Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

Clinical Trials: How Personal Information for Thousands of Australians was Exposed

Cyberinchief by Cyberinchief
November 10, 2025
Reading Time: 4 mins read
0
Clinical Trials: How Personal Information for Thousands of Australians was Exposed


RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

UpGuard can now disclose that a database containing personal information for over thirty-seven thousand individuals has been secured, preventing any future abuse. The database belonged to Neoclinical, an Australia-based company that matches individuals with active clinical trials. In reviewing the data set, the vast majority of individuals affected were in Australia and New Zealand, where Neoclinical operates clinical sites. In addition to contact information, the database included users’ responses to questions qualifying them for clinical trials, which included questions about medical diagnoses, illicit drug use, and treatments. 

The Discovery

On July 1, an UpGuard researcher detected a MongoDB database named “neoclinical.” The database included collections for different entity types involved in connecting users to clinical trials: the accounts for the medical organizations running the trials, qualifying questions to determine the fit of the users, the “users” themselves seeking entry to those trials, and more. That day the researcher sent an email notification to Neoclinical. The researcher called both phone numbers on Neoclinical’s website, one of which was disconnected and the other was configured to record a ten second message to be transcribed and sent as text. On July 25 the researcher escalated notification to AWS Security, which followed their standard procedure of responding that they would notify the owner of the database. On July 26, public access to the database was removed. 

The Significance

Modern medicine is an advanced, specialized practice, and for that reason medical procedures are typically constrained to dedicated sites, like a hospital or doctor’s office. Efforts to protect medical data likewise focus on threats to those sites, like mitigating the ransomware attacks (like WannaCry) that have struck many hospitals. The data generated from medical examinations, however, can enter other circuits of the digital world, sidestepping the regulation of the hospital. Neoclinical is one example of a company filling a particular role in the larger economy of healthcare that extends far beyond the relationship between doctor and patient within the protections of the hospital.

Research and development of new therapies is one part of healthcare writ large, and clinical trials are a subset of that development process. To confirm the effectiveness of a course of treatment requires a scientific study of the therapy’s effect with a statistically significant group of patients. Vetting individuals for inclusion in those trials requires gathering information about their health. In the case of the Neoclinical dataset, that information includes individuals revealing personal information their conditions ranging from cancer to incontinence. 

The Neoclinical website claims they have 37,170 users, and that is exactly the number of rows in the “users” collection of their database. Each of those users has a profile with a collection of information describing their fit for the various trials being coordinated with Neoclinical. Part of the profile is personal information like name, email address, physical address, geo coordinates for that address, and date of birth. Additionally, the user information includes their responses to the questions and any trials for which they qualified.

neoclinical - personal
Example of a redacted profile with name, email, address, date of birth. The “answers” field contains structured responses to questions about personal health. 
stats - users
Database statistics for the “users” collection showing 37,170 records

Each of those users has entered the Neoclinical system for the purpose of participating in a clinical trial. Whether they qualify for a trial depends on their responses to questions about their medical history. Some questions are about the frequency or severity of symptoms, while others are about past treatments. 

Buy JNews
ADVERTISEMENT
question - incontinence
Example of a series of questions about incontinence. 
questions - insulin
Questions about the use of pharmaceutical therapies
questions - chemotherapy
Questions about cancer treatments

‍

Questions about past diagnoses for heart conditions

‍

Conclusion

Without exposing documents produced by a physician– what one often thinks of as the model of “medical data”– these profiles reveal information about participants’ medical histories. That information includes information generated by their interaction with the healthcare industry, like diagnoses and past treatments, as well as reports of their personal experiences related to their health. For individuals, this case provides a reminder that whenever they pass information to a third party, they should consider the impact of that data being exposed. And for companies, it should highlight the importance of having an incident response capability so that when data leaks occur, they can be mitigated within hours rather than weeks. 



Source link

Tags: AustraliansClinicalExposedInformationpersonalThousandsTrials
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
Hacker Explains How Police Cars & Airports are Hacked | Sam Curry #004

Hacker Explains How Police Cars & Airports are Hacked | Sam Curry #004

Digital Arrest In Bengaluru 🔴LIVE : బట్టలిప్పి.. 9 గంటల వీడియో.. | Cyber Crime | RTV

Digital Arrest In Bengaluru 🔴LIVE : బట్టలిప్పి.. 9 గంటల వీడియో.. | Cyber Crime | RTV

Recommended Stories

What Is a SOC? | Functions, Tools, and Benefits Explained

What Is a SOC? | Functions, Tools, and Benefits Explained

November 20, 2025
The Truth about Cyber Security Jobs and Salaries

The Truth about Cyber Security Jobs and Salaries

October 22, 2025
बिना गलती के Bank Account Freeze By Cyber Cell | Gujarat Cyber Crime Cell #cybercell #p2p #freeze

बिना गलती के Bank Account Freeze By Cyber Cell | Gujarat Cyber Crime Cell #cybercell #p2p #freeze

December 1, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested