1 min read

Confidant Health's unsecured database unveiled by security researcher

Confidant Health logo

On September 6, 2024, Confidant Health’s unsecured database was discovered by a security researcher exposing highly sensitive information that includes therapy recordings and transcripts. 

 

What happened 

Jeremiah Fowler, an ethical security researcher, discovered a data exposure linked to Confidant Health, a virtual medical provider operating in states like Connecticut and Florida. Fowler found an unsecured database containing 5.3 terabytes of sensitive patient data including audio and video therapy sessions, transcripts, medical histories, and personally identifiable information (PII). The database housed over 120,000 files and 1.7 million activity logs. Fowler alerted Confidant Health to exposure and the company has restricted access to the database. 

 

What was said 

According to Fowler in VPNMentor, “I saw documents indicating psychotherapy intake notes and psychosocial assessments that provided details about mental health or substance abuse, touching upon the patients’ family issues, psychiatric history, trauma history, medical conditions, and additional diagnoses. I also saw references to audio and video recordings of the sessions and text transcripts…”

 

Why it matters 

Fowler discusses the particular sensitivity of the data exposed and how it can be used by threat actors. One section is dedicated to discussing the potential value of health data on the internet (starting at $1,000). There is also the matter of how the exposure of patient data leaves patients open to financial repercussions. Threat actors can often ransom the same information to patients. This is especially the case if it contains diagnosis and mental health information like the information accessible in the Confidant health case. 

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a terabyte? 

A digital storage that is equivalent to 1,000 gigabytes.

 

What is a threat actor? 

A person or entity responsible for carrying out a malicious activity. 

 

What is an unsecured database?

A data storage system that lacks sufficient security measures to prevent unauthorized access. 

Digital figure made of binary code surrounded by glowing circuit pathways and network connections

HHS identifies healthcare’s most urgent cyber threats

During the recent Safeguarding Health Information: Building Assurance through HIPAA Security conference, the HHS urged healthcare organizations to...

Read More
healthequity logo

Another top US healthcare service provider hacked

The healthcare sector's third-party security remains vulnerable, as evidenced by HealthEquity's recent disclosure of a supply chain cyberattack that...

Read More
law gavel on cash

Columbia University Health agrees to $600,000 data breach settlement

Columbia University Health Care (CUHC) has agreed to a $600,000 settlement over a class action suit following a massive data breach.

Read More