The FAQs below are intended for those organisations whose data has been impacted by the Synnovis cyberattack of June 2024.

Where there has been a data breach involving personal information:

  • the ‘Controller’ of that data is responsible for that data and has the legal obligation to keep individuals informed.
  • the ‘Processor’ handles this data but acts on the instructions of Controllers and do not have authority over it.

In this instance, the Controllers are healthcare organisations and the Processor is Synnovis.

General

Data Impact

Notification Process

Incident Background

Frequently asked questions