Sharing an X-ray with an artificial intelligence, using an app to monitor sleep, or wearing a watch that records our heart rate are gestures that are becoming increasingly common. What we may not consider is what happens to all that information once we stop using those tools.
“We are not aware” of the amount of health information we share online and, above all, of the risk involved in losing control over it, explains Francisco Valencia, CEO of Secure & IT.
And indeed our medical data can have an unexpected value. According to the expert, a VIP person’s medical history can fetch between $1,000 and $2,000 on the black market, while when large quantities are involved they can be sold for between $10 and $20 for each record.
All that can be learned about you from your medical history
A disease, an operation, a treatment, or a therapy may seem like isolated data points, but together they offer a very complete picture of a person. If a cybercriminal gains access to a medical history, they can learn about “previous surgeries, illnesses, treatments, regimens or therapies” that their victim is undergoing.
Precisely for this reason, one of the main uses of this information is blackmail. Valencia recalls that in previous health-data breaches criminals have used information about intimate illnesses to threaten their victims and demand money in exchange for not making it public.
But the problem can go even further. Medical data can be combined with other personal information, such as purchases, taxes, or providers, to create much more complete profiles of each individual.
The danger of having too many health apps
You don’t need to do anything extraordinary to expose yourself. An app that counts our steps, a watch that records our sleep, or a tool that measures our heart rate can become new sources of personal information.
The problem, according to Valencia, isn’t necessarily that these apps are malicious, but that we are increasingly using more tools and syncing them together. “It’s better to have a single trusted app than many tools accessing all kinds of data,” he notes.
Furthermore, there is a particularly important habit that we tend to overlook: uninstalling an app does not necessarily mean that our data has vanished. When we stop using a service, we rarely verify that all stored information has been deleted.
Should you upload your medical reports to an artificial intelligence?
The popularization of artificial intelligence has added another everyday risk: using these tools to consult questions related to our health.
Valencia offers a very concrete example: if we have an X-ray that a doctor should analyze, “there is no need to upload it to an AI to get its opinion.” His recommendation is simple: before sharing any medical information, we should ask ourselves why we are sharing it and who might end up accessing it.
AI can also be used to create false images and pass them off as real. According to the expert, it only takes a single image that appears genuine for it to be used as a tool for blackmail, even if what it depicts never happened.
That’s why reducing the number of health apps, reviewing what data we share, and ensuring that our information is deleted when we stop using a service are among the measures Valencia recommends.
And in the face of any attempt at blackmail or suspicious health-related contact, he advises reporting it and informing the State Security Forces.