Thousands Of Patients’ PHI Exposed By Transcription Provider MEDantex

Robinson+Cole Data Privacy + Security Insider
Contact

Medical transcription provider MEDantex has reportedly exposed thousands of patients’ medical information through its unsecured provider portal, which did not require a password for access.

According to reports, including KrebsOnSecurity, the patients’ audio medical notes were uploaded to MEDantex’s website, which were then to be transcribed and uploaded to a portal accessible to the medical providers. In order to access the transcribed notes, the provider is supposed to enter a password. Krebs has reported that he found certain portions of the website did not contain password authentication controls, thereby allowing anyone who visited the website to review patient data contained on the site and download it. Further, tools could be used by unauthorized users to add and remove authorized users, search for specific patients by physician name, and find patient information by the patient’s name.

The problem apparently occurred when MEDantex rebuilt the site after it was the victim of a ransomware attack. During the rebuild, the password protection was removed.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide