- Primary risk
- Patient data exposure
- Drivers
- DSPT, CQC, NHS contracts
- Common finding
- Shared clinical logins
- Usual start
- Cyber Essentials
Why healthcare is targeted
Patient records combine identity data, financial data and medical history that cannot be reissued. A leaked card number is replaceable; a leaked diagnosis is not. That permanence gives attackers leverage, and extortion based on threatened publication of patient data is now a routine tactic.
Clinical systems also carry an availability risk that most sectors do not. A practice that cannot access records cannot safely treat patients, and the pressure to restore quickly is acute.
What we consistently find
- Shared clinical logins — genuinely difficult in a busy clinical setting, and the reason no audit trail means anything.
- Practice management systems exposed for remote access without adequate controls.
- Medical devices and imaging systems on the same flat network as everything else, running software that cannot be patched.
- Patient data emailed unencrypted, including to patients themselves.
- Third-party clinical software adopted without due diligence or a data processing agreement.
- Backups untested, and frequently on the same network as the systems they protect.
Who is asking
Organisations connecting to NHS systems or handling NHS patient data are generally expected to complete the Data Security and Protection Toolkit, which covers a broad set of security and information governance requirements. CQC registration brings expectations around records and governance. NHS supply chain contracts frequently specify Cyber Essentials. Private medical insurers and corporate clients send their own questionnaires.
Requirements in this area change; confirm the current position for your organisation type rather than relying on a summary.
Where to start
Cyber Essentials, because it addresses the controls that stop the attacks that actually occur, and because it is frequently what a contract names. Then an access review of your practice management system — who can see full patient records, and does their role require it. Then network segmentation, particularly separating imaging and medical devices from general IT.
And test a restore. Availability is a patient safety issue here, not just an IT one.
Common questions
Do we need the DSPT?
Generally if you access NHS patient data or connect to NHS systems. The precise requirement depends on your organisation type and contracts. Check the current position directly — and note that Cyber Essentials supports several DSPT areas, so the two are usually pursued together.
Our clinical software is managed by the vendor. Is that our responsibility?
The vendor secures their application. You remain responsible for access control, who has accounts, what happens when staff leave, the network the system sits on, and your own email. Most incidents originate in those rather than in the clinical software.
Shared logins are unavoidable in our clinic. What can we do?
It's a genuine operational constraint and we won't pretend otherwise. The practical mitigations are limiting what shared accounts can do, compensating with strong physical and network controls, using individual accounts wherever the workflow allows, and ensuring anything genuinely sensitive requires a named login.
Will testing affect clinical systems?
No. External and application testing has no impact on availability. Internal testing is scoped with agreed rules of engagement, and medical devices and imaging systems are excluded from active scanning as standard — they are exactly the systems that fail when scanned.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day