home.social

#medisecure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #medisecure, aggregated by home.social.

fetched live
  1. #MediSecure, an electronic medical prescription provider, was hacked earlier this year. The result is 12.9 million profiles of #Australian users currently for sale in the dark web.

    As usual, given the anaemic data protection and privacy laws in #Australia, MediSecure has not even bothered so far to notify any of the people affected. They know they will not be held accountable and there will be no consequences to their irresponsibility.

  2. #MediSecure, an electronic medical prescription provider, was hacked earlier this year. The result is 12.9 million profiles of #Australian users currently for sale in the dark web.

    As usual, given the anaemic data protection and privacy laws in #Australia, MediSecure has not even bothered so far to notify any of the people affected. They know they will not be held accountable and there will be no consequences to their irresponsibility.

  3. The #MediSecure breach is particularly troubling because it makes plain that the government either cannot, or does not want to, help us in this sort of situation.

    Which raises questions about what the point of them is.

  4. The #MediSecure breach is particularly troubling because it makes plain that the government either cannot, or does not want to, help us in this sort of situation.

    Which raises questions about what the point of them is.

  5. As several other fellow tech nerds have commented: given that dataset and the likely database structures, we could figure out who most of the people are, because we have done similar stuff before and it's fiddly but not super hard.

    Indeed! Ponder, then, on the purpose of making it seem very difficult and mysterious and why the people doing that might want to give that impression.

    #MediSecure

  6. As several other fellow tech nerds have commented: given that dataset and the likely database structures, we could figure out who most of the people are, because we have done similar stuff before and it's fiddly but not super hard.

    Indeed! Ponder, then, on the purpose of making it seem very difficult and mysterious and why the people doing that might want to give that impression.

    #MediSecure

  7. One might also wonder wtf is the point of having the AFP, ASD, National Cyber Security Coordinator, and National Office of Cyber Security involved since their combined efforts have apparently managed to: restore the database server from backups. #MediSecure

  8. One might also wonder wtf is the point of having the AFP, ASD, National Cyber Security Coordinator, and National Office of Cyber Security involved since their combined efforts have apparently managed to: restore the database server from backups. #MediSecure

  9. Also, looking at that list of data types, it does rather contradict MediSecure's public statements about how it "only collects non-personal information about your prescription", eh?

    web.archive.org/web/2023102813

    Looks like they lied about what they were doing pretty comprehensively.

    #MediSecure

  10. Also, looking at that list of data types, it does rather contradict MediSecure's public statements about how it "only collects non-personal information about your prescription", eh?

    web.archive.org/web/2023102813

    Looks like they lied about what they were doing pretty comprehensively.

    #MediSecure

  11. The weasel words is saying "we could identify a lot of the people affected, but it'd be expensive and we don't think we could identify *everyone*, so we won't try."

    #MediSecure

  12. The weasel words is saying "we could identify a lot of the people affected, but it'd be expensive and we don't think we could identify *everyone*, so we won't try."

    #MediSecure

  13. Why is it weasel words? Because look at the kind of data that was taken:

    "
    full name;
    title;
    date of birth;
    gender;
    email address;
    address;
    phone number;
    individual healthcare identifier (IHI);
    Medicare card number, including individual identifier, and expiry;
    Pensioner Concession card number and expiry;
    Commonwealth Seniors card number and expiry;
    Healthcare Concession card number and expiry;
    Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
    prescription medication, including name of drug, strength, quantity and repeats; and
    reason for prescription and instructions.
    " #MediSecure

  14. Why is it weasel words? Because look at the kind of data that was taken:

    "
    full name;
    title;
    date of birth;
    gender;
    email address;
    address;
    phone number;
    individual healthcare identifier (IHI);
    Medicare card number, including individual identifier, and expiry;
    Pensioner Concession card number and expiry;
    Commonwealth Seniors card number and expiry;
    Healthcare Concession card number and expiry;
    Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
    prescription medication, including name of drug, strength, quantity and repeats; and
    reason for prescription and instructions.
    " #MediSecure

  15. Update on the #MediSecure breach.

    ⏳ It took 34 days to start investigating the data accessed
    📊 12.9 million Australians likely affected
    💽 6.5TB of data likely stolen
    📄 Personal and health information, plus prescription details were likely stolen
    💰 #MediSecure are out of money to investigate any further

    medisecurenotification.wordpre

  16. #Cyberattack target #MediSecure enters voluntary administration. Prescription delivery service provider , which fell victim to a large-scale #cyberbreach that compromised the personal health information of thousands of Australians in April, has entered voluntary administration and is expected to face its creditors later this month. #itsecuriry #hacking #CyberSecuriy

    smh.com.au/business/companies/

  17. So #medisecure just gets to declare insolvency and walk away? And now the government will probably give them money. Wasn't the whole issue that they had lost their contract anyway, and were transferring the data to the new provider? Is this just a quick way out of their own mess?

  18. Well that's just a terrible outcome for all concerned. If ever you wanted to know how costly a data breach can be, it doesn't get much worse than this.

    #databreach #cybersecurity #medisecure

    cyberdaily.au/security/10665-b

  19. Well that's just a terrible outcome for all concerned. If ever you wanted to know how costly a data breach can be, it doesn't get much worse than this.

    #databreach #cybersecurity #medisecure

    cyberdaily.au/security/10665-b

  20. MediSecure is dragging its feet over reporting the details of its massive May data breach, according to the Minister for Cyber Security Clare O'Neil.

    #databreach #cybersecurity #MediSecure

    cyberdaily.au/government/10645

  21. MediSecure is dragging its feet over reporting the details of its massive May data breach, according to the Minister for Cyber Security Clare O'Neil.

    #databreach #cybersecurity #MediSecure

    cyberdaily.au/government/10645

  22. I like to fall back on "the elites are lying to the public because they're afraid the public will notice how incompetent they really are" in the absence of direct evidence. Mostly because that's what history shows was usually going on with the elites. #MediSecure

  23. I like to fall back on "the elites are lying to the public because they're afraid the public will notice how incompetent they really are" in the absence of direct evidence. Mostly because that's what history shows was usually going on with the elites. #MediSecure

  24. Now that it looks like the Australian #MediSecure data is for sale online, here's a good timeline of events so far so you can stay up to date.

    Has similar vibes to the Optus 2022 data breach.

    If the data is legitimate, and initial indications suggest it likely is, that's a lot of health data......6.5TB! 😱

    cyberknow.substack.com/p/medis

  25. Here is me talking about the #MediSecure data breach on Weekend Sunrise from the weekend.

  26. Here is me talking about the #MediSecure data breach on Weekend Sunrise from the weekend.

  27. I am confirmed to be going on the TV about this #MediSecure data breach on Weekend Sunrise tomorrow at about 8:20am.

  28. I am confirmed to be going on the TV about this #MediSecure data breach on Weekend Sunrise tomorrow at about 8:20am.

  29. The ironically named Australian health information company MediSecure has had a data breach.

    medisecure.com.au/

    #MediSecure