Добавить новость
123ru.net
The Daily Dot
Март
2023

EXCLUSIVE: Breast pump company leaves millions of documents exposed—raising concerns over data safety in women’s healthcare

0

Hygeia breast pump

A breast pump manufacturer is storing millions of documents on an exposed server that includes the names, email addresses, and phone numbers of doctors across the U.S.

The California-based medical company, which the Daily Dot is declining to name, offers numerous models of breast pumps as well as referrals for customers seeking personal support from "trusted experts" in the field of breastfeeding.

The server, discovered by Anurag Sen, a cloud security researcher with CloudDefense.AI, is run by Amazon's cloud computing service and contains approximately 7,151,537 documents in total.

The documents, divided between two separate databases, hold the full names, business addresses, fax numbers, and phone numbers of those in the medical profession. National Provider Identifier (NPI) numbers, unique 10-digit identifiers issued to healthcare providers in the U.S., are also present.

Data on a US doctor on an exposed server

In remarks to the Daily Dot, Sen stated that he came across the exposed server while using his company's internal tools for monitoring data leaks. The security issue, Sen added, appears to have been caused by a configuration error that left the server exposed without password protection.

While much of the information could be found publicly, it remains unlikely that those listed are aware that their information is centrally available in a database of that size. A timestamp on one of the listings notes that it was made in July 2020.

The Daily Dot reached out to a number on the list purported to belong to a doctor in Florida and confirmed it to be accurate. After informing a secretary of the reason behind the call, the Daily Dot was swiftly hung up on.

Sen says that although he reached out to the company on March 11 to inform them of the security lapse, the company did not respond. The Daily Dot reached out over a contact form on its website and at a customer service email last week but did not receive a reply either.

The Daily Dot is declining to name the company, as the data is still available as of publication.

After reaching a customer service representative over the phone, the Daily Dot was told to once again send an email to the company that would then be forwarded to the appropriate party. After being given a full week to respond, no contact was ever made.

The pseudonymous blogger Dissent Doe, a licensed healthcare professional who chronicles such data exposures on DataBreaches.net, speculated to the Daily Dot that the data could either be a customer list or marketing list.

The blogger also noted that while the exposure is unlikely to cause any significant harm, the company could potentially "lose any competitive advantage if their contact list was acquired by competitors."

"As far as misuse of the data, I've learned not to underestimate what creative criminals can do with information, so the fact that I wouldn't see anything particularly evil other than spamming doesn't
mean that clever criminals can't figure out a way to misuse it," they said.

While the exposure of the data may not be inherently dangerous, the failure to implement basic security measures by a healthcare company marketed toward women is troubling. Companies that handle data relating to women's healthcare and pregnancy have come under increased scrutiny over the past year, following the overturning of Roe v. Wade, as fears grow that states that are outlawing abortion could use sensitive data to help prosecute abortion seekers.

Sign up to receive the Daily Dot’s Internet Insider newsletter for urgent news from the frontline of online.

The post EXCLUSIVE: Breast pump company leaves millions of documents exposed—raising concerns over data safety in women’s healthcare appeared first on The Daily Dot.

Hygeia breast pump

A breast pump manufacturer is storing millions of documents on an exposed server that includes the names, email addresses, and phone numbers of doctors across the U.S.

The California-based medical company, which the Daily Dot is declining to name, offers numerous models of breast pumps as well as referrals for customers seeking personal support from "trusted experts" in the field of breastfeeding.

The server, discovered by Anurag Sen, a cloud security researcher with CloudDefense.AI, is run by Amazon's cloud computing service and contains approximately 7,151,537 documents in total.

The documents, divided between two separate databases, hold the full names, business addresses, fax numbers, and phone numbers of those in the medical profession. National Provider Identifier (NPI) numbers, unique 10-digit identifiers issued to healthcare providers in the U.S., are also present.

Data on a US doctor on an exposed server

In remarks to the Daily Dot, Sen stated that he came across the exposed server while using his company's internal tools for monitoring data leaks. The security issue, Sen added, appears to have been caused by a configuration error that left the server exposed without password protection.

