By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechgoonduTechgoonduTechgoondu
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Search
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Reading: More than 800,000 blood donors had personal data exposed, in latest leak in Singapore
Share
Font ResizerAa
TechgoonduTechgoondu
Font ResizerAa
  • Audio-visual
  • Enterprise
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
  • PC
  • Telecom
Search
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Follow US
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Techgoondu > Blog > Internet > More than 800,000 blood donors had personal data exposed, in latest leak in Singapore
InternetSoftware

More than 800,000 blood donors had personal data exposed, in latest leak in Singapore

Alfred Siew
Last updated: August 13, 2020 at 11:38 PM
Alfred Siew
Published: March 19, 2019
6 Min Read
SHARE
SCREENSHOT: Health Sciences Authority website

In yet another data leak, 808,201 blood donors in Singapore had their personal details exposed in January this year, after a Health Sciences Authority (HSA) database was placed on an Internet-facing server.

Blood donors had their NRIC, gender, number of blood donations, dates of the last three blood donations, and in some cases, blood type, height and weight, leaked on the Net for two months until a cybersecurity expert found the loophole and informed the authorities on March 13.

Revealing the leak on March 15, the HSA said that no other unauthorised person besides the cybersecurity expert had accessed the data.

That’s the good news. The bad news is that this is the third such data leak to happen in Singapore in less than a year, which raises questions of how well private citizen data is being protected.

In January this year as well, news came that 14,200 HIV patients had their personal details exposed. In July last year, the country faced its largest data breach when it emerged that 1.5 million people had their information stolen from the SingHealth healthcare group.

So far, none of the people affected have had any practical recourse. It’s not clear if they have been advised to mitigate the problem, say, by obtaining identity theft insurance or learning how to combat online fraud.

While SingHealth and its technology vendor were fined a combined S$1 million by the government privacy watchdog, the Ministry of Health where the HIV patient data was stolen is exempt from the same penalties.

Now, the data leak at the HSA is likely to have the same outcome. The government agency will not be fined because it does not have to face the same music as private companies.

In a letter to blood donors last week, its chief executive officer, Dr Mimi Choong, apologised for the leak, which she attributed to an external vendor that had placed the unsecured database on an Internet-facing server.

Well, at least, HSA has been prompt to notify donors as well as announce the leak publicly, despite it being seemingly contained.

Public confidence is paramount here. People should be able to donate blood without worrying about exposing their personal data.

This contrasts with how the Ministry of Health handled the HIV data leak. It had known about that breach for two years but felt it had contained the leak so it didn’t go public with the news until much later.

That can’t be the way to win confidence from users in a smart nation. Government agencies, as these recent problems have shown, have to simply do better.

While the SingHealth hack was attributed to a sophisticated hacker group backed by a nation state, the HIV data leak and this HSA one are clearly down to a lack of adequate cybersecurity measures.

For the HIV case, the data was downloaded onto a USB drive, which should not have been allowed on machines holding sensitive data.

In this HSA case, the database was not secure (likely not encrypted) and it was placed by a third-party vendor on an Internet-facing server. Both cases are clearly preventable.

Sure, there should not be a blame culture at a time when the smallest mistakes can expose one to cybersecurity issues, such is the complexity of IT systems today.

Yet, these two recent cases show that measures you expect the government to take to protect confidential data are not there. That is a systemic issue that has to be tackled.

It’s also rather bizarre that the government can fine private entities, like karaoke operators or other small businesses, princely sums for losing their data, when its own agencies are not taking the expected steps to protect citizens’ data.

In 2016, K Box had to pay a fine of S$50,000 for exposing 317,000 customer names, contact numbers and addresses after it suffered a cyber attack. Its IT vendor was fined S$10,000 for simply not updating its systems to more secure versions.

Now, what is the penalty for a government agency that has just leaked more sensitive data belonging to more than 800,000 people? And that’s down to a vendor taking an unsecured database and placing it on a server connected to the Internet.

Beyond saying sorry in future, the government as a whole has to demonstrate more rigour in its cybersecurity efforts, by conducting more regular IT audits and setting up data protection software and practices across its agencies.

It has beefed things up before. Okay, it took a data breach on SingPass in 2014 before security was finally strengthened with two-factor authentication.

But today, the system for logging into government e-services has been revamped, bringing it up to date with the private sector. So, the task is not an impossible one.

The more data that is out there means there will be a higher risk of data breaches in future. That’s a given. However, there is no reason not to have tougher data protection measures. More needs to be done, as these two recent lapses now show.

When Nets goes down for nearly a couple of hours in Singapore
Splash-proof Sony Xperia Tablet S updates previous design
Five essential wine apps for wine lovers
Hands on: Nokia N8
Commentary: Singapore gets stricter with data protection, but issues persist
TAGGED:blood donorcybersecuritydata breachdatabaseHSA

Sign up for the TG newsletter

Never miss anything again. Get the latest news and analysis in your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Whatsapp Whatsapp LinkedIn Copy Link Print
Avatar photo
ByAlfred Siew
Follow:
Alfred is a writer, speaker and media instructor who has covered the telecom, media and technology scene for more than 20 years. Previously the technology correspondent for The Straits Times, he now edits the Techgoondu.com blog and runs his own technology and media consultancy.
Previous Article Goondu review: Samsung Galaxy S10+ is an attractive, if expensive, all-rounder
Next Article Singaporeans among most frequent gamers: Limelight study
2 Comments
  • Ronald Soh says:
    March 20, 2019 at 2:20 pm

    The series of security breaches and compromises is really making people losing faith in the people that is managing and securing the data integrity and confidentiality. We really need to relook at our country IT Infrastructure security.

    Reply
    • Avatar photo Alfred Siew says:
      March 20, 2019 at 4:31 pm

      Hi Ronald, yes, I think it doesn’t help that IT systems are too complex today and mistakes are a result of that. Having said that, the government has to be more stringent on its data protection measures so lapses don’t become a norm. Citizens have no choice but to transact with the government, after all.

      Reply

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

FacebookLike
XFollow

Latest News

Scammers are so successful they even accidentally scam themselves now
Cybersecurity Internet
June 10, 2025
Doom: The Dark Ages review: Future fantastic demon slaying
Gaming
June 10, 2025
Plaud NotePin review: Note-taking made easy with AI
Internet Mobile
June 9, 2025
Can smart grocery carts, biometric payments boost retailers like FairPrice?
Enterprise Internet
June 6, 2025

Techgoondu.com is published by Goondu Media Pte Ltd, a company registered and based in Singapore.

.

Started in June 2008 by technology journalists and ex-journalists in Singapore who share a common love for all things geeky and digital, the site now includes segments on personal computing, enterprise IT and Internet culture.

banner banner
Everyday DIY
PC needs fixing? Get your hands on with the latest tech tips
READ ON
banner banner
Leaders Q&A
What tomorrow looks like to those at the leading edge today
FIND OUT
banner banner
Advertise with us
Discover unique access and impact with TG custom content
SHOW ME

 

 

POWERED BY READYSPACE
The Techgoondu website is powered by and managed by Readyspace Web Hosting.

TechgoonduTechgoondu
© 2024 Goondu Media Pte Ltd. All Rights Reserved | Privacy | Terms of Use | Advertise | About Us | Contact
Join Us!
Never miss anything again. Get the latest news and analysis in your inbox.

Zero spam, Unsubscribe at any time.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?