Discovered inadvertent data disclosure

This isn’t hacking per se, but i did come across a local hospital’s data from a server purchase on fb marketplace. This includes SSNs for some patients. Is this worth any compensation by reporting to some agency or the hospital itself?

The servers seemed to be past the lifecycle as it is a R730.

Kind of surprised they didn't destroy or take the drives.

There was vmware on the server and it was behind a password but simply installing vmware on another drive and mounting the vhd to a new vm provided full access.

Any thoughts?

submitted by /u/mrfixerevo
[link] [comments]

from hacking: security in practice https://ift.tt/KDOeQC0

Comments