
Thousands of images, videos and files related to plastic surgery patients were discovered in an unsecured database that could be accessed by anyone with the right IP address, researchers report. The data includes 900,000 files, which researchers say could belong to thousands of different patients.
The data comes from clinics around the world. The images included in the files depict people before and after surgery and often contained nude photos. They also included invoice details from which someone could identify one of the patients. However, the database is now secure.
Researchers Noam Rotem and Ran Locar were the ones who discovered the exposed database. They published research on the security website vpnMonitor.
NextMotion, which says on its website that it has 170 clinics as customers in 35 countries, told its customers that it had addressed the issue. “We immediately took corrective steps and the company itself officially guarantees that the flaw has been fully addressed,” said NextMotion CEO Emmanuel Elard. “Elard also apologized for the “fortunately limited incident.”
While NextMotion stated that there was no information such as names and other identifying details in the database, many of the images show the faces of the patients, according to vpnMonitor. Also, some of the invoices describe in detail the types of procedures the patients underwent, such as scar removal or plastic surgery in the abdominal area and contain patient names and other identifying information.
The leak follows a series of database breaches that have exposed the personal data of patients and other citizens. The problem stems from companies moving their customer data to the cloudwithout proper privacy protocols in place.
The NextMotion website states that it provides a “secure medical cloud”, for storing files of aesthetic procedures from around the world.
