#medisecure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #medisecure, aggregated by home.social.
-
#MediSecure, an electronic medical prescription provider, was hacked earlier this year. The result is 12.9 million profiles of #Australian users currently for sale in the dark web.
As usual, given the anaemic data protection and privacy laws in #Australia, MediSecure has not even bothered so far to notify any of the people affected. They know they will not be held accountable and there will be no consequences to their irresponsibility.
-
#MediSecure, an electronic medical prescription provider, was hacked earlier this year. The result is 12.9 million profiles of #Australian users currently for sale in the dark web.
As usual, given the anaemic data protection and privacy laws in #Australia, MediSecure has not even bothered so far to notify any of the people affected. They know they will not be held accountable and there will be no consequences to their irresponsibility.
-
The #MediSecure breach is particularly troubling because it makes plain that the government either cannot, or does not want to, help us in this sort of situation.
Which raises questions about what the point of them is.
-
The #MediSecure breach is particularly troubling because it makes plain that the government either cannot, or does not want to, help us in this sort of situation.
Which raises questions about what the point of them is.
-
As several other fellow tech nerds have commented: given that dataset and the likely database structures, we could figure out who most of the people are, because we have done similar stuff before and it's fiddly but not super hard.
Indeed! Ponder, then, on the purpose of making it seem very difficult and mysterious and why the people doing that might want to give that impression.
-
As several other fellow tech nerds have commented: given that dataset and the likely database structures, we could figure out who most of the people are, because we have done similar stuff before and it's fiddly but not super hard.
Indeed! Ponder, then, on the purpose of making it seem very difficult and mysterious and why the people doing that might want to give that impression.
-
One might also wonder wtf is the point of having the AFP, ASD, National Cyber Security Coordinator, and National Office of Cyber Security involved since their combined efforts have apparently managed to: restore the database server from backups. #MediSecure
-
One might also wonder wtf is the point of having the AFP, ASD, National Cyber Security Coordinator, and National Office of Cyber Security involved since their combined efforts have apparently managed to: restore the database server from backups. #MediSecure
-
Also, looking at that list of data types, it does rather contradict MediSecure's public statements about how it "only collects non-personal information about your prescription", eh?
https://web.archive.org/web/20231028131540/https://www.medisecure.com.au/privacy-policy/
Looks like they lied about what they were doing pretty comprehensively.
-
Also, looking at that list of data types, it does rather contradict MediSecure's public statements about how it "only collects non-personal information about your prescription", eh?
https://web.archive.org/web/20231028131540/https://www.medisecure.com.au/privacy-policy/
Looks like they lied about what they were doing pretty comprehensively.
-
The weasel words is saying "we could identify a lot of the people affected, but it'd be expensive and we don't think we could identify *everyone*, so we won't try."
-
The weasel words is saying "we could identify a lot of the people affected, but it'd be expensive and we don't think we could identify *everyone*, so we won't try."
-
Why is it weasel words? Because look at the kind of data that was taken:
"
full name;
title;
date of birth;
gender;
email address;
address;
phone number;
individual healthcare identifier (IHI);
Medicare card number, including individual identifier, and expiry;
Pensioner Concession card number and expiry;
Commonwealth Seniors card number and expiry;
Healthcare Concession card number and expiry;
Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
prescription medication, including name of drug, strength, quantity and repeats; and
reason for prescription and instructions.
" #MediSecure -
Why is it weasel words? Because look at the kind of data that was taken:
"
full name;
title;
date of birth;
gender;
email address;
address;
phone number;
individual healthcare identifier (IHI);
Medicare card number, including individual identifier, and expiry;
Pensioner Concession card number and expiry;
Commonwealth Seniors card number and expiry;
Healthcare Concession card number and expiry;
Department of Veterans’ Affairs (DVA) (Gold, White, Orange) card number and expiry;
prescription medication, including name of drug, strength, quantity and repeats; and
reason for prescription and instructions.
" #MediSecure -
Update on the #MediSecure breach.
