Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Honasa widens premium play with oral magnificence wager, says fast commerce drives 10% of complete income

November 12, 2025

This American hashish inventory is likely one of the greatest, analyst says

November 12, 2025

Maya1: A New Open Supply 3B Voice Mannequin For Expressive Textual content To Speech On A Single GPU

November 12, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Honasa widens premium play with oral magnificence wager, says fast commerce drives 10% of complete income
  • This American hashish inventory is likely one of the greatest, analyst says
  • Maya1: A New Open Supply 3B Voice Mannequin For Expressive Textual content To Speech On A Single GPU
  • Date, time, and what to anticipate
  • Extra Northern Lights anticipated after 2025’s strongest photo voltaic flare
  • Apple’s iPhone 18 lineup might get a big overhaul- Particulars
  • MTN, Airtel dominate Nigeria’s ₦7.67 trillion telecom market in 2024
  • Leakers declare subsequent Professional iPhone will lose two-tone design
Wednesday, November 12
NextTech NewsNextTech News
Home - Africa - M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data
Africa

M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data

NextTechBy NextTechNovember 12, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
M-Tiba took 10 days to detect breach exposing 5m Kenyans’ well being data
Share
Facebook Twitter LinkedIn Pinterest Email


A cyberattack on M-Tiba, a Kenyan healthtech platform, went undetected for 10 days, exposing the private and medical data of almost 5 million Kenyans, in keeping with an inside standing report seen by TechCabal.

The report—shared by M-Tiba’s operator CarePay Restricted to insurance coverage firms together with Jubilee, Constancy, GA Insurance coverage, and AAR Insurance coverage—reveals that the breach occurred between October 17 and 25, however was solely found on October 27 at 1:23 p.m.

The report paints an image of delayed detection, restricted communication, and potential violations of Kenya’s information safety legal guidelines.

10-day blindspot

CarePay mentioned the intrusion started when a third-party healthcare supplier’s system was infiltrated, compromising their person credentials. Utilizing the stolen particulars, the attackers compelled entry to M-Tiba’s Model 2 platform and extracted a big dataset masking insurance coverage claims, affected person data, and scientific data.

“Roughly 4.8 million data have been illegally obtained in relation to beneficiaries and claims throughout numerous healthcare payers,” CarePay mentioned within the report. “A pattern of the dataset has been made out there for downloading by way of the darkish internet.”

Whereas CarePay has not but contacted affected people, the corporate says it has notified information controllers, together with insurance coverage companies, who’re anticipated to achieve out to information topics immediately.

“Because the processor, we’ve knowledgeable the controllers who will subsequently inform information topics,” the report mentioned.

CarePay didn’t reply to a request for remark.

The affected information consists of monetary data equivalent to insurance coverage claims, profit limits, and utilisation; personally identifiable data, together with full names, ID numbers, pictures, and get in touch with particulars; in addition to delicate well being data equivalent to diagnoses, lab outcomes, prescriptions, and discharge summaries.

These affected embrace insurance coverage firms, healthcare suppliers, and policyholders — together with kids.

A TechCabal evaluation of the accessed information discovered that each one main insurance coverage companies have been affected, together with hundreds of well being amenities—public, non-public, and people run by non secular establishments such because the Catholic Church—unfold throughout the nation, together with rural areas. This factors to an enormous breach which will have been considerably underreported.

Silence and confusion

4 individuals at Jubilee and AAR Insurance coverage who requested to not be named advised TechCabal that they realized of the incident from media experiences, not from CarePay or the ODPC. 

The regulator itself appeared to verify this communication lapse. In a public discover on October 29, the ODPC mentioned it turned conscious of the M-Tiba incident by means of media experiences.

“The ODPC is conscious of media experiences that mobile-health-wallet platform M-Tiba might have skilled a cyber-incident involving the potential publicity of non-public and well being information of customers,” the regulator mentioned.

ODPC didn’t reply to TechCabal’s request for remark.

Underneath Kenya’s Knowledge Safety Act (2019), information controllers and processors are required to report breaches inside 72 hours of turning into conscious of them and to promptly notify affected people if the breach is more likely to lead to a excessive danger to their rights.

CarePay’s timeline exhibits that the breach was lively for 10 days earlier than being detected, and that neither M-Tiba nor its companion insurers have but notified affected customers.

“Because the processor, we’ve knowledgeable the controllers who will subsequently inform information topics,” the corporate mentioned, referring to insurers and well being payers liable for affected person information.

Regulatory reckoning 

The regulator has opened investigations into the incident. An official confirmed to TechCabal that the workplace obtained the report however was reviewing whether or not the corporate complied with native information legal guidelines.

If discovered to have violated reporting and notification necessities, CarePay may face fines and enforcement orders beneath the Knowledge Safety Act.

M-Tiba, launched in 2016 by means of a partnership between CarePay, Safaricom, and the PharmAccess Basis, permits customers to save lots of and spend cash particularly for healthcare. It handles tens of millions of insurance coverage and out-of-pocket medical transactions yearly and claims to have partnerships with over 3,000 hospitals.



Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s developments right this moment: learn extra, subscribe to our publication, and develop into a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Date, time, and what to anticipate

November 12, 2025

MTN, Airtel dominate Nigeria’s ₦7.67 trillion telecom market in 2024

November 12, 2025

Cassava launches AI multi-model trade for cellular operators

November 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

Honasa widens premium play with oral magnificence wager, says fast commerce drives 10% of complete income

By NextTechNovember 12, 2025

Honasa Client, the guardian of non-public care manufacturers Mamaearth and The Derma Co, stated fast…

This American hashish inventory is likely one of the greatest, analyst says

November 12, 2025

Maya1: A New Open Supply 3B Voice Mannequin For Expressive Textual content To Speech On A Single GPU

November 12, 2025
Top Trending

Honasa widens premium play with oral magnificence wager, says fast commerce drives 10% of complete income

By NextTechNovember 12, 2025

Honasa Client, the guardian of non-public care manufacturers Mamaearth and The Derma…

This American hashish inventory is likely one of the greatest, analyst says

By NextTechNovember 12, 2025

Haywood’s Neal Gilmer stated Inexperienced Thumb’s diversified product portfolio and disciplined price…

Maya1: A New Open Supply 3B Voice Mannequin For Expressive Textual content To Speech On A Single GPU

By NextTechNovember 12, 2025

Maya Analysis has launched Maya1, a 3B parameter textual content to speech…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!