Unsecured database exposes 1 billion CVS Health records: 5 things to know

A public database exposed more than 1 billion CVS Health records, according to a June 16 report by ABC News.

Advertisement

Four details:

  1. The unsecured data was discovered by cybersecurity researcher Jeremiah Fowler in late March. He swiftly alerted the company of the breach.
  2. CVS said the database was hosted by a third-party vendor. CVS will continue to utilize the vendor and is working toward preventing a recurrence, according to a news statement obtained by ABC News.
  3. Breach records did not include patient data, but Mr. Fowler said some of the information revealed in the searches could have been linked to someone’s identity.
  4. “Some search entries included email addresses and should be a wake-up call for companies to ensure their data security is solid,” he said. “There were certain times where individuals put their own email addresses into the search bar and then that correlated with a visitor ID and user ID, and then usually it showed what they searched for. So, hypothetically, you could have connected those three and figured it out.”

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.