SHINDO4

Mazda Hospital

Patients626people

EXPOSEDHealth / medical / treatment / Full nameMisconfiguration · Closed (final report)

Open in the live monitor ▶
Disclosed
May 11, 2026
Detected
Nov 2024
Detection to disclosure
556 days
Leak
Exposed, access unknown
Type
Misconfiguration
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityName in Roman letters or katakana
Account dataPatient ID
Special-care dataScan date, type, body part and number of parts

Not leaked

  • Images, test results and diagnoses were not included

How many

  • Patients 626 people

Who is affected

  • Patients who had CT, MRI or RI scans in February and March 2021

Cause

When the contractor saved patient data to the cloud, the sharing setting had no access restriction, so third parties could view it

Timeline

  1. Saved to the cloud with the wrong setting
  2. The contractor noticed the setting error
  3. Setting fixed and access blocked
  4. The contractor formally reported to the hospital
  5. Security NEXT report date

Response

  • Config review
  • Notified individuals

Notified patients individually; cloud setting already fixed

What you should do

  1. Health data can't be taken back. Don't answer blackmail; call the police (#9110) or the consumer hotline (188)
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Two-person review and pre-release tests for sharing and cache changes; monitor cloud config (CSPM)
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources