News
  • Login
  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
Monday, December 8, 2025
No Result
View All Result

NEWS

3 °c
London
8 ° Wed
9 ° Thu
11 ° Fri
13 ° Sat
  • Home
  • Video
  • World
    • All
    • Africa
    • Asia
    • Australia
    • Europe
    • Latin America
    • Middle East
    • US & Canada

    'We deserve to have a say' – Australian teens on the social media ban

    Trump criticises Henry Cuellar over not switching parties after pardon

    Benin coup thwarted by loyalist troops, President Talon tells nation

    India’s poll workers flag harsh conditions amid rising deaths

    New US security strategy aligns with Russia’s vision, Moscow says

    Death of Venezuelan opposition figure in custody ‘vile’, US says

    Bethlehem Christmas tree lights up for first time since Gaza war

    California wild mushroom poisoning leaves 1 dead, 20 injured

    Can you ban kids from social media? Australia is about to try

  • UK
    • All
    • England
    • N. Ireland
    • Politics
    • Scotland
    • Wales

    Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

    Teenager Mitchell Lawrie beaten by Jimmy van Schie in WDF World Championship final

    Merthyr couple hope new room will stop A&E fear for ALN families

    Murder inquiry launched after child and woman die in fire

    Covid fraud and error cost taxpayers £10.9bn, report will say

    How Lando Norris achieved his lifetime’s ambition of F1 world title by ‘winning it my way’

    Army veteran shocked by XL bully owner’s sentence after attack

    Why do Gen Z have a growing appetite for retro tech?

    Champions Cup: Scarlets 16-17 Bristol – Louis Rees-Zammit seals win for Bears

  • Business
    • All
    • Companies
    • Connected World
    • Economy
    • Entrepreneurship
    • Global Trade
    • Technology of Business

    Can Japan get more female business leaders?

    Canadia airline to halt flights ahead of strike

    What is the Office for Budget Responsibility and why has its boss resigned?

    Sold 30 items on Vinted? Don’t panic if you get a message about tax

    West Midlands people urged to ‘shop local’ and back small firms

    People admit to ‘secret spending’ without telling partners

    Five takeaways from the blockbuster Netflix Warner Brothers deal

    Ryanair scraps printed boarding passes to go fully digital

    Reeves will not face ethics probe over pre-Budget remarks

  • Tech
  • Entertainment & Arts

    Dancers say Lizzo ‘needs to be held accountable’ over harassment claims

    Freddie Mercury: Contents of former home being sold at auction

    Harry Potter and the Cursed Child marks seven years in West End

    Sinéad O’Connor: In her own words

    Tom Jones: Neighbour surprised to find singer in flat below

    BBC presenter: What is the evidence?

    Watch: The latest on BBC presenter story… in under a minute

    Watch: George Alagiah’s extraordinary career

    BBC News presenter pays tribute to ‘much loved’ colleague George Alagiah

    Excited filmgoers: 'Barbie is everything'

  • Science
  • Health
  • In Pictures
  • Reality Check
  • Have your say
  • More
    • Newsbeat
    • Long Reads

NEWS

No Result
View All Result
Home Tech

Software bug at firm left NHS data ‘vulnerable to hackers’

March 10, 2025
in Tech
6 min read
247 5
0
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter


Ben Morris

Editor, Technology of Business

Getty Images A nurse fills in a form in front of screensGetty Images

Medefer handles around 1,500 referrals a month

The NHS is “looking into” allegations that patient data was left vulnerable to hacking due to a software flaw at a private medical services company.

The flaw was found last November at Medefer, which handles 1,500 NHS patient referrals a month.

The software engineer who discovered the flaw believes the problem had existed for at least six years.

Medefer says there is no evidence the flaw had been in place that long and stressed that patient data has not been compromised.

The flaw was fixed a few days after being discovered.

In late February the company commissioned an external security agency to undertake a review of its data management systems.

An NHS spokesperson said: “We are looking into the concerns raised about Medefer and will take further action if appropriate.”

Medefer’s system allows patients to book virtual appointments with doctors, and gives those clinicians access to the appropriate patient data.

However, the software bug, discovered in November, made Medefer’s internal patient record system vulnerable to hackers, the engineer said.

The software engineer, who does not want to be named, was shocked by what he uncovered.

“When I found it, I just thought ‘no, it can’t be’.”

The problem was in bits of software called APIs (application programming interfaces), which allow different computer systems to talk to each other.

The engineer says that at Medefer those APIs were not properly secured, and could potentially have been accessed by outsiders, who would have been able to see patient information.

He said it was unlikely that patient information was taken from Medefer, but that without a full investigation, the company could not have known for sure.

“I’ve worked in organisations where, if something like this happened, the whole system would be taken down immediately,” he said.

On discovering the flaw the engineer told the company that an external cybersecurity expert should be brought in to investigate the problem, which he says the company did not do.

Medefer says the external security agency has confirmed that it has found no evidence of any breach of data and that all the company’s data systems were currently secure.

It says the process of investigating and fixing the API flaw was “extremely open”.

