AIIMS Data Theft: How Safe Are We From Online Threats?
AIIMS authorities took six days to recover the hospital’s e-data, which had been compromised following a ransomware attack on its servers. However, the network is still being cleaned up, and it might take some more time before the online services are fully restored, according to sources.
The process is taking some time due to the volume of data and the numerous servers and computers used for hospital services, according to a statement released on Tuesday by AIIMS. They omitted to mention the day that online services would resume, though. Officials from AIIMS stated that “measures are being taken for cyber security” and added that all hospital services, including outpatient, inpatient, and laboratory operations, continue to operate manually.
AIIMS Lost Data Of Around 4 Crore Patients
Faculty members and other AIIMS staff were instructed to install a new antivirus and given step-by-step instructions for doing so. They are instructed to remove the old antivirus software from the computer.
On day seven of the server outage, patient care services in the OPD, billing, and labs were being managed manually. However, the hospital administration issued an SOP for manual sample processing. It stated that only “priority samples” will be taken up.
It is feared that the breach discovered on November 23 may have exposed the data of 3–4 crore patients. The administration is keeping quiet about this matter, though.
Two Analysts Suspended
The Intelligence Fusion and Strategic Operations division of the Delhi Police has filed a case of cyberterrorism and extortion. In a statement released on Monday, the Delhi Police claimed that the AIIMS authorities had not been made aware of any ransom demand, despite reports to the contrary in some media outlets.
Two system analysts have been suspended by the hospital administration because of some procedural errors. They have also received show cause letters for alleged duty neglect.
Internet Services Blocked in Hospital Buildings
According to the official sources, the investigating agencies’ recommendations led to the hospital’s internet services being disabled.
It is important to note that the AIIMS server has medical records for a number of high-profile individuals, including former prime ministers, ministers, officials, and judges.
Hackers have allegedly demanded around Rs 200 crore in cryptocurrency, according to one of the sources.
NIC Team at Work
The NIC e-hospital database and application servers have been back online in the interim. According to sources, the NIC team is sanitising other AIIMS-located e-hospital servers that are necessary for the provision of medical services.
Four physical servers have been set up, scanned, and ready for the databases and applications in order to restore e-hospital services.
In addition, the AIIMS network is being sanitised, and antivirus programmes have been set up for computers and servers.
Out of 5,000 computers, antivirus has been installed on almost 1,200 so far.Twenty out of 50 servers have reportedly been scanned, and this activity is ongoing around-the-clock, according to sources.
The AIIMS ransomware attack and the significant data breach that affected millions of people, including dignitaries of the Indian government, judiciary, and administrative bodies, present a convincing argument for how the legislature is unaware of the true risks to data privacy.
What issues does the draught bill on digital personal data protection not address?
Due to the unethical hacking of their personal data, which left them open to extortion by Chinese loan apps, many Indian citizens lost their lives.
Although the Chinese loan apps’ victims’ families and loved ones may never receive compensation, the Enforcement Directorate (ED) is pursuing the offenders. This is due to the fact that the draught bill on digital personal data protection does not address misuse of data by criminals.
Who should be held accountable for the cyberattack and who should pay out compensation is up for debate even in a case like AIIMS. It must be remembered that the law applies to all data fiduciaries operating in India, with the same implications for AIIMS.
Should AIIMS be regarded legally as a data fiduciary who has compromised vital information about Indian citizens or as a victim of a data breach?
The truth is that there are no laws dictating what security precautions a private or public organisation must take to protect the data it holds. Only situations where a data-fiduciary compromises personal digital data due to non-compliance are covered by the current Draft Bill.
Should you be concerned about your privacy when your security is compromised?
The Fortune India report on Digital Policy Paralysis, which was released on November 4, 2022, highlighted the vulnerability of digital India. As things stand today, India lacks a law that effectively addresses real-life cases like the AIIMS cyber attack, which pose real threats to citizens’ lives due to data breaches.
The Delhi Police’s Intelligence Fusion and Strategic Operations (IFSO) division has filed an extortion and cyberterrorism case in connection with the cyber-attack on AIIMS. The case must be added to the long list of cyber-attacks that have plagued India for many years with little respite for the victims.
In the first half of 2022, the Indian Computer Emergency Response Team (CERT-In) reported more than 6.7 lakh cyber security incidents. The average cost of a data breach in India is $2.32 million, according to IBM’s Cost of Data Breach 2022 report. A single data breach costs a company an average of Rs. 17.4 crore.
Since 2018, the legislature has engaged in multiple deliberations and likely expended countless man-hours in preparing three draft-bills on the issue of personal data-privacy. However, the latest Draft Bill on Digital Personal Data Protection is not only the most ambiguous and ineffective of the three, but it also fails to ensure data security for Indian citizens.
Conclusion
When it comes to developing legislation for data privacy and protection, there appears to be a dichotomy between the threat to the nation and the threat perceived by the government.
The authorities appear to place an unequal value on user-generated content in regulatory frameworks, with free speech appearing to be the pivotal threat perceived.
The Ministry of Electronics and Information Technology’s current Social Media regulations are largely designed to prohibit social-media posts that violate public policy. The government also has the authority to direct a social media intermediary to remove any posts or block any individual from accessing his or her social media account without giving the individual posting the content any notice.