Top storiesNew ZealandPoliticsBusinessEntertainmentSportsWorld

Intimate medical data exposed in clinical trial database breach

Friday, 9 August 2019

UpGuard said the vast majority of the 37,170 users were Kiwis and Aussies.
UpGuard said the vast majority of the 37,170 users were Kiwis and Aussies.

Intimate medical data of tens of thousands of Kiwis and Australians was exposed in a database breach at clinical trial company Neoclinical.

Cybersecurity company UpGuard said details on client bladder control, skin conditions and illegal drug use were exposed when one of its researchers discovered the Neoclinical breach last month.

The clinical trial client data included personal and medical history information.
The clinical trial client data included personal and medical history information.

Sydney-based Neoclinical said the company 'server was temporarily opened' but all data stayed password-protected.

Stuff asked Neoclinical how many of the reported 37,170 people in the database were New Zealanders.

**READ MORE:

Patient documents missing, reportedly lost in 'a gust of wind'

GCSB cyber security told Treasury its computer network not compromised

Over-55s most vulnerable to cyber attacks**

Neoclinical said its database was in 'complete lockdown' on Thursday and that information was unavailable.

'A US cyber security company which trawls the internet looking for data access found a way to get around the password protection and access our server,' a Neoclinical spokesperson said.

Neoclinical said it did not believe the information would be used maliciously. 

'We are seeking reassurances to this effect from the company which breached our server and are have contacted them.'

Visitors to Neoclinical's website on Thursday and Friday were met with a '502 Bad Gateway' message or blank screen.

Neoclinical said its site would stay locked down with 'operations suspended' until the company was sure a similar breach could not happen again.

'Once the breach from the cyber security company was confirmed, we immediately contacted the [Australian] Privacy Commissioners' Office about the event and we are informing everyone whose details may have been affected.'

LAW CHANGE LOOMS

On Friday, the Office of the Privacy Commissioner in New Zealand said Neoclinical had not notified it.

'Under the current Privacy Act, agencies do not have to notify our office of a data breach,' a Privacy Commissioner spokesman said.

But the new Privacy Bill before Parliament could change that.

The bill would require agencies inform the Privacy Commissioner and affected people when a privacy breach caused harm, or posed a risk of harm to people.

Mandatory data breach notification already existed in Australia.

UpGuard said the Neoclinical database, with 37,170 users' personal information, was now secured.

UpGuard said its researcher tried alerting Neoclinical on July 1 but public access to the database was not removed until July 26. 

'In reviewing the data set, the vast majority of individuals affected were in Australia and New Zealand, where Neoclinical operates clinical sites,' UpGuard added.

'Without exposing documents produced by a physician – what one often thinks of as the model of 'medical data' – these profiles reveal information about participants' medical histories,' UpGuard said on its website.

That information included diagnoses and past treatments, UpGuard added.

The cybersecurity company said the case should remind anybody passing information to third parties to consider the impact of that data being exposed. 

'And for companies, it should highlight the importance of having an incident response capability so that when data leaks occur, they can be mitigated within hours rather than weeks.'