Swedish Healthcare hotline in potential GDPR snafu after 2.7m sensitive calls exposed

170,000 hours of phone calls containing sensitive information were left exposed online for five years

A server used to store the calls made to the 1177 Swedish Healthcare Guide service, a hotline for healthcare information, has been found to be vulnerability-ridden and exposed 2.7 million sensitive phone calls between 2013 and 2018.

The open server could be accessed without using any login credentials and stored around 170,000 hours worth of phone calls containing sensitive information.

Around 57,000 of these phone calls, in which callers seeking advice also shared social security numbers, had filenames which featured the caller's phone number, reports Computer Sweden.

While recording sensitive phone calls isn't unusual (we've all been prompted that our phone calls may be monitored for training purposes), the fact that the server required no authentication to access it, is a major issue - one that could potentially lead to GDPR probes.

Upon examination, every single call found on the server could be accessed just by having the IP address and a web browser. The calls could be viewed in list form, dated, and either played straight in the web browser or downloaded as an .mp3 or .wav file.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"This is likely the worst privacy breach in Sweden in modern time," said Martin Jartelius, CSO at Outpost 24. "Looking at the breach, it is due to not only a lapse in security but a complete lack of any form of protection. The same company also exposed other outdated and very weakly protected services to the internet, some so outdated a modern system will not even be able to connect to them."

The server in question was also found to have 23 vulnerabilities on it, meaning that if it wasn't just open for anyone to see, it would most likely have been hacked at some point.

"The exposure of these call recordings is down to a security misconfiguration, and these kinds of issues are well known and currently rank at number 6 in the OWASP top 10 which documents the most critical software security flaws today," said Adam Brown, manager of security solutions at Synopsys.

"To avoid these kinds of issues, firms must have policy and process to continually monitor the security of production systems, and any findings from that process must be addressed and not simply left as a growing bug pile.

"Article 32 of the GDPR states that organisations must implement secure processing, taking into account the state of the art. This doesn't look the data processor has a defensible position in this case."

Advertisement - Article continues below

The hotline operates by triaging callers and then either referring them to local nursing teams or to outside contractors for over-the-phone healthcare advice.

This particular server belonged to Thailand-based, Swedish-owned Medicall, one of the aforementioned subcontractors used by the service to give advice.

Medicall is only used when the hotline and nursing staff are very busy and need extra help, the regions usually serviced by Medicall are Stockholm, Sdermanland and Vrmland.

Medicall uses a cloud-based call system which then saved recordings to the exposed servers. Access to the server has now been blocked.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/hardware/laptops/354533/dell-xps-13-new-9300-hands-on-review-chasing-perfection
Laptops

Dell XPS 13 (New 9300) hands-on review: Chasing perfection

14 Jan 2020
Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020