• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

EHR Fax Server Error Exposes Thousands of Physician Notes, Medical Records

by Fred Pennic 03/18/2019 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
EHR Fax Server Error Exposes Thousands of Physician Notes, Medical Records
Two leaked documents found on the fax server, redacted. (Image Credit: TechCrunch)

Thousands of physicians’ notes and medical records were left exposed by a fax server error within Meditab, an all-in-one multi-specialty EHR, Practice Management and Billing software solution, TechCrunch first reports. Dubai-based cybersecurity firm SpiderSilk discovered the unsecured exposed fax server was running an Elasticsearch database with over 6 million records since its creation in March 2018. It is unknown if anyone else discovered the exposed fax server or how long the data was exposed.

Exposed Fax Server Error Details

Since the fax server did not have a password, anyone was able to read the transmitted faxes in real-time that contained medical records, doctor’s notes, prescription amounts, and quantities, as well as illness information, such as blood test results. In addition, the faxes contained exposed names, addresses, dates of birth, and in some cases Social Security numbers and health insurance information and payment data.  None of the data was encrypted, which also included personal and health information on children.

The compromised fax server was hosted on an subdomain of MedPharm Services, a Puerto Rico-based affiliate of Meditab. TechCrunch reached out to several patients who confirmed their exposed details from the faxes.

Next Steps

TechCrunch reached out to Meditab COO Kalpesh Patel who stated in an email response the company is “looking into the issue to identify the problem and solution.” The company’s general counsel  Angel Marrero said, “we are still reviewing our logs and records to access the scope of any potential exposure.” When asked if Meditab plans to inform regulators and customers about the exposed records. Marrero stated the company “will comply with any and all required notifications under current federal and state laws and regulations, as applicable.”

Related: Does the Fax Machine Still Have A Place in Modern Healthcare?

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Cybersecurity, healthcare security breaches, medical records, Secure Cloud Faxing, secure patient data

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Research Report

2026 Best in KLAS Awards: The Full List of Software & Services Winners

Most-Read

The "Platform" Squeeze: Epic Releases Native AI Charting, Putting Venture-Backed Scribes on Notice

The “Platform” Squeeze: Epic Releases Native AI Charting, Putting Venture-Backed Scribes on Notice

Analysis: Oracle Cerner’s Plans for a National EHR

Oracle May Cut 30k Jobs and Sell Cerner to Fund $156B OpenAI Deal

The $1.9B Exit: Why CommonSpirit is Insourcing Revenue Cycle and Tenet is Betting Big on Conifer AI

The $1.9B Exit: Why CommonSpirit is Insourcing Revenue Cycle and Tenet is Betting Big on Conifer AI

KLAS 2026 Rankings: Aledade and Guidehealth Named Top VBC Enablement Firms

KLAS 2026 Rankings: Aledade and Guidehealth Named Top VBC Enablement Firms

Beyond the Hype: New KLAS Data Validates the Financial and Clinical ROI of Ambient AI

Beyond the Hype: New KLAS Data Validates the Financial and Clinical ROI of Ambient AI

Anthropic Debuts ‘Claude for Healthcare’ and Opus 4.5 to Engineer the Future of Life Sciences

Anthropic Debuts ‘Claude for Healthcare’ and Opus 4.5 to Engineer the Future of Life Sciences

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

OpenAI Debuts ChatGPT Health: A ‘Digital Front Door’ That Connects Medical Records to Agentic AI

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

From Genes to Hackers: The Hidden Cybersecurity Risks in Life Sciences

Utah Becomes First State to Approve AI System for Prescription Renewals

Utah Becomes First State to Approve AI System for Prescription Renewals

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

NYC Health + Hospitals to Acquire Maimonides in $2.2B Safety Net Overhaul

Secondary Sidebar

Footer

Company

  • About Us
  • 2026 Editorial Calendar
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2026. HIT Consultant Media. All Rights Reserved. Privacy Policy |