After we take into consideration our information being leaked onto the web, we regularly image it as our monetary information, our passwords, our names and addresses… what’s much less usually thought-about is the publicity of our non-public medical info.
A French hospital has discovered itself within the unenviable place of studying that hackers have gained entry to the medical information of over 750,000 sufferers following a cyber assault.
A hacker calling themselves “nears” claims to have compromised the techniques of a number of healthcare services throughout the nation, claiming to have gained entry to the information of over 1.5 million folks.
In line with “nears”, the safety breach was made doable after they gained unauthorised entry to Mediboard, an digital affected person file (EPR) system utilized by many hospitals throughout Europe.
Softway Medical Group, the builders of Mediboard, has confirmed {that a} malicious hacker did reach compromising a Mediboard account however declared that the safety breach was not the results of a misconfiguration or software program flaw however as an alternative via the theft of login credentials utilized by the unnamed hospital.
In a letter shared with French journalists, Softway Medical Group mentioned the assault was detected inside a healthcare facility utilizing Mediboard on November 19 2024, and emphasised that the stolen information was not hosted by Softway.
As Bleeping Laptop stories, the purported stolen information of 758,912 sufferers consists of:
- Full names
- Dates of start
- Gender
- House addresses
- Telephone numbers
- E mail addresses
- Doctor particulars
- Prescription histories
- Well being card utilization info
Posting on an underground web site, “nears” has supplied on the market entry to the Mediboard platform for different hospitals in France, claiming that purchasers would be capable to view delicate healthcare and billing info, schedule appointments, and modify affected person information.
On the time of writing, there isn’t a proof that anybody has bought the information, though the hacker claims to have shared information with three potential patrons.
There are clearly severe dangers from delicate info like this falling into the fingers of cybercriminals. The risk that the information might nonetheless be leaked on-line stays (no matter whether or not a purchaser is discovered or not), and sufferers might doubtlessly be uncovered to id theft, phishing, and social engineering assaults from fraudsters and scammers.
Be sure that to examine Tripwire’s recommendation and options for serving to healthcare establishments shield affected person information and guarantee compliance with regulatory requirements.
Editor’s Notice: The opinions expressed on this visitor creator article are solely these of the contributor and don’t essentially mirror these of Tripwire.