The UK National Health Services’ emergency services are being affected by a substantial and ongoing interruption of services triggered by a cyberattack impairing the systems of their managed service provider.
The attack was first noticed at 07:00 BST on Thursday.
The attack is disrupting all NHS 111 services across the UK. The Welsh Ambulance Services were the first to make a statement, saying “There is a major outage of a computer system that is used to refer patients from NHS Wales to out-of-hours GP providers“.
“A Business Continuity Incident has been declared, and partners across Wales have developed and deployed plans so services can continue to operate“.
Advanced MSP’s Adastra client patient management solution, used by 85% of NHS 111 services, was hit by a major outage, alongside several other services provided by the MSP, as stated in a status page released by the company (this status can now only be accessed by customers and employees).
Advanced provides business software to more than 22,000 global customers in various industry verticals from healthcare, education, transport, and charities.
Aside from the NHS, Advanced have customers including the UK Department for Work and Pensions (DWP), London City Airport, and Harvey Nicholas.
The full list of affected Advanced solutions are:
- Adastra – a clinical patient management software that impacts around 40 million patients.
- Caresys – a care home management software that helps over 1,000 care organisations.
- Carenotes – an electronic patient record software used by over 40,000 clinicians.
- Crosscare – a clinical management system for hospices and private practice used by over 70 adult and children’s hospices across the UK.
- Staffplan – a care management software that helps over 1,000 care organisations.
While public access to Advanced’s status page is now blocked by a login form, Advanced’s Chief Operating Officer Simon Short confirmed that the incident was caused by a cyberattack detected on Thursday morning.
In Short’s statement, shared with the BBC, he declared that “A security issue was identified yesterday, which resulted in a loss of service“.
“We can confirm that the incident is related to a cyber-attack and as a precaution. we immediately isolated all our health and care environments“.
“Early intervention from our Incident Response Team contained this issue to a small number of servers representing 2% of our Health & Care infrastructure“.
Cyber Security expert Robert Pritchard has stated that the attack was likely to have been Ransomware.
Cyber Criminal gangs who use ransomware software seek to encrypt vital data and then demand a ransom to get the information decrypted frequently target public organisations such as schools and hospitals, due to the substantial amount of personal data held, and low tolerance for downtime.
Cyber Security expert Jamie Moles, has said that questions need to be answered about how the threat actors breached the Advanced network.
“Are suppliers to the NHS like Advanced doing as much as they can to protect themselves and patient data – or are outsourced services a big risk to the NHS?”
“The improper outsourcing of IT services begs the question – who is making sure these external businesses are doing everything they can to protect patient data and make sure the provision of services is resilient?”








