2020 Dr Lal PathLabs — public AWS storage exposed diagnostic booking spreadsheets
Data compromised
Patient identity, contact, appointment, and clinical-testing context per security researcher and press summaries
Technical writeup
Independent researchers reported an unauthenticated Amazon S3 bucket containing large spreadsheets of patient bookings—names, phones, addresses, test metadata, and COVID-era result flags—for India's Dr Lal PathLabs chain, with TechCrunch and Indian Express coverage describing months-long exposure until the bucket was closed following coordinated disclosure.
Root cause
Object storage misconfiguration without mandatory authentication on sensitive healthcare workflow exports
References
- https://techcrunch.com/2020/10/08/dr-lal-pathlabs-exposed-patient-lab-data/
- https://indianexpress.com/article/technology/tech-news-technology/lalpath-labs-leaked-data-millions-patients-in-public-6716966/
- https://databreaches.net/2020/10/08/dr-lal-pathlabs-one-of-indias-largest-blood-test-labs-exposed-patient-data/