No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

NHS Breach, HSE Bug Expose Healthcare Data in the British Isles

March 17, 2024
in Protection
0
NHS Breach, HSE Bug Expose Healthcare Data in the British Isles


This week, a division of the National Health Service (NHS) Scotland was struck by a cyberattack, potentially disrupting services and exposing patient and employee data. Meanwhile, a researcher disclosed a Salesforce configuration error that exposed millions of Irish citizens’ COVID vaccination data from that country’s Health Service Executive (HSE).

The two incidents, separated by a quick hop over the Irish Sea, speak to the ongoing challenges healthcare organizations face in protecting patients’ most sensitive personal identifiable information (PII) and personal health information (PHI).

Salesforce Bug in Ireland’s COVID Vaccination Portal

During the onset of COVID’s Omicron variant in December 2021, Aaron Costello, principal SaaS security engineer at AppOmni, discovered a severe misconfiguration in the Salesforce-based online vaccination portal for Ireland’s HSE.

In a blog post published on March 14, he explained how an oversight allowed regular, low-level accounts belonging to HSE patients unprecedented access to the part of the system responsible for storing information about vaccine administration.

The exposed object in question included full names of patients and all information relating to their jabs: the brand of vaccine, date, location, and site at which it was administered, and any reasons they accepted or refused it.

Documents belonging to staff members, and information related to internal IT issues and processes, were also exposed.

“For Salesforce administrators and security practitioners on SaaS platforms, there was a lack of understanding of the implications of misconfigured permissions,” Costello tells Dark Reading. “They weren’t acutely aware that these things are possible — that a low-privileged user could be pulling this data.”

In the time since, Salesforce has gradually implemented a number of positive changes for preventing this kind of error and mitigating the consequences that might occur from it. A built-in health scanner attempts to uncover such vulnerabilities in customers’ environments, and more robust logging allows administrators to better analyze the activity of users, especially when they’re interacting with potentially sensitive APIs. Also, new policies and configurations attempt to conceal sensitive information, even in cases where they’re exposed by misconfigurations.

“So not only have they improved the post-breach process of log analysis, they’ve also introduced ways in which administrators can easily detect these issues with the health scanner, and also reduce the extent of exposures by reducing the scope of the data that becomes available in certain scenarios,” Costello says.

However, he warns, “There are a lot of organizations still misconfiguring these kinds of access controls to this very day. I still think there is a knowledge gap in the industry, and part of the issue is: Who’s responsible for the security of SaaS platforms? Is it the platform administrators? Do you pull in your security team when these things are being deployed to do an audit?”

Scotland’s NHS Breach

Also this week, NHS Dumfries and Galloway published an alert revealing that it is experiencing a “focused and ongoing” cyberattack.

Dumfries and Galloway is the southernmost council area of Scotland, with a population of approximately 150,000.

As a result of the breach, it warned, some services may experience disruption, and the attackers may have obtained “a significant quantity of data” belonging to patients and staff. More specific details about the cause, nature, and consequences of the breach are yet to be publicized.

Whether it’s a breach in Scotland or an overlooked system misconfiguration in Ireland, Costello says, “I think it all comes back to budget and funding. And the result of that is, firstly, understaffing for cybersecurity positions within these organizations. That is a massive, massive problem.

“We cannot point the finger solely at the employees of these organizations when they’re working under a very restricted budget and a very restricted headcount. They’re doing their best with the resources they have available to them.”



Editorial Team

Editorial Team

Related Posts

Amazon's Prices on the Fire TV 4-Series Are Ridiculously Low During the Big Spring Sale
Protection

Amazon’s Prices on the Fire TV 4-Series Are Ridiculously Low During the Big Spring Sale

March 25, 2026
The Best Budget Treadmill Is Even Cheaper During Amazon's Big Spring Sale
Protection

The Best Budget Treadmill Is Even Cheaper During Amazon’s Big Spring Sale

March 25, 2026
These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale
Protection

These Refurbished AirPods4 (With ANC) Are Just $118 During the Amazon Big Spring Sale

March 25, 2026
The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale
Protection

The Apple Watch Ultra 2 Is Nearly $200 Off for the Amazon Big Spring Sale

March 25, 2026
Follow the Best Deals From Amazon's Big Spring Sale in Real Time
Protection

Follow the Best Deals From Amazon’s Big Spring Sale in Real Time

March 25, 2026
This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale
Protection

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

March 25, 2026
Load More
Next Post
Here's Why I Wouldn't Buy

Here's Why I Wouldn't Buy

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • Majority of Fitch-rated sub lines have AA+ rating

    0 shares
    Share 0 Tweet 0

Latest News

Condé Nast Traveler

How Do You Spend 19 Hours on Board a Plane? We Have Ideas

March 25, 2026
0

When I could no longer fight my body’s hunger signals, I stopped pretending to be asleep. Getting served a meal...

Super Micro, Dell and HPE have been red-hot stocks this week. What’s behind the big moves.

Super Micro, Dell and HPE have been red-hot stocks this week. What’s behind the big moves.

March 25, 2026
0

Server makers could benefit from a possible easing of memory pressures and renewed interest in central processing units.

Western Union Eyes Stablecoin Card for Inflation Zones

Payy raises $6m seed to build private stablecoin payments on zero-knowledge rails

March 25, 2026
0

Payy raised $6m led by FirstMark to build a zero-knowledge L2 and wallet that make USDC payments private by default,...

Factbox-What did jury decide in social media case against Meta and Google?

Factbox-What did jury decide in social media case against Meta and Google?

March 25, 2026
0

Factbox-What did jury decide in social media case against Meta and Google?

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.