cazabon,

A followup to this thread on a huge medical-privacy in ...
https://mindly.social/@cazabon/110557881736874267

The in question, which is happy to give both your (and presumably ) to pretty much anyone who wants them, in addition to letting them see when your prescriptions are eligible for refill, order those refills, and turn on OR OFF automatic fills for your prescripts is ...

Shoppers' Drug Mart.

[...]

CanadianCrone,
cazabon,

Following links on the Shoppers' site, privacy issues are directed to the Chief Privacy Officer at Loblaws, their parent corporation. #Loblaws bought #Shoppers some years ago in a megamerger.

Shoppers is, I believe, the single largest source of #Canadians' #prescriptions. So this affects a lot of Canadians.

I tried to engage in #responsible #disclosure. I emailed the person in question, twice. I have the logs from my email server showing the messages getting to them.

[...]

cazabon,

And in response, I got ... #crickets.

I did not even receive an acknowledgement that they received my emails, despite knowing they did receive them.

So... if you've ever filled a prescription at Shoppers, or possibly even just received a #vaccine there, be aware that anyone who can guess which location you deal with and knows your #name and #phone number, can create a web #account attached to your medical files at Shoppers.

[...]

cazabon,

That attacker can see exactly what you've been prescribed - helpfully including both the brand name and the generic name - in what dosage, how often you take it, and which doctor prescribed it.

Most #people would consider this #information highly personal, and would expect Shoppers to #guard it carefully. It appears that isn't the case.

This is a violation of the Personal Information Protection and Electronic Documents Act, which has applied to medical settings since 2002.

[...]

cazabon,

So, more than 20 years, and Shoppers still hasn't even done the most basic testing to see if their systems are secure.

If you're pissed that your confidential medical history can be shared with almost anyone, maybe you should express your displeasure to them.

Loblaw's Chief Privacy Officer's contact email address is loblawprivacy@loblaw.ca . Maybe you'll get a response, unlike me.

This could actually be worse than I'm making it out to be.

[...]

cazabon,

For example, Shoppers has a mobile app, but I haven't tried it. I would guess creating an account on their website would result in usable in the app, but haven't checked (no mobile device).

Shoppers uses a Loblaw's-wide system. So this might also apply to pharmacies in other Loblaw's companies (Loblaw's, Great Canadian Superstore, etc), but I haven't looked at those either.

Not responding to notifications of severe privacy/security violations is, frankly, criminal.

[...]

cazabon,

So, since they don't seem to care enough to read and respond to reports, how do we get them to fix it?

All I can think of is:

(1) Mass complaints. I gave you the CPO's email address earlier in this thread. Maybe they'll pay attention if they get hundreds of complaints?

(2) Media inquiries. Big tend to pay to problems once they're being asked to on a forthcoming story about them.

[...]

cazabon,

So, any #Canadian #reporters out there interested in the story?

Anyone care to #retoot this to any reporters or news tip accounts out there?

#CBC #Global #CTV #Canada #news #privacy #medical #violation #leak #confidential

cazabon,

If any reporter is interested, I'm happy to discuss it. If you like, I can explain:

  1. exactly what the problem is
  2. how I discovered it
  3. what measures Shoppers' systems should have included to make this attack impossible in the first place
  4. what Responsible Disclosure is and how it works
  5. what standard, industry-wide IT security practice mandates for systems handling confidential data, and which this problem demonstrates Shoppers didn't even attempt to do

[...]

cazabon,

I thought of one more avenue that might cause them to sit up and take #notice.

(3) some #lawyer decides to start a class-action #lawsuit against the Loblaw corporation for negligently potentially exposing many thousands of Canadians' highly confidential medical history to pretty much anyone who wants it, and then #negligently failing to do anything about it once informed of that fact.

That lawyer can feel free to #tip me 1% of the proceeds in thanks, I guess.

#ClassAction #privacy

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Canada
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • megavids
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • Leos
  • cisconetworking
  • provamag3
  • JUstTest
  • lostlight
  • All magazines