All Article Properties:
{
"access_control": false,
"status": "publish",
"objectType": "Article",
"id": "2645015",
"signature": "Article:2645015",
"url": "https://staging.dailymaverick.co.za/article/2025-03-23-national-health-laboratory-cyberatack-regulator-demands-details/",
"shorturl": "https://staging.dailymaverick.co.za/article/2645015",
"slug": "national-health-laboratory-cyberatack-regulator-demands-details",
"contentType": {
"id": "1",
"name": "Article",
"slug": "article"
},
"views": 0,
"comments": 3,
"preview_limit": null,
"excludedFromGoogleSearchEngine": 0,
"title": "Information Regulator demands details on cyberattack from National Health Laboratory Service",
"firstPublished": "2025-03-23 21:38:34",
"lastUpdate": "2025-03-23 21:38:38",
"categories": [
{
"id": "26",
"name": "Sci-Tech",
"signature": "Category:26",
"slug": "sci-tech",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/sci-tech/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
},
{
"id": "387188",
"name": "Maverick News",
"signature": "Category:387188",
"slug": "maverick-news",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/maverick-news/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
}
],
"content_length": 5544,
"contents": "<span style=\"font-weight: 400;\">The National Information Regulator has demanded details on the protection of personal information that was in place at the time of a devastating cyberattack at the National Health Laboratory Service (NHLS) in July 2024.</span>\r\n\r\n<span style=\"font-weight: 400;\">Regulator spokesperson Nomzamo Zondi said they are not investigating the cyberattack itself but want to determine compliance with the Protection of Personal Information Act (Popia).</span>\r\n\r\n<span style=\"font-weight: 400;\">This would mean that those whose information was compromised must be notified and this notification must include:</span>\r\n<ul>\r\n \t<li>A description of the possible consequences of the security compromise;</li>\r\n \t<li>A description of the measures that the responsible party (the NHLS) intends to take or has taken to address security;</li>\r\n \t<li>A recommendation with regard to the measures to be taken by the data subject to mitigate the possible adverse effects of the security compromise;</li>\r\n \t<li>If known to the responsible party, the identity of the unauthorised person who may have accessed or acquired the personal information; and</li>\r\n \t<li>Whether the responsible party had reasonable technical and organisational measures in place to protect the integrity and confidentiality of personal information in its possession or under its control in terms of the law.</li>\r\n</ul>\r\n<span style=\"font-weight: 400;\">“We have sent the NHLS a detailed correspondence requesting more information on the incident of which the NHLS provided. We are studying the information with a view to either conducting a full investigation or an own-initiative assessment,” Zondi added.</span>\r\n\r\n<b>Read more: </b><a href=\"https://www.dailymaverick.co.za/article/2025-03-22-cyber-hack-attack-how-one-click-on-an-email-link-paralysed-sas-national-health-laboratory-service/?dm_source=dm_block_list&dm_medium=card_link&dm_campaign=main\"><span style=\"font-weight: 400;\">Cyber hack attack – how one click on an email link paralysed SA’s National Health Laboratory Service</span></a>\r\n\r\n<span style=\"font-weight: 400;\">Zondi said they have in the past fined one government department, the Department of Justice and Constitutional Development, for not complying with legal measures to keep personal information safe.</span>\r\n\r\n<span style=\"font-weight: 400;\">In July 2023, that department was fined R5-million for failing to comply with an enforcement notice compelling it to upgrade its antivirus software.</span>\r\n\r\n<span style=\"font-weight: 400;\">The notice had required the department to submit proof to the Regulator within 31 days of receipt of the notice that the Trend Anti-Virus licence, the SIEM licence (security information and event management) and the Intrusion Detection System licence had been renewed. It also required the department to institute disciplinary proceedings against the official or officials who failed to renew the licences, which are necessary to safeguard the department against security compromises. </span>\r\n\r\n<span style=\"font-weight: 400;\">This followed a ransomware attack in 2021 that led to all information systems being encrypted. Neither employees nor members of the public could access information and this included letters of authority, bail services, e-mail and its website.