News: 1620326227

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK vaccine booking website had unexpected side effect: It leaked people's jab status

(2021/05/06)


An NHS Digital-run vaccine-booking website exposed just how many vaccines individual people had received – and did so with no authentication, according to the Guardian .

The booking page, aimed at English NHS patients wanting to book first and second coronavirus jabs, would tell anyone at all whether a named person had had zero, one or two vaccination doses, the newspaper [1]reported on Thursday.

All you need, it says, are the date of birth and postcode of the person whose vaccination status you wanted to check up on. These details are not difficult to find online with some obvious search terms.

[2]

[3]

[4]

Exposure of confidential medical information could be achieved thanks to a design decision, similar to a flaw in the UK census online form reset request that [5]could have let anyone spoof households’ details.

[6]East London council blurts thousands of residents' email addresses in To field blunder

[7]Brit MPs and campaigners come together to oppose COVID status certificates as 'divisive and discriminatory'

[8]UK government opens vaccine floodgates to over-45s, NHS website predictably falls over

[9]NHS COVID-19 app update blocked by Apple, Google over location privacy fears

Those with no COVID-19 vaccination have to sign up and hand over some personally identifying data as they do so; recipients of the first and second doses already have that info on file.

“For users who have not had any jabs, entering personal details takes them straight through to a standard screening page, while for users who have had their first shot and booked their second, they are presented with a screen asking for their booking reference to continue,” said the Grauniad. If you input the personal details of someone who had already had both jabs, that dumped you to a screen saying “you have had both of your appointments”.

An underhand employer, anti-vaxxer nutjob or similarly malicious person could therefore run vaccine checks on the status of random people with no authentication.

Various civil liberties folk queued up (rightly) to condemn this laxity, with Big Brother Watch’s Silkie Carlo leading the charge, describing it as “seriously shocking” and calling for “robust protections to be put in place immediately”.

[10]

“This online system has left the population’s Covid vaccine statuses exposed to absolutely anyone to pry into," she said. "Date of birth and postcode are fields of data that can be easily found or bought, even on the electoral roll."

NHS Digital said in a statement: “The system does not have any direct access to anyone’s medical record and people should not be fraudulently using the service – it should only be used by people booking their own vaccines or for someone who has knowingly provided their details for this purpose.”

Vaccination status is set to become a political hot potato as the UK restarts its economy following the 2020 COVID-19 shutdown. Government policy is to enforce vaccine passports, initially as a [11]means of deterring overseas travel but rumours persist that they will be required for domestic activities. To that end, the ruling Conservatives’ insincere promise in December that vaccine passports wouldn’t become reality at all has [12]prompted a 350,000 strong Parliamentary petition against them.

[13]

Carelessness around health data in general has [14]been a feature of the current government’s tech-driven approach to tackling COVID-19. Such repeated incidents have a habit of lodging themselves in the public’s consciousness, making it harder to gain consent for genuine health-boosting measures based on handing data over to public sector bodies. ®

Get our [15]Tech Resources



[1] https://www.theguardian.com/world/2021/may/06/nhs-covid-jab-booking-site-leaks-peoples-vaccine-status

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJRm9pxUuXT4NHYQHBhHQwAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJRm9pxUuXT4NHYQHBhHQwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJRm9pxUuXT4NHYQHBhHQwAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/04/12/ons_census_data_security/

[6] http://www.theregister.com/2021/05/05/tower_hamlets_email_fail/

[7] http://www.theregister.com/2021/04/28/covid_status_certificates_uk/

[8] http://www.theregister.com/2021/04/13/covid_vaccine_site/

[9] http://www.theregister.com/2021/04/13/uk_covid_app/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJRm9pxUuXT4NHYQHBhHQwAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.thetimes.co.uk/article/covid-vaccine-passport-not-ready-nhs-app-travel-mmvwbkg23

[12] https://petition.parliament.uk/petitions/569957

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJRm9pxUuXT4NHYQHBhHQwAAAME&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2020/05/04/uk_covid_app_human_rights_parliament/

[15] https://whitepapers.theregister.com/

"run vaccine checks on the status of random people with no authentication"

Pascal Monett

Well thank goodness you're out of the EU now - that would have been a prime violation of GDPR.

But you've taken back control, so there's no problem, right ?

Re: "run vaccine checks on the status of random people with no authentication"

Foxglove

'Well thank goodness you're out of the EU now - that would have been a prime violation of GDPR.'

From:

https://ico.org.uk/for-organisations/dp-at-the-end-of-the-transition-period/data-protection-now-the-transition-period-has-ended/the-gdpr/

'The GDPR is retained in domestic law now the transition period has ended'.

It might change but for now it is still the same.

And of course now we've left we have £350 million a week extra in our economy (do we fuck) and it will all be spent on the NHS as promised on the bus (even if we had it it wouldn't have been).

And yes, technically we've taken back control. What power we have to do with that control is up for debate.

Early days but I'd say we have much less influence than our 'Leave' politicians promised.

I voted to remain as I saw almost no benefit in leaving.

I've seen nothing to change my mind on that.

Stay well Pascall.

Re: "run vaccine checks on the status of random people with no authentication"

Anonymous Coward

"I voted to remain as I saw almost no benefit in leaving.

I've seen nothing to change my mind on that."

But what about all that fish? We've won the Battle of St Helier!!! Cry ‘God for Harry, England, and Saint George!’

"people should not be using it fraudulently"

spireite

.... that alright then.....

Can I check if 'er indoors has been to my local 'clinic' *wink* on another site?

people should not be fraudulently using the service

Howard Sway

This is an original attitude towards information security : saying "now don't you come in here and look at all this personal data and misuse it, or I'll be somewhat miffed!".

Re: people should not be fraudulently using the service

Martin Gregorie

Unfortunately, waving their hands in the air while feebly whining that "people should not be fraudulently using the service" seems to be typical of almost everybody who has been put in charge of NHS medical data for the last two decades. Just how big a clue stick do we need to clobber them with before they realise that a British citizen's medical data is PRIVATE and not theirs to do what they like with.

The people charged with protecting medical data are subject to GDPR penalties if they sell it, give it to PeterTheil because he's a mate or to the spawn of Google because that seems like a good idea after a few pints, so why have none of these people been charged under GDPR, which has now been incorporated into UK law, and sacked?

Bastards, all of them.

Re: people should not be fraudulently using the service

Andy Non

Or even positively peeved.

Ducharme's Precept:
Opportunity always knocks at the least opportune moment.

Ducharme's Axiom:
If you view your problem closely enough you will recognize
yourself as part of the problem.