A bug in a medical nascency’s website put thousands of COVID- 19 test results
Veterans Memorial Stadium at Long Beach City College is experiencing problems. Image Sources Los Angeles Times(opens in a new window)/Getty Images AllenJ. After a consumer created a vulnerability that permitted access to other people's specific information, a California-based medical facility that offers COVID-19 testing throughout Los Angeles has taken down a website it used to allow visitors to view their test results. Each week, "thousands" of COVID- 19 tests are processed at businesses, sporting events, and schools by Total Testing Results, which operates 10 COVID- 19 testing locations throughout Los Angeles. Upon completion of the test, guests receive a dispatch with a link to a website where they can access their results.
But one client claimed that by modifying a single digit in the website's address, they created a vulnerability that allowed them to access the information of other visitors. The customer was then able to view the names of other visitors and the testing date. The website's COVID- 19 test results may also be accessed by entering a person's date of birth, which the customer who found the vulnerability claimed "wouldn't take long" to brute-force or just guess.(For anyone under the age of 30, that only amounts to 11,000 birthday hypotheses.)
READ further ON TECHCRUNCH
How Jamaica handled its Jam COVID criticism after exposing thousands of passengers' data on their immigration website How to react when a data breach occurs The test results website is protected by a login runner that requests the user's dispatch address and password, but the vulnerable portion of the website that allowed the user to change the web address and access the information of other visitors could be entered directly from the web, completely avoiding the sign-in prompt.
In order to have the vulnerability repaired before it is discovered or exploited by someone else, the customer gave TechCrunch information about it. TechCrunch supported the customer's findings, but even though we did not list every result, we may infer from the confined testing environment that the vulnerability probably caused roughly 60,000 tests to fail.
Basic Discovered Test
TechCrunch notified TTS's top medical officer, Geoffrey Trenkle, of the vulnerability. Trenkle did not contest the number of tests discovered but claimed the vulnerability was restricted to an on-premises garçon that was once used to provide heritage test results but has since been shut down and replaced by a new palliative system.
In a statement, Trenkle stated, "We were recently made aware of an implicit security weakness in our prior on-demesne garçon that may provide access to specific patient names and results via a mix of URL manipulation and date of birth programming canons. The vulnerability was restricted to patient data collected at open testing sites prior to the development of the pall-based garçon.
We immediately shut down the on-premise program in reaction to this implicit problem, and we started moving the data to a secure pall-based system to prevent further problems with data breaches.
Vulnerability Assessment
We also started a vulnerability analysis, which included looking into garçon access logs to spot any strange network activity or login errors.
” Trenkle declined to comment on the origins of the pall garçon or why the purported heritage garçon's most recent test results were from last month. As a result of the problems with its former garçon, TTS is currently unaware of any breach of loosely protected health information.
We are aware of no actual compromise of patient health information, and all issues have been resolved moving forward, according to Trenkle.
Trenkle stated that the business will adhere to its legal obligations under state law but abruptly stopped short of stating specifically if the business intended to alert visitors to the danger.
Although businesses aren't required to notify the attorney general of their state or their customers about vulnerabilities, many do out of an abundance of caution because it's not always feasible to tell if there was unintentional access.
Comments
Post a Comment