Pager leaks patient sensitive information in Vancouver

Speaker : Erica

Outline

  • Preface
  • Introduction of this incident
  • Conclusion
  • Reference

Preface

What is pager ?

A pager is a wireless telecommunications device that receives and displays alphabets, numbers or voice messages.

About pager

The pager is an important tool for the hospital to keep in-hospital communication.

And it can avoid the use of technologies that may interfere with the work of some important instruments.

Pager communication is seldom encrypted.

Crackers only need a set of SDR tools and linked with a special USB. They can receive and steal these medical messages or identity data and even tamper them.

Introduction of this incident

Open Privacy Research Society discovers unencrypted patient medical information broadcast across Vancouver.
So the Office of the Privacy Commissioner starts an investigation.

About this event

The patient information leaked from the incident included:

  • name
  • age
  • gender
  • diagnosis record
  • attending doctors
  • ward number

Impact of the event

The Open Privacy Research Society has compared those leaked information and found that contain real information about the patient.

"VCH takes patient privacy very seriously and is actively working to mitigate the privacy risks you have identified. Please note, however, that VCH has no information to suggest that patient information has been compromised or used for a malicious purpose."

Respond by the General Privacy Officer at Vancouver Coastal Health. 

"As of the drafting of this press release the data breach is still active and ongoing."

- Open Privacy Research Society

Conclusion

How to prevent ?

Organizations should use communications technologies that are more secure and comply with data privacy regulations.

  • Avoid using unsafe or old communication systems.
  • Strengthening cybersecurity and incident response policies

Reference

呼叫器洩漏加拿大溫哥華病患敏感資料:這對企業的意義為何?

https://blog.trendmicro.com.tw/?p=62214

 

Press Release: Open Privacy discovers unencrypted patient medical information broadcast across Vancouve

https://openprivacy.ca/blog/2019/09/09/open-privacy-discovers-vancouver-patient-medical-data-breach/

Thank you for listening

Made with Slides.com