While much of the information could be found publicly, it remains unlikely that those listed are aware that their information is centrally available in a database of that size. A timestamp on one of the listings notes that it was made in July 2020.

The Daily Dot reached out to a number on the list purported to belong to a doctor in Florida and confirmed it to be accurate. After informing a secretary of the reason behind the call, the Daily Dot was swiftly hung up on.

Sen says that although he reached out to the company on March 11 to inform them of the security lapse, the company did not respond. The Daily Dot reached out over a contact form on its website and at a customer service email last week but did not receive a reply either.

The Daily Dot is declining to name the company, as the data is still available as of publication.

After reaching a customer service representative over the phone, the Daily Dot was told to once again send an email to the company that would then be forwarded to the appropriate party. After being given a full week to respond, no contact was ever made.

The pseudonymous blogger Dissent Doe, a licensed healthcare professional who chronicles such data exposures on DataBreaches.net, speculated to the Daily Dot that the data could either be a customer list or marketing list.

The blogger also noted that while the exposure is unlikely to cause any significant harm, the company could potentially "lose any competitive advantage if their contact list was acquired by competitors."

"As far as misuse of the data, I've learned not to underestimate what creative criminals can do with information, so the fact that I wouldn't see anything particularly evil other than spamming doesn't
mean that clever criminals can't figure out a way to misuse it," they said.

While the exposure of the data may not be inherently dangerous, the failure to implement basic security measures by a healthcare company marketed toward women is troubling. Companies that handle data relating to women's healthcare and pregnancy have come under increased scrutiny over the past year, following the overturning of Roe v. Wade, as fears grow that states that are outlawing abortion could use sensitive data to help prosecute abortion seekers.

Sign up to receive the Daily Dot’s Internet Insider newsletter for urgent news from the frontline of online.

The post EXCLUSIVE: Breast pump company leaves millions of documents exposed—raising concerns over data safety in women’s healthcare appeared first on The Daily Dot.






Загрузка...


Губернаторы России
Москва

Собянин: В кварталах реновации появится более 70 социальных объектов


Спорт в России и мире
Москва

Навка: во время болезни Заворотнюк возили по Москве только в парандже


Загрузка...

Все новости спорта сегодня


Новости тенниса
Анна Калинская

Калинская оценила выход в финал турнира в Берлине и вспомнила о Синнере


Загрузка...


123ru.net – это самые свежие новости из регионов и со всего мира в прямом эфире 24 часа в сутки 7 дней в неделю на всех языках мира без цензуры и предвзятости редактора. Не новости делают нас, а мы – делаем новости. Наши новости опубликованы живыми людьми в формате онлайн. Вы всегда можете добавить свои новости сиюминутно – здесь и прочитать их тут же и – сейчас в России, в Украине и в мире по темам в режиме 24/7 ежесекундно. А теперь ещё - регионы, Крым, Москва и Россия.


Загрузка...

Загрузка...

Экология в России и мире
Москва

В Москве презентовали награду в честь знаменитого лесничего Ленобласти





Путин в России и мире
Москва

Путин запланировал международные контакты в Москве на следующей неделе


Лукашенко в Беларуси и мире



123ru.netмеждународная интерактивная информационная сеть (ежеминутные новости с ежедневным интелектуальным архивом). Только у нас — все главные новости дня без политической цензуры. "123 Новости" — абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Smi24.net — облегчённая версия старейшего обозревателя новостей 123ru.net.

Мы не навязываем Вам своё видение, мы даём Вам объективный срез событий дня без цензуры и без купюр. Новости, какие они есть — онлайн (с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии).

123ru.net — живые новости в прямом эфире!

В любую минуту Вы можете добавить свою новость мгновенно — здесь.





Зеленский в Украине и мире

Навальный в России и мире


Здоровье в России и мире


Частные объявления в Вашем городе, в Вашем регионе и в России






Загрузка...

Загрузка...



Виктор Цой

Благовещенск с благодарностью будет помнить Виктора Цоя



Москва

Врач рассказала, какие продукты вызывают аритмию

Друзья 123ru.net


Информационные партнёры 123ru.net



Спонсоры 123ru.net