Serviceaide database exposure hit 483,000 Catholic Health patients

Organization
Serviceaide
Exploit
Misconfiguration
Industry
Information Technology

Serviceaide, a Santa Clara IT service management vendor, disclosed in May 2025 that an Elasticsearch database it maintained for Catholic Health had been reachable from the internet without any authentication. The six-hospital Catholic Health system, based in Buffalo, New York, uses Serviceaide as a business associate for IT support management.

According to the notice summarized by HIPAA Journal and SecurityWeek, the database was exposed from 19 September to 5 November 2024, a window of roughly six weeks. HIPAA Journal reported that Serviceaide identified the exposure on 15 November 2024.

The information at risk varied by individual and could include names, dates of birth, Social Security numbers, medical record and patient account numbers, medical and clinical information, health insurance details, prescription and treatment records, provider names and locations, and email addresses or usernames together with passwords. Serviceaide said forensic analysis found no evidence that data had been copied, but that exfiltration could not be ruled out.

Serviceaide reported the incident to the Department of Health and Human Services Office for Civil Rights on 9 May 2025, listing 483,126 affected individuals, and began mailing notification letters. Those affected were offered complimentary credit monitoring and identity theft protection services. SecurityWeek described the offer as covering 12 months.

Sources