Thousands of healthcare records exposed online, including private patient information
- Security researcher finds finds huge non-password-protected database online
- It contained personally identifiable information, as well as medical data
- The database was since locked down
ESHYFT, a technology platform designed for nurses across the United States, reportedly kept an unprotected database online, exposing thousands of sensitive records to anyone who knew where to look.
Security researcher Jeremiah Fowler found the database, which contained 86,341 records, and that it exceeded 100 GB in size. The archive contained all sorts of sensitive data, from names and IDs, to medical reports, and more.
ESHYFT is a technology platform that connects nurses (CNAs, LPNs, and RNs) with per diem shifts at long-term care facilities across the US, offering flexible work opportunities for healthcare professionals and a reliable staffing solution for facilities.
You may like
Addressing the problem
It is not known for how long the database remained unprotected, or if any threat actors accessed it before Fowler did. We also don’t know if ESHYFT maintains the database itself, or if it outsourced it to a third party.
“In a limited sampling of the exposed documents, I saw records that included profile or facial images of users, .csv files with monthly work schedule logs, professional certificates, work assignment agreements, CVs and resumes that contained additional PII,” Fowler explained, noting he reported it to both Website Planet, and later – ESHYFT.
“One single spreadsheet document contained 800,000+ entries that detailed the nurse’s internal IDs, facility name, time and date of shifts, hours worked, and more.”
“I also saw what appeared to be medical documents uploaded to the app. These files were potentially uploaded as proof for why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
After Fowler reported his findings to ESHYFT, the firm locked the database down a month later, telling him it was, “actively looking into this and working on a solution”.
You might also like
Security researcher finds finds huge non-password-protected database online It contained personally identifiable information, as well as medical data The database was since locked down ESHYFT, a technology platform designed for nurses across the United States, reportedly kept an unprotected database online, exposing thousands of sensitive records to anyone who knew…
Recent Posts
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Wired found code for an unreleased facial recognition feature in Meta’s AI app
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023