Notice
The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)
Issued 2025-10-20View on ODPA's website Source document
Summary
This is a public enforcement notice from the Guernsey Office of the Data Protection Authority (ODPA) announcing an administrative fine of £100,000 against The Medical Specialist Group LLP (MSG) following a personal data breach caused by a cyber-attack. The breach, which began in August 2021 and was detected in December 2021, exposed sensitive patient health data and led to phishing campaigns targeting MSG patients.
- Cause of breach: MSG failed to install security updates to its e-mail server for 13 months, including patches directly related to the exploited vulnerability.
- Detection failures: Inadequate threat detection software meant a three-and-a-half month delay between compromise and detection.
- Investigation failures: MSG failed to identify the root cause of the vulnerability or recognise its own security shortcomings when investigating the breach.
- Legal basis: The Authority found MSG breached the Data Protection (Bailiwick of Guernsey) Law, 2017 by failing to take reasonable steps to secure personal data, particularly special category health data.
- Sanction: A £100,000 administrative fine was imposed, split into £75,000 payable within 60 days and £25,000 payable in 14 months, with the latter waived if MSG completes its committed remedial Action Plan.
The notice also sets out lessons for other organisations: implement timely security update processes, treat security measures as an ongoing rather than one-off responsibility, and conduct thorough root-cause investigations following any data breach.
Key obligations
- MSG must pay £75,000 of the administrative fine within 60 days of the determination.
- MSG must pay the remaining £25,000 within 14 months of the determination, unless it completes all remedial actions in its agreed security safeguard Action Plan within that timeframe.
- Organisations generally are required under the Law to take reasonable steps to ensure an appropriate level of security for personal data, with particular care for special category data.
Applies to
data controllers, healthcare providers handling special category data, organisations subject to the Data Protection (Bailiwick of Guernsey) Law, 2017
Deadlines
- within 60 days of this determination: MSG must pay £75,000 of the administrative fine.
- 14 months from this determination: MSG must pay the remaining £25,000 of the fine, unless waived by completion of its remedial Action Plan.