Frequently asked questions

The FAQs below provide additional information for individuals who may have been impacted by this incident.

We completed the process of notifying the organisations whose data was affected by the end of November 2025.

UK data protection law states that in the event of a data breach, it is the controller of your data – the healthcare provider that requests any testing services from us – who is responsible for assessing patient impact and any requirement to contact patients directly. The timeline for any onward patient notification is up to those organisations and is likely to be different for each organisation.

It is important to note that Synnovis will not be contacting patients directly. Anyone who contacts you about your data claiming to be from Synnovis should be reported to Action Fraud, who are the UK’s national reporting centre for fraud and cybercrime. They can be contacted on 0300 123 2040.

General

Data Impact

Notification Process

Incident Background