
An unsecured MongoDB database belonging to the health insurance site MedicareSupplement.com was found exposed online last month. The database contained 5 million records . These records included personal and medical information.
MedicareSupplement.com is owned and operated by Solutions . The site aims to help people find a suitable Medigap insurance plan. This is a form of private insurance . On its Facebook, the company claims to have helped more than 400,000 people find the right insurance.
Essentially, the site helps potential customers decide which insurance plan they want by offering them a comparison of all the possible options available outside of Medicare. However, users must enter some personal information into an online form to receive a free quote.
The public database was revealed on May 13 by researchers at Compariteh, who collaborated with Bob Diachenko, a security expert who specializes in identifying sensitive data that has been exposed online.

The informationcontained in the database is sufficient to identify individuals and determine their health insurance interests. This information is names, mailing addresses, email addresses, dates of birth, gender, telephone numbers, and IP addresses.
The researchers notified MedicareSupplement.com about the exposed database, but the website's representatives did not respond. They simply modified the MongoDB server configuration to protect the database.
Diachenko warns users that the lack of authentication helps hackers gain access to open MongoDB servers and install malware.
Hackers can also gain full administrator privileges on the exposed system , which allows them to remotely access server resources. This would allow them to execute malicious code and steal or destroy stored data on the server.
Individuals whose data is exposed can become targets of other attacks.
