9 ms·
2.7M medical calls breached in Sweden
- deleted 8y ago[deleted]
- liquidise 8y agoLet's talk legal ramifications. The cause of technical breaches falls onto a sliding scale in my mind. That scale goes from pure technical negligence to overbearing technical complexity. This breach seems like pure negligence. In a surgery this wouldn't be "complications", it would be malpractice. Does GDPR protect those breached here? What recourse do these people have? We really need to change the narrative around data. It should be a liability. Unlike other disruptions software drives, this will need to be driven by governments.
- acd 8y agoSure! Breach against patientdatalagen and GDPR Shall be encrypted so that the patients identity are protected. "Uppgifter om en patients identitet som har dokumenterats inom hälso- och sjukvården och som landstingen ska sambearbeta med sådana uppgifter som avses i första stycket, ska vara krypterade så att patientens identitet skyddas vid behandlingen. Lag (2013:1024)." "Information about a patient's identity that has been documented in the health and medical care and which the county councils are to co-operate with the information referred to in the first paragraph, shall be encrypted so that the patient's identity is protected during the treatment. Swedish law (2013: 1024)" Transfer of personal data outside EU Tredjelandsöverföring. "Transfers of personal data to third countries or international organisations" Thailand is not on the list of authorized countries. https://gdpr-info.eu/chapter-5/ https://gdpr-info.eu/chapter-5/ The GDPR section about sensitive data records * medical records. Den personuppgiftsansvarige ska genomföra lämpliga tekniska och organisatoriska åtgärder för att, i standardfallet, säkerställa att endast personuppgifter som är nödvändiga för varje specifikt ändamål med behandlingen behandlas. Den skyldigheten gäller mängden insamlade personuppgifter, behandlingens omfattning, tiden för deras lagring och deras tillgänglighet. Framför allt ska dessa åtgärder säkerställa att personuppgifter i standardfallet inte utan den enskildes medverkan görs tillgängliga för ett obegränsat antal fysiska personer. Further persons working at tillsyndsmyndigheter may have done "Tjänstefel", that is fault committed by a public sector official servant that is not minor. 20 kap. Om tjänstefel m. m. "Section 1 Anyone who intentionally or negligently neglects the exercise of authority by action or omission shall be sentenced for misconduct for fines or imprisonment for a maximum of two years. If the act, having regard to the perpetrator's powers or the task's relation to the exercise of authority in other respects or to other circumstances, is to be regarded as poor, shall not be held liable." Failure to run a network security scanner, failure to encrypt sensitive data records, failure to use passwords, failure to limit access to sensitive records
- aboutruby 8y agoThe government can't fine itself I guess, so it would have to be the EU that fines sweden? Or some kind of class action from swedes?
- maeln 8y agoGovernment is not the justice system. It is one of the basis of Democracy: separation of power. You can absolutely take your government to court (at least in democratic country). Class action doesn't exist in all country though. Each person that want to sue the government might have to do it in his own name.
- styren 8y agoWhy not fine the company, Medicall, responsible for taking the calls? Or Voice Integrate Nordic, who supplied the callcenter-system, depending on who is at fault.
- makkesk8 8y agoA class action is not likely. Most Swedes will probably see this as a minor setback and just move on.
- bjoli 8y agoMy whole family (not affected, btw) is livid. I didn't even bring it to their attention. I am going to say the exact opposite: this will be one of the most widely publicised health care scandals since forever.
- makkesk8 8y agoI agree, it will definitely be the largest health care scandal in Sweden's history, but it will most likely not end up with a class action lawsuit.
- Sverigevader 8y agoOn my machine Google translate seems to "boot-loop" that site because of the cookie settings so I'll just do this: Files were stored on a server using HTTPS but requiring no credentials. http://188.92.248.19:443/medicall/ http://188.92.248.19:443/medicall/ Part of the calls were saved as .mp3s with the customers phone number as file name. CEO when confronted wouldn't believe it and hung up when the reporter asked if he could play one of the tapes. The articles states that the server was a NAS (nas.applion.se). All files have been available since 2013. When calling 1177, there's no need to identify yourself with your personal identity number. You can if you want to if your medical history is of significance to your call. Source: Am swede and this article... https://computersweden.idg.se/2.2683/1.714787/inspelade-samtal-1177-vardguiden-oskyddade-internet https://computersweden.idg.se/2.2683/1.714787/inspelade-samt... And I want you guys to hear it from me before you hear it on the streets... I once called 1177 wanting to order a new pair of knees because one of mine hurt. The nurse who answered had a good laugh.
