{"id":13170,"date":"2025-04-28T14:26:44","date_gmt":"2025-04-28T13:26:44","guid":{"rendered":"https:\/\/pstqb.pt\/?p=13170"},"modified":"2025-04-29T10:06:38","modified_gmt":"2025-04-29T09:06:38","slug":"bug-deixa-dados-de-pacientes-do-sns-britanico-vulneraveis-a-ataques","status":"publish","type":"post","link":"https:\/\/pstqb.pt\/en\/bug-deixa-dados-de-pacientes-do-sns-britanico-vulneraveis-a-ataques\/","title":{"rendered":"Bug Leaves British NHS Patient Data Vulnerable to Attack"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"13170\" class=\"elementor elementor-13170\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6e368fa elementor-section-boxed elementor-section-height-default elementor-section-height-default wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no\" data-id=\"6e368fa\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8b4cf3a\" data-id=\"8b4cf3a\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-24d535f wpr-stt-btn-align-fixed wpr-stt-btn-align-fixed-right elementor-widget elementor-widget-wpr-back-to-top\" data-id=\"24d535f\" data-element_type=\"widget\" data-widget_type=\"wpr-back-to-top.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"wpr-stt-wrapper\"><div class='wpr-stt-btn' data-settings='{&quot;animation&quot;:&quot;fade&quot;,&quot;animationOffset&quot;:&quot;0&quot;,&quot;animationDuration&quot;:&quot;200&quot;,&quot;fixed&quot;:&quot;fixed&quot;,&quot;scrolAnim&quot;:&quot;800&quot;}'><span class=\"wpr-stt-icon\"><i class=\"fas fa-chevron-up\"><\/i><\/span><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b122b8c elementor-widget elementor-widget-text-editor\" data-id=\"b122b8c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In November last year, a <em>bug<\/em> in the Modefer application, which manages around 1,500 patients a month for the UK's National Health Service (NHS). The <em>software<\/em> has left patient data vulnerable to hacker attacks, says the\u00a0<a href=\"https:\/\/www.bbc.com\/news\/articles\/c5yxv7wylz7o\" target=\"_blank\" rel=\"noopener noreferrer\">BBC<\/a> and according to the software engineer who discovered it, it has existed for at least six years. Modefer says it has no proof that the vulnerability has existed for so long and says that patient data has not been compromised. Days after the discovery <em>bug<\/em> has been corrected, the company assures. An NHS spokesperson said it was taking note of the concerns raised about Medefer and will take the necessary action.<\/p><p>It was explained that Medefer's system allows patients to make virtual appointments with doctors, who have access to the associated clinical data. The engineer who discovered the vulnerability said that the APIs Medefer used were not properly secured and could be accessed by malicious third parties and have access to patient information. The engineer also accuses Medefer of not taking appropriate action as soon as the vulnerability was discovered. \"I've worked in organizations where if something like this happened, the whole system would be shut down immediately\" - he adds that an external cybersecurity specialist should have been called in to investigate the problem, something Medefer failed to do.<\/p><p>On the other hand, the company says that an external security agency has analyzed the problem and that the data is safe. This was confirmed by the company's founder, Bahman Nedjat-Shokouhi, who said that the fix was released within 48 hours of the vulnerability being discovered. He also points out that the claim that the bug gave access to large amounts of patient data is false. \"We take our duties to patients and the NHS very seriously. We have regular external security audits of our systems, on several occasions annually.\"<\/p><p>Because Medefer deals with highly sensitive patient data, such as medical information, cybersecurity experts who analyzed the case presented by the engineer from <em>software<\/em>The report, which was published in the Official Journal of the European Union, points out that NHS data was not as secure as it should have been and that external cybersecurity experts should have been called in immediately to ascertain the true scale of the problem.<\/p><p>\u00a0<\/p><p>The original article via <i>Sapo24 <\/i>can be read <a href=\"https:\/\/tek.sapo.pt\/noticias\/internet\/artigos\/bug-de-software-deixou-dados-de-pacientes-do-servico-nacional-de-saude-britanico-vulneraveis-a-ataques\">here<\/a>.\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>In November last year, a bug was discovered in the Modefer application, which manages around 1,500 patients a month for the UK's National Health Service (NHS). The software flaw left patient data vulnerable to hacker attacks, reports the BBC, and according to the software engineer who discovered it, it has existed for at least six years. Modefer says it has no proof that the vulnerability has existed for so long and says that patient data has not been compromised. Within days of the discovery, the bug was fixed, the company assures. An NHS spokesperson said that it was taking note of the concerns raised about Medefer and will take the necessary action. It was explained that Medefer's system allows patients to make virtual appointments with doctors, who have access to the associated clinical data. The engineer who discovered the vulnerability said that the APIs Medefer used were not properly secured and could be accessed by malicious third parties and have access to patient information. The engineer also accuses Medefer of not taking appropriate action as soon as the vulnerability was discovered. \"I've worked in organizations where if something like this happened, the entire system would be shut down immediately\" - he adds that an external cybersecurity specialist should have been called in to investigate the problem, something Medefer failed to do. On the other hand, the company says that an external security agency has analyzed the problem and that the data is safe. This was confirmed by the company's founder, Bahman Nedjat-Shokouhi, who said that the fix was released within 48 hours of the vulnerability being discovered. He also points out that the claim that the bug gave access to large amounts of patient data is false. \"We take our duties to patients and the NHS very seriously. We have regular external security audits of our systems, on several occasions annually.\" Because Medefer deals with highly sensitive patient data, such as medical information, cybersecurity experts who analyzed the case presented by the software engineer point out that the NHS data was not as secure as it should have been and that external cybersecurity experts should have been called in immediately to ascertain the true scale of the problem.   The original article via Sapo24 can be read here.\u00a0<\/p>","protected":false},"author":2,"featured_media":13177,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[31],"tags":[],"class_list":["post-13170","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-destaque"],"_links":{"self":[{"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/posts\/13170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/comments?post=13170"}],"version-history":[{"count":0,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/posts\/13170\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/media\/13177"}],"wp:attachment":[{"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/media?parent=13170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/categories?post=13170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pstqb.pt\/en\/wp-json\/wp\/v2\/tags?post=13170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}