Data Breach of Over 12.5 Millions Records of Indian Pregnant Women!!!

Hello and welcome to New Age Informers where we believe in sharing knowledge!!!

I know our readers are wondering that why there were no regular posts or articles on blog. I apologize for the unavailability due to some unavoidable circumstances, but now we are on again. Now, without wasting time, coming to the topic of discussion today. We all know that data breach is getting common nowadays. But, it makes us worry when the data breach is related to our health.

Yes, today we are going to discuss on how data of around 12.5 million pregnant women's data leaked. One of the medical agency, working with Government of India has kept data of Indian pregnant women uncovered online. The whole database having more than 12.5 million Indian women details was available online for almost one month. After that, when Indian health agency came to know that, they removed it.


A researcher, Bob Diachenko, has disclosed that an Indian health agency has negligently disclosed massive data online. This data consists of every single information of more than 12.5 million pregnant women from India. It is came to knowledge that due to some security mis-configuration in a Mongo DB, this data breach has happened. Bob Diachenrsko found this database online on 7th of March, this year. And he found it when he was performing a routine audit or check of a search engine stream named 'BinaryEdge'.

 In his personal blog, he said that the data which is being leaked contains almost every medical information of patients. He stated that, "The India-based IP contained a publicly accessible dataset of what appeared to be patients records, doctors, children details, admin passwords, and logins." Trying to explain it in deep he said, "The database records included different forms which pregnant women are required to complete and has questions ranging from the mother's age to family history of genetic ailments, details of the pregnancy and other sensitive information."

The disclosed database counted 7,449,714 "form F". Now, let us understand why form F and what is it's purpose. It is a form which should be filled by every pregnant women to accept the anti-sex discrimination abortions made by Indian Pre-Conception and Pre-Natal Diagnostic Techniques (PCPNDT) Act. ZDNet, also claimed that they found some documents related to the bodies who performs sex determination tests in black.

 Researcher tried many times to reach out to the owner of this database but not succeed, so at last he contacted the CERT-IN (Indian CERT) and reported this flaw to them. As soon as they came to know about this, they removed it. That database was related to Department of Medical, Health and Family Welfare of North-Indian states. This whole process took almost a month to get this highly confidential database down! This is not stopped yet. Yes, ZDNet dined to disclose the name of the state who is still having such mis-configured MongoDB online. 

You guys will be shocked but in the beginning of this week, a data breach of about 800,000 blood donors reported.  


Stay tuned and stay safe!!!

Comments