Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later
Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

Why it matters
What this means for organisations holding critical data
Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.
Families of vulnerable children whose personal health information was accessed during a cyber attack on a healthcare provider have spoken of their anger after being informed more than 18 months after the incident, the BBC reported on 15 September 2026.
Relatives of children in Wiltshire and Bath and North East Somerset received letters warning that medical information may have been compromised at HCRG Care Group, formerly known as Virgin Care, during an attack in February 2025. The company runs NHS-funded community health and social care services across Wiltshire, Bath and North East Somerset, and Swindon.
What was exposed
According to the letters, affected information could include names, addresses, dates of birth, NHS numbers and health and care records. One relative told BBC Points West that her two teenage nieces were now receiving scam calls that she fears may be linked, adding: "We are now really worried that their very private information could be held or sold on the dark web."
An anonymous district nurse who contacted the BBC alleged that the compromised systems also contained highly sensitive safeguarding information relating to children and adults, including information connected to domestic abuse and other vulnerable circumstances. The BBC noted it had not been able to independently verify those claims.
HCRG declined to confirm the scale of the incident, saying it included "a cross-section" of patients and that the "complex" investigation had "only recently concluded", accounting for the delay.
The delay is its own harm
This is the second wave of distress from the same incident. In June, the BBC revealed that patients were only then beginning to receive letters, including a 69-year-old Bath resident who said he was "fuming" at being told 15 months after the fact. Some families have now waited more than 18 months.
Notification delay is not an administrative footnote. Every month of silence is a month in which affected people cannot change routines, watch for misuse or protect their children, while whoever holds the data faces no such constraint. Under the United Kingdom data protection framework, breaches likely to result in a high risk to individuals must be communicated without undue delay; safeguarding data concerning children sits at the sharpest end of that obligation.
HCRG said it acted immediately to contain and resolve the incident, reported it to law enforcement and the Information Commissioner's Office, and that the ICO concluded its consideration and closed the matter without further action. The company said there is no evidence the information has appeared online or been misused, and that it contacted everyone identified as affected as soon as it had the facts to inform them accurately.
The care sector keeps appearing in these stories
Health and care providers hold exactly the records criminals value most: identity, medical history, safeguarding context and family detail, much of it about people who cannot protect themselves. The sector also runs on tight margins, legacy systems and shared community infrastructure, which makes it a persistent target.
Firevault's own published customer story involves a multi-site care organisation protecting storage and backups for precisely this reason. The controls that matter are not exotic: strict separation between the systems that face the internet and the systems that retain records, and a copy of the most sensitive data that no remote session can reach at all.
Where Offline Secure Storage fits
If an attacker reaches the live network, everything continuously connected to that network is in scope: it can be browsed, copied, encrypted or deleted. Records held on dedicated hardware with no standing network path are not in scope, because there is no route to them. Access opens only through an authorised, out-of-band request for a defined window and then closes again.
That does not prevent a breach of live systems, and it does not absolve any provider of the duty to notify quickly. What it changes is the ceiling on the damage: retained records, archives and safeguarding files that were offline at the moment of intrusion remain untouched, recoverable and provably so.
For organisations caring for vulnerable people, that ceiling is the difference between a contained incident and a letter to a frightened family 18 months later.
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






