Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • Biden Directed Funds To Afghanistan Over 9/11 Victims
    • IMAGINE THAT: Homicides Are Down 60 Percent in Denver Following ICE Deportations | The Gateway Pundit
    • TikToker Spills On Zak Bagans Amid Holly Madison Cheating Rumors
    • Cassie forced to read aloud explicit messages with Sean ‘Diddy’ Combs at his sex trafficking trial
    • Al-Qaeda affiliate claims 200 soldiers killed in Burkina Faso attack | Armed Groups News
    • The ‘NBA’s active playoff assist leaders’ quiz
    • CNN’s Scott Jennings Gets Democrat to Admit NY Case Against Trump Was Just Part of the Organized ‘Resistance’ (VIDEO) | The Gateway Pundit
    • Kamie Crawford Touches On Strained Relationship With Nev Schulman
    News Study
    Friday, May 16
    • Home
    • World News
    • Latest News
    • Sports
    • Politics
    • Tech News
    • World Economy
    • More
      • Trending News
      • Entertainment News
      • Travel
    News Study
    Home»Tech News

    Software bug at firm left NHS data ‘vulnerable to hackers’

    Team_NewsStudyBy Team_NewsStudyMarch 10, 2025 Tech News No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Ben Morris

    Editor, Expertise of Enterprise

    Getty Images A nurse fills in a form in front of screensGetty Pictures

    Medefer handles round 1,500 referrals a month

    The NHS is “wanting into” allegations that affected person information was left weak to hacking because of a software program flaw at a personal medical providers firm.

    The flaw was discovered final November at Medefer, which handles 1,500 NHS affected person referrals a month.

    The software program engineer who found the flaw believes the issue had existed for not less than six years.

    Medefer says there isn’t a proof the flaw had been in place that lengthy and pressured that affected person information has not been compromised.

    The flaw was fastened a number of days after being found.

    In late February the corporate commissioned an exterior safety company to undertake a evaluate of its information administration techniques.

    An NHS spokesperson mentioned: “We’re wanting into the considerations raised about Medefer and can take additional motion if acceptable.”

    Medefer’s system permits sufferers to guide digital appointments with medical doctors, and provides these clinicians entry to the suitable affected person information.

    Nonetheless, the software program bug, found in November, made Medefer’s inner affected person file system weak to hackers, the engineer mentioned.

    The software program engineer, who doesn’t need to be named, was shocked by what he uncovered.

    “When I discovered it, I simply thought ‘no, it will probably’t be’.”

    The issue was in bits of software program referred to as APIs (utility programming interfaces), which permit totally different laptop techniques to speak to one another.

    The engineer says that at Medefer these APIs weren’t correctly secured, and will doubtlessly have been accessed by outsiders, who would have been in a position to see affected person info.

    He mentioned it was unlikely that affected person info was taken from Medefer, however that with out a full investigation, the corporate couldn’t have recognized for certain.

    “I’ve labored in organisations the place, if one thing like this occurred, the entire system could be taken down instantly,” he mentioned.

    On discovering the flaw the engineer advised the corporate that an exterior cybersecurity knowledgeable ought to be purchased in to research the issue, which he says the corporate didn’t do.

    Medefer says the exterior safety company has confirmed that it has discovered no proof of any breach of knowledge and that every one the corporate’s information techniques had been at present safe.

    It says the method of investigating and fixing the API flaw was “extraordinarily open”.

    Medefer mentioned it had reported the difficulty to the ICO (Info Commissioner’s Workplace) and the CQC (Care High quality Fee), “within the pursuits of transparency”, and that the ICO had confirmed there isn’t a additional motion to be taken as there isn’t a proof of a breach.

    The engineer, who had been contracted in October to check for flaws within the firm’s software program, left the corporate in January.

    In a press release Dr Bahman Nedjat-Shokouhi, founder and CEO of Medefer, mentioned: “There is no such thing as a proof of any affected person information breach from our techniques.”

    He confirmed that the flaw had been found in November and a repair was developed in 48 hours.

    “The exterior safety company has asserted that the allegation that this flaw may have offered entry to massive quantities of sufferers’ information is categorically false.”

    The safety company will full its evaluate later this week.

