30,000 Cannabis Users’ Data Exposed

Robinson+Cole Data Privacy + Security Insider
Contact

A point of sale vendor for at least three cannabis dispensaries in the United States exposed the personal data of at least 30,000 cannabis users, including full names, photo IDs, dates of birth, telephone numbers, home addresses, medical ID numbers, email addresses, signatures, cannabis variety and quantity purchased, and sales figures when it failed to password protect the information online.

According to security researchers, the exposure of the information in the cloud occurred between December 24, 2019, and January 14, 2020, when 85,000 files were left unprotected in a cloud database. They “were able to access…the database because it was completely unsecured and unencrypted. We could access all files hosted on the database.”

Two of the dispensaries that used the third-party point of sale vendor dispense medical marijuana, while the third dispenses cannabis for recreational use.

According to the security researchers at vpnMentor, “This raises serious privacy concerns. Medical patients have a legal right to keep their medical information private.” Others have commented that the information could be used by threat actors for targeted scams, sophisticated phishing attacks, or embarrassment and shame scams.

One of the dispensaries admitted that its users’ information may have been involved, and that it will identify and notify any affected individuals as required under HIPAA.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide