AI “digital helper” Lena Health breach exposed some Houston Methodist patients’ medical info (1)
ID: be01d306-766a-5b75-b622-ca5b7fa8cb38
STIX ID: report--be01d306-766a-5b75-b622-ca5b7fa8cb38
Feed Name: DataBreaches.Net
A report details two healthcare data breaches tied to AI-enabled vendors: Serviceaide’s 2024 incident impacting 483,000 Catholic Health patients, and a Lena Health breach in which FulcrumSec claims to have exploited an early-December public vulnerability to access an unencrypted database export in a public S3 bucket, exposing patients’ PHI, thousands of recorded calls/transcripts, discharge documents, and API keys/credentials. FulcrumSec posted proofs on a hacking forum, alleged nonpayment after contact attempts, and released redacted samples; Lena Health acknowledged a contained security incident and engagement of third-party investigators while notifying affected parties.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
