Major hospitals in London have declared a critical incident after a cyber-attack led to operations being cancelled and emergency patients being diverted elsewhere.
It applies to hospitals partnered with Synnovis – a provider of pathology services.
King’s College Hospital, Guy’s and St Thomas’ – including the Royal Brompton and the Evelina London Children’s Hospital – and primary care services are among those affected.
The incident has had a “major impact” on the delivery of services, especially blood transfusions and test results.
Some procedures have been cancelled or have been redirected to other NHS providers as the hospitals try to establish what work can be carried out safely.
The NHS said emergency care continued to be available.
GP services across Bexley, Greenwich, Lewisham, Bromley, Southwark and Lambeth boroughs have also been affected.
A spokesperson from Synnovis said the company had sent in a “taskforce of IT experts” to “fully assess” the impact.
The NHS apologised for the inconvenience and said it was working with the National Cyber Security Centre to understand the impact.
‘Go home and wait’
One patient, Oliver Dowson, 70, was prepared for an operation from 06:00 at the Royal Brompton. He was told by a surgeon at about 12:30 that it would not be going ahead.
“The staff on the ward didn’t seem to know what had happened, just that many patients were being told to go home and wait for a new date,” he said.
“I’ve been given a date for next Tuesday and am crossing my fingers.
“It’s not the first time that they have cancelled, but that was probably staff shortages in half-term week.”
Vanessa Welham from Streatham, south-west London, said her husband’s blood test at Gracefield Gardens health centre was cancelled on Monday evening.
“My husband received a text message last night advising his appointment this morning had been cancelled due to circumstances beyond their control, and that all major south London hospitals are unable to take any bookings for an indefinite period of time.
“He went on to the Swift website and made a new appointment – the earliest available was June 17, but that’s probably questionable.”
‘Incredibly sorry’
A spokesperson for NHS England London region confirmed Synnovis was the victim of a ransomware cyber attack.
“Emergency care continues to be available, so patients should access services in the normal way, and patients should continue to attend appointments unless they are told otherwise,” they said.
“We will continue to provide updates about the impact on services and how patients can continue to get the care they need.”
A spokesperson for Synnovis said: “We are incredibly sorry for the inconvenience and upset this is causing to patients, service users and anyone else affected.
“We are doing our best to minimise the impact and will stay in touch with local NHS services to keep people up to date with developments.”
‘Harsh reminder’
The spokesperson added it had “invested heavily” in “ensuring our IT arrangements are as safe as they possibly can be”.
“This is a harsh reminder that this sort of attack can happen to anyone at any time and that, dispiritingly, the individuals behind it have no scruples about who their actions might affect.
“The incident is being reported to law enforcement and the Information Commissioner, and we are working with the National Cyber Security Centre and the Cyber Operations Team.”
The incident is thought to have occurred on Monday, meaning some departments could not connect to a main server.
The Health Service Journal (HSJ) reported a senior source said gaining access to pathology results could take “weeks, not days”.
There are suggestions urgent and emergency care at the hospitals will be affected as they may not be able to access quick-turnaround blood test results, it added.