Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Image
 Medical laboratory
Medical laboratory - Credit: bogdan.hoda / DepositPhotos - License: DepositPhotos
Crime
Business
Tech
Clinical Diagnostics
Dutch Health and Youth Care Inspectorate
IGJ
cybercrime
data protection authority
European Data Act
Wednesday, 13 May 2026 - 13:40

Share this article:

Opens in a new window Opens in a new window Opens in a new window Opens in a new window Opens in a new window Opens in a new window

Dutch watchdog says healthcare lab failed data security rules before cyberattack

The Dutch Health and Youth Care Inspectorate (IGJ) has concluded that Clinical Diagnostics failed to adequately protect its data before last year’s cyberattack. During the breach, hackers obtained the medical records of hundreds of thousands of women who had taken part in cervical cancer screening tests.

The organisation said the laboratory failed to meet mandatory legal standards. Among other shortcomings, its cybersecurity measures had not undergone an independent review. Clinical Diagnostics also had not carried out a proper risk assessment, meaning it was unable to identify which safeguards were needed to secure sensitive information.

Had the lab followed the rules properly, this “could have reduced the likelihood of a major data breach and limited its consequences,” the inspectorate said.

The ransomware group “Nova” was behind the attack in July 2025. They demanded a ransom of about 1.1 million euros in cryptocurrency and still published parts of the stolen data on the dark web.

The IGJ investigated whether Clinical Diagnostics followed healthcare data-processing laws when handling personal information. While the inspectorate itself cannot issue fines, the Dutch Data Protection Authority can. The Dutch privacy regulator is separately investigating whether the lab adhered to European data protection rules.

The scale of the data breach turned out to be significantly greater than first believed. While initial estimates suggested 485,000 victims, cybercriminals are now believed to have obtained the personal information of over 850,000 individuals.

Dutch prosecutors and police are carrying out a criminal investigation into the data breach, with 118 formal complaints submitted so far. Meanwhile, personal injury attorneys are organising large-scale compensation claims representing tens of thousands of women impacted by the leak.

Reporting by ANP and NL Times

More like this

Image
Cropped shot of lawyer using laptop and lady justice statue on table.
Dutch women launch mass lawsuit over cervical cancer screening data breach
Image
Empty swing
Report highlights shortcomings in care before killing of 11-year-old Sohani
Image
Scientist working in a laboratory
Hackers threatening to leak more data stolen from Dutch laboratory
Image
Domestic violence helpline
Details of women staying in domestic violence shelters also leaked in laboratory hack
Make NL Times your top Google source

Follow us:

Latest stories

  • Dutch gov't doing enough to protect locals in climate deal with Tata Steel, court rules
  • Europe slaps Google with €890 mil. fine for prioritizing own services in search results
  • Thialf ice skating stadium hit by ransomware attack
  • Dozens of Dutch tourists affected by wildfires in France, Spain
  • Dutch crime boss Willem Holleeder transferred to less secure prison

Top stories

  • Thialf ice skating stadium hit by ransomware attack
  • Romanian gang considered Amsterdam sex workers their property; Exploited dozens of women
  • Netherlands to implement points system for unsafe driving
  • New U.S. import tariffs: Netherlands facing 10% along with other EU Member States
  • Walkers set off on last day of Vierdaagse; 42,450 people finished hardest 3rd day

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content