Once we take into consideration our knowledge being leaked onto the web, we regularly image it as our monetary information, our passwords, our names and addresses… what’s much less typically thought of is the publicity of our non-public medical data.
A French hospital has discovered itself within the unenviable place of studying that hackers have gained entry to the medical information of over 750,000 sufferers following a cyber assault.
A hacker calling themselves “nears” claims to have compromised the techniques of a number of healthcare amenities throughout the nation, claiming to have gained entry to the information of over 1.5 million folks.
In keeping with “nears”, the safety breach was made potential after they gained unauthorised entry to Mediboard, an digital affected person report (EPR) system utilized by many hospitals throughout Europe.
Softway Medical Group, the builders of Mediboard, has confirmed {that a} malicious hacker did reach compromising a Mediboard account however declared that the safety breach was not the results of a misconfiguration or software program flaw however as an alternative by way of the theft of login credentials utilized by the unnamed hospital.
In a letter shared with French journalists, Softway Medical Group stated the assault was detected inside a healthcare facility utilizing Mediboard on November 19 2024, and emphasised that the stolen knowledge was not hosted by Softway.
As Bleeping Laptop studies, the purported stolen information of 758,912 sufferers contains:
- Full names
- Dates of start
- Gender
- Dwelling addresses
- Telephone numbers
- Electronic mail addresses
- Doctor particulars
- Prescription histories
- Well being card utilization data
Posting on an underground web site, “nears” has supplied on the market entry to the Mediboard platform for different hospitals in France, claiming that purchasers would be capable to view delicate healthcare and billing data, schedule appointments, and modify affected person information.
On the time of writing, there is no such thing as a proof that anybody has bought the information, though the hacker claims to have shared information with three potential patrons.
There are clearly severe dangers from delicate data like this falling into the fingers of cybercriminals. The menace that the information might nonetheless be leaked on-line stays (no matter whether or not a purchaser is discovered or not), and sufferers might doubtlessly be uncovered to identification theft, phishing, and social engineering assaults from fraudsters and scammers.
Ensure that to examine Tripwire’s recommendation and options for serving to healthcare establishments shield affected person knowledge and guarantee compliance with regulatory requirements.
Editor’s Be aware: The opinions expressed on this visitor creator article are solely these of the contributor and don’t essentially mirror these of Tripwire.