After we take into consideration our knowledge being leaked onto the web, we frequently image it as our monetary information, our passwords, our names and addresses… what’s much less typically thought-about is the publicity of our non-public medical info.
A French hospital has discovered itself within the unenviable place of studying that hackers have gained entry to the medical information of over 750,000 sufferers following a cyber assault.
A hacker calling themselves “nears” claims to have compromised the techniques of a number of healthcare amenities throughout the nation, claiming to have gained entry to the information of over 1.5 million folks.
In response to “nears”, the safety breach was made attainable after they gained unauthorised entry to Mediboard, an digital affected person file (EPR) system utilized by many hospitals throughout Europe.
Softway Medical Group, the builders of Mediboard, has confirmed {that a} malicious hacker did reach compromising a Mediboard account however declared that the safety breach was not the results of a misconfiguration or software program flaw however as an alternative by the theft of login credentials utilized by the unnamed hospital.
In a letter shared with French journalists, Softway Medical Group stated the assault was detected inside a healthcare facility utilizing Mediboard on November 19 2024, and emphasised that the stolen knowledge was not hosted by Softway.
As Bleeping Laptop reviews, the purported stolen information of 758,912 sufferers contains:
- Full names
- Dates of beginning
- Gender
- Residence addresses
- Cellphone numbers
- Electronic mail addresses
- Doctor particulars
- Prescription histories
- Well being card utilization info
Posting on an underground web site, “nears” has supplied on the market entry to the Mediboard platform for different hospitals in France, claiming that purchasers would have the ability to view delicate healthcare and billing info, schedule appointments, and modify affected person information.
On the time of writing, there is no such thing as a proof that anybody has bought the info, though the hacker claims to have shared information with three potential consumers.
There are clearly severe dangers from delicate info like this falling into the fingers of cybercriminals. The menace that the info may nonetheless be leaked on-line stays (no matter whether or not a purchaser is discovered or not), and sufferers may probably be uncovered to identification theft, phishing, and social engineering assaults from fraudsters and scammers.
Ensure to examine Tripwire’s recommendation and options for serving to healthcare establishments shield affected person knowledge and guarantee compliance with regulatory requirements.
Editor’s Observe: The opinions expressed on this visitor creator article are solely these of the contributor and don’t essentially replicate these of Tripwire.