brain scan

More Than One Billion Medical Images Remain Unprotected On The Web

Some security experts and lawmakers have criticized the Department of Health and Human Services for failing to enforce privacy laws and fine organizations that did not protect patient records.

Over a billion medical images remain exposed due to hospitals, medical offices and imaging centers running insecure storage systems, according to a TechCrunch report.

The storage systems allow anyone with an internet connection and free software to access the sensitive images, about half of which belong to patients in the U.S. The number of exposed images has only increased since the issue was first revealed in September by ProPublica.

At first, a security firm found that the number of images was 720 million. Now, the problem has grown to 1.19 billion scans, and medical offices have not taken action to secure their servers since being notified by security researchers who discovered the issues.

“The amount of data exposed is still rising, even considering the amount of data taken offline due to our disclosures,” Dirk Schrader, who led research at the security firm Greenbone Networks, told TechCrunch, adding: “It seems to get worse every day.”

Patients are largely unaware of the fact that their medical images are being stored online for nearly anyone to see, and that the exposed information puts them at a higher risk of being targeted for insurance fraud and identity theft, according to TechCrunch.

Nearly 600 million images could be secured if all remaining medical offices removed their accessible servers from the internet. But even after being contacted by the news outlet about the status of their servers, many did not take action.

Lawmakers and former Department of Health and Human Services officials say that more must be done to address the lack of privacy and security standards for health organizations. While medical records are protected by HIPAA, the main privacy law for medical patients, HHS has not done enough to enforce penalties for security lapses, according to Sen. Mark Warner (D-Va.).

“To my knowledge, Health and Human Services has done nothing about it,” Warner told TechCrunch. “As Health and Human Services aggressively pushes to permit a wider range of parties to have access to the sensitive health information of American patients without traditional privacy protections attached to that information, HHS’s inattention to this particular incident becomes even more troubling.”

Last year, one Tennessee medical imaging company was fined $3 million for accidentally exposing a server containing 300,000 records. Former government officials said that there needs to be more security assistance available to smaller health organizations so that HHS would have more resources to dedicate to enforcing security violations.

“It may be too big of a problem for any single law enforcement agency to truly put a dent in,” said Deven McGraw, a former top privacy official in HHS’ Office of Civil Rights, which enforces the law.

In response to the criticism, the Office of Civil Rights defended its past actions to enforce HIPAA security violations.

“OCR has taken enforcement action in the past to address violations concerning unprotected storage servers, and continues robust enforcement of the HIPAA rules,” a spokesperson told TechCrunch.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • The Future is Happening Outside the Cloud

    For years, the cloud has captivated the physical security industry. And for good reason. Remote access, elastic scalability and simplified maintenance reshaped how we think about deploying and managing systems. But as the number of cameras grows and resolutions push from HD to 4K and beyond, the cloud’s limits are becoming unavoidable. Bandwidth bottlenecks. Latency lags. Rising storage costs. These are not abstract concerns. Read Now

  • The Impact of Convergence Between IT and Physical Security

    For years, the worlds of physical security and information technology (IT) remained separate. While they shared common goals and interests, they often worked in silos. Read Now

  • Unlocking Trustworthy AI: Building Transparency in Security Governance

    In situations where AI supports important security tasks like leading investigations and detecting threats and anomalies, transparency is essential. When an incident occurs, investigators must trace the logic behind each automated response to confirm its validity or spot errors. Demanding interpretable AI turns opaque “black boxes” into accountable partners that enhance, rather than compromise, organizational defense. Read Now

  • Seeking Innovative Solutions

    Denial, Anger, Bargaining, Depression and Acceptance. You may recognize these terms as the “5 Phases” of a grieving process, but they could easily describe the phases one goes through before adopting any new or emerging innovation or technology, especially in a highly risk-averse industry like security. However, the desire for convenience in all aspects of modern life is finally beginning to turn the tide from old school hardware as the go-to towards more user-friendly, yet still secure, door solutions. Read Now

  • Where AI Meets Human Judgment

    Artificial intelligence is everywhere these days. It is driving business growth, shaping consumer experiences, and showing up in places most of us never imagined just a few years ago. Read Now

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.