On August 2, a researcher contacted DataBreaches.net about a misconfigured Amazon s3 storage bucket they had discovered. The bucket contained more than 10,000 files, recently updated, with protected health information of patients seen by or involved with BioTel Heart cardiac data network. Sometimes it is easy to figure out the likely owner of an Amazon…
Category: Health Data
Federal Appeals Court Dismisses CareFirst Data Breach Appeal
From EPIC.org: The D.C. Circuit has ruled that it lacks jurisdiction to hear the appeal of CareFirst customers whose data was stolen in a 2014 data breach. The lower court in Attias v. CareFirst dismissed most of the plaintiffs and claims in the case for failure to allege damages and certified the dismissed claims for appeal. The D.C. Circuit…
Argentina exposes COVID-19 health data in error
Another elastic search instance, it seems. Tim Sandle reports: Argentina’s health officials have apparently exposed personal medical data relating to some 115,000 COVID-19 quarantine exemption applicants, in what represents a major health sector data breach. Read more on Digital Journal.
Revealed: 1,400 data breaches at HSE included patient photos and medical files
Ken Foxe reports: The HSE has suffered almost 1,400 separate data breaches over the past two years involving photographing of patients, infection status being disclosed to other family members, and the discovery of confidential medical files in public places. The number of breaches showed a sharp rise between 2018, when 556 incidents were recorded, and…
Ashley County Medical Center investigates former employee accused of violating federal privacy laws
Gabrielle Phifer reports: Ashley County Medical Center is investigating a former employee they claim inappropriately viewed medical records of 772 patients. According to a release, ACMC’s policy and procedures revealed that a former employee, who has been identified as a nurse, accessed some patient information for purposes unrelated to care and treatment. Based on investigations…
Three more medical practices hit by ransomware
Atlanta does not seem to be a safe place for cybersecurity of orthopedic patients’ data. In 2016, orthopedic clinics in Atlanta got clobbered by two big breaches involving thedarkoverlord. The first was a hack and extortion demand on Athens Orthopedic Clinic, an organization that had more than a dozen locations but somehow didn’t have enough…