- Security researcher finds huge non-passord protected database online
- It contained personally identifiable information as well as medical data
- The database was since locked down
Eshyft, a technology platform designed for nurses all over the United States, allegedly held an unprotected database online that exposed thousands of sensitive items to anyone who knew where to see.
Security researcher Jeremiah Fowler found the database containing 86,341 items and exceeding 100 GB in size. The archive contained all kinds of sensitive data, from names and IDs, to medical reports and more.
Eshyft is a technology platform that connects nurses (CNAs, LPNs and RNS) with DIEM shifts on long-term care facilities throughout the United States and offers flexible work opportunities for healthcare professionals and a reliable staff resolution for facilities.
Addressing the problem
It is not known for how long the database remained unprotected or if any threat actors who became access to it before Fowler did. We also do not know if the Eshyft maintains the database itself or whether it outsourced it to a third party.
“In a limited sampling of the vulnerable documents, I saw items that included profile or face images of users, .CSV files with monthly work plan files, professional certificates, work assignments, CVs and resumes that contained additional PII,” Fowler explained, noticing that he reported it to both Site planeAnd later – Eshyft.
“A single spreadsheet document contained 800,000+ items that detailed the nurse’s internal IDs, facility name, time and date of shifts, working hours and more.”
“I also saw what seemed to be medical documents uploaded to the app. These files were potentially uploaded as evidence of why individual nurses missed shifts or took sick leave. These medical documents included medical reports containing information about diagnosis, prescription or treatments that could potentially fall under HIPA’s rules. “
After Fowler reported his findings to Eshyft, the company locked the database a month later and told him it was, “looked at this actively and worked on a solution”.