NTreatment Exposes Thousands of Health Records and Lab Results in a Security Lapse

Date:

Share post:

In a cloud storage security lapse, NTreatment exposed around 109,000 files that contained health records and lab results.

The said cloud server was hosted on Microsoft Azure.

NTreatment, a U.S.-based health tech company, experienced a security lapse on one of its cloud storage servers hosted on Microsoft Azure, which lacked password protection. The incident exposed around 109,000 files that contained health records, doctors’ notes, insurance details and claims, lab results, and much more. NTreatment, if proven guilty for the lack of basic security protocols, can attract a hefty fine from the Health Insurance Portability and Accountability Act (HIPAA).

Reason Behind the Lapse

NTreatment provides electronic health records (EHR) maintenance services for doctors based in the U.S. The lapse was found when researchers from TechCrunch stumbled upon the trove during a separate investigation. However, with the amount of PII being exposed, they decided to investigate it deeper. Researchers found three astonishing findings:

  1. The Microsoft Azure server used to store the data that did not have any password.
  2. None of the data discovered on the server was encrypted.
  3. All the exposed data could be easily viewed in any browser.

Related News:

Jackson Health’s HIPAA Violation Costs US$ 2.15 million fine

NTreatment’s exposed data contained the following set of information:

  • Lab test results from third-party providers like LabCorps.
  • Medical records, doctors’ notes, insurance claims, and other sensitive health data of patients having tie-up doctors and healthcare providers using NTreatment HER services.
  • Company’s internal documents, including a non-disclosure agreement (NDA) with a prescription provider.

TechCrunch’s researchers reached out to NTreatment to get the issue fixed to which they responded promptly. For the time being, any exploitation or download of the said data is not known. However, the set of data exposed included a certain subset of information, which is deemed highly protected under the HIPAA. Although they have dodged the bullet from threat actors, the researchers believe that NTreatment can be slapped with a heavy fine.

Related News:

Failure in HIPAA Compliance Costs URMC $3 million fine

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...

5th Edition MENA CYBER SECURITY CONFERENCE – RIYADH EDITION

Name: 5th Edition MENA CYBER SECURITY CONFERENCE - RIYADH EDITION Website: https://mena-cybersecurity.com/riyadh/ Date: September 8th, 2026 Location: Crowne Plaza Riyadh Palace,...