Tech
CoWIN app on phone.
Amid the media reports claiming breach of data of beneficiaries who have received COVID vaccination in the country, the Union Health Ministry has requested the Indian Computer Emergency Response Team (CERT-In) to look into this issue and submit a report, according to an official release.
Further, an internal exercise has been initiated to review the existing security measures of CoWIN.
The media reports allege breach of data from the Co-WIN portal of the Union health Ministry, which is repository of all data of beneficiaries who have been vaccinated against COVID-19, according to a Health Ministry release on Monday (12 June).
The ministry said that certain posts on the social media platform Twitter have claimed that using a Telegram (online messenger application) BOT, the personal data of individuals who have been vaccinated is being accessed.
According to the claims, the BOT has been able to pull individual data by simply passing the mobile number or Aadhaar number of a beneficiary.
In the statement, the ministry clarified that "all such reports are without any basis and mischievous in nature".
Health Ministry's Co-WIN portal is "completely safe with adequate safeguards for data privacy", it said.
"Furthermore, security measures are in place on Co-WIN portal, with Web Application Firewall, Anti-DDoS, SSL/TLS, regular vulnerability assessment, Identity & Access Management etc," the ministry said, adding that only OTP (One-Time Password) authentication-based access of data is provided.
The ministry assured that all steps have been taken and are being taken to ensure security of the data in the CoWIN portal.
According to the ministry, at present individual level vaccinated beneficiary data access is available at three levels:
Co-WIN authorised user- The vaccinator with use of authentic login credential provided can access personal level data of vaccinated beneficiaries. But the COWIN system tracks & keeps record of each time an authorized user accesses the COWIN system.
API based access – The third party applications who have been provided authorised access of Co-WIN APIs can access personal level data of vaccinated beneficiaries only through beneficiary OTP authentication.
The ministry said that without OTP, vaccinated beneficiaries’ data cannot be shared to any BOT.
"Only Year of Birth (YOB) is captured for adult vaccination but it seems that on media posts it has been claimed that BOT also BOT mentioned date of Birth (DOB)," the ministry.
It added that there is no provision to capture address of beneficiary.
Further, the ministry said that the development team of COWIN has confirmed that there are no public APIs where data can be pulled without an OTP.
In addition to the above, there are some APIs which have been shared with third parties such as ICMR for sharing data.
"It is reported that one such API has a feature of sharing the data by calling using just a mobile number of Aadhaar. However, even this API is very specific and the requests are only accepted from a trusted API which has been white-listed by the Co-WIN application," the ministry said.
"Union Health Ministry has requested the Indian Computer Emergency Response Team (CERT-In) to look into this issue and submit a report," it said.
According to the ministry, CERT-In in its initial report has pointed out that backend database for Telegram bot was not directly accessing the APIs of CoWIN database.