ADD ANI AS A TRUSTED SOURCE
googleads
Menu
General News

CoWIN data leak: Centre says portal completely safe, reports of leak 'mischievous'

The Centre on Monday said that the CoWIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy and teamed the media reports claiming breach of data of beneficiaries who have received COVID vaccination in the country as "mischievous in nature".

ANI Jun 12, 2023 16:55 IST googleads

Representative Image

New Delhi [India], June 12 (ANI): The Centre on Monday said that the CoWIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy and termed the media reports claiming breach of data of beneficiaries who have received COVID vaccination in the country as "mischievous in nature".
There are some media reports claiming the breach of data of beneficiaries who have received COVID vaccination in the country, on some social media platforms. These reports allege a breach of data from the Co-WIN portal of the Union Health Ministry, which is repository of all data of beneficiaries who have been vaccinated against COVID19, the statement said.
Certain posts on the social media platform Twitter have claimed using a Telegram (online messenger application) BOT, the personal data of individuals who have been vaccinated is being accessed. It is reported that the BOT has been able to pull individual data by simply passing the mobile number or Aadhaar number of a beneficiary.
According to the statement, it is clarified that all such reports are without any basis and mischievous in nature. The CoWIN portal of the Health Ministry is completely safe with adequate safeguards for data privacy. Furthermore, security measures are in place on the Co-WIN portal, with Web Application Firewall, Anti-DDoS, SSL/TLS, regular vulnerability assessment, Identity & Access Management etc. Only OTP authentication-based access to data is provided. All steps have been taken and are being taken to ensure the security of the data in the CoWIN portal.
COWIN was developed and is owned and managed by MoHFW. An Empowered Group on Vaccine Administration (EGVAC) was formed to steer the development of COWIN and for deciding on policy issues. The former CEO National Health Authority (NHA), chaired EGVAC which also included members from MoHFW and MeitY, the statement added.
Co-WIN data access - At present individual level vaccinated beneficiary data access is available at three levels, as below:
Beneficiary dashboard- The person who has been vaccinated can have an access to the Co-WIN data through use of registered Mobile number with OTP authentication.
Co-WIN authorized user- The vaccinator with use of authentic login credential provided can access personal level data of vaccinated beneficiaries. But the COWIN system tracks & keeps record of each time an authorized user accesses the COWIN system.
API based access - The third party applications who have been provided authorised access of Co-WIN APIs can access personal level data of vaccinated beneficiaries only through beneficiary OTP authentication.
Telegram BOT -
Without OTP vaccinated beneficiaries' data cannot be shared to any BOT.
Only Year of Birth (YOB) is captured for adult vaccination but it seems that on media posts it has been claimed that BOT also BOT mentioned date of Birth (DOB).
There is no provision to capture address of beneficiary.
The development team of COWIN has confirmed that there are no public APIs where data can be pulled without an OTP. In addition to the above, there are some APIs that have been shared with third parties such as ICMR for sharing data. It is reported that one such API has a feature of sharing the data by calling using just a mobile number of Aadhaar. However, even this API is very specific and the requests are only accepted from a trusted API that has been white-listed by the Co-WIN application, the statement further said.
Union Health Ministry has requested the Indian Computer Emergency Response Team (CERT-In) to look into this issue and submit a report. In addition, an internal exercise has been initiated to review the existing security measures of CoWIN.
CERT-In in its initial report has pointed out that the backend database for the Telegram bot was not directly accessing the APIs of the CoWIN database. (ANI)

Get the App

What to Read Next

Politics

Giriraj Singh slams Rahul Gandhi over conduct in Parliament

Giriraj Singh slams Rahul Gandhi over conduct in Parliament

Speaking to reporters here on Thursday, Singh said the opposition had sought permission to speak on the issue of LPG, but did not adhere to the subject.

Read More
Politics

YSRCP files PIL challenging Andhra Pradesh govt’s land policy

YSRCP files PIL challenging Andhra Pradesh govt’s land policy

Former Andhra Pradesh Minister Gudivada Amarnath on Thursday said that the YSR Congress Party (YSRCP) has filed a Public Interest Litigation (PIL) challenging the land policy of the state government, alleging that large extents of valuable public land are being allotted to a few real estate companies at very low prices.

Read More
Politics

Congress' Muraleedharan says LPG shortage "affecting families"

Congress' Muraleedharan says LPG shortage

"Most of the hotels are closed. Even in the few that are open, we are not getting proper food. This situation is affecting families as well. Therefore, we request the Central Government to intervene in this matter and take strong action to ensure the supply of LPG gas," Muraleedharan told reporters in Thiruvananthapuram.

Read More
General News

Woman found dead in hotel room in North Delhi

Woman found dead in hotel room in North Delhi

According to Delhi Police, around 12:30 am, staff of Prince Hotel located at SPM T-point on Church Mission Road informed the beat staff that Room No. 205 was locked and the guest inside was not responding despite repeated knocking.

Read More
Politics

"No shortage of petrol, diesel or LPG": Hardeep Singh Puri

In his statement in the Lok Sabha, Puri said the government has taken multiple measures to safeguard the country's energy security and ensure the uninterrupted availability of petroleum products, cooking gas, and natural gas.

Read More
Home About Us Our Products Advertise Contact Us Terms & Condition Privacy Policy

Copyright © aninews.in | All Rights Reserved.