TechCrunch reported on July 16, 2021 that California insurance-technology startup BackNine had a misconfigured Amazon storage bucket that allowed anyone to access its 711,000 files. BackNine builds back-office software for carriers that sell life and disability insurance and offers a white-label quote form. The files included completed applications with names, addresses, phone numbers, Social Security numbers, diagnoses, medications, health questionnaires, and lab and test results such as blood work and electrocardiograms, plus images of signatures. None of the data was encrypted.

The documents dated from 2015 to the month of the report. Security researcher Bob Diachenko emailed the company in early June, got an initial response, then heard nothing and the bucket stayed open. TechCrunch also contacted BackNine's vice president Reid Tattersall and was ignored. Within minutes of TechCrunch giving the bucket's name to Tattersall alone, the data was locked down.

Many of the applications were for large carriers including AIG, TransAmerica, John Hancock, Lincoln Financial Group and Prudential, which did not comment. BackNine did not answer whether it had alerted authorities under state breach-notification laws or would notify the affected individuals.

Because Amazon buckets are private by default, someone at BackNine had to change the permissions to public.

The files were stored unencrypted, so open access meant full access to sensitive personal and medical data.

The company did not act on the researcher's early-June warning until a journalist named the bucket in July.

Storage that is private by default has to be made public by someone. Leaving applicants' health data open, then ignoring the researcher who warned, turns a setting error into a disclosure failure.

The bucket was locked down within minutes of TechCrunch's email to Tattersall. As of publication, BackNine had not responded to TechCrunch's questions about breach notification, and TechCrunch noted companies can face stiff penalties for failing to disclose a cybersecurity incident.

FOLLOW THE EVIDENCE

The sources

  1. An insurtech startup exposed thousands of sensitive insurance applications techcrunch.com