3 ms·
It's easy for people to pile on to Babylon Health and suggest they are both evil and incompetent in their approach to patient data. And it's easy for BBC journa
by FearNotDaniel 6y ago
It's easy for people to pile on to Babylon Health and suggest they are both evil and incompetent in their approach to patient data. And it's easy for BBC journalists with a strong pro-NHS, anti-private-healthcare agenda to spin it into a clickbaity "suffered a data breach" headline which, though technically true, implies something much worse than what actually happened here.
Sounds like somebody accidentally shipped a bug that didn't lock down permissions properly. Not something any of us wants to happen, that's why we have QA procedures, code reviews, and hopefully somebody independently auditing any new code that touches personally-sensitive data to ensure security standards remain watertight. Obviously that part of the process failed this time round and the bug slipped through the net.
Bugs happen. Nobody releases 100% bug-free code 100% of the time. Not even NASA. Some firms, due to the nature of their data and the risks involved, have a greater responsibility to run processes that minimize the likelihood of bugs but also to deal with them quickly when they are spotted in the field.
This was fixed two hours after it was reported. A handful of users had temporary access to other users' data that they shouldn't have had. And then they didn't. There is no evidence of any enormous data dump on the dark web containing yottabytes of personally identifiable patient secrets, though that is no doubt what a journalist wants you to imagine/fear when you read the words "data breach".
Regardless of your political/economic view of Babylon's business model and its potential negative effect on the public healthcare system (which may well be valid criticisms), it sounds like from a purely engineering perspective they should get some credit here for addressing the issue so soon after it became apparent.