LifeLabs pays ransom after data breach affecting up to 15M Canadians
theglobeandmail.com
theglobeandmail.com
I have tried more than once to make secretaries, assistants and nurses to understand how bad most of their systems are and how easy it is to expose the information of all their patients to malicious actors, but arguing with them is pointless because they barely understand what I am talking about or do not have the power to change anything. And the worst thing is, I have to visit LifeLabs again next month for another physical checkup and to take some X-rays and these news will not change anything.
Side note…
I used to work as a malware researcher for a security information company in the US. One day I remembered the story of Sisyphus:
> In Greek mythology Sisyphus was the king of Ephyra (now known as Corinth). He was punished for his self-aggrandizing craftiness and deceitfulness by being forced to roll an immense boulder up a hill only for it to roll down when it nears the top, repeating this action for eternity — https://en.wikipedia.org/wiki/Sisyphus
I ended up quitting my job no long after reading this story because it made me realize I was fighting an endless fight.
You knew from the moment you walked into the laboratory that their data handling practices were inadequate and prone to being hacked/leaked. How?
You tried to explain this to their secretaries and nurses. Why bother when it's obvious they can't/won't do anything about it? Why not contacting their management or IT?
The laboratory is divided into small rooms where the patient talks with the nurse and/or doctor, each room looks something like this [1] along with a computer that is connected to whatever system LifeLabs uses. When I arrived for my appointment the nurse left me alone in the room for approximately 15 minutes, the computer was on, and the user session (which I believe was created using the doctor’s credentials) was still alive, I could have done a lot with that computer while the nurse was outside checking the other patients.
Later, the doctor came to do the initial physical checkup and then left for another 10-15 minutes to talk with another nurse. This gave me more time to “snoop around” and in fact, I took the opportunity to take a picture of the computer screen [1]. Ironically, you can see in the picture that the doctor uses a Post-it Note to cover the webcam, which means they do care about their privacy but not the privacy of their patient’s.
You may think “this is not LifeLabs fault but the doctor’s fault” but this is how social engineering works and as people say “A chain is only as strong as its weakest link”.
> You tried to explain this to their secretaries and nurses.
> Why bother when it's obvious they can't/won't do anything about it?
> Why not contacting their management or IT?
Yes, good point, but this doesn’t disprove the rest of my anecdote.
I witnessed that happen to a few prominent financiers in Toronto while I was getting some bloodwork done. It was terrifying within about 5 minutes I had all the personal information I’d need to do some seriously nefarious things.
This happens on most every occasion I visit a clinic in Canada. Nurses and secretaries do not care.
Not sure what the solution is.
Yes yes I know Sisyphus is a metaphor for the pointlessness of life - but that doesn't mean you have to take it at face value.
or perhaps that the work itself is the reward
In the original myth the rock rolls down alright, but it rolls down over our hero and then he has to go down and push it back up again knowing what will happen.
The other main option is Dynacare. Besides those two, who else is there? Both have built up convenient infrastructure where results are fed back into doctors' EHR systems.
I wouldn't be against more competition, but it seems that there are certain economies of scale that make bigger more efficient:
* https://healthydebate.ca/2015/02/topic/private-medical-labs-...
* https://toronto.citynews.ca/2017/12/22/lab-industry-need-ove...
Side note: LifeLabs is owned by the OMERS pension fund.
Welcome to the Canadian Healthcare system. It's free, but not without issue, even ignoring the long wait times and inability to get a doctor in most places in the country.
Did you know I'm not allowed to go get my blood tested privately, even if I pay for it? That I require a requisition from a doctor (which I don't have, so I have to go to a walk-in clinic and take up the time of a doctor who could care less what they are signing)? And that the results then get shared back with said doctor, who's discretion it is what data he shares with me? It's bizarre.
I often see Americans pointing to Canada's system as a shining example. I mean, sure, we don't have crushing medical debt, which is AWESOME. But our healthcare system has so many problems itself...
I'm not saying it shouldn't be an option for blood tests in particular (as is your example) but there are multiple things to consider when you start opening those up to anyone willing/able to pay.
Do you really think a walk-in doctor "could care less"? What a ridiculous statement. They're just as professionally governed and concerned as any doctor.
"Did you know I'm not allowed to go get my blood tested privately"
There are private blood testing services in Canada, though it's a small market given that the workflow of labs is overwhelmingly geared towards the public market. Most labs will happily provide you your own blood test results (a cursory search of both LifeLabs and Dynacare, two of the most common, show their patient portals).
"I often see Americans pointing to Canada's system as a shining example"
Canada is almost always the punching bag for the US -- usually based upon lies or the singular complainer, for instance I and my family have had a family doctor everywhere we've lived, have always had a great experience, etc -- and of course -- like every complex system in the world -- it has flaws. But it isn't as good as France's system, or a couple of others.
Whomever broke into their systems knows a great deal about the private health information of a large fraction of Canadians.
Here in Quebec we generally get our blood drawn for tests at a local public clinic called a CLSC, and can eventually view the results in a public government web system, but I'm not sure where the actual analysis happens.
That’s it? If I was Canadian I’d want to see execs going to jail and or their contract yanked. If they switched over to using a webapp or chromeos on the desktop things would probably be much more secure.
But that’s not going to happen, cuz it’s owned by the pension system.
Also wonder how motivated they are to do security right if insurance covers it: In an interview, LifeLabs CEO Charles Brown said the company had purchased cyberinsurance, but did not provide details on the coverage.
It makes me sad to see Marriott, Equifax and others skipping along with stocks at near record highs and little long-term impact from their incidents.
To go where? Socialized healthcare creates monopolies. There are few competitors. You trust your data more to some upstart entity that doesn't yet exist?
I guess in the future with all these data breaches one will be able to get any private information on just about anyone by paying for it on the dark net. Basically there will be darknet data brokers who basically have unlimited inventory of information because they aggregate from the various data breaches.
Will people get spam calls from a call center in a low cost country that bring up your test results from LifeLabs and threaten to share them with your employer or significant other unless you pay up?
If not now, this will be happening in the near future.
Here is the CEO's letter to those 15 million or so victims: https://customernotice.lifelabs.com
Concerned Canadians could/should contact their government about this incident. I don't have a deep link but assume it's buried in this maze: https://www.priv.gc.ca/
[1] https://www.lifelabs.com/lifelabs-releases-open-letter-to-cu...
I would not be surprised if a LOT of Lifelabs customers used the same password on their Lifelabs accounts that they use for their email. FWIW, Lifelabs has two sub-sites that use different credentials - one for test results, and one for booking appointments.
- if you have a condition that puts you at higher risk for receiving disability or workers compensation.
- if you have been pregnant and when.
- if you got tested for an STD because you thought you needed to, and the frequency of your testing.
- if you have an STD and around when you contracted it.
That's without getting into specifics around medications, and the greater harm of people not getting tests done because they do not trust the privacy and security of the health system. These are typical threat model use cases in health information privacy assessment and systems design.
In terms of consequences, the disclosure risk of this information can break up families and households, and silently disqualify people from jobs, both of which put their kids at a long term disadvantage, destroys familial wealth and assets, and in effect impoverishes everyone involved.
Once the gravity of this sinks in, I'd be concerned for the mental health of the CEO.
I'm confused, how do you pass from "proactive surveillance" to "there's a ransom to pay"?
Is anyone surprised they actually got the data back? Why are they convinced the 'hackers' won't still do anything with it.
Reporting is weak on this as it doesn't say straight out ransomware that encrypted machine with data. That it likely came from any random email that someone opened. Not that there's some evil hacker person on the other end targetting LifeLabs and it could and does happen to anyone.