</span>\r\n\r\n<span style=\"font-weight: 400;\">In 2024, the same department suffered another cyberattack that compromised the child maintenance payout system.</span>\r\n\r\n<span style=\"font-weight: 400;\">This month, while testifying before the parliamentary portfolio committee on health, the CEO of the NHLS admitted that its IT systems were out of date and could not be updated, and its staff were not fully apprised of the danger of clicking on unknown links when its system was hacked in June 2024.</span>\r\n\r\n<span style=\"font-weight: 400;\">Patient information, however, was held on a separate server and was not compromised, but the data warehouse where historical information was kept was also rendered out of bounds by the attack. It is understood that the system used by the NHLS uses a unique identifying number for tests and these are later linked to patients.</span>\r\n\r\n<span style=\"font-weight: 400;\">Parliament heard that security upgrades to the IT system were not possible and it was vulnerable to attack because of several IT-related issues at the service. Acting IT executive manager John Mukomana said the NHLS was still working to get its IT system up to “minimum acceptable standards”.</span>\r\n\r\n<span style=\"font-weight: 400;\">BlackSuit, an extortion syndicate, gained access to the NHLS’s database on 21 June 2024 after an employee clicked on a phishing link, said the service. In previous statements, it explained that the hackers used ransomware that encrypts data until the syndicate is paid, in effect freezing the system. The ransom was not paid, it added.</span>\r\n\r\n<span style=\"font-weight: 400;\">The NHLS is the public sector medical laboratory and 400,000 tests are done per day. It is one of the cornerstones of South Africa’s fight against HIV and TB and a critical part of the public health system. </span>\r\n\r\n<span style=\"font-weight: 400;\">Most significantly, the attack rendered the TrakCare laboratory information system unusable, so although it was possible for medical tests to be done, the results could not be seen by the requesting doctors. The laboratory information system allows for the uploading of test results so that doctors can view them on their side. </span>\r\n\r\n<span style=\"font-weight: 400;\">Mukomana said most of the NHLS’s IT infrastructure was out of date. “We were not able to update our systems or put security patches in place,” he said. </span>\r\n\r\n<span style=\"font-weight: 400;\">Since the attack, however, extensive upgrades have been made to the service’s security measures.</span>\r\n\r\n<span style=\"font-weight: 400;\">“We need to improve our governance structures,” Mukomana added. “Also, IT issues must be listened to.” </span>\r\n\r\n<span style=\"font-weight: 400;\">He said that before the attack there was a lack of IT skills at the NHLS and even its executive was lacking technology skills.</span>\r\n\r\n<span style=\"font-weight: 400;\">The CEO of the NHLS, Professor Koleka Mlisana, told Parliament that they are investing at least R300-million in strengthening their IT systems, with more that needs to be done. This included R15-million for security operations services for three years; R28-million for new desktops and laptops; R164-million for safe switches, firewalls and enhanced security for five years; and R94-million for an upgrade of the data warehouse. </span><b>DM</b>",
"teaser": "Information Regulator demands details on cyberattack from National Health Laboratory Service",
"externalUrl": "",
"sponsor": null,
"authors": [
{
"id": "35529",
"name": "Estelle Ellis",
"image": "https://www.dailymaverick.co.za/wp-content/uploads/58374149_10157269559658767_6240197467992752128_n.jpg",
"url": "https://staging.dailymaverick.co.za/author/estelle-ellis/",
"editorialName": "estelle-ellis",
"department": "",
"name_latin": ""
}
],
"description": "",
"keywords": [
{
"type": "Keyword",
"data": {
"keywordId": "12440",
"name": "Ransomware",
"url": "https://staging.dailymaverick.co.za/keyword/ransomware/",
"slug": "ransomware",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Ransomware",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "54794",
"name": "Phishing",
"url": "https://staging.dailymaverick.co.za/keyword/phishing/",
"slug": "phishing",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Phishing",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "57825",
"name": "Protection of Personal Information Act",
"url": "https://staging.dailymaverick.co.za/keyword/protection-of-personal-information-act/",
