NHS Lothian A.I CyberSecurity Scoring
NHS Lothian
Company Information
Website:https://www.nhslothian.scot/Pages/default.aspx
Employees number:6,761
Number of followers:0
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:nhslothian.scot
NHS Lothian Risk Score (AI oriented)
Between 750 and 799
NHS LothianHospitals and Health Care
Updated:
31/03/2026
31/03/2026
795/1000
Fair
Baa
NHS Lothian Global Score (TPRM)
xxxx
NHS LothianHospitals and Health Care
Score locked

NHS LothianFair
Current Score
795Baa (FAIR)
01000
3 incidents
-54 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
798
MAY 2026
797
APRIL 2026
796
MARCH 2026
795
FEBRUARY 2026
794
JANUARY 2026
794
DECEMBER 2025
632
NOVEMBER 2025
683
Breach
31 Oct 2025 • NHS Lothian
NHS Lothian
NHS Lothian Patient Data Breach
629
HIGH-54
NHS0302603110125
A data breach at NHS Lothian was discovered during a routine audit, revealing that unauthorized individuals had accessed the medical records of an unspecified number of patients. The breach was identified last month, prompting an immediate investigation. While the exact number of affected patients remains undisclosed, the health board confirmed that 'appropriate action' was taken, including notifying impacted patients, reporting the incident to Police Scotland, and informing the Information Commissioner’s Office (ICO). The breach involved the inappropriate access of sensitive patient records, raising concerns over privacy violations and potential misuse of personal health information. Dr. Tracey Gillies, NHS Lothian’s medical director, assured that measures were implemented to address the incident but declined to comment on whether an internal employee was responsible. The breach underscores vulnerabilities in healthcare data security, particularly when insider threats or unauthorized access protocols are exploited. The incident remains under investigation by law enforcement, with potential regulatory repercussions pending the ICO’s review.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
683
SEPTEMBER 2025
682
AUGUST 2025
680
JULY 2025
678
MAY 2025
727
Breach
01 May 2025 • NHS Lothian
NHS Lothian
Patient records accessed in NHS Lothian data breach
673
HIGH-54
NHS3032230110125
A data breach at NHS Lothian was discovered during a routine internal audit last month, revealing unauthorized access to the medical records of an unspecified number of patients. While the exact scale of the breach remains unconfirmed by the health board, the incident involved the exposure of sensitive patient data, which may include personal and medical information. NHS Lothian has stated that 'appropriate action' has been taken in response, though specific remediation steps or the root cause (e.g., insider threat, system vulnerability, or external attack) were not disclosed. The breach raises concerns over patient privacy, potential misuse of health records, and compliance with data protection regulations like the UK GDPR. Given the nature of the compromised data—medical records—the incident could lead to reputational damage, regulatory scrutiny, and erosion of public trust in the healthcare provider’s ability to safeguard confidential information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2023
773
Breach
01 Sep 2023 • NHS Lothian
NHS Lothian
NHS Lothian Patient Data Breach
709
CRITICAL-64
NHS1732417110125
A data breach at NHS Lothian was uncovered during a routine audit, revealing that an unauthorized individual—later identified as a female employee—had inappropriately accessed the private medical records of approximately 100 patients. The breach was detected in September 2023, prompting an immediate internal investigation. Affected patients were notified, and the incident was escalated to Police Scotland and the Information Commissioner’s Office (ICO). Authorities confirmed that a woman had been charged in connection with the breach, with the case referred to the procurator fiscal for prosecution. The breach involved sensitive patient data, including confidential medical histories, which were accessed without legitimate cause. While the exact motive remains undisclosed, the incident highlights vulnerabilities in internal access controls within the healthcare system. NHS Lothian emphasized that no evidence suggested wider exploitation (e.g., ransomware or external hacking), but the unauthorized access alone constitutes a serious violation of patient privacy and trust. The health board assured that corrective measures were implemented, though specifics were not detailed to avoid compromising the ongoing legal process.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for NHS Lothian ??
What was NHS Lothian's A.I Rankiteo Cyber Score in May 2026 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in April 2026 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in March 2026 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in February 2026 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in January 2026 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in December 2025 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in November 2025 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in October 2025 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in September 2025 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in August 2025 ??
What was NHS Lothian's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on NHS Lothian's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with NHS Lothian ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view NHS Lothian's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?