Exposure

Personal data of 16 million Brazilian COVID-19 patients exposed online by Albert Einstein Hospital employee error

Today’s example of “no need to hack if it’s leaking,” Catalin Cimpanu reports: The personal and health information of more than 16 million Brazilian COVID-19 patients has been leaked online after a hospital employee uploaded a spreadsheet with usernames, passwords, and access keys to sensitive government systems on GitHub this month. Among the systems that had...

Sophos notifies customers of data exposure after database misconfiguration

Catalin Cimpanu reports: UK-based cyber-security vendor Sophos is currently notifying customers via email about a security breach the company suffered earlier this week. “On November 24, 2020, Sophos was advised of an access permission issue in a tool used to store information on customers who have contacted Sophos Support,” the company said in an...

Fairchild Medical Center server was exposing patient information for 4.5 years until a security firm alerted them

Ugh. Fairchild Medical Center had a misconfigured server exposing PHI from December 16, 2015 until they were alerted to the problem in late July by an unnamed security company who discovered the exposure. Here’s their press release, below. Note that this does not (yet) appear on HHS’s breach tool. YREKA, Calif., Nov. 25, 2020 /PRNewswire/ —...

Disabled children’s names revealed in Bristol City Council email

BBC reports: The identities of hundreds of families with disabled children have been shared with other parents without their consent by a council, in a “fundamental breach of trust and data”. Bristol City Council sent an email asking for views on a new support service to hundreds of people. The names of all the...