"slug": "protection-of-personal-information-act",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Protection of Personal Information Act",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "60989",
"name": "Cyberattack",
"url": "https://staging.dailymaverick.co.za/keyword/cyberattack/",
"slug": "cyberattack",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Cyberattack",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "63342",
"name": "National Health Laboratory Service",
"url": "https://staging.dailymaverick.co.za/keyword/national-health-laboratory-service/",
"slug": "national-health-laboratory-service",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "National Health Laboratory Service",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "68202",
"name": "Information Regulator",
"url": "https://staging.dailymaverick.co.za/keyword/information-regulator/",
"slug": "information-regulator",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Information Regulator",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "177282",
"name": "NHLS",
"url": "https://staging.dailymaverick.co.za/keyword/nhls/",
"slug": "nhls",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "NHLS",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "193224",
"name": "Popia",
"url": "https://staging.dailymaverick.co.za/keyword/popia/",
"slug": "popia",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Popia",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "431653",
"name": "cyber hack",
"url": "https://staging.dailymaverick.co.za/keyword/cyber-hack/",
"slug": "cyber-hack",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "cyber hack",
"translations": null
}
}
],
"short_summary": null,
"source": null,
"related": [],
"options": [],
"attachments": [
{
"id": "8441",
"name": "",
"description": "",
"focal": "50% 50%",
"width": 0,
"height": 0,
"url": "https://dmcdn.whitebeard.net/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"transforms": [
{
"x": "200",
"y": "100",
"url": "https://dmcdn.whitebeard.net/i/JDi7aR_NzKXloF99E_4HMqm41M8=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg"
},
{
"x": "450",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/YqvROw7XTAXdr4vPOYki0b_EzKM=/450x0/smart/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg"
},
{
"x": "800",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/GH3-ezBhU8hH8wC-cFXTrJu7-SY=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg"
},
{
"x": "1200",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/iFnVdbdBAS7C9H6NEuR_fzH1nu4=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg"
},
{
"x": "1600",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/UpcH7K756-bLctNTvmMMgVsexzg=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg"
}
],
"url_thumbnail": "https://dmcdn.whitebeard.net/i/JDi7aR_NzKXloF99E_4HMqm41M8=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"url_medium": "https://dmcdn.whitebeard.net/i/YqvROw7XTAXdr4vPOYki0b_EzKM=/450x0/smart/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"url_large": "https://dmcdn.whitebeard.net/i/GH3-ezBhU8hH8wC-cFXTrJu7-SY=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"url_xl": "https://dmcdn.whitebeard.net/i/iFnVdbdBAS7C9H6NEuR_fzH1nu4=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"url_xxl": "https://dmcdn.whitebeard.net/i/UpcH7K756-bLctNTvmMMgVsexzg=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2024/07/414057531.jpg",
"type": "image"
}
],
"summary": "South Africa’s Information Regulator has written to the National Health Laboratory to gather information on whether the organisation was compliant with the Protection of Personal Information Act at the time of a devastating cyberattack in July 2024.",
"template_type": null,
"dm_custom_section_label": null,
"elements": [],
"seo": {
"search_title": "Information Regulator demands details on cyberattack from National Health Laboratory Service",
"search_description": "<span style=\"font-weight: 400;\">The National Information Regulator has demanded details on the protection of personal information that was in place at the time of a devastating cyberattack at the Nati",
"social_title": "Information Regulator demands details on cyberattack from National Health Laboratory Service",
"social_description": "<span style=\"font-weight: 400;\">The National Information Regulator has demanded details on the protection of personal information that was in place at the time of a devastating cyberattack at the Nati",
"social_image": ""
},
"cached": true,
"access_allowed": true
}