NHS vaccination website leaks people's medical data

NHS
(Image credit: Shutterstock)

A gaping security hole has been discovered in the NHS vaccination booking website, which can be easily exploited to find out whether someone has received a jab.

The problem relates to the way the website treats different users, depending on how far along they are in the vaccination process.

For example, if someone has not yet received any jabs, they will be funnelled to a screening page, while someone using the website to book a second jab will be prompted for a booking reference. A user who has already received both shots, meanwhile, will be redirected to a page that reads: “You have had both of your appointments.”

While the website asks users for their NHS number, bookings can also be made using basic personal information, meaning anyone could exploit the system to access the vaccination status of anyone else.

Even more egregious, the website allows anyone with access to someone else’s personal data to book a second vaccination appointment on that person’s behalf, provided the first jab was administered by a GP.

Vaccine data disaster

Beyond the obvious breach of privacy, there are concerns vaccination status data could be abused by employers to check which of their staff have been vaccinated. Others have suggested scammers could use the information to execute targeted phishing attacks.

“This is a seriously shocking failure to protect patients’ medical confidentiality at a time when it could not be more important,” said Silkie Carlo, Director at privacy advocate group Big Brother Watch.

“This online system has left the population’s Covid vaccine statuses exposed for absolutely anyone to pry into. Date of birth and postcode are fields of data that can be easily found or bought, even on the electoral roll.”

In response to complaints, NHS Digital has said it will revise the booking process to shield the vaccination status of UK citizens. However, the health service technology provider defended the simplicity of the website, which it claims has allowed millions to book vaccination appointments with ease.

“The online ‘book a coronavirus vaccination’ service has enabled millions of people to book their vaccinations quickly and easily, with over 17 million first and second dose appointments made in over four months,” said an NHS Digital spokesperson.

“The system does not have any direct access to anyone’s medical records and people should not be fraudulently using the service. It should only be used by people booking their own vaccines or for someone who has knowingly provided their details for this purpose.”

Via The Guardian

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
healthcare
Over a million clinical records exposed in data breach
Data Breach
Thousands of healthcare records exposed online, including private patient information
healthcare
Top IVF firm says hackers accessed private data during cyber incident
healthcare
Almost a million ConnectOnCall users may have had data stolen by hackers
A graphic showing fleet tracking locations over a city.
Disability monitoring tool leaked personal information online
Latest in Pro
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Racks of servers inside a data center.
Modernizing data centers: an efficient path forward
Dr. Peter Zhou, President of Huawei Data Storage Product Line
Why AI commonization is so important for business intelligent transformation and what Huawei’s data storage has to offer
Wix automation
The world's leading website builder aims to save businesses time with new tool
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough