Cyber Crime

Two ambulance services in UK lost access to patient records after a cyber attack on software provider

Swedish software firm Ortivus suffered a cyberattack that has resulted in at least two British ambulance services losing access to electronic patient records.

Two British ambulance services were not able to access electronic patient records after a cyber attack that hit their software provider Ortivus.

Ortivus was a Swedish software company specializing in providing solutions for the healthcare and medical industry. They focused on developing technology for electronic patient record systems and related medical data management applications.

The company explained that the attack took place on the evening of 18 July, 2023, and the incident impacted UK customer systems within its hosted datacenter environment.

“The electronic patient records are currently unavailable and are until further notice handled using manual systems. No patients have been directly affected. No other systems have been attacked and no customers outside of those in the hosted datacenter have been affected.” reads the advisory. “Ortivus are currently working in close collaboration with the affected customers to restore the systems and recover data. The affected customers are the ones using MobiMed ePR, electronic patient record systems in a hosted environment.”

The company confirmed that they were forced to hand patient data using manual systems.

The company did not share details about the attack, it also informed customers that notified the authorities. 

Ortivus CEO Reidar Gårdebäck told The Register that the alternative system was ready within 24 hours of the attack. Gårdebäck also added that they have no evidence that threat actors have stolen customers’ data.

“Our focus now is just to restore the services and we’re doing everything we can, with all our resources, to get the system up and running again. The discussion regarding compensation will be done later on,” he said.

“We have no indication that any data has been stolen or lost. Of course, we are monitoring that.”

The company did not reveal the name of the impacted ambulance services, however, El Register revealed that they are South Western Ambulance Service Trust and South Central Ambulance Service Trust. Both organizations moved to a hosted environment for Ortivus’s MobiMed software following an agreement signed in 2020. The two services serve a permanent population of around 12 million people.

On July 20, 2023, Ortivus announced that it was ready to initiate MobiMed ePR, electronic patients records for the British customers that got affected during the recent cyberattack.

“Ortivus can announce that the MobiMed ePR system that was hit by the previously reported cyber-attack is ready to be re-initiated for the affected customers as an interim live environment has been constructed using new equipment. Before the system can be brought into operation it has to be approved and verified by an independent actor to ensure that the system meets certain criteria indicated by NHS England and the Ambulance Trusts. This external analysis is ongoing and is expected to be finished at the beginning of next week.” reads the announcement. “Meanwhile, paramedics can use the MobiMed ePR application locally on their computers. However, they will not be able to import or export patient data before the approval has been received.”

Follow me on Twitter: @securityaffairs Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ambulance services)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

20 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

21 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.