• Latest
  • Trending
  • All

Software bug at firm left NHS data ‘vulnerable to hackers’

March 10, 2025

Oil prices slide after Pakistan announces deal between US and Iran

June 15, 2026

Starmer set to ban under-16s from major social media platforms

June 15, 2026

Social media on trial: Four important cases to watch

June 15, 2026

Hamilton says Barcelona win beyond wildest dreams

June 14, 2026

UK electric car sales target set to be weakened

June 14, 2026

Why the US economy keeps defying the odds

June 14, 2026

What we know about US sea drone used in helicopter crew rescue mission

June 14, 2026

Fears dogs to blame for drop in little tern numbers

June 14, 2026

Sinkholes near Purley bridge halt Gatwick trains

June 14, 2026

Friends hope death of footballer leads to new cardiac arrest rule

June 14, 2026

Glasgow race attacks a 'mark against the reputation of the city'

June 14, 2026

Jade Jones could face Sheena Bathory after dominant second boxing win

June 14, 2026
News
  • Login
  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Monday, June 15, 2026
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    Clinical Australia upset Turkey in World Cup opener

    Swiss voters reject 10 million population cap, early projections say

    World Cup 2026: Fifa to pay Somali referee full tournament fee

    Vincent's parents 'never say he's good enough' – so he turned to a middle-aged couple online

    Royal Marines board Russian shadow fleet oil tanker in English Channel

    Armed men kidnap high-ranking security official in Haiti

    The nuclear challenge at the heart of Trump's Iran negotiations

    New York Knicks win NBA championship for first time in over 50 years

    Bangladesh beat Australia to claim first ODI series win against six-time World Cup winners

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Starmer set to ban under-16s from major social media platforms

    Hamilton says Barcelona win beyond wildest dreams

    Sinkholes near Purley bridge halt Gatwick trains

    Glasgow race attacks a 'mark against the reputation of the city'

    Jade Jones could face Sheena Bathory after dominant second boxing win

    Days of violence 'a stain on NI's international reputation'

    Molly Russell's dad says PM rushing social media restrictions 'deplorable'

    Eight arrests at anti-immigration and counter protest in Brighton

    Thousands gather for anti-racism rally in Belfast after disorder

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Oil prices slide after Pakistan announces deal between US and Iran

    UK electric car sales target set to be weakened

    Why the US economy keeps defying the odds

    Teen plans to leave uni 'debt free' after making £35,000 selling vintage football shirts

    Beauty Pie LED mask ad banned over misleading anti-wrinkle claim

    Elon Musk becomes world's first trillionaire as SpaceX soars in stock market debut

    'I was employee number one at SpaceX'

    Reporter Reads

    Elon Musk’s SpaceX raises $75bn ahead of record stock market debut

  • Tech
  • Entertainment & Arts

    Meghan hits red carpet at Power of Women in Hollywood

    Margot Robbie unable to speak at Saltburn premiere

    Barbra Streisand: Siri can now pronounce my name

    Wes Anderson’s The Grand Budapest Hotel inspires cinema’s look

    Taylor Swift/ Travis Kelce romance reaches White House

    The Killers booed at Georgia concert after inviting Russian fan on stage

    Watch: Memorable moments from Parkinson's star-studded show

    Tom Jones: Neighbour surprised to find singer in flat below

    Black Country Folk Festival showcases local musicians

    Watch: Australians set new world record with Tina Turner dance

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

Software bug at firm left NHS data ‘vulnerable to hackers’

March 10, 2025
in Tech
6 min read
248 5
0
492
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Ben Morris

Editor, Technology of Business

Getty Images A nurse fills in a form in front of screensGetty Images

Medefer handles around 1,500 referrals a month

The NHS is “looking into” allegations that patient data was left vulnerable to hacking due to a software flaw at a private medical services company.

The flaw was found last November at Medefer, which handles 1,500 NHS patient referrals a month.

The software engineer who discovered the flaw believes the problem had existed for at least six years.

Medefer says there is no evidence the flaw had been in place that long and stressed that patient data has not been compromised.

The flaw was fixed a few days after being discovered.

In late February the company commissioned an external security agency to undertake a review of its data management systems.

An NHS spokesperson said: “We are looking into the concerns raised about Medefer and will take further action if appropriate.”

Medefer’s system allows patients to book virtual appointments with doctors, and gives those clinicians access to the appropriate patient data.

However, the software bug, discovered in November, made Medefer’s internal patient record system vulnerable to hackers, the engineer said.

The software engineer, who does not want to be named, was shocked by what he uncovered.

“When I found it, I just thought ‘no, it can’t be’.”

The problem was in bits of software called APIs (application programming interfaces), which allow different computer systems to talk to each other.

The engineer says that at Medefer those APIs were not properly secured, and could potentially have been accessed by outsiders, who would have been able to see patient information.

