Submit incident
Documented

483,000 Patients' Health Records Exposed Through a Misconfigured AI Platform

May 9, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiid:1070View source ↗
LinkedInX

What happened

Sometime before May 2025, an Elasticsearch database at the center of Serviceaide's agentic AI infrastructure was left misconfigured and accessible without proper controls. The data inside belonged to patients of Catholic Health. Medical records, insurance details, and login credentials for 483,000 people were sitting in a database that lacked the access restrictions that patient data of that sensitivity requires. The exposure placed one of the most complete and exploitable personal data combinations a breach can produce into an inadequately protected environment.

Serviceaide operates an AI-driven service management platform built around agentic capabilities, meaning the system is designed to route requests, automate workflows, and handle IT and healthcare operations with reduced human intervention at each step. Catholic Health had contracted with Serviceaide to provide that infrastructure. The exposed Elasticsearch instance was not a peripheral storage archive. It was a working component of the platform's operational data layer, the kind of component that gets queried and updated as the system processes live requests on behalf of the health system.

By the time the breach was reported in May 2025, investigators had found no confirmed evidence that an unauthorized party had pulled or exploited the records. That qualification offered limited reassurance. Medical records combined with insurance details and login credentials form one of the most complete personal data packages a healthcare breach can produce. The nature of the exposed data prompted regulatory scrutiny and the opening of legal investigations on timelines that had not yet concluded.

The absence of confirmed misuse is a qualified statement in a specific way. A database that was misconfigured was, by definition, one that had not been audited before the exposure was discovered. If the configuration was never verified, access to it was never verified either. The logs that would confirm no unauthorized query ever reached the database are the same logs that a properly secured environment would have been generating continuously.

This incident reveals a gap that scales with the complexity of the system in which it occurs. An agentic AI platform touches more data, across more components, than a traditional application, and when the infrastructure supporting it is misconfigured, the exposure surface grows accordingly. Reconstructing what actually happened after the fact becomes harder as the system becomes more capable and interconnected. Closing that gap requires more than patching the configuration error once it is found. It requires a provable record of what the system did, which components accessed which data, and when those components last passed an independent verification check. Without that record, the 483,000 people whose information was exposed can only be told that nothing appears to have gone wrong.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AI Incident Database
Also catalogued in
483,000 Patients' Health Records Exposed Through a Misconfigured AI Platform
2025-05-09