Serviceaide, an AI-powered IT management provider, inadvertently exposed a Catholic Health Elasticsearch database containing sensitive information of 483,126 patients for nearly seven weeks due to a misconfiguration, leading to potential privacy violations and identity theft risks.
In November 2024, California-based Serviceaide, a provider of AI-powered IT management and workflow software, discovered that an Elasticsearch database containing Catholic Health patient information had been inadvertently made publicly accessible. The exposure occurred between September 19 and November 5, 2024, affecting 483,126 patients from Catholic Health, a network of six hospitals in western New York. The exposed data included names, Social Security numbers, dates of birth, medical record numbers, patient account numbers, medical and health information, health insurance information, prescription and treatment information, clinical information, provider names and locations, and email usernames and passwords. While Serviceaide found no evidence that the information was copied, the company stated it could not rule out unauthorized access. The incident was reported to the U.S. Department of Health and Human Services on May 9, 2025. Serviceaide has implemented additional security measures and is offering affected individuals 12 months of complimentary credit and identity monitoring services. Multiple class action lawsuits have been filed against Serviceaide, and the incident highlights ongoing vulnerabilities in third-party healthcare IT systems.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
AI systems that memorize and leak sensitive personal data or infer private information about individuals without their consent. Unexpected or unauthorized sharing of data and information can compromise user expectation of privacy, assist identity theft, or cause loss of confidential intellectual property.
AI system
Due to a decision or action made by an AI system
Unintentional
Due to an unexpected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed