MICKAI®ArticlesThe Synnovis Fallout Keeps Growin…
Article · 30 July 2026

The Synnovis Fallout Keeps Growing: Who Should Hold NHS Data?

Patient records stolen in 2024 are still surfacing in 2026, and the safest answer is for clinical data and the AI that works on it to stay inside the trust's own perimeter.

Author
Micky Irons
Published
30 July 2026
Follow Micky Irons
LinkedInX
sovereign-ainhs-data-securityair-gapped-airansomwarehealthcare
The Synnovis Fallout Keeps Growing: Who Should Hold NHS Data?

Patient data is safest when the intelligence that works on it never leaves the building, and the continuing fallout from the Synnovis attack shows why. In June 2026, further NHS trusts confirmed that patient records stolen in the 2024 Qilin ransomware attack on pathology provider Synnovis had been exfiltrated and published, with Bedfordshire Hospitals disclosing on 1 June that nearly 33,000 of its patients were affected. Two years after the original incident, the damage is still being counted. The lesson is not about one supplier's security posture. It is about where sensitive clinical data sits, who can reach it, and what happens when a system built for scale becomes a route out of the building.

We build MICKAI, a Sovereign Intelligence Operating System that runs on an organisation's own hardware, on premise and air-gapped where the work demands it. We will not claim that any system makes breaches impossible, because nobody honest can. What we can do is look at what the latest Synnovis disclosures reveal about data custody, and why we believe the question of who holds patient data should be settled before any model is allowed near a patient record.

Why are records stolen in 2024 still being disclosed in 2026?

Because exfiltrated data does not expire, and the full scope of a large breach tends to emerge in stages as stolen material is analysed and matched to the people it describes. The June 2026 disclosures, including Bedfordshire Hospitals confirming on 1 June that nearly 33,000 of its patients were affected, show trusts still working through the consequences of an attack that happened two years earlier. A ransomware incident is an event. A data breach is a long tail. Once clinical records are published they cannot be recalled, and every new confirmation widens the circle of patients whose most private information is permanently exposed.

What does the Synnovis attack tell us about how NHS data is held?

It tells us that concentration is a risk in its own right. Synnovis provides pathology services to NHS trusts, which means clinical data from many organisations flowed through one supplier's systems. When that supplier was compromised in 2024, the blast radius was not a single hospital but a network of them, and the disclosures that continued into June 2026 show the network was wider than first understood. None of this requires the supplier to have been careless. It is a structural property of centralised processing. Aggregate enough sensitive data in one externally reachable place and that place becomes a single point of catastrophic failure for everyone connected to it.

The same structural logic applies to AI. Every cloud service that ingests patient records to summarise a discharge letter or draft a clinic note is another concentration of clinical data outside the trust's perimeter, another set of credentials to phish, and another third party whose compromise becomes the trust's incident and the trust's letters to patients.

How does an air-gapped operating system change the risk?

It removes the route out. MICKAI runs entirely on the trust's own hardware and can operate fully offline, so the sovereign models working over patient records have no network path to an attacker's infrastructure and no telemetry flowing back to us or anyone else. A hardware-held root of trust binds the system to machines the trust controls, so it cannot simply be lifted, copied and run somewhere else. The data stays where the duty of care sits.

When the data cannot leave the enclave, a supplier compromise does not automatically become a patient data leak. That is not a policy promise. It is a property of the architecture.

Mickai

Air-gapping is sometimes dismissed as impractical for modern AI. We designed against that assumption. Our own models run locally, the reasoning happens locally, and the evidence of what happened stays local too.

Can AI work on patient data without becoming a new attack surface?

Yes, if the controls are built into the operating system rather than bolted on around a cloud API. In MICKAI, a cooperative multi-model consensus substrate means specialist models must agree before any sensitive action runs, so a single manipulated or mistaken output cannot quietly commit the system to something irreversible. Sensitive actions are additionally gated by voice biometrics, so a stolen password is not enough to authorise them. And every action, from a query over a pathology result to an administrative change, is written to the Open Audit Record, cryptographically signed with post-quantum algorithms, tamper-evident and verifiable offline. If an incident does occur, the trust holds a complete, provable account of what the system did, rather than reconstructing events from a supplier's logs it does not control.

What should NHS trusts ask before deploying AI over clinical data?

The Synnovis disclosures suggest the first questions should be about custody and evidence, not model benchmarks. Before any deployment touches patient records, we would ask five things:

  • Where does the data physically sit while the model works on it, and can the system operate with no external connection at all?
  • If the supplier is compromised, does patient data leave with them, or does the compromise stop at the perimeter?
  • Who authorises sensitive actions, and is that authorisation bound to a person by more than a password?
  • Is there a tamper-evident record of every AI action that the trust itself holds and can verify offline?
  • Can the system keep working, and keep its records, when the wider network is down or deliberately isolated during an incident?

These are the questions we built MICKAI to answer. It is one operating system with 87 studios spanning clinical, administrative and operational work; ten are production-ready and we launch with those ten, while 77 remain in development. The architecture behind it is covered by 104 filed UK patent applications across 2,340 claims, owned by Mickai LTD, which we treat as a moat around the engineering rather than the headline.

The NHS will always depend on suppliers, and sovereignty does not mean building everything in house. It means choosing systems whose failure modes stop at the perimeter, so the next Qilin finds a locked enclave rather than a shared artery. The trusts still writing to patients this summer deserve architectures that make the next set of letters unnecessary.

Frequently asked questions

What happened in the Synnovis breach?

Synnovis, a pathology provider serving NHS trusts, was attacked by the Qilin ransomware group in 2024. Stolen patient records were exfiltrated and published, and disclosures continued into June 2026, when Bedfordshire Hospitals confirmed that nearly 33,000 of its patients were affected.

Why does air-gapped AI matter for the NHS?

Air-gapped AI matters because it removes the network route attackers use to exfiltrate data. When models run on the trust's own hardware with no external connection, patient records processed by the system cannot be pulled out through a supplier's compromised infrastructure.

What is the Open Audit Record?

The Open Audit Record is MICKAI's evidence layer. Every action the system takes is cryptographically signed with post-quantum algorithms, tamper-evident and verifiable offline, so an organisation holds its own provable account of what its AI did and who authorised it.

Can an on-premise system still be assured and audited?

Yes, and more directly than a cloud service. Because the trust holds the hardware, the data and the signed Open Audit Record, auditors verify evidence the organisation controls itself, rather than relying on a supplier's attestations about systems nobody outside can inspect.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on premise and air-gapped, with every action signed to the tamper-evident Open Audit Record. It spans 87 studios on one operating system, with ten production-ready at launch and 77 in development, and is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/synnovis-nhs-records-dark-web-data-control. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles