Menu
Browse

Cyber Incident Victim: Health Solutions

Date:

Dec 2016

Location:

India

Summary

A major Indian diagnostic laboratory experienced a cybersecurity breach where hackers accessed approximately 35,000 medical records, including sensitive HIV reports, patient names, ages, genders, blood test results, and lipid profiles. The compromised data primarily involved Mumbai patients, though contact details and photographs remained secure. Following detection, administrators removed the entire online database to mitigate risks, though the extent of stolen files remains unclear. This incident marked one of three breaches within a single week against the same website, prompting the organization to halt file uploads and transition to a new system. An investigation identified an Indian hacker using a Chinese server, with legal action under consideration. The company acknowledged prior recurring breaches but had not yet notified affected patients at the time of reporting.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 2, 2016, hackers breached the website of Health Solutions (hsppl.com), a major Indian diagnostic laboratory, accessing a database containing approximately 35,000 medical records. The compromised data included sensitive patient information such as names, ages, genders, blood test reports, lipid profiles, and HIV test results, primarily affecting individuals from Mumbai. While photographs and contact details remained secure, the attackers exfiltrated medical files from a repository of 40,000 total documents. Website administrators detected the intrusion and responded by erasing the entire database from their web platform to prevent further exposure. Company representatives characterized the stolen records as one year old at the time of theft. Patients remained unaware of the breach initially, with no immediate confirmation from Health Solutions regarding notification plans.

Cyber Incident Image

This incident marked at least the third security compromise affecting Health Solutions within a single week, following prior unreported breaches that prompted administrators to halt new file uploads to the vulnerable website. Company officials acknowledged their inability to prevent the recurring intrusions despite awareness of systemic vulnerabilities, stating they were transitioning to a new IT infrastructure. Health Solutions initiated an internal investigation focused on identifying the perpetrator, whom they described as an Indian national operating through Chinese servers. The organization announced intentions to pursue legal action against the attacker while continuing to assess the full scope of data exfiltration. No evidence suggested public release of stolen records at the time of reporting, though the repeated breaches exposed systemic security deficiencies in patient data management.

Sources
Sources available to members
1 source