HomeSecurityRedcliffe Labs: Data Breach Exposes 12 Million Patient Records

Redcliffe Labs: Data breach exposes 12 million patient files

A cybersecurity expert said that diagnostic testing services company , Redcliffe Labs , has been the victim of a cyberattack that exposed more than 12 million medical records.

See also: Seiko: BlackCat ransomware attack led to data breach
Redcliffe Labs

Expert Jeremiah Fowler revealed that the database was not password-protected and contained over 12 million records of medical diagnostic scans, test results and other potentially sensitive medical records.

In an email shared with Financial Express.com, a person with knowledge of the incident revealed that the misconfigured database had been open for an unknown period of time. It was also shared that the data contained 12,347,297 records, totaling 7TB in size, and included important detailssuch as medical test results and internal compensation documents.

Additionally, Fowler has argued that this data breach could lead to misuse of personal health information, medical identity theft, and ransomware.

Although Redcliffe Labs' website states that they have 2.5 million customers, he said that in the database folder called "test results" there are over 6 million PDF files. "This could indicate either that more customers may have been affected or that these were likely multiple tests from the same customers," he said.

See also: ASVEL basketball team confirms data breach due to ransomware

Notably, Fowler has also shared images of some of the documents he found during his investigation, such as a patient's X-ray report, which contains personally identifiable information such as date of birth, an internal compensation document that reveals employee names, office or travel location, and other information, a blood test that included the patient's name, patient ID number, detailed health information, doctor's name, and other test-related information.

Fowler also revealed that in addition to millions of medical records, the database also contained development files from their mobile app . It was also reported that one of the biggest potential risks is tampering or modification of the app’s code files. As of press time, it is not known whether Redcliffe Labs has notified the relevant authorities or potentially affected individuals about the data leak, he said.

See also: University of Michigan: Student and employee data breach

data breach
Common forms of cyberattacks targeting healthcare providers include:
  1. Phishing: This attack is usually done via email or text message, where attackers pretend to be legitimate senders and ask recipients to reveal personal information, such as passwords or credit card numbers. The attackers then use this information to gain access to sensitive data or to commit fraud.
  2. Malware: This includes viruses, trojans, and other harmful software that enters systems through malicious file attachments, malicious links, or security vulnerabilities. This software can cause data leaks, information loss, or even lock the system with a demand for ransom to restore the data.
  3. DDoS attack: This attack aims to overload the healthcare provider's network by sending a large volume of traffic from multiple sources. This results in the network failing to respond to user requests, making services unavailable to patients and hospital staff.
  4. Ransomware Attack : In this attack, attackers use malware to encrypt a healthcare provider’s data and demand a ransom to decrypt it. This can lead to the loss of personal medical records, breach of patient privacy, and disruption of critical hospital operations
  5. Zero-day attack: This attack exploits security vulnerabilities in software or systems that have not yet been discovered by developers or vendors. Attackers discover and exploit these vulnerabilities to gain access to sensitive data or cause damage to healthcare providers’ systems.

Source: financialexpress

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS