📷 Image: Wikimedia Commons / Prime Minister's Office
Health
CAG cites failure to safeguard data after ransomware hit Punjab cancer centre
✍️ The Times of India
🗓 27 Aug 2026, 02:36 AM
👁 2
The Comptroller and Auditor General has flagged the Punjab cancer centre's inability to protect sensitive patient information after a ransomware breach.
The Comptroller and Auditor General (CAG) has issued a report highlighting serious lapses in data protection at a leading cancer treatment facility in Punjab. The audit found that the centre was unable to prevent a ransomware attack that compromised sensitive patient records, raising concerns over the security of health information.
According to the CAG findings, the ransomware incident exposed personal and medical details of numerous patients, indicating inadequate cybersecurity measures and insufficient safeguards for confidential data. The report calls for immediate remedial actions to strengthen digital defenses and ensure compliance with data protection norms.
The centre's administration has been urged to conduct a thorough forensic investigation, restore affected systems, and implement robust encryption and access controls. The CAG also recommended that the state health department monitor compliance and provide guidance to prevent similar breaches in the future.
Stakeholders, including patient advocacy groups, have expressed alarm over the potential misuse of health data and stressed the need for transparent communication about the breach and corrective steps being taken.
According to the CAG findings, the ransomware incident exposed personal and medical details of numerous patients, indicating inadequate cybersecurity measures and insufficient safeguards for confidential data. The report calls for immediate remedial actions to strengthen digital defenses and ensure compliance with data protection norms.
The centre's administration has been urged to conduct a thorough forensic investigation, restore affected systems, and implement robust encryption and access controls. The CAG also recommended that the state health department monitor compliance and provide guidance to prevent similar breaches in the future.
Stakeholders, including patient advocacy groups, have expressed alarm over the potential misuse of health data and stressed the need for transparent communication about the breach and corrective steps being taken.