ADVERTISEMENT
NewsDio.com
  • Home
  • Entertainment
  • TV SHOWS
  • Technology
  • Movies
  • News
  • Health
  • Write for Us
  • Fashion
  • Travel
  • Lifestyle
  • Food
  • Home
  • Entertainment
  • TV SHOWS
  • Technology
  • Movies
  • News
  • Health
  • Write for Us
  • Fashion
  • Travel
  • Lifestyle
  • Food
No Result
View All Result
NewsDio.com
No Result
View All Result
ADVERTISEMENT
Home Technology

the labcorp website error exposed thousands of medical documents

by Danish
June 6, 2021 4:21 am EDT
Reading Time: 3 mins read

NewsDio.com Staff : A security flaw in LabCorp’s website exposed thousands of medical documents, like test results containing sensitive health data.

It’s the second incident in the past year after LabCorp said in June that 7.7 million patients had been affected by a credit card data breach of a third-party payments processor. That breach also hit several other laboratory testing companies, including Quest Diagnostics.

This latest security lapse was caused by a vulnerability on a part of LabCorp’s website, understood to host the company’s internal customer relationship management system. Although the system appeared to be protected with a password, the part of the website designed to pull patient files from the back-end system was left exposed. That unprotected web address was visible to search engines and was later cached by Google, making it accessible to anyone who knew where to look. The cached search result only returned one document — a document containing a patient’s health information. But changing and incrementing the document number in the web address made it possible to access other documents.

The bug is now fixed.

Using computer commands, we determined the approximate number of exposed documents by asking the exposed server if a document existed by returning certain properties about the file — such as its size — but not the document itself. This allowed us to see if a document was on the server without accessing large amounts of patient information, and thus preventing any further exposure to the patient’s privacy.

RELATED POSTS

The Importance of Private IP Addresses in Network Security

Strategies for Effective Link-Building Campaigns

SiMontok APK : Latest version 2020 2.3 Get It now

The results showed at least 10,000 documents were exposed.

Of the handful of files we examined to understand what kind of data was exposed, the documents largely appeared to affect cancer patients under the laboratory’s Integrated Oncology specialty testing unit.

The documents contained names, dates of birth and, in some cases, Social Security numbers of patients. The documents also contained lab test results and diagnostic data, a class of data considered protected health information under the Health Insurance Portability and Accountability Act (HIPAA). A couple of the documents we reviewed contained a footer notice, which said: “This document contains private and confidential health information protected under state and federal law.”

Running afoul of HIPAA can result in heavy fines.

“This is a massive privacy issue — and one that could impact affected users and patients for years to come,” said Rachel Tobac, a hacker, social engineer and founder of SocialProof Security. “The sensitive nature of those documents and the leak of private medical status is a huge privacy violation for those patients for obvious reasons, but also sadly for some possibly less glaring reasons, as well.”

Tobac, who reviewed our findings, said medical information can be “terribly useful” for criminals in identity theft, extortion and phishing, because the victim may be more likely to trust the sender “under the assumption that the message is legitimate because it contains information only their medical provider could or should know.”

The vulnerability was found in-house at TechCrunch and was reported to LabCorp, which later pulled the server offline. Although the web address remains in Google’s search results, the link is now dead.

“I can confirm that we have terminated access to the system,” said LabCorp spokesperson Donald Von Hogan.

LabCorp’s Von Hogan said in a call that the company would not confirm the documents found on the exposed server “are in fact LabCorp information.”

TechCrunch reached out to a number of patients to verify their information. Only one person confirmed by phone that the information in their exposed file was accurate, but expressed that they did not want to be named for this story.

ADVERTISEMENT

Two other people whose names were in the files had since passed away, according to obituaries.

In a statement emailed after publication, LabCorp said it would notify affected patients “as may be appropriate,” but would not say if it would inform state and federal authorities under data breach notification laws.

Read full article here.

Related

ShareTweet

Danish

Danish is Internet marketer, Owner of Many sites like Newsdio.com SEO and SMO expert and he have good knowledge of Online Marketing industry. Skype : live:.cid.1ce32a7cf39b81c4

Related Posts

Technology

Tubidy io: Download free music of your choice with the best site

November 7, 2023 8:34 pm EST

...

Technology

How to login TCS Ultimatix first time

November 5, 2023 12:39 am EDT

...

Technology

Four Incontestable Reasons to Buy an Electric Lawn Mower

November 4, 2023 12:36 am EDT

...

Tech

The Importance of Private IP Addresses in Network Security

October 31, 2023 8:55 pm EDT

...

A Magical Countdown to Christmas? Evaluating the Harry Potter Advent Calendar

A Magical Countdown to Christmas with Funko Pop!

Harry Potter Funko Pop Advent Calendars: An Annual Holiday Tradition

Lego Fortnite: Bringing the Popular Video Game to Life in Brick Form

Benny Blanco: Hitmaker Producer and Songwriter

Oldest Celebrities Still Alive in the USA in 2023

A Magical Countdown to Christmas? Evaluating the Harry Potter Advent Calendar

December 8, 2023 1:11 am EST

A Magical Countdown to Christmas with Funko Pop!

December 8, 2023 1:01 am EST

Harry Potter Funko Pop Advent Calendars: An Annual Holiday Tradition

December 8, 2023 12:38 am EST

Lego Fortnite: Bringing the Popular Video Game to Life in Brick Form

December 8, 2023 12:15 am EST

Benny Blanco: Hitmaker Producer and Songwriter

December 7, 2023 11:42 pm EST

Oldest Celebrities Still Alive in the USA in 2023

December 7, 2023 2:19 am EST

NewsDio.com is Famous News website which is operates from 5 years. Email : sbanu034@gmail.com

  • Contact Us
  • NewsDio Authors
  • Newsdio Copyright
  • NewsDio Corrections Policy
  • NewsDio Ethics Policy
  • Newsdio Fact Checking Policy
  • NewsDio Ownership, Funding, and Advertising Policy
  • NewsDio Terms of Use
  • Write for Us

© 2021 NewsDio.

No Result
View All Result
  • Entertainment
  • Technology
  • Movies
  • News
  • Finance
  • Sports
  • Health
  • Write for Us

© 2021 NewsDio.