    Dr Nedjat-Shokouhi added: “We take our duties to sufferers and the NHS very severely. We maintain common exterior safety audits of our techniques by impartial exterior safety companies, undertaken on a number of events yearly.”

    Getty Images A vial of blood in front of a some medical scansGetty Pictures

    Big quantities of medical information must be shared amongst medical doctors and hospitals

    Cybersecurity specialists, who’ve checked out info provided by the software program engineer, have expressed their concern.

    “There may be the likelihood that Medefer saved information derived from the NHS not as securely as one would hope it might be,” mentioned Prof Alan Woodward, a cybersecurity knowledgeable on the College of Surrey.

    “The database is likely to be encrypted and all the opposite precautions taken, but when there’s a method of glitching the API authorisation, anybody who is aware of how may doubtlessly acquire entry,” he added.

    One other knowledgeable identified that as Medefer offers with highly-sensitive, medical information, the corporate ought to have purchased in cybersecurity specialists as quickly as the issue was recognized.

    “Even when the corporate suspected that no information was stolen, when going through a difficulty that might have resulted in a knowledge breach, particularly with information of the character in query, an investigation and affirmation from a suitably certified cybersecurity knowledgeable could be advisable,” says Scott Helme, a safety researcher.

    Medefer was based in 2013 by Dr Nedjat-Shokouhi, with a objective to enhance outpatient care. Since then its expertise has been utilized by NHS trusts throughout the nation.

    In a press release the NHS spokesperson mentioned these trusts are liable for their contracts with the non-public sector.

    “Particular person NHS organisations should guarantee they meet their authorized duties and nationwide information safety requirements to guard affected person information when appointing suppliers, and we provide them assist and coaching nationally on how this ought to be completed.”



    Source link

    Team_NewsStudy
    • Website

    Keep Reading

    The camera tech propelling shows like Adolescence

    IEEE standard offers 6 steps for AI system procurement

    Crypto exchange Coinbase faces up to $400m hit from cyber attack

    Co-op narrowly avoided an even worse cyber attack, BBC learns

    AlphaEvolve Tackles Kissing Problem & More

    Richard L. Garwin, a Creator of the Hydrogen Bomb, Dies at 97

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Biden Directed Funds To Afghanistan Over 9/11 Victims

    May 16, 2025

    IMAGINE THAT: Homicides Are Down 60 Percent in Denver Following ICE Deportations | The Gateway Pundit

    May 16, 2025

    TikToker Spills On Zak Bagans Amid Holly Madison Cheating Rumors

    May 16, 2025

    Cassie forced to read aloud explicit messages with Sean ‘Diddy’ Combs at his sex trafficking trial

    May 16, 2025

    Al-Qaeda affiliate claims 200 soldiers killed in Burkina Faso attack | Armed Groups News

    May 16, 2025
    Categories
    • Entertainment News
    • Latest News
    • Politics
    • Sports
    • Tech News
    • Travel
    • Trending News
    • World Economy
    • World News
    About us

    Welcome to NewsStudy.xyz – your go-to source for comprehensive and up-to-date news coverage from around the globe. Our mission is to provide our readers with insightful, reliable, and engaging content on a wide range of topics, ensuring you stay informed about the world around you.

    Stay updated with the latest happenings from every corner of the globe. From international politics to global crises, we bring you in-depth analysis and factual reporting.

    At NewsStudy.xyz, we are committed to delivering high-quality content that matters to you. Our team of dedicated writers and journalists work tirelessly to ensure that you receive the most accurate and engaging news coverage. Join us in our journey to stay informed, inspired, and connected.

    Editors Picks

    Justin Baldoni Claims He Has ‘Cold Hard Proof’ Blake Lively Targeted Him

    February 1, 2025

    US bans flights to Haiti after three jetliners hit by gunfire

    November 13, 2024

    US tech firm Salesforce to invest US$1 billion in Singapore

    March 12, 2025

    Sajad Shakoor brings hope and halal meals to California prisoners | Fork the System

    December 25, 2024
    Categories
    • Entertainment News
    • Latest News
    • Politics
    • Sports
    • Tech News
    • Travel
    • Trending News
    • World Economy
    • World News
    • Privacy Policy
    • Disclaimer
    • Terms & Conditions
    • About us
    • Contact us
    Copyright © 2024 Newsstudy.xyz All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.