
The NHS said it is investigating claims of patient data being left vulnerable to hacking thanks to a critical software vulnerability affecting its service provider Medefer.
Headquartered in London, Medefer is an inventive outpatient service that helps patients get care quickly and easily. When a patient is referred to Medefer for an online appointment, the firm receives patient data from the NHS’s e-referral system (e-RS) or the NHS Spine to make it available to medics for consultations.
Recently, the BBC reported that in November, an anonymous whistleblower identified a software flaw that made Medefer’s internal patient record system vulnerable to hackers.
According to the whistleblower, a software testing contractor at the company, Medefer’s APIs were not properly secured and could potentially be accessed by outsiders, resulting in the compromise of patient information.
The whistleblower then contacted the company and urged it to get an external cyber security expert, which Medefer did not do.
Responding to the claims, Medefer’s CEO, Dr Bahman Nedjat-Shokouhi, said that the issue was fixed within 48 hours of being notified. The company also reported the incident to the Information Commissioner’s Office which said no further action needs to be taken as there is no evidence of a breach.
In a statement shared with the media, Nedjat-Shokouhi said, “There is no evidence of any patient data breach from our systems. The external security agency has asserted that the allegation that this flaw could have provided access to large amounts of patients’ data is categorically false.
“We take our duties to patients and the NHS very seriously. We hold regular external security audits of our systems by independent external security agencies, undertaken on multiple occasions every year,” he added.
Commenting on the incident, a NHS spokesperson said, “We are looking into the concerns raised about Medefer and will take further action if appropriate."
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543