- Chilinot 8y agoThe "funny" thing is, it wasnt using HTTPS, it was on the 443 port. But the data was sent unencrypted.
- dcplogic 8y agoThese calls were answered by Swedish-speaking people in Thailand. Their business idea was to handle calls that were placed in inconvenient hours, relative to Swedish business hours. My best guess is that the Thai ISP this office used filtered all outgoing connections except port 80 and 443. And then someone decided that the way to implement this securely while still allowing this office to access the data was to put a plain HTTP server on port 443. "Who is ever going to crack that?"
- bobl 8y agoI would guess the server is run by the voip provider in Stockholm, which literally seems to be 1-3 contractors. Reading between the lines of the few articles published about the call center it seems like their business idea is to hire old nurses and not pay them very much. https://www.voiceintegrate.com/se/support/vi-som-jobbar-h%C3%A4r-7589699 https://www.voiceintegrate.com/se/support/vi-som-jobbar-h%C3...
- rb808 8y agoI'm not clear on why medical records are so sensitive. I can understand some people might want to hide HIV status - but is there anything else? In the US people have wanted to hide prior conditions from insurance companies, but I wouldn't expect this a problem in Sweden.
- proaralyst 8y agoThere are many more embarrassing medical conditions other than HIV status.
- runj__ 8y agohttp://threewordphrase.com/presentation.htm http://threewordphrase.com/presentation.htm
- maeln 8y agoThere is many example why medical record is a very sensitive data. You can be blackmailed because you have or had a "shameful" disease, a potential employer can deny you a job because you were too often sick for his own taste, insurance might deny you because you have a too risky profile, ...
- krn1p4n1c 8y agoNone of those scenarios are viable in Sweden.
- ubercow13 8y agoBecause Swedes are uniquely morally upstanding and non-judgemental?
- krn1p4n1c 8y agoNo, we're highly judgemental, but an employer is not allowed to inquire or make hiring/firing decisions with regard to your health status. Likewise life insurance might have a higher premium if you regularly engage in extreme sports, but they can't deny you. Health care is ubiquitous regardless of your condition.
- teddyh 8y agoOriginal source: https://computersweden.idg.se/2.2683/1.714790/1177-lackan-integritetshaveri https://computersweden.idg.se/2.2683/1.714790/1177-lackan-in...
- testplzignore 8y agoThere are quite a few hosts responding on port 80 in the 188.92.248.0/21 subnet, including versions of httpd and php over a decade old. I wouldn't be surprised if there are more things unsecured. Yikes.
- deleted 8y ago[deleted]
- z3t4 8y agoNot a good idea to show the ip addr in the screenshot.
- hybro 8y agoI think we can assume this data is now part of a dataset in some data mining engine somewhere.
- rollulus 8y agoSeeing posts like this remind me of a nice quotation I saw somewhere, which is like "all data will eventually be either public or gone forever". Unfortunately my search skills are insufficient to find the exact wording or author.
- lucb1e 8y agoI'm okay with that: when I'm dead, do with my data what you will (of course, so long as anyone implicated like chat partners in chat data, are also dead). But I guess the quote refers to shorter timespans than that.
- oldmanhorton 8y agoExcept with medical history, your data can impact your children and grandchildren (both positively and negatively, but also hopefully privately regardless).
- vectorEQ 8y agohacking things together in an agile environment :') just deploy to production. no worries! be happy!
- pure-awesome 8y agoWith the level of IT competence displayed here, I doubt they've even heard of Agile.
