LabCorp website bug exposed thousands of medical documents


A security flaw in LabCorp’s website exposed thousands of medical documents, like test results containing sensitive health data.
It’s the second incident in the past year after LabCorp said in June that 7.7 million patients had been affected by a credit card data breach of a third-party payments processor. The breach also hit several other laboratory testing companies, including Quest Diagnostics.
This latest security lapse was caused by a vulnerability on a part of LabCorp’s website, understood to host the company’s internal customer relationship management system. Although the system appeared to be protected with a password, the part of the website designed to pull patient files from the back-end system was left exposed. That unprotected web address was visible to search engines and was later cached by Google, making it accessible to anyone who knew where to look. The cached search result only returned one document — a document containing a patient’s health information. But changing and incrementing the document number in the web address made it possible to access other documents.
The bug is now fixed.
Using computer commands, we determined the approximate number of exposed documents by asking the exposed server if a document existed by returning certain properties about the file — such as its size — but not the document itself. This allowed us to see if a document was on the server without accessing large amounts of patient information, and thus preventing any further exposure to the patient’s privacy.
The results showed at least 10,000 documents were exposed.
Of the handful of files we examined to understand what kind of data was exposed, the documents largely appeared to affect cancer patients under the laboratory’s Integrated Oncology speciality testing unit.
The documents contained names, dates of birth, and in some cases Social Security numbers of patients. The documents also contained lab test results and diagnostic data, a class of data considered protected health information under the Health Insurance Portability and Accountability Act (HIPAA). A couple of the documents we reviewed contained a footer notice, which said: “This document contains private and confidential health information protected under state and federal law.”
Running afoul of HIPAA can result in heavy fines.
“This is a massive privacy issue — and one that could impact affected users and patients for years to come,” said Rachel Tobac, a hacker, social engineer, and founder of SocialProof Security. “The sensitive nature of those documents and the leak of private medical status is a huge privacy violation for those patients for obvious reasons, but also sadly for some possibly less glaring reasons, as well.”
Tobac, who reviewed our findings, said medical information can be “terribly useful” for criminals in identity theft, extortion, and phishing, because the victim may be more likely to trust the sender “under the assumption that the message is legitimate because it contains information only their medical provider could or should know.”
The vulnerability was found in-house at TechCrunch and was reported to LabCorp, which later pulled the server offline. Although the web address remains in Google’s search results, the link is now dead.
“I can confirm that we have terminated access to the system,” said LabCorp spokesperson Donald Von Hogan. But the company would not ay if it planed to inform patients and state authorities under data breach notification laws to the security lapse.
LabCorp’s Von Hogan said in a call that the company would not confirm the documents found on the exposed server “are in fact LabCorp information.”
TechCrunch reached out to a number of patients to verify their information. Only one person confirmed by phone that the information in their exposed file was accurate, but expressed that they did not want to be named for this story.
Two other people whose names were in the files had since passed away, according to obituaries.
A security flaw in LabCorp’s website exposed thousands of medical documents, like test results containing sensitive health data. It’s the second incident in the past year after LabCorp said in June that 7.7 million patients had been affected by a credit card data breach of a third-party payments processor. The…
Recent Posts
- Instagram’s Reels may get its own app
- The official ChatGPT Android app may have just leaked the GPT-4.5 launch early
- Xiaomi 15 Ultra is a small update with a big periscope lens
- Amazon’s upgraded Alexa+ will enable Fire TV devices to skip to a particular scene in a movie just by describing it
- Prime Video puts a Supernatural spin on The Boys season 5 cast as Jared Padalecki and Misha Collins sign on to the popular show in mystery roles
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010