Personal details of millions of citizens registered in the Brazilian healthcare system have been exposed in separate blunders relating to data management and security involving the country's Ministry of Health (MoH).
The most recent incident entails the exposure of details such as names, addresses and telephone numbers, as well as taxpayer registration numbers belonging to approximately 243 million Brazilians. The number is greater than the current population size of 212 million because the leak also included information about deceased citizens.
The leak was first reported by Brazilian newspaper O Estado de São Paulo in an article published last Wednesday (2). According to the article, login and password details to ministerial systems had been openly published online. One of the systems in question, e-SUS Notifica, handles the registration of suspected and confirmed Covid-19 cases, developed in partnership by technology company Zello.
After the problem was exposed, the supplier and the MoH found there was a vulnerability in the integration between the ministerial back-end systems and the system front-end, according to a statement issued by Zello, which noted that the vulnerability was patched by the ministry as soon as the Estado article was published.
The latest leak relating to Brazil's Ministry of Health follows another security incident, also reported by O Estado de São Paulo four days earlier, relating to the exposure of personal details of millions of Brazilians who tested positive for Covid-19 after passwords to systems maintained by the MoH were openly published online.
The passwords were published on code hosting platform platform GitHub by an employee from Albert Einstein Hospital, one of the main private healthcare organizations in Brazil, according to the report. Both institutions collaborate on projects under a cooperation between the public and private sector for the national