Medical records are among the most valuable data on criminal markets — a complete health record sells for significantly more than a credit card number because it contains everything needed for identity theft, insurance fraud, and targeted extortion. Healthcare SMEs in the UK — dental practices, GP surgeries, optometry practices, physiotherapy clinics, private hospitals — hold exactly this data and are routinely targeted by ransomware groups and data brokers who know that small healthcare businesses typically have weaker security than NHS trusts.

The WannaCry attack on the NHS in 2017 was the most visible UK healthcare cyber incident, but smaller practices are targeted continuously, often without making national news. The ICO enforcement record shows dozens of healthcare SME fines and enforcement notices annually for avoidable data breaches.

Why Healthcare SMEs Are Targeted

Medical records command premium prices: NHS numbers, medical histories, prescription records, and patient demographics sell for significantly more than financial data on criminal markets. The information enables insurance fraud, prescription fraud, and highly personalised phishing attacks.

Practices have regulatory pressure that creates leverage for ransomware: A dental practice with patient records encrypted two days before a full appointment schedule faces enormous pressure to pay. Ransomware groups know this. The 72-hour ICO reporting obligation adds to the pressure — if the practice pays before reporting, it may avoid some public exposure.

Clinical systems are old and hard to update: EMIS Web, SystmOne, Dentally, and other clinical practice management systems are critical infrastructure that can’t be patched casually. Delayed updates create persistent vulnerabilities. Many practices run clinical systems on Windows versions that are near or past end-of-life because the clinical software vendor hasn’t certified newer versions.

Staff turnover creates credential risks: Healthcare practices have high staff turnover. Access credentials for leavers are frequently not revoked promptly, creating dormant accounts that can be exploited.

NHS integration means bidirectional risk: NHS-connected practices use N3/HSCN connectivity for NHSmail, electronic prescription service, and clinical data exchange. This connectivity has its own security requirements, and a breach on the practice side can affect NHS systems.

The Specific Threats

Ransomware Targeting Patient Records

Ransomware groups including ALPHV (BlackCat), LockBit successors, and several others specifically target healthcare. The attack typically begins with a phishing email that delivers malware, which then moves laterally across the practice network before encrypting files and demanding payment.

Healthcare practices are attractive targets because:

  • Patient record backups are often inadequate or connected to the same network being encrypted
  • The clinical systems may not have granular access controls, so one compromised account can reach all patient data
  • Regulatory pressure creates payment motivation

The critical defence is tested, offline backups. If your patient records can be restored from a backup that the ransomware couldn’t reach, the attack becomes an operational disruption rather than a catastrophe.

Supply Chain Attacks via Clinical Software Updates

Clinical practice management software connects to update servers, NHS infrastructure, and third-party integrations. Compromised software updates — similar to the supply chain attacks seen in other sectors — are a realistic attack vector for healthcare software that practices install with high trust.

Mitigation: Ensure your clinical software updates come from the vendor’s official channels. Be cautious about installing plugins, add-ons, or integrations that aren’t approved by your primary clinical system vendor. Review what third-party systems have access to your patient data.

Phishing Targeting Clinical Staff

Healthcare staff are targeted with phishing emails that impersonate NHS IT support (“your NHSmail account requires verification”), HMRC, the CQC or GDC, or clinical suppliers. The combination of authority (regulatory bodies) and urgency (account suspension, compliance deadlines) is effective.

Training staff to verify out-of-band — call the sender on a known number rather than clicking a link or calling back on a number in the email — is the primary defence. Clinical staff are not naturally suspicious of emails from bodies they regularly interact with; training needs to be explicit.

Unsecured Medical Devices

Dental X-ray systems, diagnostic imaging equipment, connected medical devices, and practice monitoring systems often run embedded operating systems with default credentials and infrequent firmware updates. These devices are frequently on the same network as clinical PCs, meaning a compromised device provides a foothold into the practice network.

Segment devices onto separate VLANs where possible. Change default credentials on any networked medical device. Ensure firmware updates are applied when available.

Key Compliance Obligations

UK GDPR and Data Protection Act 2018

Patient health data is special category data under UK GDPR, requiring a higher standard of protection. Practices processing special category data must have a lawful basis (typically explicit consent or provision of healthcare) and must document their data processing activities.

A breach affecting patient data must be reported to the ICO within 72 hours if it is likely to result in risk to individuals. This includes ransomware attacks that may have exposed patient records, even if the attacker hasn’t explicitly confirmed accessing the data. The ICO takes the view that an attacker with access to encrypted files may have exfiltrated them before encrypting.

ICO enforcement against healthcare SMEs for data protection failures is consistent. Fines range from a few thousand pounds for minor breaches to over £100,000 for significant failures. Practices with demonstrably good security practices receive more lenient treatment than those with no security measures.

CQC Registration (England)

The Care Quality Commission’s fundamental standards require providers to protect patients from avoidable harm, including harm arising from data breaches. A significant cyber incident that disrupts patient care or exposes patient data can trigger CQC inspection and, in serious cases, enforcement action.

CQC inspections increasingly include questions about information governance and cybersecurity. Having documented security policies and evidence of staff training is part of demonstrating compliance with the fundamental standards.

GDC and Other Regulatory Bodies

Dental practices registered with the General Dental Council must comply with its standards for patient confidentiality and record keeping. A breach that exposes patient dental records is relevant to GDC fitness to practise proceedings if the practice can’t demonstrate reasonable security measures.

