Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
July 30, 2025
No Result
View All Result
Concur News

Home » Security Breach Compromises Personal Data of Organ Donors

Security Breach Compromises Personal Data of Organ Donors

July 29, 2025
in India
Reading Time: 3 mins read
Security Breach Compromises Personal Data of Organ Donors
Share on LinkedinShare on Whatsapp

Massive Data Leak Found in AIIMS Organ Donor Website, Now Fixed

An independent researcher recently discovered a serious security issue on the website of the Organ Retrieval Banking Organisation (ORBO), which is part of the All India Institute of Medical Sciences (AIIMS), New Delhi.This vulnerability exposed the personal details of people who had voluntarily registered as organ donors from across India. The leaked information included names, health records, contact numbers, home addresses, blood groups, and even emergency contact details.

Aniket Tomar, a cybersecurity researcher, discovered the vulnerability in mid-May 2025. He reported the issue to the Indian Computer Emergency Response Team (CERT-In), which is responsible for handling cybersecurity threats in the country. After receiving his alert, CERT and AIIMS took action, and the exposed data is no longer available to the public.

What ORBO Does

ORBO plays a key role in organ and tissue donation in India. ORBO manages the registry of people who are declared brain dead and coordinates donations and transplants. It also works with hospitals to spread awareness and streamline the donation process.

Consent Foundation

Unfortunately, this platform had a flaw. It allowed anyone to access sensitive personal and medical information without logging in or providing any authentication.

This made it possible for unauthorized individuals to view data that should have remained private.

Expert Raises Alarm Over Data Safety

In his alert, Aniket Tomar warned that the data leak was serious and could allow cybercriminals to exploit it. They could use the exposed information for identity theft, phishing scams, and other harmful activities. He stressed that such a leak from a top medical institution like AIIMS damages public trust in India’s digital health systems.

Tomar further pointed out that the breach violated the rules set by the Digital Personal Data Protection (DPDP) Act, 2023. The Act requires institutions to protect sensitive personal data. He also urged the government to review and audit similar websites of other hospitals and health portals to ensure they are secure.

CERT Responds, ORBO Fixes Issue

CERT officially thanked Tomar on June 18, 2025, for his efforts. Tomar confirmed that the developers fixed the vulnerability and removed public access to the data. However, he recommended that AIIMS should notify all affected donors and take further steps to prevent such incidents in the future.

“I was able to see lakhs of donor records, and they were not just from Delhi—they came from across the country,” Tomar told The Hindu. “This is a serious privacy issue. People who donated their organs trusted the system to keep their information safe. That trust has now been shaken.”

He also called this more than just a technical problem—it’s an ethical issue that puts India’s entire healthcare system under the spotlight. People may hesitate to join life-saving programs like organ donation if they lose trust in how institutions handle their data.



Also read: https://news.concur.live/parliament-panel-questions-meity-on-delays-in-implementing-dpdp-act/

Tags: Data breachData privacyData ProtectionTechnology

Related Posts

Rajya Sabha Wants Clear Meaning of ‘Traffic Data’ in New Telecom Cybersecurity Rules
India

Rajya Sabha Wants Clear Meaning of ‘Traffic Data’ in New Telecom Cybersecurity Rules

July 30, 2025
States Sue Trump Administration Over Data Collection from SNAP Recipients
LAW

States Sue Trump Administration Over Data Collection from SNAP Recipients

July 30, 2025
Allianz - news.concur.live
China

Major Data Breach at Allianz Life Exposes Personal Information of Customers

July 30, 2025
Sanjiv
Interview

Interview with Sanjiv Arora on Leading Cybersecurity Strategy Across RBI, IRDA, SEBI, and DPDPA Compliance

July 30, 2025

RECOMMENDED NEWS

DAU Unveils Executive Programme on Data Privacy and AI

DAU Unveils Executive Programme on Data Privacy and AI

5 days ago
ID Privacy

Data Safeguard India Unveils ID-PRIVACY

4 months ago
Are Gurugram's Gate Apps Compromising Your Privacy?

Are Gurugram’s Gate Apps Compromising Your Privacy?

3 months ago
Tiffany Korea

Tiffany Confirms South Korea Data Breach After Similar Dior Incident

2 months ago

BROWSE BY TOPICS

AI AI Governance AI in education AI Privacy banks Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital Digital India DPDP DPDPA DPDP Act Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy RBI SPAM Startek Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager