News: 1608032405

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

45 million medical scans from hospitals all over the world left exposed online for anyone to view – some servers were laced with malware

(2020/12/15)


Two thousand servers containing 45 million images of X-rays and other medical scans were left online during the course of the past twelve months, freely accessible by anyone, with no security protections at all.

Or so says research by CybelAngel, which sells a Digital Risk Protection Platform. Not only was the sensitive personal information unsecured, but malicious folk had also accessed those servers and poisoned them with apparent malware, the company added.

"The fact that we did not use any hacking tools throughout our research highlights the ease with which we were able to discover and access these files," said David Sygula, a senior cybersecurity analyst at CybelAngel and author of the firm's report.

The research did not name any care providers or medical institutions that were found to fall short of running secure systems.

Among the data - drawn from unprotected online storage devices with ties to hospitals and medical centres all over the planet - were 23,000 images of UK patients, left exposed to the public internet on 90 separate servers. X-rays and CT scans were accessible online thanks to what CybelAngel said was a combination of unsecured NAS storage and the 1980s-vintage DICOM medical data transmission protocol.

While it is adequate for the task demanded of it, DICOM's security protocols are merely advisory. The [1]standard itself says:

This Standard assumes that the Application Entities involved in a DICOM interchange are implementing appropriate security policies, including, but not limited to access control, audit trails, physical protection, maintaining the confidentiality and integrity of data, and mechanisms to identify users and their rights to access data. Essentially, each Application Entity must insure that their own local environment is secure before even attempting secure communications with other Application Entities.

Exposed images included, in some cases, "up to 200 lines of metadata per record which included PII (personally identifiable information; name, birth date, address, etc.)" and personal health information including a patient's "height, weight, diagnosis" and so on.

Even a specialist firm "advertising a paid service to securely host and manage DICOM images" was leaking around 500,000 files online because nobody had thought to secure its Network File System (NFS) on port 2049, Cybelangel found.

Although Cybelangel said it had used many tools to poke around online and find exposed DICOM data, its report featured screenshots from Shodan and frank findings by researchers who had simply typed common DICOM ports into the insecure kit search engine to see what devices responded.

Aside from the obvious data protection concerns, most worrying was CybelAngel's finding that it was "not the first to have a look at these servers". The report said: "Some of [the servers] included malicious scripts. The infection of unprotected servers is very common and usually done through automation scripts, especially to install Bitcoin (or similar) miners."

The firm recommended that medical orgs "should ensure proper network segmentation of connected medical imaging equipment" as one means of preventing malicious people from accessing things they shouldn't.

Last year Greenbone Networks carried out similar research, popping likely search terms and port numbers through Shodan to [2]discover 24 million people's medical information had been exposed online as 737 million items of DICOM data. ®

Get our [3]Tech Resources



[1] http://dicom.nema.org/medical/dicom/current/output/html/part15.html

[2] https://www.theregister.com/2019/09/17/24m_medical_records_unsecured_online/

[3] https://whitepapers.theregister.com/

quelle surprise?

N2

The incompetence of it all beggars belief.

Re: quelle surprise?

Gene Cash

Well, most all of the doctors I've met absolutely despise all technology, including computers.

I get the impression they'd be happy with a bottle of leeches and a candle.

Re: quelle surprise? @Gene Cash

Santa from Exeter

I would suggest you change your doctors then.

Most of the ones I know are at least au fait with the technology they use day to day and many actually love it as it maked their job easier.

There again, maybe I just know *competent* doctors

Re: quelle surprise? @Gene Cash

Kefik

"Most of the ones I know are at least au fait with the technology"

You're bloody right. Some are even checking their mail while you are on the operating table.

Re: quelle surprise? @Gene Cash

N2

I would suggest you change your doctors then.

No thanks, perhaps we are alone in that we know competent doctors and whilst mine speaks with a funny accent, I get to manage my own records.

Re: quelle surprise?