- jdmoreira 8y agoEither me, my girlfriend or both of us are in those phone calls. I feel absolutely betrayed by the state. I always knew that Sweden's obsession with medical data collection would back-fire but audio recordings? That's just too much. I hope everyone involved gets sued into oblivion!
- C1sc0cat 8y agoMaybe the phone company responsible needs to have its licence revoked without compensation.
- tapland 8y agoPhone company? It's the comapny employing nurses receiving the calls.
- C1sc0cat 8y agoAh that's the reason you exert the maximum pain at a high enough level - then the phone companies will take security properly and enforce it on third parties.
- ptaipale 8y agoI guess "phone company" is used here loosely, to describe the provider of VoIP call center and recording service provider employed by the service (which is owned by the municipal/county co-operation organisation SKL, Sveriges Kommuner och Landsting).
- tapland 8y agoYep. My calls with personal identification number are absolutely in there, with list of 10+ medications, and medical history including genetic disorders and other things. Imagine becoming a public person in the future with random russian mobs blackmailing me based on me and my family's medical history.
- buboard 8y ago> blackmailing me based on me and my family's medical history. like "we 'll tell everyone you re 1.5 times more likely to get ulcer?"
- tapland 8y agoNo.
- jacquesm 8y agoI keep seeing your account closely correlated with low quality and/or un-informed comments, could you please try to do a little better? Thanks!
- pbhjpbhj 8y agoMaybe you were raped but don't want everyone to know, but you spoke to your doctor about psych referral for rape victims? Or you had a mental health crisis? Or you had/have sexually transmitted diseases/infections? Maybe you've been suicidal, and work will fire you if they find out? Perhaps you have cancer, a degenerative disease, but you don't want your family/employer/SO to know? Seems like lots of possible blackmail opportunities. But even something like having an ulcer could be used against you. I recall one national ruler using another's fear of dogs to humiliate them as part of a negotiation. Give someone food to inflame their ulcer prior to a business negotiation, use their discomfort to wrong-foot them ...
- MasterScrat 8y ago> My calls with personal identification number are absolutely in there Is this an assumption, or were you able to find a list of leaked calls somewhere?
- mrintegrity 8y agoThe site hosting this seems to be dead, probably from the load but hopefully from action taken by the company now that it's public knowledge. Does anyone have a list of the affected phone numbers? I would like to check if mine is in there
- dontbenebby 8y agoWhy would you even record these calls indefinitely, without a deletion schedule? Were they recording all calls, not just a subset to be audited for customer service? Why not have an auditor listen to the call live and destroy the recording if everything is done by the book and evidence need not be retained?
- NeedMoreTea 8y agoMedical advice over the phone? What happens when someone dies, or gets worse? One of the first things you'll want to know is what advice was offered. I would imagine they had to record all, and keep for some preset period.
- dontbenebby 8y agoOh yeah, I don't think it's weird that it's recorded, but having it delete after X days is so simple I'm shocked it wasn't implemented in a Nordic country w/ strong privacy laws. On the upside, at least it's probably harder to sift through that data to find embarrassing and/or sensitive information than if it was textual. (This is one reason that if I'm having a personal issue, I prefer to do a voice call with a friend rather than use IMs like many in my generation are so fond of)
- jacquesm 8y agoSo, who thought it was a good idea to record these in the first place and then to store them on an internet facing server? It doesn't surprise me one bit though.
- jks 8y agoRecording the calls could even be a requirement. You call in to get medical advice, then later decide the advice was wrong and sue them for malpractice. Recordings of the calls could be crucial to deciding the case later on.
- ObscureScience 8y agoTheir router admin page and ssh are also open to the internet.
- teddyh 8y agoLatest news: The company with the security breach reports the reporter and news organization to the police for unauthorized entry into their computer system: https://www.dn.se/sthlm/medhelp-polisanmaler-tidningen-computer-sweden/ https://www.dn.se/sthlm/medhelp-polisanmaler-tidningen-compu...
- teddyh 8y agoNon-paywall: https://www.svt.se/nyheter/medhelp-anmaler-computer-sweden https://www.svt.se/nyheter/medhelp-anmaler-computer-sweden