A database containing thousands of healthcare related records was left open to the internet, a researcher found. Staffing agency app ESHYFT, which provides professionals with a mobile platform on which to connect to long-term care centers for per diem work, had a 108.8 GB, 86,341 record database publicly exposed and free of password protection for an unknown amount of time before Cybersecurity Researcher Jeremiah Fowler discovered it. Red alert. Fowler, reporting on the breach on Website Planet, said that he alerted ESHYFT of the breach and that it was closed “over a month later.” Fowler added that he did not download any of the data and that there was no sign that anyone had accessed the information. Fowler reported that in a limited sampling of the data, he found medical documents, Social Security cards, profile and facial images, and various other examples of PII. “One single spreadsheet document contained 800,000+ entries that detailed the nurse’s internal IDs, facility name, time and date of shifts, hours worked, and more,” Fowler wrote. Travel time. ESHYFT is available in 27 states. While the demand for traveling nursing is no longer at the peak it was during the pandemic, the traveling nursing market dropped 40% in 2023 from 2022. Akin Demehin, the American Hospital Association’s senior director of quality and patient safety policy, noted last year that full-time work is becoming more of a priority to healthcare centers. Keep reading here.—EH |