NHS vendor Advanced has been fined £3 million ($3.8 million) for not implementing basic security measures prior to a ransomware attack in 2022.
The fine is half of what the Information Commissioner's Office (ICO) initially sought, which was over £6 million.
The ICO found that Advanced broke data protection law by not fully implementing multi-factor authentication, allowing hackers to breach the system and steal personal information of thousands of people.
The ransomware attack on Advanced caused widespread outages across NHS systems.