Anonymous Coward

My experience is they love tech but hate security as it's inconvenient.

Re: quelle surprise?

Anonymous Coward

My daughter, a Hospital Doctor, says that most Consultants have to take a Doctor on the ward rounds to access the data and to type in the treatment updates. They were much happier when they could scribble illegibly on paper at the foot of the bed, although many wouldn't even lower themselves to that!

Who is at fault?

hoola

This is not the fault of the medical professionals but the IT teams that support them coupled with the incompetent layers of management that inhabit every NHS trust. The underlying problem is that in the rush to provide diagnostic material online or across different Health Authorities basic security principals appear to have been abandoned. Doctors often have all sorts of convoluted steps to be able to login to systems to provide secure access but it is becoming increasingly common for the source to be as secure as a sieve.

You can put as much MFA, VPN and whatever you like between the consumer of the material and the system in the hospital but it the raw data is directly accessible it is a smokescreen.

Re: Who is at fault?

Kefik

Naturally it is only at the front-end where security is beefed up. Your back-end penetrability is their business model.

Re: Who is at fault?

Anonymous Coward

My Hospital Doctor daughter counted it one day. 49 times she had to log into one system or another, and that's 7 different logins - no wonder they use the same password across all the systems!

Until 2 months into Covid they were still having to carry personal phones around all day for the 2FA - scrubs do not have pockets!

Things actually changed when the IT Manager caught Covid - yes, they dispensed with the 2FA on personal phones!

Anonymous for hopefully obvious reasons

Some ol' fashioned Naming and Shaming would be nice..

Blazde

..otherwise what does Joe Public do with this info? (Aside from applying for a job at CybelAngel of course)

X-rays and other medical scans were left online

Winkypop

Why did it take so long to see though the problem?

--> Not a lab coat

each Application Entity must insure that their own local environment is secure

Neil Barnes

And that's the problem right there. They insured it, when they should have ensured it...

The one with the sheaf of policy documents in the pocket --->

Security model is upside down so they can't implement SSO

MadAsHell

There are some interesting and valid comments here. Yes, the number of logins required to pull together all of the imaging for a given patient can be a real PITA, hence why busy docs in overloaded clinics hate the login process. Answer, you say, a SSO.

But since the idiots in DoH/DHSC (and HMRC) went 'digital' they've turned the security model upside down. Back in the day, your medical notes and silver-based imaging were physical, tangible entities. Difficult to find (because no-one in the DoH had heard of barcodes in the 1990s, except us) but impossible to snoop. No idle trawling through some remote DB, thinking 'I wonder if Matt Hancock's syphilis test result is back yet?' Same with tax records: it was policy that your tax office was the other end of the country to where you worked and lived. No social engineering there either.

Skip forward and *all* tax records are on a single system and every HMRC call centre operative can pull up John Smith's tax records. Except that HMRC realised this might be an issue: there's an entirely separate tax record system for MPs/celebs and VIPs! No browsing through the declared tax from the nomenclatura/friends of Gov with their snouts in the PPE trough.

But in Health Care, ALL records are on line, belonging to each Trust. So imagine the impact of a single-sign-on solution across the NHS. Any GP's receptionist could idly trawl through anyone's health care records. Given how many warranted coppers and civilian workers are disciplined or fired each year for inappropriate access to the PNC (hint: El Reg article 11th Nov 2019 - about 1 every 3 days), imagine the leaks from all of those juicy WAGS and COVIDiot browsing sessions.

Shudder!

<Knghtbrd> Even with overbrights, Quake's color palette is full of dull,
flat colors
<LordHavoc> knghtbrd: quake's palette is very vibrant unless you use gamma
correction
<LordHavoc> well actually I agree, it's nowhere near as vibrant as Unreal
<Deek> Q3 on the other hand...NEON.
<LordHavoc> Q3 is just ridiculous
<Deek> Q3 takes the medieval church-dungeon and puts it in Vegas.