Notice
Determination - The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)
Issued 2025-10-20View on ODPA's website Source document
Summary
This is a published enforcement determination by the Office of the Data Protection Authority (Guernsey) against the Medical Specialist Group LLP (MSG), a Bailiwick healthcare provider, following a cyber-attack that compromised its on-premises Microsoft Exchange server via the ProxyShell vulnerabilities. The Authority found MSG breached its data protection principles and security duties under sections 6 and 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017, and imposed a fine of £100,000.
- Failure to patch: MSG failed to install multiple critical Microsoft Exchange security updates over an extended period, leaving its server exposed to known ProxyShell vulnerabilities despite an internal update procedure that was not followed.
- Threat detection failures: MSG's threat detection software identified 54 unique malicious files between September and December 2021 that went unnoticed for months due to failed alerting and inadequate monitoring, delaying discovery of the compromise by up to 83 days.
- Aggravating factors: Systemic, repeated (not one-off) patching failures, MSG's denial of responsibility, misleading assurances to the Authority about patch status, and a prior unrelated determination against MSG.
- Mitigating factors: MSG notified affected individuals, migrated to a cloud-based managed service to reduce recurrence risk, and made financial investment in security improvements.
- Sanction: A fine of £100,000 was imposed, with MSG's public-service healthcare funding role considered in setting the amount.
Although this document is a case-specific enforcement notice rather than general rulemaking, it illustrates the Authority's expectations for controllers processing special category (health) data: robust patch management, effective and monitored threat detection, and thorough post-breach investigation and remediation.
Key obligations
- MSG must pay the imposed fine of £100,000.
- MSG must meet with the Authority no later than 12 months after issuance of the determination to present the actions taken under its Action Plan to elevate data protection for patients' data.
- Controllers processing personal data, particularly special category/health data, must take reasonable steps to ensure a level of security appropriate to that data, including timely installation of vendor security updates and effective, monitored threat detection measures, per sections 6 and 41 of the Data Protection (Bailiwick of Guernsey) Law, 2017.
Applies to
data controllers, processors, healthcare providers processing health data, the Medical Specialist Group LLP
Deadlines
- no later than 12 months after the issuance of this determination: MSG must meet with the Authority to present the actions taken under its Action Plan to ensure an elevated level of data protection for patients' data.