Similar obligations apply to practices registered with the GMC, GOC (optometry), and HCPC (physiotherapy, podiatry, etc.).

NHS Data Security and Protection Toolkit

Practices with NHS contracts are required to complete the Data Security and Protection (DSP) Toolkit annually. The toolkit assesses 10 data security standards developed from the National Data Guardian’s review. For many practices, the toolkit requirements provide a useful baseline security framework even beyond NHS contractual compliance.

Practical Security Steps

Securing Clinical Systems

Apply updates promptly: Yes, clinical systems are complex, but running unpatched software compounds risk significantly. Work with your clinical system vendor to understand the update schedule and apply updates during low-activity periods.

Use role-based access: Clinical system staff should have access to the patient records they need for their role, not all patient records. Most clinical systems support this — configure it. A receptionist doesn’t need access to clinical notes; a nurse doesn’t need access to billing data.

Enable audit logging: All clinical system access should be logged. Who accessed which patient record, when. Most clinical systems support this. Review logs periodically for unusual access patterns — after hours, bulk record access, access to records of public figures or staff members.

Separate clinical and admin networks: If your clinical PCs (running EMIS, SystmOne, Dentally) are on the same network as your admin PCs and internet-facing devices, a compromise of any device can reach the clinical data. VLAN segmentation with a firewall between segments is the right architecture. An IT provider familiar with healthcare can implement this.

Backups

The backup strategy for a healthcare practice needs to be specific:

  • Daily backups of all patient record data, including from your clinical system
  • Backup stored separately from the main network — ideally cloud backup plus an offline copy. If the backup is on a NAS drive attached to the practice network, ransomware will encrypt it
  • Tested restores: Run a restore test at least quarterly. A backup you’ve never restored from may not work when you need it
  • Retention: Keep at least 90 days of backup history. Some ransomware encrypts files gradually over weeks before triggering visible encryption — a backup from yesterday may already contain encrypted files

Clinical system vendors often provide backup tools or cloud backup options as part of their service agreements. Check what’s included and verify it meets these requirements.

Email and Phishing

Enable MFA on all email accounts: NHSmail has MFA available; enable it. Practice email accounts on Office 365 or Google Workspace should have MFA enabled for all users.

Set up DMARC: Prevents criminals from sending emails that appear to come from your practice domain. This protects your patients as well as your practice — attackers impersonating your practice to contact patients are a real risk.

External email banners: Configure your email system to add a banner to emails from outside your organisation. Makes it immediately visible when an email claiming to be from a colleague is actually external.

Staff training: Include specific scenarios: NHSmail reset emails, CQC inspection notifications, urgent patient referral attachments, software licence expiry notices. The more specific the training, the more likely staff recognise real examples.

Physical Security

Patient records in paper form and on unlocked workstation screens are physical security risks as well as digital ones. Basic requirements:

  • Screen locks after 5 minutes of inactivity (configurable in Windows Group Policy or macOS settings)
  • No patient data visible on screens facing public waiting areas
  • Prescription pads and patient summary sheets locked away when unattended
  • CCTV in server room or wherever practice servers and network equipment are located
  • Visitor access controls — visitors shouldn’t be able to reach clinical areas without escort

Staff Leavers

When a staff member leaves, their access to clinical systems, email, and any other systems must be revoked on their last working day. This includes:

  • Clinical system login
  • NHSmail account
  • Practice email
  • WiFi credentials (if shared)
  • Physical access — keys, door codes
  • Access to any cloud services used by the practice

Maintain a list of all systems each staff member has access to, updated when access is granted. Revoking access without this list means inevitably missing something.

Incident Response for Healthcare Practices

When something goes wrong — a suspicious email opened, an unusual login, files not opening normally — the response steps:

  1. Isolate the affected device: Disconnect from the network immediately. Don’t try to fix it while it’s connected.
  2. Contact your IT support: Call, don’t email — email may be compromised.
  3. Assess scope: What data was potentially accessed or encrypted? What systems are affected?
  4. Notify the ICO within 72 hours if patient data was likely accessed or exposed. The ICO reporting portal is at ico.org.uk. If in doubt, report — failing to report is an additional offence.
  5. Notify affected patients if their data was likely accessed and there’s a risk to them.
  6. Contact your cyber insurer if you have one — before engaging forensic services, check what your policy covers.
  7. Report to Action Fraud at actionfraud.police.uk or by calling 0300 123 2040.

The NCSC provides free Cyber Incident Response guidance at ncsc.gov.uk for organisations without dedicated security teams.

Quick-Win Checklist

  • MFA enabled on NHSmail and practice email for all staff
  • Clinical system role-based access configured and reviewed
  • Backup tested and stored separately from the practice network
  • DMARC set up on practice email domain
  • Staff leaver process documented and followed for last two leavers
  • DSP Toolkit completed for current year (NHS-contracted practices)
  • Medical device firmware checked and updated where possible
  • Clinical and admin network segmented (or this added to IT project list)
  • ICO incident reporting process understood before an incident happens

Most UK healthcare SMEs are underprotected relative to the sensitivity of the data they hold. Working through this checklist gets a practice into the top tier of security for its size — and provides documentation that both the ICO and regulatory bodies treat as evidence of reasonable effort when reviewing incidents.