Telangana Cyber Security Bureau registers case over alleged leak of Star Hospitals’ patient data
The Telangana Cyber Security Bureau has registered a case after Star Hospitals alleged that sensitive patient records, employee details and confidential internal documents were published on an unauthorised website. Police are investigating the alleged breach under the BNS and Information Technology Act.
Published Date - 3 August 2026, 11:10 AM
Hyderabad: The Telangana Cyber Security Bureau (TGCSB) has registered a case after a leading hospital alleged that sensitive patient health records, personal information and confidential internal data were illegally published on a vernacular website.
The complaint was lodged by Star Hospitals CEO Rahul Medakkar, who alleged that the hospital’s IT team discovered confidential data hosted on a website identified as “warehouse.diy” without authorisation.
The complaint further stated that login credentials to access the website were also being circulated through WhatsApp.
According to the complaint, the exposed data allegedly includes patients’ personal details, medical records, employee information and confidential hospital documents. The hospital authorities warned that the leak could expose patients and staff to identity theft, financial fraud, harassment and reputational damage.
Meanwhile, Star Hospitals said it shares data only with its authorised technology partners—Kranium Healthcare Systems, HEAPS Health Solutions India, Verventus Healthtech (Medblaze), IMImobile Cloud Communications (Cisco) and MarketXpander Services, for legitimate business purposes, and denied authorising any other entity to access or publish the information.
Suspecting that unknown persons intentionally obtained and published the data, the hospital requested police to identify those responsible, block the website, preserve server logs and metadata.
Based on the complaint, the TGCSB booked a case under sections of the BNS and IT Act and are investigating.