NHS: Cybersecurity

(asked on 26th June 2026) - View Source

Question to the Department of Health and Social Care:

To ask the Secretary of State for Health and Social Care, what assessment he has made of the long-term patient safety impact of the Synnovis ransomware attack on NHS trusts in south-east London.


Answered by
Preet Kaur Gill Portrait
Preet Kaur Gill
This question was answered on 3rd July 2026

Cyber security is not just a technology risk. In 2024, a cyber-attack affecting Synnovis, a supplier of pathology services to the National Health Service, caused delays to over 11,000 out-patient and elective procedure appointments and, tragically, contributed to the death of a patient. We must see cyber security and resilience as a patient safety issue. Throughout the Synnovis incident, data was published on the NHS website, including on cancelled or delayed appointments.

Following the incident, the South East London Integrated Care System ran a patient safety investigation, which identified levels of patient harm seen during the Synnovis cyber-attack. Any new cases of patients coming to moderate harm or more as a result of the cyber incident would be reported through the quality reporting governance systems of the integrated care board as per NHS England reporting guidance.

Any national considerations are based on the reporting from affected trusts, which have been used to inform national processes. In addition, as competent authority under the Network and Information Systems Regulations, working on behalf of my Rt Hon. Friend, the Secretary of State for Health and Social Care, the Department has investigated the impact of the incident to understand the patient safety and service continuity impacts for operators of essential services.

Cyber incidents, including WannaCry in 2017, Advanced in 2022, and Synnovis in 2024, show that it is a matter of when, not if, the next cyber-attack on the NHS will take place. The impact of cyber incidents can be severe, including cancelled appointments, delays, or data breaches. Therefore, preparing for and responding to incidents is an important part of our programme. Following the Synnovis cyber-attack, the Department identified a set of lessons from the incident. These have been actioned and assigned to owners, with a large number completed and long-term improvements integrated into our ambitious Cyber Improvement Programme. The completed actions have included improvements made to the way in which patient harm is identified following a cyber incident. This aligns with other national incident processes.

Reticulating Splines