⏳ It took 34 days to start investigating the data accessed
📊 12.9 million Australians likely affected
💽 6.5TB of data likely stolen
📄 Personal and health information, plus prescription details were likely stolen
💰 #MediSecure are out of money to investigate any further -
12.9 Million Australians Impacted in MediSecure Data Breach https://thecyberexpress.com/12-9-million-australians-impacted-in-medisecure-data-breach/ #largesthealthcaredatabreach #MediSecuredatabreach #TheCyberExpressNews #CybersecurityNews #CyberEssentials #TheCyberExpress #DataBreachNews #FirewallDaily #databreach #MediSecure #Australia #OAIC #ASD
-
12.9 Million Australians Impacted in MediSecure Data Breach https://thecyberexpress.com/12-9-million-australians-impacted-in-medisecure-data-breach/ #largesthealthcaredatabreach #MediSecuredatabreach #TheCyberExpressNews #CybersecurityNews #CyberEssentials #TheCyberExpress #DataBreachNews #FirewallDaily #databreach #MediSecure #Australia #OAIC #ASD
-
Australian eScript company #MediSecure in administration just weeks after confirming large cyber attack #ransomware
https://www.abc.net.au/news/2024-06-05/hacked-health-company-goes-into-administration-/103938942
-
Australian eScript company #MediSecure in administration just weeks after confirming large cyber attack #ransomware
https://www.abc.net.au/news/2024-06-05/hacked-health-company-goes-into-administration-/103938942
-
#Cyberattack target #MediSecure enters voluntary administration. Prescription delivery service provider , which fell victim to a large-scale #cyberbreach that compromised the personal health information of thousands of Australians in April, has entered voluntary administration and is expected to face its creditors later this month. #itsecuriry #hacking #CyberSecuriy
-
So #medisecure just gets to declare insolvency and walk away? And now the government will probably give them money. Wasn't the whole issue that they had lost their contract anyway, and were transferring the data to the new provider? Is this just a quick way out of their own mess?
-
Well that's just a terrible outcome for all concerned. If ever you wanted to know how costly a data breach can be, it doesn't get much worse than this.
-
Well that's just a terrible outcome for all concerned. If ever you wanted to know how costly a data breach can be, it doesn't get much worse than this.
-
MediSecure is dragging its feet over reporting the details of its massive May data breach, according to the Minister for Cyber Security Clare O'Neil.
-
MediSecure is dragging its feet over reporting the details of its massive May data breach, according to the Minister for Cyber Security Clare O'Neil.
-
I like to fall back on "the elites are lying to the public because they're afraid the public will notice how incompetent they really are" in the absence of direct evidence. Mostly because that's what history shows was usually going on with the elites. #MediSecure
-
I like to fall back on "the elites are lying to the public because they're afraid the public will notice how incompetent they really are" in the absence of direct evidence. Mostly because that's what history shows was usually going on with the elites. #MediSecure
-
Now that it looks like the Australian #MediSecure data is for sale online, here's a good timeline of events so far so you can stay up to date.
Has similar vibes to the Optus 2022 data breach.
If the data is legitimate, and initial indications suggest it likely is, that's a lot of health data......6.5TB! 😱
https://cyberknow.substack.com/p/medisecure-data-posted-to-forum
-
Welp, looks like the #MediSecure database was completely copied. https://www.smh.com.au/technology/medisecure-patient-data-up-for-sale-on-russian-hacking-forum-20240524-p5jggb.html
-
Welp, looks like the #MediSecure database was completely copied. https://www.smh.com.au/technology/medisecure-patient-data-up-for-sale-on-russian-hacking-forum-20240524-p5jggb.html
-
Here is me talking about the #MediSecure data breach on Weekend Sunrise from the weekend.
-
Here is me talking about the #MediSecure data breach on Weekend Sunrise from the weekend.
-
Major prescription vendor down over ransomware⤵️
#MediSecure #Australia #ransomware #privacy #cybersecurity #infosec -
Major prescription vendor down over ransomware⤵️
#MediSecure #Australia #ransomware #privacy #cybersecurity #infosec -
I am confirmed to be going on the TV about this #MediSecure data breach on Weekend Sunrise tomorrow at about 8:20am.
-
I am confirmed to be going on the TV about this #MediSecure data breach on Weekend Sunrise tomorrow at about 8:20am.
-
I remained a cantankerous luddite whenever a doctor tried to palm off an #EScript to me, and today I'm vindicated. #MediSecure.
-
The ironically named Australian health information company MediSecure has had a data breach.