Menu

Hyderabad’s STAR Hospitals alleges confidential patient data was leaked, published online; FIR registered

The hospital alleged that the information published on the website included "patient records, medical/health information, employee or organizational confidential data," which it said constitutes "personal data" and "sensitive personal data."

Published Aug 03, 2026 | 1:58 PMUpdated Aug 03, 2026 | 1:58 PM

Hospital data
Make Us Your Preferred Source on Google

Synopsis: Hyderabad-based STAR Hospitals has alleged that confidential patient and organisational data was published on an unauthorised website, with login credentials allegedly circulating on WhatsApp. The Telangana Cyber Security Bureau has registered a criminal case and launched an investigation into the alleged exposure, while the hospital seeks immediate takedown of the website and preservation of digital evidence.

Hyderabad-based STAR Hospitals has alleged that confidential patient records, medical information and organisational data were published without authorisation on a website, with login credentials to access the portal also being circulated through WhatsApp. The Telangana Cyber Security Bureau has registered a criminal case and launched an investigation into the incident.

The complaint, filed by Rahul Medakkar, Chief Executive Officer of Unimed Healthcare Private Limited, which owns and operates STAR Hospitals, alleged that the hospital’s IT team discovered confidential organisational and patient-related personal data on a website hosted at warehouse.diy, allegedly registered through or hosted by Namecheap Inc. The hospital clarified that it operates only through its official website, starhospitals.in.

“It came to the notice of the Complainant’s IT Team that confidential organizational and/or patient-related personal data belonging to the Complainant had been published, without any authorization whatsoever, on a website hosted at the domain ‘https://warehouse.diy’,” the complaint by CEO Rahul Medakkar states.

The complaint further alleged that “a message was also being circulated in WhatsApp with the credentials for logging into the said website,” while reiterating that “the Complainant operates only through starhospitals.in.”

Based on the complaint, the Cyber Crime Police Station of the Telangana Cyber Security Bureau registered FIR No. 54/2026 under Sections 43, 66, 66B and 72A of the Information Technology Act, 2000, read with Sections 303(2) and 316(2) of the Bharatiya Nyaya Sanhita. The investigation has been entrusted to Inspector D. Srinu.

Also Read: Viral Instagram reels promote eye wash cups; ophthalmologists say healthy eyes don’t need them

Hospital identifies data shared with authorised vendors

The complaint states that STAR Hospitals collects, stores and processes confidential organisational information and patient-related personal data, including sensitive health information, in the course of providing healthcare services. It also identifies the technology partners with whom patient data is shared for specific purposes.

According to the complaint, Chennai-based Kranium Healthcare Systems Pvt. Ltd. serves as the hospital’s Hospital Information System (HIS) and is “the primary source for collection and management of patient data.” Data is shared with HEAPS Health Solutions India Pvt. Ltd. “solely for analytics purposes,” while Verventus Healthtech Solutions Pvt. Ltd. (Medblaze) receives patient data through secure APIs for “feedback collection and patient experience management.”

Laboratory reports are communicated to patients through the hospital’s registered WhatsApp Business account facilitated by IMImobile Cloud Communications (India) Pvt. Ltd. (Cisco). The complaint also names MarketXpander Services Pvt. Ltd. among its authorised service providers.

“The data shared by the Hospital is only with its authorized vendors for legitimate business and healthcare purposes,” the complaint states, adding that “such data sharing is limited to the services provided by these authorized vendors.”

Also Read: Manipal IPO reveals India’s new hospital economics; occupied bed matters more than patients

‘Never authorised publication of this data’

The hospital alleged that the information published on the website included “patient records, medical/health information, employee or organizational confidential data,” which it said constitutes “personal data” and “sensitive personal data” which comes under the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000.

STAR Hospitals maintained that it had “at no point in time, authorized the collection, extraction, storage or publication of this data on the offending website or any other such unauthorized domains.”

The complaint added that the alleged publication exposes “the Complainant’s patients, employees and the organization at large to a material risk of identity theft, financial fraud, harassment and reputational harm, and may amount to a breach of applicable data-protection law.”

It further alleged that the hospital has reason to believe the “unauthorized access, extraction and/or publication of this data is the result of a deliberate act by unknown person(s),” and requested that those responsible be identified and prosecuted. The hospital also informed police that it had initiated an internal inquiry and would provide additional information as it became available.

Besides seeking registration of a criminal case, STAR Hospitals requested authorities to immediately remove or block the website to prevent further exposure of confidential information.

It also sought coordination with the Indian Computer Emergency Response Team (CERT-In) and the Indian Cyber Crime Coordination Centre (I4C), preservation of “all relevant logs, records and metadata associated with the offending domain and hosting account,” including those maintained by Namecheap Inc., and an investigation to identify those responsible for the alleged unauthorised publication of the data.

The FIR does not disclose the number of patients who may have been affected, the specific categories of patient information allegedly exposed, or how long the information remained accessible on the website.

(Edited by Fayisa CA)

journalist-ad