Tech News : Hacked MSP Fined £6m (Provisionally)

Table of Contents

A provisional £6m fine has been imposed on an NHS software provider Advanced Computer Software Group following a 2022 data breach that affected more than 80,000 people.

Advanced Software Group 

Founded in 2008, Advanced Computer Software Group, often referred to as “Advanced,” is a UK-based software and IT services company that provides a range of digital solutions primarily to the public sector, healthcare, and private sector organisations. As an IT and software services provider to organisations including the NHS and other healthcare providers, in the eyes of the law, it handles people’s personal information on behalf of these organisations as their ‘data processor’.

What Happened? 

In 2022, hackers accessed a number of Advanced’s health and care systems via a customer account that did not have multi-factor authentication. The personal information belonging to 82,946 people was stolen following the attack. This information included phone numbers and the medical records, as well as details of how to gain entry to the homes of 890 people who were receiving care at home.

Serious Failings 

John Edwards, UK Information Commissioner, has highlighted how the ICO, which has investigated the incident, provisionally found “serious failings” in Advanced’s “approach to information security prior to this incident”. Mr Edwards noted how Advanced “failed to keep its healthcare systems secure” when it should have been taking steps to secure its systems, such as “regularly checking for vulnerabilities, implementing multi-factor authentication and keeping systems up to date with the latest security patches.” 

The Obligations of Data Processors 

In his online statement, Mr Edwards noted that although data processors act on the instructions of their clients, the data controllers, data processors, such as Advanced, “still have their own obligations to implement appropriate technical and organisational measures to ensure personal information is kept secure” and this includes “taking steps to assess and mitigate risks”. 

Health Service Disruption Also Caused 

In his online statement, Mr Edwards also noted that in addition to the theft of personal information, the hack caused disruption to some health services, i.e. disrupting their ability to deliver patient care. Mr Edwards said this meant that “a sector already under pressure was put under further strain due to this incident”. 

Provisional Fine 

The ICO has stated that on the grounds that Advanced failed to implement measures to protect the personal (and some sensitive) information of the 80,000+ people, it has “provisionally decided” to impose a £6.09m fine on Advanced.

However, despite choosing to issue the statement about it, the ICO’s findings and fine are “provisional”. This means that conclusions shouldn’t be drawn at this stage about whether there’s actually been any breach of data protection law or that a financial penalty will ultimately be imposed.

The Commissioner says that any representations from Advanced will now be carefully considered before any final decision is made “with the fine amount also subject to change.” 

Illustrates The Importance of Prioritising Information Security 

UK Information Commissioner, said in his statement about the provisional fine: “This incident shows just how important it is to prioritise information security. Losing control of sensitive personal information will have been distressing for people who had no choice but to put their trust in health and care organisations.” 

What Does This Mean For Your Business? 

The provisional £6 million fine imposed on Advanced Computer Software Group serves as a stark reminder of the critical importance of businesses and organisations prioritising information security. This incident highlights how even well-established companies with significant responsibilities (such as handling sensitive healthcare data) are not immune to severe consequences when security measures are insufficient. The breach at Advanced not only compromised the personal and medical information of over 80,000 individuals but also disrupted essential health services, demonstrating the far-reaching impact of inadequate data protection.

For your business, this underscores the need to rigorously assess and enhance your cybersecurity practices, particularly if you are a data processor or handle sensitive information on behalf of clients. The ICO’s findings point to specific failings, such as the lack of multi-factor authentication and the failure to regularly update systems, which could have prevented the breach. Implementing robust security protocols, including regular vulnerability assessments, system updates, and comprehensive risk mitigation strategies, is not just a legal obligation but a business imperative.

Also, the incident shows how the failure to prioritise information security can lead to significant financial and reputational damage. While the ICO’s decision and fine are currently provisional, the potential for such penalties should serve as a wake-up call for businesses and organisations to take proactive steps in safeguarding personal data. As the Information Commissioner noted, this case demonstrates the distress caused to individuals who trust organisations with their sensitive information, making it clear that maintaining this trust should be a top priority.

Recent Blog Posts

As the countdown to October 14, 2025 continues, the end of support for Windows 10 ...

What is an IT support specialist? Technology is at the core of every ...

Google has filed a set of proposed remedies in its high-profile antitrust case ...

Client Testimonials

Stuart B.
10:16 10 Sep 24
Flyford have helped out IT throughout our growth. So, matching our systems to not only what we need now, but what we will be needing in the future; future proofing.They just make it all easy, and take the stress out of IT for us.
Xanthe S.
12:12 06 Jul 22
We would highly recommend Flyford’s services. They are always on hand for help and advice, nothing is ever too much trouble. All the guys are knowledgable, helpful and friendly. You can’t want much more from a company! Many thanks from us all at Green Mile Trees.
Alan G.
18:08 23 May 22
I messed up my Dell laptop downloading non standard updates and lost the inbuilt system update. I tried for a week to rectify my mistake and couldn’t. Then I installed BT Cloud and that wouldn’t work either. John from Flyford sorted it out within 30 minutes. Big thanks to everyone, highly recommended.👍
Hanicks L.
11:34 26 Mar 22
Excellent support
Stephanie M.
15:33 10 Feb 22
Flyford run the IT for our accountancy firm in Retford. We rely heavily on IT for our business and they are always efficient dealing with our requests and keeping us up and running at all times. They also help us forward plan for our growing needs, keeping in mind budgets and working to our time frames
The team at Flyford are great for our business based in Lincoln. We are only a small company, so its great to know we have help with our computers should we need it. We have recommended Flyford to other business’s in the area.
js_loader

Areas we cover

We provide it support, telephony and it managed services to the following locations and their surrounding areas:

Doncaster, Sheffield , Tickhill , Maltby , Rotherham, Swallownest , Barnsley , Lincoln, Nottingham, Worksop, Retford, Newark, Harworth, Edwinstowe, Barlborough

Freqently Asked
Questions:

If you have any further questions please feel free to contact us

Contact Us >

We offer a wide range of services, including IT computer supportmanaged services IT supportIT consultancycybersecurity, and more. Whether you’re looking for company IT support or help with specific issues, we’ve got you covered.

We pride ourselves on providing tailored IT support solutions for businesses of all sizes. Our expert team delivers high-quality, 24/7 IT support, ensuring that your systems are always running smoothly.

IT support is essential for increasing productivity, safeguarding your valuable data, and reducing downtime, helping your business run smoothly and efficiently. With reliable IT support in place, you can focus on your core operations while knowing your systems are secure, reliable, and performing at their best. Additionally, you’ll have the peace of mind that expert assistance is always on hand whenever you need it.
There are different levels of IT support, including remote IT support, 24/7 IT support, and on-site assistance. Services range from basic troubleshooting to full IT management support.
IT support provides assistance for managing and troubleshooting technology. It’s essential for businesses that rely on technology to ensure smooth operations and reduce downtime.