Skip to main content
  1. Home
  2. Computing
  3. News

A simple password mistake led to 5.3 million leaked health records

Add as a preferred source on Google

Update: A representative from Ecaresoft has reached out to Digital Trends and claimed that the initial Cybernews report had some inaccurate information in it. The first sticking point from Ecaresoft was that the affected server was “a non-production environment, containing anonymized, randomly generated test data, not real patient data.” If that’s true, there was no actual risk of exposed patient data. Ecaresoft also claims that the reported number of records “exceeds the total number of records we have in our system at this time.”

Our story as published on October 23 is below:

Recommended Videos

Cybernews reports its research teams found a 500GB unprotected database of a Mexican health care company on August 26, 2024. The database exposes sensitive information such as names, personal identification numbers (CURP), phone numbers, descriptions of payment requests, and more.

The total amount of affected people adds up to 5.3 million, making up approximately 4% of the country’s population, as Cybernews notes. The Cybernews report indicates that the security mistake occurred with a “misconfigured” use of a data visualization tool called Kibana, which appears to have been left unauthenticated.

The massive volume of data was later credited to Ecaresoft, a Texas-based software company behind cloud-based Hospital Information Systems such as Anytime and Cirrus. More than 30,000 doctors, 65 hospitals, and 110 outpatient care centers use Ecaresoft services to manage tasks such as appointment booking, medicine management, inventory management, and more.

Other stolen data includes ethnicities, nationalities, religions, blood types, dates of birth, gender, email addresses, the amount charged for health care services, and the hospitals visited. This time around, threat actors are not to blame as the cause. There is no official information about whether the affected users are aware of the situation or how long the database (now taken down) was up and running.

The affected users’ health records were not taken, but with their Mexican government identification (equivalent to the U.S. Social Security number) at risk, they are exposed to wire fraud and phishing (among other things). The company has yet to release a statement about the unprotected data, but hopefully, we’ll hear something official soon. When data is left unprotected, it can be indexed by search engines and taken by threat actors who are constantly scanning the internet for these types of unprotected files.

While those in the U.S. don’t need to worry about their personal information being compromised in this instance, it shows just how important password security is. An easy-to-guess password makes you as vulnerable as no password at all. Another one of the worst password mistakes in the past decade was Equifax, the 2017 data breach that, due to using “admin” as their password, made it easy for hackers to steal their data.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
The Sashimi robot is real and it doesn’t fumble at slicing and dicing
Three arms, a GelSight sensor, and surprisingly clean chopstick work.
Laboratory, Robot

Robots can pick up boxes, sort packages, and screw in bolts without breaking a sweat. Some of them can even walk and run like humans. Hand one a floppy, slippery piece of raw salmon, though, and everything starts falling apart. 

A team at the Norwegian University of Science and Technology set out to solve that problem. The result is the Sashimi-Bot, a three-armed robot that can prepare sashimi from a raw salmon loin without a chef in sight.

Read more
macOS 27 means the end of the Hackintosh Era, but does anyone still need one?
Apple's latest software update shuts the door on x86, but today's Macs have already made the original Hackintosh dream surprisingly accessible.
Apple macOS 27 With Hackintosh in background

While the tech world was busy obsessing over Liquid Glass, smarter Apple Intelligence features, and all the shiny new additions arriving with macOS 27 Golden Gate, Apple quietly slipped in another announcement at WWDC 2026 that didn't get nearly as much attention. Buried in the compatibility list was a simple but significant detail: Intel Macs are no longer supported. For millions of users, that's just another software update requirement. For a passionate corner of the internet that has spent nearly two decades bending technology to its will, it's something far bigger. It's the end of the traditional Hackintosh era.

If the term sounds unfamiliar, here's the quick version. A Hackintosh is a regular PC that's been modified to run macOS instead of Windows or Linux. Using community-developed bootloaders such as OpenCore and carefully selected hardware, enthusiasts managed to convince Apple's operating system that it was running on a genuine Mac. The process was anything but straightforward, but for many, that challenge became part of the fun.

Read more
Instacart is testing camera-ready AI shopping carts that sound convenient, but equally scary
Caper Carts promise faster checkout and personalized savings, but the cameras, location tracking, and on-cart ads make grocery shopping feel a lot less private.
Basket, Shopping Cart, Machine

Instacart's AI shopping carts are moving into select Weis Markets stores in Pennsylvania, with more locations planned this year. On the surface, the Caper Cart upgrade sounds useful, since shoppers can see a running total, clip digital coupons, use loyalty rewards, weigh items, and pay from the cart.

The privacy tension comes from the hardware needed to make that work. The carts include basket-facing cameras, outward-facing cameras, location-tracking systems, scales, touchscreens, and payment terminals, turning an ordinary grocery basket into a rolling sensor platform.

Read more