← the record
AIAAIC-0315

Cense AI exposes 2.5 million personal records

A data leak i nvolving the exposure of approximately 2.5 million sen sitive personal records by New York-based Cense AI raised questions about the company's security. Records exposed in what seemed to be a temporary repository intended for staging purposes, possibly for use in an AI bot or management system , included sensitive personal information such as names, insurance details, medical diagnosis notes, and payment records. The data appeared to be related to individuals involved in car accidents, with references to chiropractic and neck or spinal injuries. The leak was discovered by a security researcher who identified the records as publicly accessible online. Upon validation, the researcher promptly notified Cense AI, leading to the restriction of public access to the database. The exposure of such sensitive medical data is viewed as particularly concerning due to its high value on the black market, where medical records can be sold for significantly more than other types of personal information. System 🤖 Unknown Operator: Cense AI Developer: Cense AI Country: USA Sector: Automotive; Health Purpose: Technology: Machine learning Issue: Privacy; Security

Date it happened
2020-08-01
Organisation involved
Cense AI
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.