What You Should Know:
– CybelAngel tools scanned approximately 4.3 billion IP addresses and detected more than 45 million unique medical images left exposed on over 2,140 unprotected servers across 67 countries including the US, UK, and Germany.
– The report highlights the security risks of publicly accessible images containing highly personal information including ransomware and blackmail.
The analyst team at CybelAngel, a global leader in digital risk protection, has discovered that more than 45 million medical imaging files – including X-rays and CT scans – are freely accessible on unprotected servers, in a new research report.
Medical Device Data Leaks
The report “Full Body
Exposure” is the result of a six-month investigation into Network Attached
Storage (NAS) and Digital Imaging and Communications in Medicine (DICOM), the
de facto standard used by healthcare professionals to send and receive medical
data. The analysts discovered millions of sensitive images, including personal
healthcare information (PHI), were available unencrypted and without password
CybelAngel tools scanned approximately 4.3 billion IP addresses and detected more than 45 million unique medical images left exposed on over 2,140 unprotected servers across 67 countries including the US, UK, and Germany.
The analysts found that openly available medical images, including up to 200 lines of metadata per record which included PII (personally identifiable information; name, birth date, address, etc.) and PHI (height, weight, diagnosis, etc.), could be accessed without the need for a username or password. In some instances, login portals accepted blank usernames and passwords.
“The fact that we did not use any hacking tools throughout our research highlights the ease with which we were able to discover and access these files,” says David Sygula, Senior Cybersecurity Analyst at CybelAngel and author of the report. “This is a concerning discovery and proves that more stringent security processes must be put in place to protect how sensitive medical data is shared and stored by healthcare professionals. A balance between security and accessibility is imperative to prevent leaks from becoming a major data breach.”
3 Steps to Safeguard The Way Providers Share & Store
CybelAngel advises there are simple steps that healthcare facilities can take to safeguard the way they share and store data including:
– Determine if pandemic response exceeds your security policies: Ad hoc NAS devices, file-sharing apps, and contractors may take data beyond your ability to enforce access controls
– Ensure proper network segmentation of connected medical
imaging equipment: Minimize any exposure critical diagnostic equipment and
supporting systems have to wider business or public networks
– Conduct real-world audit of third-party partners: Assess
which parties may be unmanaged or not in compliance with required policies and
– CybelAngel provides a complimentary, comprehensive 30-day
data exposure assessment healthcare and other organizations use to measure
their risk and uncover priority issues.