In a major breach of public health data, Uttar Pradesh’s largest referral hospital has been found to have made confidential medical records and personal information – including Aadhaar number – of kidney donors and beneficiaries public, since at least May 2018.

A 21-year-old information security researcher, Rishi Dwivedi, had detected the open directory containing sensitive information of over 150 such transplants, stored on the server itself and easily accessible on Google.

Known as the “AIIMS of Lucknow”, Sanjay Gandhi Post Graduate Institute of Medical Sciences (SGPGI), however, has dismissed it as “impossible”.