Sernac demands details from Clínica Dávila after massive data leak

Chile's National Consumer Service (Sernac) has issued a formal request to Clínica Dávila following a cyberattack that leaked about 250 gigabytes of sensitive patient data. The agency demands detailed information within 10 business days on the incident, attributed to a foreign ransomware group named Devman. Compromised data includes clinical records, diagnoses, and medical test results, such as HIV screenings.

Chile's National Consumer Service (Sernac) has stepped in regarding a serious cybersecurity incident at Clínica Dávila and Servicios Médicos S.A., where a hack led to the exfiltration of roughly 250 gigabytes of confidential patient information. The attack, linked to the foreign ransomware group Devman, exposed clinical files, medical diagnoses, sensitive test results including HIV screenings, identity card copies, and operational databases of the facility.

Sernac has required the clinic to provide within 10 business days a timeline of the incident, the total number of affected patients broken down by data type, existing security measures at the time of the breach, and the attack vector used. It also seeks details on containment actions, notification methods to those impacted, received complaints, and preventive steps for future threats. The clinic must state its stance on potential civil and administrative liabilities.

The agency stressed that data protection is a core right under the Consumer Protection Law (LPC). Failure to meet the deadline could prompt judicial and administrative actions from Sernac. It urged possible victims to file claims through the Consumer Portal using Clave Sernac or ClaveÚnica, or via phone and in-person channels nationwide.

This episode highlights the fragility of healthcare systems to cyber threats, emphasizing the importance of strong security protocols to protect patient privacy.

संबंधित लेख

Illustration of ANCI-confirmed cyber infiltration in Chilean public agency due to stolen credentials, featuring hacker screens and government imagery.
AI द्वारा उत्पन्न छवि

ANCI confirms infiltration in public agency due to stolen credentials

AI द्वारा रिपोर्ट किया गया AI द्वारा उत्पन्न छवि

Chile's Agencia Nacional de Ciberseguridad (ANCI) detected an infiltration in a public agency after a staff member's login credentials were stolen. Security Minister Trinidad Steinert described the alert as delicate and deferred the investigation to ANCI. The issue was resolved by closing accesses, though most circulating data stems from prior leaks.

Chile's National Cybersecurity Agency (ANCI) ruled out a recent cyberattack following reports of a suspected data leak at the General Treasury of the Republic (TGR). Authorities confirm services are operating normally and data was previously leaked. Lawmakers voiced concerns over structural cybersecurity shortcomings.

AI द्वारा रिपोर्ट किया गया

Colombian banks face a potential indirect cyberattack via an external debt collection provider, compromising customer data such as names, IDs and phone numbers. BBVA and Nu Colombia confirmed the incident and activated security protocols. No entity reports access to keys or deposits.

The PSPV denounced an internal circular from April 27 that denied validity to health certificates for the migrant regularization process. Conseller Marciano Gómez clarified it was a draft and presented the official May 6 document ordering that required documentation be provided.

AI द्वारा रिपोर्ट किया गया

The National Health Superintendency ordered the closure of plastic surgery, aesthetic and pharmaceutical services at Clínica Láser Surgical in Bogotá for violating a prior precautionary measure.

A report by the Génération Libre think tank links rising data breaches in France to European regulations. The CNIL is tightening controls after a record year in 2025.

AI द्वारा रिपोर्ट किया गया

A hacker known as Rootboy has begun daily data dumps from Standard Bank's systems on the dark web since 14 April, following the bank's refusal to pay a 1 Bitcoin ransom. The attack, which started on 27 February, exfiltrated 1.2TB of data from Standard Bank and Liberty. The bank has confirmed exposure of some credit card details but no CVV numbers.

 

 

 

यह वेबसाइट कुकीज़ का उपयोग करती है

हम अपनी साइट को बेहतर बनाने के लिए विश्लेषण के लिए कुकीज़ का उपयोग करते हैं। अधिक जानकारी के लिए हमारी गोपनीयता नीति पढ़ें।
अस्वीकार करें