He said it was unlikely that patient information was taken from Medefer, but that without a full investigation, the company could not have known for sure.

“I’ve worked in organisations where, if something like this happened, the whole system would be taken down immediately,” he said.

On discovering the flaw the engineer told the company that an external cybersecurity expert should be brought in to investigate the problem, which he says the company did not do.

Medefer says the external security agency has confirmed that it has found no evidence of any breach of data and that all the company’s data systems were currently secure.

It says the process of investigating and fixing the API flaw was “extremely open”.

Medefer said it had reported the issue to the ICO (Information Commissioner’s Office) and the CQC (Care Quality Commission), “in the interests of transparency”, and that the ICO had confirmed there is no further action to be taken as there is no evidence of a breach.

The engineer, who had been contracted in October to test for flaws in the company’s software, left the company in January.

In a statement Dr Bahman Nedjat-Shokouhi, founder and CEO of Medefer, said: “There is no evidence of any patient data breach from our systems.”

He confirmed that the flaw had been discovered in November and a fix was developed in 48 hours.

“The external security agency has asserted that the allegation that this flaw could have provided access to large amounts of patients’ data is categorically false.”

The security agency will complete its review later this week.

Dr Nedjat-Shokouhi added: “We take our duties to patients and the NHS very seriously. We hold regular external security audits of our systems by independent external security agencies, undertaken on multiple occasions every year.”

Getty Images A vial of blood in front of a some medical scansGetty Images

Huge amounts of medical data has to be shared among doctors and hospitals

Cybersecurity experts, who have looked at information supplied by the software engineer, have expressed their concern.

“There is the possibility that Medefer stored data derived from the NHS not as securely as one would hope it would be,” said Prof Alan Woodward, a cybersecurity expert at the University of Surrey.

“The database might be encrypted and all the other precautions taken, but if there is a way of glitching the API authorisation, anyone who knows how could potentially gain access,” he added.

Another expert pointed out that as Medefer deals with highly-sensitive, medical data, the company should have brought in cybersecurity experts as soon as the problem was identified.

“Even if the company suspected that no data was stolen, when facing an issue that could have resulted in a data breach, especially with data of the nature in question, an investigation and confirmation from a suitably qualified cybersecurity expert would be advisable,” says Scott Helme, a security researcher.

Medefer was founded in 2013 by Dr Nedjat-Shokouhi, with a goal to improve outpatient care. Since then its technology has been used by NHS trusts across the country.

In a statement the NHS spokesperson said those trusts are responsible for their contracts with the private sector.

“Individual NHS organisations must ensure they meet their legal responsibilities and national data security standards to protect patient data when appointing suppliers, and we offer them support and training nationally on how this should be done.”



Source link

Tags: bugdataFirmhackersleftNHSsoftwarevulnerable

Related Posts

Social media on trial: Four important cases to watch

June 15, 2026
0

Social media firms face thousands of lawsuits, the BBC looks at four which could be significant. Source link

Who is Elon Musk and what is his net worth?

June 14, 2026
0

The boss of X, Tesla and SpaceX, already the world's richest person, is now also its first trillionaire. ...

Elon Musk's stratospheric rise to trillionaire status – in charts

June 13, 2026
0

The BBC breaks down how the tech mogul's fortune has grown. Source link

  • Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

    677 shares
    Share 271 Tweet 169
  • Belgian footballer arrested in cocaine investigation

    533 shares
    Share 213 Tweet 133
  • Next to raise prices to help pay for rising wage costs

    531 shares
    Share 212 Tweet 133
  • South Wales Police officers injured, one arrested

    525 shares
    Share 210 Tweet 131
  • Charities to get £15m fund to save surplus farm food

    516 shares
    Share 206 Tweet 129
  • Trending
  • Comments
  • Latest

Lee McGregor: Scot seeks world title in 2025 & Nathaniel Collins bout

January 16, 2025

Belgian footballer arrested in cocaine investigation

January 27, 2025

Next to raise prices to help pay for rising wage costs

January 7, 2025

World Cup 2022: TikTok brings football fever to millions of fans

0

UK economy will get worse before it gets better, warns chancellor

0

One of Central America’s most active volcanoes erupts again

0

Oil prices slide after Pakistan announces deal between US and Iran

June 15, 2026

Starmer set to ban under-16s from major social media platforms

June 15, 2026

Social media on trial: Four important cases to watch

June 15, 2026

Categories

Business

Oil prices slide after Pakistan announces deal between US and Iran

June 15, 2026
0

Under the agreement, the key Strait of Hormuz waterway will be reopened, US President Donald Trump said. Source...

Read more

Starmer set to ban under-16s from major social media platforms

June 15, 2026
News

© 2023 GODJ - NEWS CORP - news.godj.com.

Explore NEWS.GODJ.COM

  • Home
  • News
  • Sports
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

© 2023 GODJ - NEWS CORP - news.godj.com.

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.