{"id":2731,"date":"2024-03-15T15:37:49","date_gmt":"2024-03-15T20:37:49","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/nhs-breach-hse-bug-expose-healthcare-data-british-isles"},"modified":"2024-03-15T15:37:49","modified_gmt":"2024-03-15T20:37:49","slug":"nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/15\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles\/","title":{"rendered":"NHS Breach, HSE Bug Expose Healthcare Data in the British Isles"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltb0344a2d58b6ce4f\/654e39a8aea73b040a977e79\/doctor_tablet_Panther_Media_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This week, a division of the National Health Service (NHS) Scotland was struck by a cyberattack, potentially disrupting services and exposing patient and employee data. Meanwhile, a researcher disclosed a Salesforce configuration error that exposed millions of Irish citizens&#8217; COVID vaccination data from that country&#8217;s Health Service Executive (HSE).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The two incidents, separated by a quick hop over the Irish Sea, speak to the ongoing <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/hospitals-must-treat-patient-data-health-equal-care\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">challenges healthcare organizations face<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in protecting patients&#8217; most sensitive personal identifiable information (PII) and personal health information (PHI).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Salesforce Bug in Ireland's COVID Vaccination Portal\">Salesforce Bug in Ireland&#8217;s COVID Vaccination Portal<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During the onset of COVID&#8217;s Omicron variant in December 2021, Aaron Costello, principal SaaS security engineer at AppOmni, discovered a severe misconfiguration in the Salesforce-based online vaccination portal for Ireland&#8217;s HSE.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/appomni.com\/blog_post\/saas-risks-in-healthcare-data-exposure-in-hse\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">a blog post published on March 14<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, he explained how an oversight allowed regular, low-level accounts belonging to HSE patients unprecedented access to the part of the system responsible for storing information about vaccine administration.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The exposed object in question included full names of patients and all information relating to their jabs: the brand of vaccine, date, location, and site at which it was administered, and any reasons they accepted or refused it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Documents belonging to staff members, and information related to internal IT issues and processes, were also exposed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;For Salesforce administrators and security practitioners on SaaS platforms, there was a lack of understanding of the implications of misconfigured permissions,&#8221; Costello tells Dark Reading. &#8220;They weren&#8217;t acutely aware that these things are possible \u2014 that a low-privileged user could be pulling this data.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the time since, Salesforce has gradually implemented a number of positive changes for preventing this kind of error and mitigating the consequences that might occur from it. A built-in health scanner attempts to uncover such vulnerabilities in customers&#8217; environments, and more robust logging allows administrators to better analyze the activity of users, especially when they&#8217;re interacting with potentially sensitive APIs. Also, new policies and configurations attempt to conceal sensitive information, even in cases where they&#8217;re exposed by misconfigurations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;So not only have they improved the post-breach process of log analysis, they&#8217;ve also introduced ways in which administrators can easily detect these issues with the health scanner, and also reduce the extent of exposures by reducing the scope of the data that becomes available in certain scenarios,&#8221; Costello says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, he warns, &#8220;There are a lot of organizations still misconfiguring these kinds of access controls to this very day. I still think there is a knowledge gap in the industry, and part of the issue is: Who&#8217;s responsible for the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cloud-security\/salesforce-devops-needs-guardrails\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">security of SaaS platforms<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">? Is it the platform administrators? Do you pull in your security team when these things are being deployed to do an audit?&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Scotland's NHS Breach\">Scotland&#8217;s NHS Breach<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Also this week, NHS Dumfries and Galloway <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.nhsdg.co.uk\/cyberattack\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">published an alert<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> revealing that it is experiencing a &#8220;focused and ongoing&#8221; cyberattack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dumfries and Galloway is the southernmost council area of Scotland, with a population of approximately 150,000.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As a result of the breach, it warned, some services may experience disruption, and the attackers may have obtained &#8220;a significant quantity of data&#8221; belonging to patients and staff. More specific details about the cause, nature, and consequences of the breach are yet to be publicized.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Whether it&#8217;s a breach in Scotland or an overlooked system misconfiguration in Ireland, Costello says, &#8220;I think it all <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/why-healthcare-boards-lag-other-industries-in-preparing-for-cyberattacks\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">comes back to budget and funding<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. And the result of that is, firstly, understaffing for cybersecurity positions within these organizations. That is a massive, massive problem.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We cannot point the finger solely at the employees of these organizations when they&#8217;re working under a very restricted budget and a very restricted headcount. They&#8217;re doing their best with the resources they have available to them.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/nhs-breach-hse-bug-expose-healthcare-data-british-isles\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week, a division of the National Health Service (NHS)<\/p>\n","protected":false},"author":12,"featured_media":2732,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2731","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=2560%2C1514&ssl=1",2560,1514,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=300%2C177&ssl=1",300,177,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=640%2C378&ssl=1",640,378,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=640%2C378&ssl=1",640,378,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=1536%2C908&ssl=1",1536,908,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=2048%2C1211&ssl=1",2048,1211,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=1024%2C605&ssl=1",1024,605,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nhs-breach-hse-bug-expose-healthcare-data-in-the-british-isles-scaled.jpg?fit=2560%2C1514&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2731"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2731\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2732"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}