UPDATED 22:33 EDT / JANUARY 28 2020

SECURITY

Lab testing firm LabCorp exposes patient data via unsecured CRM system

Lab testing firm Laboratory Corp. of America Holdings, better known as LabCorp, is back in the news again for all the wrong reasons: TechCrunch today reported that the company left thousands of medical documents exposed online.

LabCorp was last in the news in June when 7.7 million patient records were stolen. They included patient names, dates of birth, addresses, phone numbers, dates of service and provider along with in some cases credit card and bank account information. And in July 2018, the company was a victim of a ransomware attack.

This time around, LabCorp exposed the patient records via an unsecured part of its customer relationship management system. Whether the data was accessed by bad actors isn’t clear, but TechCrunch noted that the data, which primarily related to cancer patients, could be found with only simple effort.

The data included names, dates of birth and in some cases Social Security numbers of patients. In addition, some of the exposed data included lab test results and diagnostic data — protected data under the Health Insurance Portability and Accountability Act or HIPAA.

“The LabCorp security flaw is a case of Insecure Direct Object References Vulnerability that allowed the attacker to discover and bypass authorization and access critical resources directly,” Chetan Conikee, chief technology officer of continuous application security platform provider ShiftLeft Inc., told SiliconANGLE. Likely the attacker modified the value of a parameter, probably a patient ID, in order to gain access to personally identifiable information data, he added.

“Such critical resources can be database entries belonging to other users, files in the system and more,” Conikee said. “This is caused by the fact that the application takes user-supplied input and uses it to retrieve an object without performing sufficient authorization and validation checks.”

Robert Prigge, chief executive officer of identity verification company Jumio Corp., thinks the impact on the lives of thousands of affected patients may be significant, since there’s a good chance much of their information is now on the dark web, a shady part of the internet reachable with special software. That leaves them vulnerable to identity theft, account takeover and even prescription fraud.

The healthcare industry is a prime target for cybercriminals because the data can be very profitable when sold on the dark web, said Stephan Chenette, co-founder and CTO of enterprise security firm AttackIQ Inc.

“Unlike, for example, financial data, healthcare data usually contains fixed information, such as dates of birth and Social Security numbers, which thieves can leverage to commit identity theft for years to come,” Chenette explained. “LabCorp and other healthcare organizations, who manage large amounts of confidential patient information, must take proactive approaches to protect their data.”

Image: LabCorp

 


A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.