Site navigation

National Records of Scotland Data Published in NHS Dumfries and Galloway Breach

Elizabeth Greenberg

,

nhs dumfries and galloway data breach
In an update to the NHS Dumfries and Galloway data breach story, even more sensitive and personal data is revealed to have been accessed. 

The National Records of Scotland (NRS) has disclosed that personal and sensitive data it held was accessed and published as part of the cyber-attack on NHS Dumfries and Galloway which was first reported in March.

NRS holds information on the NHS Dumfries and Galloway IT network as it runs an administrative service for the NHS to allow the transfer of patient records when people move between health board areas, across borders within the UK or move overseas.

Based on their internal audit of the stolen information, the NRS has identified “a small number of cases where there was sensitive information help temporarily on the network at the time of the attack,” a statement read.

NRS says that they are already engaging with affected individuals and has informed the Information Commissioner.

Some information which comes from the statutory births, deaths and marriages registers was also accessed.

“We are aware that this will be distressing news for those individuals most directly affected. This is a live criminal investigation, and we are working closely with NHS Dumfries and Galloway, Police Scotland, Scottish Government and other agencies involved in the inquiry,” NRS chief executive Janet Edgell said.

“NRS takes cyber security and privacy seriously. This includes ensuring the continued safe provision of the service we provide.”

The initial cyber-attack took place in March and accessed and stole data from the Dumfries and Galloway NHS Health Board. Later, in May, the threat actor group threatened to publish 3TB of data, which was published on the 6th of May.


Recommended reading


In March, the cyber gang Inc Ransom posted a ‘proof pack’ of data stolen from the health board, threatening to lead the sensitive information unless its “unspecified demands” were met.

The health board denied to comply, and the data was released. While the health board confirmed that the gang did not access primary patient health information records, the information published could put NHS staff at greater risk of identity theft.

While patient records themselves were not accessed in full, millions of small, separate pieces of data were accessed, including highly personal information about patients, which could put them at greater risk of targeted attacks.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data