Patient death linked to cyber attack on NHS pathology provider

  • 26 June 2025
Patient death linked to cyber attack on NHS pathology provider
Credit: Shutterstock.com
  • The first patient death linked to the cyber attack last year on NHS pathology system provider Synnovis has been confirmed
  • A spokesperson for King’s College Hospital NHS Foundation Trust said confirmed that "a number of contributing factors" to the death were identified, including a long wait for a blood test result" as a result of the cyber attack
  • Synnovis chief executive Mark Dollar said the company is "deeply saddened" by the death

A patient death has been linked to the cyber attack on NHS pathology system provider Synnovis, King’s College Hospital NHS Foundation has confirmed.

TheĀ ransomware attack on 4 June 2024Ā caused widespread disruption to NHS services in London, withĀ 10,152 acute outpatient appointments and 1,710 elective procedures postponed at King’s College Hospital NHS Foundation Trust and Guy’s and St Thomas’ NHS Foundation Trust, and delays to blood testing in primary care.

A spokesperson for King’s College Hospital told Digital Health News that one patientĀ  died unexpectedly during the cyber attack.

“As is standard practice when this happens, we undertook a detailed review of their care.

ā€œThe patient safety incident investigation identified a number of contributing factors that led to the patient’s death.

ā€œThis included a long wait for a blood test result as a result of the cyber attack impacting pathology services at the time.

“We have met with the patient’s family and shared the findings of the safety investigation with them,ā€ the spokesperson said.

They added that the date of the death or person’s age cannot be confirmed due to confidentiality.

Responding to the news, Mark Dollar, chief executive at Synnovis, said: ā€œWe are deeply saddened to hear that last year’s criminal cyber attack has been identified as one of the contributing factors that led to this patient’s death.

“Our hearts go out to the family involved.ā€

Initial figures released by NHS South East London Integrated Care Board in November 2024, recorded five cases of moderate harm and 114 cases of low harm as a result of the attack, but did not report any cases of serious harm.

However, in January 2025 NHS data obtained by Bloomberg News revealed that healthcare professionals across at least four London boroughs recorded two cases of severe harm, 11 cases of moderate harm, and more than 120 cases of low harm as a direct consequence of the cyber attack.

Dr Saif Abed, founding partner and director of cybersecurity advisory services at The AbedGraham Group, told Digital Health News: “This tragedy, sadly, will not be unique and will be repeated again, likely at scale, in future unless political leadership re-prioritises the issue.

“I ask the health secretary to commission an independent, clinically focused review into NHS cybersecurity and patient safety.

“Likewise I ask the Health Select Committee to commence with an inquiry as a matter of urgency given the broken nature of the NHS’s digital supply chain.”

Digital Health News reported that the cyber attack on Synnovis could have been prevented by two-factor authentication.

Meanwhile, suppliers to the NHS have been urged by NHS England and the Department of Health and Social Care to sign a charter of cyber security best practice.

The charter, published on 15 May 2025, requests suppliers to take steps which include maintaining support for systems, applying patches to known vulnerabilities, applying multi-factor authenticationĀ to networks and systems, and keeping ā€œimmutable backupsā€ of critical business data.

In April 2025, the governmentĀ published its plans for the Cyber Security and Resilience Bill, whichĀ is intended to prevent attacks similar to theĀ Synnovis attack.

Subscribe to our newsletter

Subscribe To Our Newsletters

Related News

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare flags cyber security risk

Birmingham Community Healthcare NHS Foundation Trust (BCHC) has flagged an exposed vulnerability that could lead to a cyber attack.Ā 
Two NHS trusts affected by cyber attack on mobile phone software

Two NHS trusts affected by cyber attack on mobile phone software

NHSE is investigating a cyber incident at two NHS trusts after hackers exploited a vulnerability in software used to manage mobile phones.
ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

ā€˜Lessons can be learned’ from DHSC cyber progress, says PAC

The Public Accounts Committee has said ā€œlessons can be learnedā€ from DHSC’s efforts to improve cyber resilience in public services.