesperson mentioned these trusts are liable for their contracts with the non-public sector.

    “Particular person NHS organisations should guarantee they meet their authorized obligations and nationwide knowledge safety requirements to guard affected person knowledge when appointing suppliers, and we provide them assist and coaching nationally on how this needs to be performed.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBack from Extinction: How Colossal Is Charting a New Frontier in Genomics
    Next Article Understanding Advanced preprocessing in NLP | by Azad Kumar Jha | Mar, 2025
    Team_AIBS News
    • Website

    Related Posts

    Technology

    Transform Complexity into Opportunity with Digital Engineering

    July 1, 2025
    Technology

    HP’s PCFax: Sustainability Via Re-using Used PCs

    July 1, 2025
    Technology

    Bell Labs DSP Pioneer Jim Boddie Leaves Lasting Legacy

    June 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    How This Man Grew His Beverage Side Hustle From $1k a Month to 7 Figures

    July 1, 2025

    I Tried Buying a Car Through Amazon: Here Are the Pros, Cons

    December 10, 2024

    Amazon and eBay to pay ‘fair share’ for e-waste recycling

    December 10, 2024

    Artificial Intelligence Concerns & Predictions For 2025

    December 10, 2024

    Barbara Corcoran: Entrepreneurs Must ‘Embrace Change’

    December 10, 2024
    Categories
    • AI Technology
    • Artificial Intelligence
    • Business
    • Data Science
    • Machine Learning
    • Technology
    Most Popular

    Instagram Is Paying Creators Up to $20,000 for Referrals

    May 21, 2025

    3vHabits That Made Me Sharper, Stronger and More Successful

    April 19, 2025

    U.A.W. Seeks Union Election at Ford Battery Plant in Kentucky

    January 9, 2025
    Our Picks

    How This Man Grew His Beverage Side Hustle From $1k a Month to 7 Figures

    July 1, 2025

    Finding the right tool for the job: Visual Search for 1 Million+ Products | by Elliot Ford | Kingfisher-Technology | Jul, 2025

    July 1, 2025

    How Smart Entrepreneurs Turn Mid-Year Tax Reviews Into Long-Term Financial Wins

    July 1, 2025
    Categories
    • AI Technology
    • Artificial Intelligence
    • Business
    • Data Science
    • Machine Learning
    • Technology
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Aibsnews.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.