Welcome to Radar Healthcare Assurance. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust and Assurance Hub to learn about our security posture and request access to our security documentation.
Subprocessors
- How does Radar Healthcare support the NHS's standards for information governance?
Radar Healthcare Assurance Updates
Penetration Test Update – Digital Consent and Patient Information v8
Digital Consent Platform version 8.2 has been released. This update resolves the three low-severity findings identified during penetration testing of version 8. https://status.eidohealthcare.com/history/1
Radar Healthcare has completed an independent penetration test of the latest Version 8 release of the Digital Consent and Patient Information platform.
The assessment concluded that the application demonstrates a strong security posture, with no critical, high, or medium severity vulnerabilities identified.
Three low-severity findings were identified during testing. These findings do not present a significant risk to the confidentiality, integrity, or availability of customer data or the platform. The issues have been logged within our remediation programme and are scheduled to be addressed in Version 8.2, which is currently targeted for release in early to mid-September 2026.
The penetration test confirmed that the platform's existing security controls provide a sound security baseline. Radar Healthcare remains committed to continuous security improvement and will continue to review, test, and enhance the platform as part of our ongoing secure development and vulnerability management processes.
NPM Supply Chain Attack (Shai-Hulud)
We are aware of the recently disclosed npm supply chain attacks affecting a number of widely used open-source packages, including the Keyv package family and related dependencies. Security researchers have reported that malicious code was introduced into specific package versions and distributed through the npm ecosystem
Following a review of the published lists of affected packages and versions, Radar Healthcare has assessed its software repositories and dependency lock files. While some of the referenced packages are used within our development ecosystem, our production and main/master code branches are currently locked to older, non-affected versions. Based on our investigation to date, we have found no evidence that Radar Healthcare systems, products, or customer data have been impacted by this attack.
As an additional precaution, our development teams have reviewed recent dependency updates. We have confirmed that no affected package versions have been introduced into code intended for production deployment. Radar also utilises security controls designed to help reduce supply chain risk, including package reputation and age-based protections on developer endpoints.
We continue to actively monitor the situation and will take any further action necessary should new information emerge. At the time of writing, our assessment is that Radar Healthcare remains unaffected by this incident.
NPM Supply Chain Incident – @tanstack Packages
Clarification on scope of update
The initial update referenced @tanstack packages as the primary focus, reflecting the dependencies in use within Radar Healthcare.
While this activity is consistent with a broader supply‑chain attack pattern (commonly referred to as “Shai‑Hulud”) affecting multiple npm namespaces, Radar Healthcare does not utilise the other identified packages within this wider campaign.
Our assessment was therefore scoped to the dependencies and environments in use, with @tanstack representing the relevant exposure for Radar Healthcare. All validation and assurances provided above relate to this confirmed scope.
On 11 May 2026 (19:20–21:30 UTC), malicious versions of several @tanstack npm packages were temporarily published and available for installation.
These packages were designed to identify further dependencies for infection and attempt to exfiltrate sensitive credentials (including npm, GitHub, AWS, Kubernetes, SSH and secret vault tokens).
Radar Healthcare conducted a review across all relevant repositories and development activity. This confirmed that:
- Affected dependencies were pinned to safe versions released prior to the incident
- No updates were applied during the exposure window
- Development environments were not impacted
Based on this assessment, no evidence of compromise to Radar Healthcare has been identified. Monitoring will continue as a precaution should further information emerge.
This incident reinforces the risk of open-source supply chain attacks. Radar Healthcare maintains robust controls over dependency management and monitoring and continues to enhance these as part of ongoing security improvement.
Security Advisory: Axios Supply Chain Incident – Impact Assessment and Position Statement
Axios is used within the Radar platform, primarily in the frontend, and may also appear as a transitive dependency in other services. Our production implementation is on version 1.9.0, and we have confirmed that we were not impacted by the recent supply chain compromise affecting specific Axios versions. No affected versions were installed or in use within our production environment during the relevant window. Indirect dependencies identified are on versions not associated with the reported incident and are managed in line with our vulnerability management process.
We continuously monitor third-party components through our secure development lifecycle, assessing and prioritising vulnerabilities based on risk, with remediation undertaken accordingly. Based on our review, we have identified no evidence that this issue has impacted the confidentiality, integrity, or availability of the Radar platform or customer data.
Security Advisory: Review of ChipSoft Ransomware Incident
We are aware of the recent ransomware incident involving ChipSoft. Radar Healthcare is not affected. As part of our internal continuous improvement process, we have reviewed the incident and its relevance to our threat landscape. We regularly assess sector-wide events to inform our security posture and ensure our controls remain robust and aligned with best practices.




