Recognising the significant number of section 39 agencies that provide various levels of health and social care services and the variation within them as to the extent to which they leverage digital solutions to provide services, officials in my department have not been notified directly of any material breaches or cyber attacks on Section 39 agencies. The HSE has also confirmed they they have not been affected in any material way by issues that may have arisen within section 39 agencies. In practice, the primary focus for building cyber resilience across the health service is in the HSE, large voluntary hospitals and other section 38 agencies. The section 39 organisations have responsibility to manage cyber attacks and data breaches under existing regulations. The role of the HSE is to ensure that where and if they have digital connections with section 39 agencies (as is the case for all 3rd parties the HSE interacts with) that the necessary precautions and processes are in place to avoid contagion and limit the impact, in the case of such an incident.