Babylon Health announced that its data, including confidential patient information, was recently leaked. Babylon Health is a $2bn+ UK healthcare provider that offers patients telemedicine, i.e. remote consultations with doctors and healthcare professionals via messaging and video, through its mobile app . The news of the leaked patient data was revealed via Twitter when a user of Babylon’s video consultation app revealed that he was able to view other patients’ appointments. At a time when the adoption of telemedicine services is increasing due to the COVID-19 pandemic , such incidents highlight the vulnerable nature of telemedicine, as well as the importance of adequate cybersecurity and privacy protections to prevent the leakage of critical patient information.
At this point, it is worth mentioning what Ted Wagner, Director of Information Security at SAP National Security Services, and Sebastian Seiguer, CEO of emocha, a telehealth company, said in an interview. Specifically, Ted Wagner said that due to the pressure to provide telehealth services to the public, not all collaboration systems have been fully tested for security. He also added that the Babylon Health data leak was likely due to a software bug and not a malicious attack. He also noted that it is important for telehealth providers to prioritize the security of confidential information, as a lot of personal and sensitive data is at stake. As the use of these services expands, so does the risk to data. Over time, data leaks will hit providers that do not prioritize security. Thus, customers will choose teledoc providers they feel they can trust, and they in turn will have information protection frameworks, such as HITRUST CSF. A thorough security investigation is essential as it can identify technical issues or vulnerabilities.

Sebastian Seiguer highlighted the impact of data breaches on patients, and what can be done to ensure their privacy is protected. Specifically, he said that data breaches inevitably lead to a loss of trust, especially for patients who have been stigmatized by certain conditions. Companies have a great responsibility to protect their users. If they do not respond properly, the new consumer – the patient – will go elsewhere.
Additionally, Ted Wagner emphasized that the maturity of video collaboration technology enables secure communications, but requires a combination of people, technology, and processes to effectively mitigate security risks. There is a problem with extending this technology to the general public, who may come from different platforms. The use of multi-factor authentication, encryption, and strict access control can mitigate these risk factors, but some of these can make telehealth less accessible. Users accessing the service from a less secure location or platform can open the door to cyberattacks.

Sebastian Seiguer said that there are many security frameworks to protect consumers and patients. A leak or breach will be punished by the existing frameworks. There is no need for another layer of bureaucracy.
Finally, Ted Wagner emphasized that, given existing NIST security controls and HIPAA regulations, he believes there is sufficient guidance on how to secure collaboration platforms. He also mentioned that the bugs presented by Zoom highlight the fact that software bugs will arise over time and timely software updates are the “key” to mitigating risks. Good security is an ongoing and demanding process. It is not enough to just have security controls in place, but organizations must also monitor and update their systems regularly.
