1 / 3100%
Healthcare data is valuable on the black market because it often
contains all of an individual’s personally identifiable information, as
opposed to a single piece of information that may be found in a
financial breach. Often these attacks see hundreds of thousands of
patient’s data and privacy compromised or stolen by those with
malicious intent.
Mobile health apps leak sensitive data through APIs
30 mobile health apps to highlight the threats they face through
application program interfaces (APIs). ll of the apps were found to be
vulnerable to API attacks, and some allowed access to electronic
health records (EHRs). The 30 apps collectively expose 23 million
mobile health users to attacks, Knight reported. Of the 30 apps tests,
77% contained hardcoded API keys, of which some do not expire,
according to the report, and 7% had hardcoded usernames and
passwords. APIs allow mobile phones to access X-rays, pathology
reports and allergy data. The COVID-19 pandemic has accelerated
the use of mobile health apps and virtual care, and this push
motivated.
An API is an Application Programming Interface. API’s transmit data
between software products. The researcher’s findings showed that
100 percent of API endpoints were susceptible to Broken Object
Level Authorization (BOLA) attacks. She was able to see personally
identifying information and personal health information that was not
authorized in the clinician account the researcher used. It is
imperative to secure apps before they are produced and launched for
public testing and use.
“With APIs providing access to the most coveted health data, it is
urgent that we secure these APIs,” said Ben Denkers, senior vice
president, security and privacy services at cybersecurity consulting
firm CynergisTek.
946 UNC patients' billing info is potentially exposed by
unauthorized account access
Chapel Hill, N.C.-based UNC Health is notifying 946 patients that
billing information linked to their accounts might have been accessed
by another person who was incorrectly given access.
UNC Health discovered their billing system contained incorrect
authorization information in the billing portion of their patient’s EHR
account. This breach affected the billing authorization field that
normally contains a patient’s relative name or someone they trust.
Furthermore, when a name is present in this field, it gives the
individual the ability to access the patient’s billing information. After
the investigation, UNC stated credit card information, Social Security
numbers, and payer identification numbers were not compromised.
The patients were comprised because the unauthorized user gained
access to UNC EHR. A billing data field was altered which granted
access to an unauthorized person that the patient did not know.
When billing data is breached, there is always a possibility of financial
loss to the patient. However, UNC states there is no reason to believe
any affected patients are or will be at financial risk because of the
breach. UNC has since implemented changes to its EHR system to
prevent future breaches. They immediately reset the billing field that
contained the inaccurate information. They also, upgraded their EHR
administration to limit the number of people that will be authorized to
access and or update this field. Assigning risk management tasks
throughout your organization makes it less likely that threats will slip
through the cracks.
References
Fierce Healthcare. (2021, February 24). Mobile health apps leak
sensitive data through APIs. Retrieved June 2, 2022, from
https://www.fiercehealthcare.com/tech/mobile-health-apps-leak-
sensitive-data-through-apis-report-finds
Mitchell, H. (2021, November 5). 946 UNC patients’ billing info
potentially exposed by unauthorized account access. Hannah Mitchell.
Retrieved June 2, 2022, from
https://www.beckershospitalreview.com/cybersecurity/946-unc-
patients-billing-info-potentially-exposed-by-unauthorized-account-
access.html
SecureLink, Inc. (2022, May 6). The Value of Healthcare Data.
SecureLink. Retrieved June 2, 2022, from
https://www.securelink.com/blog/healthcare-data-new-prize-
hackers/#:%7E:text=Healthcare%20data%20is%20valuable%20on%
20the%20black%20market,compromised%20or%20stolen%20by%2
0those%20with%20malicious%20intent.
Students also viewed