Ransomware hit Synnovis, the pathology provider for several south-east London NHS trusts and GP practices. Blood testing and matching collapsed, more than 11,000 appointments and procedures were postponed, O-type blood ran short nationally, and one death was later partly attributed to a delayed result.
PathConnectivity & data → Human handoff
Sources checked when written 26 September 2026
TierPathology IT was down for months; hospitals ran reduced blood matching and postponed work. Power and phones were not affected in the sources. How tiers are assigned.
What happened
Synnovis says the 3 June 2024 attack affected almost all of its IT systems and interrupted many pathology services. Stolen data were published on 20 June, and full restoration took until late autumn 2024. Because the affected hospitals could not match patients' blood at the usual frequency, NHS Blood and Transplant appealed on 10 June for O-positive and O-negative donors. NHS England reported 10,152 acute outpatient appointments and 1,710 elective procedures postponed at King's College Hospital and Guy's and St Thomas'. The UK government now uses Synnovis as its case study for designating 'critical suppliers' under the Cyber Security and Resilience Bill, citing more than 11,000 disrupted appointments and operations and estimated losses of £32.7m.
In June 2025 King's College Hospital said a patient safety investigation into one patient's unexpected death had found several contributing factors, including a long wait for a blood test result caused by the attack. The Register reported that South East London ICB recorded 170 patients harmed, mostly low harm. In 2026 The Record reported that South London and Maudsley was still working with pathology systems that had not been fully restored, and had logged 122 incidents of incorrect, unavailable or delayed results.[1,2,3,4,5,6,7,8]
Documented harm
One death in which the delayed blood result was a contributing factor (KCH, June 2025). About 170 patients harmed, mostly low harm, per South East London ICB as reported by The Register. More than 10,000 appointments and 1,710 procedures postponed.
What it teaches
Outsourced diagnostics are a clinical dependency: plan for weeks, not hours, without them.
Loss of electronic crossmatch pushes blood banks to universal-donor units and drains regional stocks.
Harm from delayed results surfaces months later; run structured harm reviews during and after the outage.
One pathology supplier shared by several trusts and GP practices was a regional single point of failure.
Loss of blood matching spread to national blood stocks through extra O-type demand.
Recovery of downstream organisations can lag the supplier's recovery by more than a year.
Regulators are moving to put critical suppliers under direct cyber rules.
The failure of one supplier's lab system can drop several hospitals to tier 2 at once.
Manual fallbacks such as universal-donor blood draw down national stocks, so the cascade reaches beyond the region.
Recovery is prioritised and staged, and can take months.
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.
Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and:
Power loss, disaster or resource needs: go through your local or county emergency management. They escalate to the state, and the state requests FEMA support; hospitals do not call FEMA directly.
A medical device problem: report it to the manufacturer and to FDA MedWatch.
Outside the US: your national emergency number and national cyber agency (in the UK, NCSC).