Data Security, Patch/Configuration Management, Identity

Millions of US patient data exposed by MongoDB misconfiguration

Health and Technology Stethoscope on Circuit Board blue

Cybernews reports that almost 2.7 million U.S. patients' profiles and 8.8 million appointment records have been inadvertently exposed by an unsecured MongoDB database believed to have been owned by U.S. dental marketing firm Gargle.

Included in the misconfigured MongoDB instance, which has since been secured, were individuals' names, birthdates, addresses, phone numbers, emails, gender, language preferences, chart IDs, and billing information, as well as appointment records that contained timestamps, patient metadata, and institutional references, according to Cybernews researchers, who suspected that the data may have spilled from third-party service-linked internal infrastructure. With the massive data compromise potentially resulting in identity theft, insurance fraud, phishing, and social engineering campaigns, Gargle should immediately notify those impacted by the incident in compliance with the Health Insurance Portability and Accountability Act. Meanwhile, individuals who may have been affected were urged to be vigilant of suspicious emails and unauthorized medical or insurance record activity, as well as seek identity theft monitoring services.

An In-Depth Guide to Identity

Get essential knowledge and practical strategies to fortify your identity security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds