Desk live·
ForensicPost
Breaches/Healthcare/File 25-1214b

DXS International Incident Hit Clinical Software Used by 2,000 GPs

DXS International, which supplies clinical decision support used by around 2,000 general practitioners, discovered a security incident affecting its office servers on 14 December 2025.

Constructed geometry · not a chart of case data
TargetDXS International
ActorUnattributed
S. Rosler12 min readConfidence: high3 sources reviewed

DXS International, a healthcare technology supplier to the NHS, disclosed that it had discovered a security incident affecting its office servers on 14 December 2025. Its software is used by around 2,000 general practitioners, who oversee the care of approximately 17 million patients.

Seventeen Million Patients, And No Patient Relationship

The corpus filed at 25-0801 that the largest healthcare exposure of the year happened at a company with no patients, and treated it as a pattern rather than an observation. This is the same pattern in a different health system.

A patient chooses a GP practice. The practice chooses clinical software. The patient has no relationship with the supplier, will not have heard of it, and cannot evaluate or change it.

The 17 million figure describes the reach of the software, not a confirmed affected population — a distinction this desk drew at 25-0717 between reachable, taken and published, and one the corpus should hold firmly here.

Office Servers Is A Narrower Claim Than It Sounds

The disclosure describes office servers rather than clinical systems or patient data. That is a meaningful distinction and the corpus records it as the company’s characterisation.

It is also the sort of early scoping statement that 25-0807 noted is sometimes revised. This desk filed at 25-0815b that a specific, falsifiable claim about which systems were unaffected deserves recording; the same applies here, with the same caution.

A Small Supplier At A Critical Dependency

DXS is not a large company. It sits at exactly the position the corpus identified at 25-1124 as the designation problem: criticality is emergent, and a supplier serving 2,000 practices will not appear on a prospective list of critical national suppliers.

The UK Bill at 25-1113 proposes extending scope to designated critical suppliers. Whether a clinical decision support vendor would be designated before an incident is precisely the question that file left open.

How we reported this

Compiled from public reporting and the company’s regulatory disclosure, listed below. No patient data exposure has been established and none is asserted. Corrections: corrections@forensicpost.com.

Sources
  1. Tech provider for NHS England confirms data breachTechCrunch
  2. NHS supplier DXS International confirms cyber attackIT Pro
  3. NHS GP software supplier hit by cyber attackDigital Health
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary