ICO proposes $7.8M fine against NHS contractor in warning to IT providers

ICO_web

The U.K. Information Commissioner’s Office (ICO) proposed a 6.1 million pound (U.S. $7.8 million) fine against Advanced Computer Software Group, an IT contractor for the National Health Service (NHS) that allegedly failed to secure the data of 83,000 people after a cyberattack.

The ICO said in a press release Wednesday it provisionally penalized Advanced after the company allegedly failed to implement basic cybersecurity controls to protect personal data. If finalized, the enforcement action would be the agency’s first financial penalty against a data processor under the U.K. General Data Protection Regulation.

Advanced provides the NHS and other healthcare providers with IT and software services. In August 2022, the company suffered a ransomware attack that gave hackers access to some of the company’s health and care systems via a customer account that did not have multi-factor authentication.

lock iconTHIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.