Health eDevices


Secure Your Health, One Device at a Time

LEARN MORE

Health eDevices


Privacy First: Safeguarding Your Medical Devices with Health eDevices

LEARN MORE

Health eDevices


Empowering Your Well-being with Safe and Secure Health Device Management!

LEARN MORE

Health eDevices


Protecting Your Medical Data, Enhancing Your Peace of Mind

LEARN MORE

Health eDevices


Where Safety Meets Innovation in Medical Technology

LEARN MORE

What is a Health eDevice?

A Health eDevice is a medical, fitness, or lifestyle device whose goal is to try to provide a tool or service that will help you be healthier. The Health eDevices platform provides education and alerts for privacy, security, and safety related aspects of electronic medical devices.

Health eDevices are utilized by laypeople at home, paramedical workers and clinicians at outlying clinics, optometrists, dentists, and health-care professionals in cutting-edge medical facilities, for screening and prevention, as well as in palliative care. These medical technologies are employed in the diagnosis and treatment of acute and chronic illnesses, as well as in the support of persons with disabilities.

How Can Health eDevices Help You?

Health eDevices is designed to be a comprehensive solution for consumers looking to enhance the privacy, security, and safety of their health and medical devices. This innovative application offers a suite of services tailored to meet the evolving needs of health technology users, ensuring that their sensitive health data remains protected while maximizing the benefits of their devices.

Robust Privacy Management

This system enables users to control who has access to their health data, ensuring that personal information is shared only with authorized parties such as healthcare providers or family members. The application employs advanced encryption methods and compliance with health data protection regulations, such as HIPAA in the United States, to secure data both at rest and in transit.

Powerful Support

Health eDevices stands at the forefront of health and medical device management, offering a secure, user-friendly platform that empowers consumers to take control of their health technology. With its focus on privacy, security, and safety, Health eDevices is an essential tool for anyone looking to navigate the complexities of modern healthcare technology.

Security Alerts and Patch Notifications

Health eDevices offers comprehensive security features designed to protect devices from unauthorized access and cyber threats. This includes real-time monitoring for potential vulnerabilities, regular security updates to safeguard against the latest threats, and detailed security assessments for each connected device. By identifying and mitigating risks, Health eDevices ensures that users' health devices operate safely and reliably.

Device Safety

The application provides users with safety alerts and recommendations for their medical devices, including updates on recalls or safety concerns issued by manufacturers or regulatory bodies. Furthermore, it offers educational resources to help users understand how to use their devices safely and effectively, promoting better health outcomes and peace of mind.

 

 

23andMe Data Breach Implications and the Continued Fallout

What to consider if you shared your DNA data

Nathan E Botts 01802
Categories: Security
23andMe Data Breach Implications and the Continued Fallout

Genetic profiling company 23andMe is currently investigating a data scraping incident where private user information was stolen from its website. The confirmation came five days after an undisclosed entity advertised the sale of private data of millions of 23andMe users on an online crime forum. The alleged stolen data included details like origin estimation, phenotype, health records, photographs, and other identification data. Speculation arose that the CEO of 23andMe knew about this breach two months prior and had kept it under wraps. However, in response, a representative of the company contested that there's no proof of 'health information' being part of the posted data and currently, these are just unverified claims.

Recent updates have identified further fallout of the 23andMe breach. A spokesperson for 23andMe, Katie Watson, informed TechCrunch that hackers accessed the personal data of approximately 5.5 million customers who use the DNA Relatives feature. This feature allows users to share some of their genetic data with others. The compromised data includes names, birth years, relationship labels, the percentage of DNA shared with relatives, ancestry reports, and self-reported locations.

Additionally, another group of about 1.4 million people who opted into DNA Relatives had their Family Tree profile information accessed. This includes display names, relationship labels, birth years, self-reported locations, and information on whether they chose to share their data. 23andMe had declared part of its email as "on background," meaning both parties must agree to the terms in advance. TechCrunch published the reply as they were not given an opportunity to reject these terms.

The breach was attributed to data scraping, a method where attackers systematically extract smaller bits of information available to individual users, ultimately compiling large volumes of data. The attackers had unauthorized access to specific 23andMe accounts, which had the DNA relative feature activated. This feature lets users find potential relatives by viewing the basic profile details of others who have also opted into the feature. Officials from 23andMe emphasized that there isn’t any evidence suggesting a direct breach in their security systems. Instead, they suspect the login credentials might have been gathered from data leaks from other platforms where users reused their passwords. It was highlighted that the attackers have, in all likelihood, violated the company’s terms of service. Reports have emerged claiming that the data dump consists of 13 million pieces of information, with specifics regarding the nature and number of affected users still undisclosed. However, notable mentions include a leaked database of 1 million users of Ashkenazi descent and another 300,000 users of Chinese descent, all of whom had activated the DNA relative feature.

Recent events highlight the inherent risks associated with storing genetic data online. In 2018, another genetic data company, MyHeritage, faced a breach where over 92 million users' email addresses and passwords were compromised. The same year, officials in California utilized a different genealogy site, GEDMatch, to locate a suspect related to murders that had taken place 40 years prior. The suspect was identified not through his DNA but a relative's who had submitted a sample to GEDMatch. Storing genetic information online offers benefits like tracing lineage and finding relatives, but it also poses significant privacy threats. Even with strong passwords and two-factor authentication, as advocated by 23andMe, users' data remains vulnerable. The only foolproof way to safeguard it from online theft is to avoid online storage altogether.

SOAP Notes on what to consider about the 23andMe breach: Subjective, Objective, Assessment, and Plan

Subjective (Patient's feelings, history, complaints, etc.):

  • Concerns about the safety and security of storing genetic information online.
  • Anecdotal mentions of past breaches affecting other users.

 

Objective (Factual, measurable data):

  • 23andMe confirmed a data scraping incident involving private user data.
  • Unknown entity advertised the sale of millions of 23andMe user data.
  • Data purportedly includes origin estimation, phenotype, health records, photos, and identification.
  • Attackers gained unauthorized access using the DNA relative feature.
  • There are claims of around 13 million pieces of data being stolen.
  • In 2018, MyHeritage reported a breach affecting 92 million users.
  • Law enforcement officials have previously used genealogy sites for investigations.

 

Assessment (Professional's judgment based on the above two):

  • DNA testing platforms, while beneficial for tracing lineage and identifying relatives, carry inherent risks regarding user data privacy.
  • Even with advanced security features, such as strong passwords and two-factor authentication, vulnerabilities still exist.
  • External breaches (as seen in other online platforms where users recycle passwords) can indirectly compromise security in DNA testing platforms.

 

Plan (Recommendations or future plans):

  • Users should exercise caution when deciding to store genetic information online.
  • Always use unique, strong passwords for each online platform and avoid reusing passwords across platforms.
  • Frequently review and update security settings on DNA testing platforms.
  • Remain informed and periodically check the privacy policies and terms of service of these companies.
  • Consider the benefits against potential risks before opting into additional features like the DNA relative feature.
  • If possible, avoid online storage of critical genetic information altogether.

 

 

Share
Print
Please login or register to post comments.