Overview
Severity: CRITICAL | Affected: HealthCorp AI | Category: breach
HealthCorp AI, a leading provider of AI-driven diagnostic tools for hospitals, has disclosed a significant data breach affecting approximately 2 million patient records. The breach occurred due to an insecure API endpoint used by their 'DiagnoseAI' platform, which was inadvertently exposed to the public internet without proper authentication. Attackers exploited this vulnerability to exfiltrate sensitive data, including patient names, diagnostic images, medical histories, and physician notes. The company stated that the API was a legacy endpoint used for data ingestion by partner clinics and was not intended for external access. The incident highlights the growing risk of insecure integrations in complex AI systems, where data pipelines can create new, unforeseen attack surfaces. Regulatory bodies have launched an investigation into potential HIPAA violations.