NHS Lanarkshire has suffered another major cyber-attack, only three months after WannaCry bombarded its IT systems. The Trust manages the Hairmyres Hospital, Monklands Hospital and Wishaw General Hospital in central Scotland serving over 650,000 people, but warned that it would only handle emergency cases while the situation was contained. The incident is frightening – and as is so often the case, there are more questions than answers.
The breach was certainly dangerous enough for Medical Director for the Acute Division Dr. Jane Burns to ask patients on Friday via a Facebook update to reconsider their visits. She said: “I would ask that patients do not attend our hospitals unless it is essential. If you do turn up at A&E and do not require emergency care you may be sent away from the department or you may experience a lengthy wait. Emergency care will still be provided for those who do require to be seen.”
Déjà vu?
While the situation was largely contained by Saturday morning, eyebrows are likely to be raised.
NHS Lanarkshire was one of the 11 NHS Scotland Trusts to be majorly hit by WannaCry back in May. The WannaCry attack spread among a large number of computers running on outdated software, encrypting files and demanding payment for their release. The NHS was one of the worst-affected institutions worldwide, and around 70,000 devices – from computers to MRI scanners – across the UK were affected by the attack.
Friday’s assault was not a repeat of the Wannacry ransomware, but a different form of Malware which normally damages files and systems. In a subsequent update issued by Facebook on Saturday, the NHS Lanarkshire clarified that its ‘staff bank’ and telephone systems had been taken offline, and that an emergency phone line had been set up.
One Facebook commentator asked NHS Lanarkshire: “When is the NHS going to install the latest security software so these hackers can’t keep doing this? It’s people’s personal information your [sic] dealing with”. In response the Trust insisted that all of its security systems were “up to date”, “but nothing offers 100% protection”.
This raises multiple questions – none of which has a clear answer. Was the issue human error or hacker-savviness? Are Scottish NHS staff, most of whom are already under extreme pressure, given the time that they need to adapt to their increasingly digitised platform? Are Scottish health systems – like Turas for staff education and SPIRE for academic studies – ready for adoption despite the admission that no systems are 100% safe?
Containment
According to NHS Lanarkshire Chief Executive Calum Campbell, eHealth technicians worked through the night on Friday to identify the malware and reinstate IT systems. Calum confirmed that a number of appointments had been cancelled or postponed as a result of the incident. He also warned that while most of the services had returned to normal by Saturday morning, visitors and patients might experience longer waits over the weekend.
Calum said: “Our staff have worked hard to minimise the impact on patients and our contingency plans have ensured we have been able to continue to deliver services while the IT issues were resolved. Unfortunately a small number of procedures and appointments have been cancelled as a result of the incident. I would like to apologise to anyone who has been affected by this disruption, however I can assure you that work is already underway to reappoint patients.”
‘Contingency plans’ are a reassuring start. Less-so is Calum’s assurance that, “investigations are ongoing as to how this was able to infiltrate our network.” Of-course, plugging holes will keep a ship afloat, but hindsight does little to prevent physical damage to real people if and when an outage occurs. When all systems return to normal, more transparency is needed from NHS Lanarkshire on the issue as soon as possible.





