Data Security

Misconfigured Perfectshift database leaks Stanford Health Care, Hillsboro Medical Center data

(Adobe Stock)

Stanford Health Care and Hillsboro Medical Center had more than 50,000 records belonging to its staff members and contractors inadvertently exposed by an unsecured MongoDB database managed by healthcare workforce management services firm Perfectshift, reports Cybernews.

Included in the misconfigured database were payroll details, full names, work email addresses, IP addresses, hashed passwords, browser agents, session cookies, and authorization tokens, according to Cybernews researchers.

"While it appeared that the data was imported to the database from encrypted sources, the data in the database was not encrypted or access-controlled," noted researchers, who warned of the increased risk of social engineering, phishing, and credential stuffing attacks against impacted individuals.

Perfectshift, which closed the unprotected database on Oct. 30, was urged to not only restrict public access to the database and enable authentication and authorization capabilities, but also reset exposed credentials and promptly notify affected organizations and individuals.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds