toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

273
active users

#medisecure

0 posts0 participants0 posts today

I missed this in regard to #medisecure

"The OAIC will not pursue an investigation into the personal information handling practices of MediSecure as the possible remedies that we could obtain for the community will not be proportionate to the resources required for a comprehensive investigation. This should not be of comfort to any organisations that hold personal information and do not have appropriate data security policies and practices in place."

oaic.gov.au/news/media-centre/

So the OAIC has done nothing, there have been no changes to the design of electronic prescribing systems to prevent this happening again, and no news that I know of from the AFP on their investigation.

@daedalus

OAIC · Statement on MediSecure data breachThe OAIC has closed our inquiries into the MediSecure data breach.

#MediSecure, an electronic medical prescription provider, was hacked earlier this year. The result is 12.9 million profiles of #Australian users currently for sale in the dark web.

As usual, given the anaemic data protection and privacy laws in #Australia, MediSecure has not even bothered so far to notify any of the people affected. They know they will not be held accountable and there will be no consequences to their irresponsibility.

DATE: July 22, 2024 at 04:48PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#EPrescription Vendor #DataBreach Affects 12.9 Million #Aussies t.co/9VEVQXO4Ed #MediSecure #Australia

Here are any URLs found in the article text:

t.co/9VEVQXO4Ed

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

www.healthcareinfosecurity.comE-Prescription Vendor Breach Affects 12.9 Million AussiesHackers stole sensitive information belonging to roughly half of Australia's population during an April ransomware attack against e-prescription firm MediSecure,

In the ever-evolving landscape of cybersecurity, another chilling chapter has been written. Hidden amidst the #CrowdStrike news cycle, a devastating revelation emerged: #MediSecure has fallen victim to a colossal #ransomware attack, compromising the personal #data of 12.9 million individuals. This #breach exposes our digital infrastructure’s vulnerabilities.

Names, addresses, medical histories, and more—intimate details of millions—now rest in the hands of cybercriminals. The sheer scale of this attack highlights the urgent need for a seismic shift in our approach to cybersecurity.

A critical component is recognizing the importance of machine-to-machine (M2M) identity access management. In our interconnected world, ensuring each machine has a secure identity is paramount. This added security layer can prevent unauthorized access and mitigate breach risks.

Investment in cutting-edge technology and unwavering commitment to security must become our new standard.

Continued thread

The #MediSecure breach is particularly troubling because it makes plain that the government either cannot, or does not want to, help us in this sort of situation.

Which raises questions about what the point of them is.

As several other fellow tech nerds have commented: given that dataset and the likely database structures, we could figure out who most of the people are, because we have done similar stuff before and it's fiddly but not super hard.

Indeed! Ponder, then, on the purpose of making it seem very difficult and mysterious and why the people doing that might want to give that impression.

Continued thread

One might also wonder wtf is the point of having the AFP, ASD, National Cyber Security Coordinator, and National Office of Cyber Security involved since their combined efforts have apparently managed to: restore the database server from backups. #MediSecure

Why is it weasel words? Because look at the kind of data that was taken:

"
full name;
title;
date of birth;
gender;
email address;
address;
phone number;
individual healthcare identifier (IHI);
Medicare card number, including individual identifier, and expiry;
Pensioner Concession card number and expiry;
Commonwealth Seniors card number and expiry;
Healthcare Concession card number and expiry;
Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
prescription medication, including name of drug, strength, quantity and repeats; and
reason for prescription and instructions.
" #MediSecure

New statement from MediSecure, now on a Wordpress domain:

medisecurenotification.wordpre

The key update is that yes, everything in prescriptions was "impacted":

"The impacted server analysed by McGrathNicol Advisory consisted of an extremely large volume of semi-structured and unstructured data stored across a variety of data sets. This made it not practicable to specifically identify all individuals and their information impacted by the Incident without incurring substantial cost that MediSecure was not in a financial position to meet.

The analysis of the data can confirm that the kinds of information impacted by this Incident includes:
full name;
title;
date of birth;
gender;
email address;
address;
phone number;
individual healthcare identifier (IHI);
Medicare card number, including individual identifier, and expiry;
Pensioner Concession card number and expiry;
Commonwealth Seniors card number and expiry;
Healthcare Concession card number and expiry;
Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
prescription medication, including name of drug, strength, quantity and repeats; and
reason for prescription and instructions."

MediSecureMediSecureMedia / Public Statement

#Cyberattack target #MediSecure enters voluntary administration. Prescription delivery service provider , which fell victim to a large-scale #cyberbreach that compromised the personal health information of thousands of Australians in April, has entered voluntary administration and is expected to face its creditors later this month. #itsecuriry #hacking #CyberSecuriy

smh.com.au/business/companies/

The Sydney Morning Herald · Cyberattack target MediSecure enters voluntary administrationBy Millie Muroi

I like to fall back on "the elites are lying to the public because they're afraid the public will notice how incompetent they really are" in the absence of direct evidence. Mostly because that's what history shows was usually going on with the elites. #MediSecure