ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NHS contractor Medefer denies software flaw put patient data at risk of breach

The NHS said it is investigating claims of patient data being left vulnerable to hacking thanks to a critical software vulnerability affecting its service provider Medefer.

 

Headquartered in London, Medefer is an inventive outpatient service that helps patients get care quickly and easily. When a patient is referred to Medefer for an online appointment, the firm receives patient data from the NHS’s e-referral system (e-RS) or the NHS Spine to make it available to medics for consultations.

 

Recently, the BBC reported that in November, an anonymous whistleblower identified a software flaw that made Medefer’s internal patient record system vulnerable to hackers.

 

According to the whistleblower, a software testing contractor at the company, Medefer’s APIs were not properly secured and could potentially be accessed by outsiders, resulting in the compromise of patient information.

The whistleblower then contacted the company and urged it to get an external cyber security expert, which Medefer did not do.

 

Responding to the claims, Medefer’s CEO, Dr Bahman Nedjat-Shokouhi, said that the issue was fixed within 48 hours of being notified. The company also reported the incident to the Information Commissioner’s Office which said no further action needs to be taken as there is no evidence of a breach.

 

In a statement shared with the media, Nedjat-Shokouhi said, “There is no evidence of any patient data breach from our systems. The external security agency has asserted that the allegation that this flaw could have provided access to large amounts of patients’ data is categorically false.

 

“We take our duties to patients and the NHS very seriously. We hold regular external security audits of our systems by independent external security agencies, undertaken on multiple occasions every year,” he added.

 

Commenting on the incident, a NHS spokesperson said, “We are looking into the concerns raised about Medefer and will take further action if appropriate."


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543