1B+ medical images of patients found online, as hospitals and doctors' offices ignore security and upload X-rays, ultrasounds, and CT scans to unsecured servers
Every day, millions of new medical images containing the personal health information of patients are spilling out onto the internet.
TechCrunchZack Whittaker
Context & Ripple Effects
The scale of exposed medical imaging has been climbing for months: ProPublica first documented 16M scans worldwide sitting unprotected online in September 2019, and a broader audit found ~2.3B sensitive files exposed via public file storage, up 50% year over year. This report pushes the imaging-specific count past one billion — meaning the problem is not isolated misconfigurations but a default practice of hospitals and doctors' offices uploading X-rays, ultrasounds, and CT scans to servers without access controls.
What makes the finding consequential is that these images carry names, birthdates, and diagnoses alongside the scans themselves, turning an imaging-archive hygiene failure into a full identity-and-health-record exposure. Later reporting confirmed the pattern deepening rather than closing: hundreds of imaging servers in India left unsecured for months, and tens of thousands of U.S. hospital records surfacing on the dark web.
First-order effects
Hospitals and doctors' offices that uploaded scans to unsecured servers have effectively published patient identities linked to health conditions, exposing patients to blackmail, insurance discrimination, and identity theft risks right now.
Every provider running picture archiving systems faces immediate pressure to audit whether its imaging storage is internet-reachable, since the exposure stems from configuration choices, not a single vendor breach.
Second-order effects
Imaging-equipment vendors and archive-software suppliers will be pushed toward secure-by-default configurations, because their hospital customers are demonstrably unable to secure deployments themselves.
Insurers and regulators gain a documented, quantifiable pattern of negligence across thousands of facilities, strengthening the case for mandatory penalties rather than voluntary remediation when exposures are found.
Third-order effects
If unsecured uploads remain the norm, medical imaging data becomes a standing commodity for identity thieves and foreign actors, shifting healthcare security from breach-response to continuous external scanning of providers' own infrastructure.
Sustained exposure at this scale points toward regulatory intervention treating imaging archives like critical infrastructure, with compliance costs flowing back into hospital IT budgets and vendor contracts.
The trend: Medical imaging is becoming the largest systematically unprotected class of personal health data, as the volume of exposed scans grows faster than providers' willingness to secure them.
Patients are 10x more likely to have their health information hacked [from doctor's office, hospital] than to be able to access it themselves (incl X-rays, blood tests)- CNBC's @chrissyfarr told @brianmcc on TechMeme Ride Home podcast https://apple.co/2RdexJv #JPM20
A billion medical images are exposed online, as doctors ignore warnings | TechCrunch About half of all the exposed images, which include X-rays, ultrasounds and CT scans, belong to patients in the United States https://techcrunch.com/...
Hundreds of hospitals, medical offices and imaging centers are running insecure storage systems, allowing anyone with an internet connection and free-to-download software to access over 1 billion medical images of patients across the world. https://techcrunch.com/...
Thrilled to have worked with @ryfabian on this story to understand what this means for patients — who are ultimately the victims here — and what actions they can take to protect themselves. https://themighty.com/...
HIPAA is onerous, but is it also ineffective? “He demonstrated how easy it was for anyone to view exposed patient data. In just a few minutes, he found one of the largest hospitals in Los Angeles exposing tens of thousands of patients' scans...” https://techcrunch.com/...
US Healthcare. “Greenbone found 24 million patient exams storing more than 720 million medical images in September, which first unearthed the scale of the problem as reported by ProPublica.” It gets worse. https://twitter.com/...
More than a billion medical images (X-rays, MRI's, ultrasounds, etc) are exposed online, many of which contain personal data like names and diagnosis. Half of the images belong to patients in the US. https://techcrunch.com/...
5 years ago, this would have been big news. Now frightful breaches such as this are met largely with “meh”. Desensitization could be a problem for us. #cybersecurity #breaches # #privacy A billion medical images are exposed on...https://www.linkedin.com/ ... https://techcrunch.co…
This is why we need to call it out, and please don't give up on psuhing for change here. Thank you @zackwhittaker and @ryfabian Thank you @_j3lena_ @iamthecavalry @joshcorman @beauwoods @_odddie_ and all who fight to make things better https://twitter.com/...
Losing a trust, is worse nightmare that can happen in healthcare 👇 “Exposed data can also erode the relationship between patients and their doctors, leading to patients becoming less willing to share potentially pertinent information.” https://twitter.com/...
New: Over a billion X-rays, MRIs and ultrasounds are exposed online, despite warnings to hospitals and doctor's offices by security researchers. Many medical images included personal data, like names and diagnoses. “It seems to get worse every day.” https://techcrunch.com/...