A significant data breach of medical histories at Neoclinical, an example of how not to respond to a data breach meanwhile the ACCC commences action against HealthEngine for selling its customers data. Big problems with data security in the health sector, no news there…
August 8, 2019 |
Paradoxically the one type of data that is regarded as most sensitive, health information, is often the most poorly protected. The privacy protection culture is poor and insufficient resources are put into protecting personal information and staff training is often times rudimentary. There is a constant stream of breaches reported including in the last fortnight thousands of pharmaceutical records leaked in the US, a data breach in Presbyterian Healthcare Services in Alberquerque resulted in unauthorised access to 183,000 patients, the all too regular instance of medical records in paper form being left on the street, this time in London Canada and a health Centre in Kentucky paying $70,000 ransom to unlock medical records of 20,000 patients. There are clear challenges in securing personal information in health centres and hospitals with many individuals having access to data at many terminals however the challenges are surmountable. Most data breaches are a result of poor practices and insufficient time, money and effort going into setting up proper hardware and software, establishing proper processes and training and then more training.
The Nine/Fairfax press reports on a major data breach at Neoclinical, a company which matches individuals with active clinical trials. The data is sensitive by definition but it is even more concerning given the data that Neoclinical heald was users responses to questions qualifying them for clinical trials. Those sort of questions go to medical diagnoses illicit drug use and treatments received. The breach involved its 37,170 users. The breach was detected by UpGuard which sent an email to Neoclinical. Neoclinical did not notify the Information Commissioner about the breach when notified or even shortly after. It did nothing until the media asked questions about it. Then, and only then, did it notify the Commissioner, yesterday. If the Commissioner lets such an obvious breach of the mandatory data breach notification laws then it is an even weaker regulator than it is perceived to be at the moment. Neoclinical also adopted a truculent approach to its inadequate data security being exposed.
The Fairfax article provides:
Tens of thousands of Australians have had their medical histories and other private information exposed in a large data breach of a company that enabled them to participate in paid clinical trials.
The database belonging to Neoclinical exposed approximately 37,000 people’s contact information and their responses to personal medical questions qualifying them for clinical trials, which included information about diagnoses, illicit drug use and treatments.
According to US cyber security company UpGuard, which uncovered Neoclinical’s unsecured database on the internet, there were 12,388 individuals from NSW and 4916 from Victoria in the exposed database. The rest were from New Zealand or other Australian states and territories.
In a statement to The Sydney Morning Herald and The Age on Wednesday afternoon, Neoclinical admitted to the breach but said the disclosure of it “was an exercise by a cyber security company demonstrating their expertise for marketing purposes”.
“During a routine IT operation, our server was temporarily opened last month,” a Neoclinical spokesperson said.
The company has temporarily shut down its website and has informed the Privacy Commissioner.
Neoclinical’s chief executive is Geoff Denman. According to the Australian Financial Review, Mr Denman was one of the ad executives behind the “Kevin07” campaign that put Labor’s Kevin Rudd in The Lodge. He was also behind the mining industry’s assaults on Labor’s mining super-profits tax and carbon tax.
Questions answered by participants included: Do you suffer from an immune system disease?; Do you use illegal substances?; How often do you use drugs?; Do you have an implanted cardiac device?; Where is your skin condition located?; and are you looking to regain bladder control?
“A US cyber security company which trawls the internet looking for data access found a way to get around the password protection and access our server,” the Neoclinical spokesperson said. “The cyber security company advised Amazon Web Services, who are our hosting provider, who in turn advised us.
“On receiving this advice we immediately shut down all access to the server. Once the breach from the cyber security company was confirmed, we immediately contacted the Privacy Commissioner’s office about the event and we are informing everyone whose details may have been affected.”
The Neoclinical spokesperson said they did not believe the information exposed would “be used in a malicious way” by UpGuard. “We are seeking reassurances to this effect from the company which breached our server and are contacting them today,” they said.
“We take confidentiality and this breach seriously, to the extent that our site will continue to remain in lockdown and operations suspended until such time that we can be certain that a breach of this kind cannot occur again.”
UpGuard said it uncovered the database on July 1, when one of its computer security researchers detected a database named “neoclinical” on the internet.
“That day the researcher sent an email notification to Neoclinical,” UpGuard said. “The researcher called both phone numbers on Neoclinical’s website, one of which was disconnected and the other [which] was configured to record a 10-second message to be transcribed and sent as text.
“On July 25 the researcher escalated notification to Amazon Web Services security, which followed their standard procedure of saying they would notify the owner of the database.
“On July 26, public access to the database was removed.”
UpGuard said this case was a reminder to participants of clinical trials that “whenever they pass information to a third party, they should consider the impact of that data being exposed”.
“And for companies, it should highlight the importance of having an incident response capability so that when data leaks occur, they can be mitigated within hours rather than weeks,” UpGuard said.
The Privacy Commissioner was informed on Wednesday, after the Herald and The Age contacted Neoclinical.
Itnews reports on this opening salvo with ACCC takes HealthEngine to court over alleged data misuse and the ABC with HealthEngine, medical booking app, facing multi-million-dollar fines for selling patient data. It is a case worth watching as it may point the way to enforcing privacy protections. If the Information Commissioner won’t or can’t take enforcement action then the ACCC should.