Star Hospitals data leak: TGCSB registers case over alleged online exposure of patient records

HYDERABAD: The Central Crime Station (CCS) of the Telangana Cyber Security Bureau (TGCSB) has registered a case after sensitive personal and medical records of patients at Star Hospitals were allegedly leaked online.
Star Hospitals Chief Executive Officer Rahul Medakkar filed the complaint. He alleged that unknown persons uploaded confidential patient data and internal hospital information to a website without the hospital’s knowledge or permission. As a result, the hospital raised serious concerns about patient privacy and data security.
Website allegedly exposed patient and employee data
According to the complaint, the hospital’s IT team discovered confidential Star Hospitals data on a website identified as “warehouse.diy”. The hospital alleged that unauthorised users could access the information.
Moreover, the complaint stated that people were circulating login credentials for the website through WhatsApp. This increased the risk of unauthorised access to sensitive records.
The hospital alleged that the leaked database contained patients’ personal details, medical records, employee information and confidential internal documents.
If misused, the exposed data could put patients and employees at risk of identity theft, financial fraud and harassment. It could also damage the hospital’s reputation.
Hospital requests CERT-In support
The hospital told police that it shares data only with authorised technology partners for legitimate business purposes. These partners include Kranium Healthcare Systems, HEAPS Health Solutions India, Verventus Healthtech (Medblaze), IMImobile Cloud Communications (Cisco) and MarketXpander Services. It added that it had not authorised anyone else to access or publish the information.
Therefore, the hospital urged police to identify those responsible and take legal action. It also requested authorities to block the website, preserve server logs and metadata, and investigate the case with support from the Indian Computer Emergency Response Team (CERT-In) and the Indian Cyber Crime Coordination Centre (I4C).
Based on the complaint, CCS Headquarters police registered Crime No. 54/2025 under Sections 43 and 66 of the Information Technology Act, 2000, and Sections 303(2) and 316(2) of the Bharatiya Nyaya Sanhita.
Inspector D. Srinu is leading the investigation.
Police said they are examining the source of the alleged data leak. They are also investigating how the information was accessed and published. In addition, they are trying to determine whether any unauthorised individuals gained access to Star Hospitals’ systems.

