Researcher describes how hundreds of medical imaging servers in India were left unsecured months ago and are still leaving 1M+ medical records exposed
The story behind how I was able to view, edit & delete classified personal information of lakhs of patients all over India Tweets: @kingslyj , @zackwhittaker , @kmskrishna , and @zackwhittaker Tweets: @kingslyj : This is just the tip of the iceberg. Hospitals have no concept of security / privacy etc. So many of them are collecting and storing Aadhaar details of patients. They have WiFi networks which can be trivially broken into. https://twitter.com/... Zack Whittaker / @zackwhittaker : Looks like India didn't get the memo about how poor security is exposing patients' sensitive medical images. https://twitter.com/... Sai Krishna Kothapalli / @kmskrishna : Just published an article about my recent findings on Indian health care data. How easy is it to get hands-on it and how one can misuse it. I tried to cover the legal aspect of it as well. @NCIIPC @IndianCERT #india #DataSecurity #healthcare #HealthTech https://medium.com/... Zack Whittaker / @zackwhittaker : Gloss over the use of creds for a second, and let the fact that “admin:admin” is the only thing stopping a malicious actor getting into one of these systems. Utterly atrocious. https://medium.com/... https://twitter.com/...
Context & Ripple Effects
This disclosure extends a documented arc: ProPublica found 16M unprotected scans worldwide in 2019, and by January 2020 TechCrunch had counted over 1B medical images sitting on open servers. Sai Krishna Kothapalli's finding shows India is a dense node in that map — and that months after his reports, the servers were still reachable.
What makes the Indian case sharper is what sits inside the records: hospitals are reportedly collecting Aadhaar numbers alongside imaging data, repeating the same failure pattern as [[a:938765|the state gas company whose site let Google index millions of customer records with Aadhaar numbers]] in 2019.
First-order effects
- Hundreds of Indian hospitals running these imaging servers are leaving viewable, editable, deletable patient records online right now — exposure of names, scans, and reportedly Aadhaar details continues months after disclosure.
Second-order effects
- Because Aadhaar numbers ride along with the medical records, each hospital breach compounds into a national identity-fraud problem beyond healthcare, pressuring NCIIPC and India's data-protection authorities to treat hospital IT as critical infrastructure rather than a private matter.
Third-order effects
- If the 2019-to-2020 pattern holds, unsecured PACS/imaging servers are a chronic global class of exposure rather than one-off misconfigurations, pointing toward mandated security baselines for medical imaging systems in India and elsewhere.
The trend: Medical imaging infrastructure is emerging as one of healthcare's most persistently exposed data surfaces worldwide, with India's combination of scale and Aadhaar-linked records making it the sharpest edge of the problem.