Overview
Severity: CRITICAL | Affected: HealthAI Analytics | Category: breach
HealthAI Analytics, a leading provider of AI-driven diagnostic tools, disclosed a significant data breach affecting approximately 15 million patient records. The breach stemmed from a misconfigured cloud storage bucket containing de-identified, but re-identifiable, patient data used for training their proprietary diagnostic models. Attackers gained access to patient histories, diagnostic images, and clinical notes. The incident highlights the severe risks associated with managing large-scale, sensitive datasets for AI development and the potential for re-identification attacks even when data is supposedly anonymized. Regulatory bodies in the US and EU have launched investigations into potential HIPAA and GDPR violations. The company has suspended access to the affected systems and is working with cybersecurity firms to investigate the full extent of the compromise.