IT systems in Medway disconnected due to ‘suspicious activity’

  • 10 December 2024
IT systems in Medway disconnected due to ‘suspicious activity’
Shutterstock.com
  • Medway Community Healthcare announced that it has disconnected its IT systems to protect patient and staff data after detecting suspicious activity
  • The investigation is ongoing, with patients urged to use paper forms for blood tests while the systems are down
  • Richard Horne, the new head of the National Cyber Security Centre has emphasised the need for cyber defence and resilience to improve

Medway Community Healthcare (MCH) has announced that it has disconnected its IT systems to “protect patient and staff data” after detecting some “suspicious activity”.

In a statement on its website, published on 5 December 2024, the trust confirmed the decision and reason for disconnecting its systems, following the incident three day earlier.

The latest statement says: “Earlier this week we told you that we detected some suspicious activity relating to our IT systems.

“As a precaution, we therefore disconnected out systems to protect patient and staff data.”

It adds that an” investigation is ongoing” and that patients requiring blood tests will need to bring paper forms.

“If you do not have a paper form, we cannot proceed with your blood test. Unless you are told otherwise, booked appointments are still going ahead as planned.

“Our staff are working hard to continue to provide services during this time. Please bear with us, and be patient,” the statement says.

The incident was first announced on the trust’s website and on X on 2 December 2024:

 

The incident follows a cyber attack at Alder Hey Children’s NHS Foundation Trust on 28 November 2024, which also impacted Liverpool Heart and Chest Hospital and Royal Liverpool University Hospital and a cyber incident at Wirral University Teaching Hospital NHS Foundation Trust, on 25 November 2024.

Meanwhile,  Richard Horne, the new head of the National Cyber Security Centre (NCSC) called for the need for sustained vigilance.

In a speech on 3 December 2024, Horne said: “What has struck me more forcefully than anything else since taking the helm at the NCSC is the clearly widening gap between the exposure and threat we face, and the defences that are in place to protect us.

“And what is equally clear to me is that we all need to increase the pace we are working at to keep ahead of our adversaries.”

Horne highlighted the impact of cyber attacks, referencing the ransomware attack on pathology provider Synnovis in June 2024.

“In the past year, we have seen crippling attacks against institutions that have brought home the true price tag of cyber incidents.

“The attack against Synnovis showed us how dependent we are on technology for accessing our health services,” Horne said.

An updated cyber resilience framework for health and social care organisations was announced by the National Data Guardian and NHS England in September 2024.

The change to how organisations measure and self-report their data security capabilities is part of the Department of Health and Social Care’s ‘Cyber security strategy for health and social care: 2023 to 2030’, which aims to align health and care with cyber resilience standards across other sectors.

Subscribe to our newsletter

Subscribe To Our Newsletter

Subscribe To Our Newsletter

Sign up

Related News

John Quinn to leave NHS England CIO role

John Quinn to leave NHS England CIO role

John Quinn, chief information officer (CIO) at NHS England, has announced he will leave the role at the end of March 2024.
Digital Health Christmas Coffee Briefing 🎄

Digital Health Christmas Coffee Briefing 🎄

Our Christmas Coffee Briefing features festive-themed news, including a story from NHS Highland about how virtual care can make a difference.
Digital Health’s 2024 Review: Top 10 news stories

Digital Health’s 2024 Review: Top 10 news stories

Digital Health News has picked out the 10 news stories that sparked the most conversations in the sector in 2024.