Government Fixes Security Flaw in eHospital Portal That Was Exposing Data of Millions of Patients

The eHospital portal registered over 4.83 million patients across India just in the month of April.

Advertisement
By Jagmeet Singh | Updated: 3 May 2022 13:31 IST
Highlights
  • eHospital was exposing data due to a misconfigured cluster
  • The portal is aimed to digitise hospital records
  • NIC is the developer and maintainer of the eHospital portal

Bad actors could have been able to steal patients' medical history and personal data

Photo Credit: Unsplash/ charlesdeluvio

The government has fixed a server-side issue within its cloud-based hospital management information system called eHospital that was exposing personally-identifiable data including full name, age, date of birth, gender, and phone number of a large number of patients. The exposed data also included patients' medical history and their last visited hospital details, according to a researcher who informed about the issue to Gadgets 360. The eHospital portal is meant for digitising records of government hospitals and register medical facilities as well as doctors on a single platform.

Ukraine-based independent security researcher Bob Diachenko discovered the data exposed from the eHospital portal due to a misconfigured Elasticsearch cluster. He informed Gadgets 360 that due to the misconfiguration, the portal was allowing anyone on the Internet to access personal data of millions of registered patients.

Immediately after understanding the issue, Gadgets 360 reached out to the National Informatics Centre (NIC) — the developer behind the eHospital portal. The NIC team resolved the issue shortly after it was reported, and confirmed to Gadgets 360.

Advertisement

Due to the misconfigured cluster, a bad actor could have been able to steal patient details stored on the portal.

Advertisement

"At times, DevOps forget to close the permissions, opened for live data access for fixing the problem. It sometimes leads to temporary data leak and is identified by ethical hackers and cybersecurity researchers. They inform concerned organisations to plug the issues. In this case, the issue of access to data was immediately closed as soon as it was reported by cybersecurity researcher. We are thankful to them for timely reporting of the issue and confirming its closure as well," an NIC official told Gadgets 360.

According to the statistics available on the eHospital dashboard, the portal registered over 4.83 million patients across India in the month of April and ​​processed over 2.48 billion transactions since its launch in 2015. There are also over 631 hospitals on board, which include both state and central government hospitals.

Advertisement

The government launched eHospital as one of its initiatives to digitise governance in the country.

In November last year, the Union Health Ministry started digital registrations of all medical facilities and doctors under the Ayushman Bharat Digital Mission. The government made eHospital by NIC as well as e-Sushrut by Centre for Development of Advanced Computing (C-DAC) as the two solutions to digitise health records for hospitals, according to news reports.

Advertisement

Back in 2017, some security flaws within the eHospital Online Registration app had allegedly allowed a Bengaluru-based software engineer to access Aadhaar numbers and personal details of citizens. Cybersecurity experts at the time highlighted that the app was not encrypting its communication with NIC's servers. The NIC, as a result, had pulled the app altogether.


Xiaomi 12 Pro is littered with features, but is that enough? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement
Popular Mobile Brands
  1. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  2. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  3. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  4. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  5. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  6. Nubia Neo 5 GT Announced With 6,210mAh Battery: Check Price, Features
  7. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  8. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  9. Google to Allow Alternative Billing, Easier Third-Party App Store Access
  10. Xiaomi Targets Apple-Style Annual Chip Upgrades, Global Rollout Planned
  1. MWC 2026: Oppo, MediaTek Join Hands to Showcase New On-Device AI Capabilities for Future Smartphones
  2. Lava Bold 2 5G India Launch Teased; Company Teases Design Ahead of Debut
  3. Nubia Neo 5 GT With MediaTek Dimensity 7400 SoC Launched at MWC 2026: Price, Specifications
  4. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices This Year
  5. Google Play Announces New Android Policies With Expanded Billing Options, Eases Access to Third-Party App Stores
  6. Google's NotebookLM Upgraded With Cinematic Video Overviews Feature
  7. Infinix Note 60 Ultra Launched at MWC 2026 With Pininfarina Design, Satellite Calling: Price, Specifications
  8. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  9. OnePlus 15T Teasers Confirm Larger Battery, Faster Charging Speed and Higher IP Rating
  10. Nothing Phone 4a Pro Teaser Suggests Presence of Phone 3's Glyph Matrix Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.