Skip to content Skip to footer
0 items - $0.00 0

‘Uber for nurses’ exposes 86K+ medical records, PII via open S3 bucket by Twirrim

‘Uber for nurses’ exposes 86K+ medical records, PII via open S3 bucket by Twirrim

‘Uber for nurses’ exposes 86K+ medical records, PII via open S3 bucket by Twirrim

24 Comments

  • Post Author
    gnabgib
    Posted March 13, 2025 at 12:16 am

    Title: Thousands of Records, Including PII, Exposed Online in Healthcare Marketplace Connecting Facilities and Nurses Data Leak

    (vs current: "'Uber for nurses' exposes 86K+ medical records, PII via open S3 bucket")

  • Post Author
    booi
    Posted March 13, 2025 at 1:04 am

    Uber for ___ has lost all meaning

  • Post Author
    dartos
    Posted March 13, 2025 at 1:08 am

    Well there be any consequences for the company?

  • Post Author
    ethagnawl
    Posted March 13, 2025 at 1:12 am

    I'll need to dig up a source but I recently heard about this company and, apparently, before offering gigs they do a credit report to determine how much debt the person is carrying (i.e. how desperate they are) and they use that information to _round down_ the hourly rate they offer them.

    In the unlikely event that there are any negative consequences for this breach, they deserve every bit of them and more.

  • Post Author
    marcus0x62
    Posted March 13, 2025 at 1:16 am

    Move fast and violate HIPAA.

  • Post Author
    jppope
    Posted March 13, 2025 at 1:18 am

    Worth mentioning, because the authority level of medical practitioners throws people off. Don't ever give a doctor or practice your Social Security Number. They don't need it. Similarly if they want to check an ID that doesn't mean scan or photograph. Doctors, practices, etc are the worst at infosec. They have no training, basically no penalties if they do something wrong and all of that info is only to follow up in case you don't pay your bill.

  • Post Author
    gtirloni
    Posted March 13, 2025 at 1:30 am

    Why "Uber for nurses" and not the actual company name in the title?

  • Post Author
    mhitza
    Posted March 13, 2025 at 1:32 am

    I wonder how old the S3 bucket was, because at some point AWS made new S3 buckets private by default.

    Which means it's either old, or they recklessly opened it up because they couldn't get files uploaded/downloaded to the bucket from their mobile app/services.

  • Post Author
    CaffeineLD50
    Posted March 13, 2025 at 1:36 am

    Yeah I remember when Amazons AWS was new and people said "hey its cool but not secure." Then AWS added all these security features but added a caveat: BTW security is your responsibility

    Here we are. I guess we can blame the users and not any shitty security architecture slapped on AWS.

    Clearly what matters most is that legal culpability be avoided, not that users will be secure. The former is 'shite security' while the latter is good security

  • Post Author
    jihadjihad
    Posted March 13, 2025 at 1:48 am

    In the section of their Privacy Policy titled Data Security [0]:

    > We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroyed by breach of any of our physical, technical, or
    managerial safeguards. In particular, the Service is NOT designed to store or secure information that could be deemed to be Protected Health Information as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).

    IANAL and all that, but I’m not sure you can use the excuse “We didn’t design our system to be HIPAA compliant, sorry,” and hope your liability disappears. Does anyone know?

    0: https://eshyft.com/wp-content/uploads/2019/06/ESHYFT-Privacy…

  • Post Author
    ripped_britches
    Posted March 13, 2025 at 1:52 am

    What makes this uber for nurses?

  • Post Author
    dikaio
    Posted March 13, 2025 at 1:54 am

    Would be surprised if this company makes it out of this. Medical records…. Yikes

  • Post Author
    SamuelAdams
    Posted March 13, 2025 at 1:55 am

    I am confused, the article seems to be short on details. Was the attack an open S3 bucket? The company in question seems to be hiring for GCP, so I imagine they don’t use S3 at all.

    Did the submitter intentionally change the post title to get more clicks?

    https://eshyft.com/careers/gcp-devops-engineer/

  • Post Author
    whatever1
    Posted March 13, 2025 at 2:07 am

    I thought the cloud was safe, that is why you pay premium.

  • Post Author
    markus_zhang
    Posted March 13, 2025 at 2:37 am

    What a surprise. How do we, the common people dealing with corporations and governments leaking out information left and right? Even password storage services are not really safe AFAIK.

  • Post Author
    999900000999
    Posted March 13, 2025 at 2:41 am

    Are y'all gonna blame AWS like you blamed Firebase last week ?

    The security procedures I take while hacking out something for my friends at 3am should not extend to products hosting PII. It's up to YOU to implement basic data security.

  • Post Author
    bigfatfrock
    Posted March 13, 2025 at 2:45 am

    Sorry for the dude that built their infra and was really tired and then woke up to this, what a bummer.

  • Post Author
    elevatedastalt
    Posted March 13, 2025 at 2:51 am

    Annual reminder that the P in HIPAA stands for Portability, not Privacy.

  • Post Author
    RobotToaster
    Posted March 13, 2025 at 3:20 am

    Why does this keep happening? It seems like every month there's a new leak from an open S3 bucket?

  • Post Author
    j45
    Posted March 13, 2025 at 3:22 am

    I wish private data was more independently audited.

  • Post Author
    hrhbbvjhcxb
    Posted March 13, 2025 at 3:31 am

    [dead]

  • Post Author
    albert_e
    Posted March 13, 2025 at 3:32 am

    The linked article does not mention Amazon S3 or AWS

    Is there a different source for the "open S3 bucket" in HN title?

  • Post Author
    bn-l
    Posted March 13, 2025 at 3:39 am

    Always. Always the open bucket.

  • Post Author
    tmpz22
    Posted March 13, 2025 at 3:52 am

    Are we pretending that there are still functional regulatory agencies that are able to take action over this?

Leave a comment

In the Shadows of Innovation”

© 2025 HackTech.info. All Rights Reserved.

Sign Up to Our Newsletter

Be the first to know the latest updates

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.