← Dr Lal PathLabs

2020 Dr Lal PathLabs — public AWS storage exposed diagnostic booking spreadsheets

2020 Unknown records affected Share on X

Data compromised

Patient identity, contact, appointment, and clinical-testing context per security researcher and press summaries

Technical writeup

Independent researchers reported an unauthenticated Amazon S3 bucket containing large spreadsheets of patient bookings—names, phones, addresses, test metadata, and COVID-era result flags—for India's Dr Lal PathLabs chain, with TechCrunch and Indian Express coverage describing months-long exposure until the bucket was closed following coordinated disclosure.

Root cause

Object storage misconfiguration without mandatory authentication on sensitive healthcare workflow exports

References