Medefer said it had reported the issue to the ICO (Information Commissioner’s Office) and the CQC (Care Quality Commission), “in the interests of transparency”, and that the ICO had confirmed there is no further action to be taken as there is no evidence of a breach.

The engineer, who had been contracted in October to test for flaws in the company’s software, left the company in January.

In a statement Dr Bahman Nedjat-Shokouhi, founder and CEO of Medefer, said: “There is no evidence of any patient data breach from our systems.”

He confirmed that the flaw had been discovered in November and a fix was developed in 48 hours.

“The external security agency has asserted that the allegation that this flaw could have provided access to large amounts of patients’ data is categorically false.”

The security agency will complete its review later this week.

Dr Nedjat-Shokouhi added: “We take our duties to patients and the NHS very seriously. We hold regular external security audits of our systems by independent external security agencies, undertaken on multiple occasions every year.”

Getty Images A vial of blood in front of a some medical scansGetty Images

Huge amounts of medical data has to be shared among doctors and hospitals

Cybersecurity experts, who have looked at information supplied by the software engineer, have expressed their concern.

“There is the possibility that Medefer stored data derived from the NHS not as securely as one would hope it would be,” said Prof Alan Woodward, a cybersecurity expert at the University of Surrey.

“The database might be encrypted and all the other precautions taken, but if there is a way of glitching the API authorisation, anyone who knows how could potentially gain access,” he added.

Another expert pointed out that as Medefer deals with highly-sensitive, medical data, the company should have brought in cybersecurity experts as soon as the problem was identified.

“Even if the company suspected that no data was stolen, when facing an issue that could have resulted in a data breach, especially with data of the nature in question, an investigation and confirmation from a suitably qualified cybersecurity expert would be advisable,” says Scott Helme, a security researcher.

Medefer was founded in 2013 by Dr Nedjat-Shokouhi, with a goal to improve outpatient care. Since then its technology has been used by NHS trusts across the country.

In a statement the NHS spokesperson said those trusts are responsible for their contracts with the private sector.

“Individual NHS organisations must ensure they meet their legal responsibilities and national data security standards to protect patient data when appointing suppliers, and we offer them support and training nationally on how this should be done.”



Source link

Tags: bugdataFirmhackersleftNHSsoftwarevulnerable

Related Posts

Japan is facing a dementia crisis – can technology help?

December 8, 2025
0

Suranjana TewariAsia Business Correspondent, TokyoBBCScientists at Waseda University in Tokyo are developing caregiving robotsLast year, more than 18,000 older...

Elon Musk’s X fined €120m over ‘deceptive’ blue ticks

December 7, 2025
0

Liv McMahonTechnology reporterGetty ImagesThe EU has fined Elon Musk's social media platform X €120m (£105m) over its blue tick...

Twitch star QTCinderella says she wishes she never started streaming

December 6, 2025
0

Laura CressTechnology reporterBBCThe popular Twitch streamer QTCinderella says she would be a "happier person" if she could go back...

  • Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

    520 shares
    Share 208 Tweet 130
  • UK inflation: Supermarkets say price rises will ease soon

    513 shares
    Share 205 Tweet 128
  • Ballyjamesduff: Man dies after hit-and-run in County Cavan

    510 shares
    Share 204 Tweet 128
  • Somalia: Rare access to its US-funded 'lightning commando brigade

    508 shares
    Share 203 Tweet 127
  • Google faces new multi-billion advertising lawsuit

    508 shares
    Share 203 Tweet 127
  • Trending
  • Comments
  • Latest

Australia helicopter collision: Mid-air clash wreckage covers Gold Coast

January 10, 2023

UK inflation: Supermarkets say price rises will ease soon

April 19, 2023

Ballyjamesduff: Man dies after hit-and-run in County Cavan

August 19, 2022

Stranger Things actor Jamie Campbell Bower praised for addiction post

0

NHS to close Tavistock child gender identity clinic

0

Cold sores traced back to kissing in Bronze Age by Cambridge research

0

Volcanic eruption may have triggered Europe’s Black Death plague

December 8, 2025

Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

December 8, 2025

Radio 1’s Big Weekend 2026 announced for Sunderland

December 8, 2025

Categories

Science

Volcanic eruption may have triggered Europe’s Black Death plague

December 8, 2025
0

Helen BriggsEnvironment correspondentGettyThe Black Death fundamentally altered medieval societyA volcanic eruption around the year 1345 may have set off...

Read more

Heathrow ‘pepper spray attack’ and ‘Harry gun cop U-turn’

December 8, 2025
News

Copyright © 2020 JBC News Powered by JOOJ.us

Explore the JBC

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More

Follow Us

  • Home Main
  • Video
  • World
  • Top News
  • Business
  • Sport
  • Tech
  • UK
  • In Pictures
  • Health
  • Reality Check
  • Science
  • Entertainment & Arts
  • Login

Copyright © 2020 JBC News Powered by JOOJ.us

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
News
More Sites

    MORE

  • Home
  • News
  • Sport
  • Worklife
  • Travel
  • Reel
  • Future
  • More
  • News

    JBC News