Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Supreme Court. Show all posts

Supreme Court to Hear Case Over 1.5 Lakh Medical Records Breach





The Supreme Court has issued notice on a petition seeking a Central Bureau of Investigation (CBI) probe into an alleged cyberattack that Vitraya Technologies claims resulted in the theft of medical, insurance and other sensitive personal information belonging to nearly 1.5 lakh Indian citizens.

A three-judge bench comprising Chief Justice of India Surya Kant and Justices Joymalya Bagchi and V Mohana agreed to examine the petition filed by Vitraya Technologies Pvt Ltd, a health-tech company that operates a technology platform for automating and settling health insurance claims.

The case places the alleged compromise of highly sensitive healthcare information alongside questions about the adequacy of the police investigation and the protection of informational privacy. The company has approached the court under Article 32 of the Constitution, arguing that the alleged breach has implications for the fundamental right to privacy protected under Article 21.

During the hearing, senior advocate K Parameshwar, appearing for Vitraya, told the court that the alleged intrusion affected data across six states and that the company had been approaching authorities since the incident was reported in 2025.

Parameshwar said Vitraya submitted its initial complaint in March 2025 but that an FIR was not registered until August 29, 2025. He also questioned why the case continued to name unknown persons despite the company claiming that it had supplied investigators with technical information concerning the suspected intrusion.

The counsel told the bench that Vitraya had also provided information concerning a server in Singapore to which the company's investigation allegedly traced medical records belonging to almost 1.5 lakh Indians.

The petition seeks transfer of the investigation to the CBI. In the alternative, Vitraya has asked the Supreme Court to order a court-monitored Special Investigation Team (SIT).


Alleged attack began with unauthorised access

According to the petition, Vitraya detected what it described as a coordinated cyberattack in February 2025.

The alleged activity included repeated brute-force login attempts against the company's systems, unauthorised access to its digital infrastructure, bulk downloading of confidential records and the extraction of sensitive customer information.

The data allegedly exposed in the incident includes medical records, health insurance claim information, Aadhaar-linked details and other personally identifiable information.

The combination of medical information with identity and insurance data makes the alleged incident particularly sensitive. Medical records can contain information about an individual's diagnoses, treatment history and health conditions, while Aadhaar-linked information can connect those records to an identifiable individual.

Vitraya's own platform is designed to handle this type of information. The company says its technology automates health insurance claims using artificial intelligence, machine learning, medical natural-language processing and blockchain-based smart contracts. It describes its platform as being used by more than 6,000 hospitals and says it processes approximately 10 million claims worth around $2 billion annually.

The company's technology infrastructure therefore sits within a data-intensive part of the healthcare and insurance ecosystem, where information can move between healthcare providers, insurers and technology platforms during the claims process.


Vitraya alleges attack was linked to rival companies

Following an internal forensic investigation, Vitraya claims that its security team identified suspicious IP addresses, server activity and other digital footprints that it says were associated with Remedinet Technologies Pvt Ltd and IHX Pvt Ltd.

The petition further alleges that these entities were connected to Bessemer Venture Partners and that the alleged activity involved Bessemer, Medi Assist, Perfios Software Solutions Pvt Ltd and other entities described by Vitraya as competitors.

These allegations have not been established by the Supreme Court. The companies named in the petition should not be treated as responsible for the breach unless an investigation establishes their involvement.

Vitraya says its forensic examination produced technical material that it subsequently supplied to investigators. The company claims this included server information, IP addresses, technical logs, details concerning the alleged actors and other documentary evidence.

The company approached Punjab's cybercrime authorities on March 5, 2025, according to the petition.

However, Vitraya alleges that its repeated representations and cooperation during the preliminary inquiry did not result in an FIR for almost six months.

The FIR was ultimately registered on August 29, 2025, at the Punjab State Cyber Crime Police Station in SAS Nagar. According to the petition, the case was registered under Sections 66 and 66B of the Information Technology Act and against unknown persons.

Under the IT Act, Section 66 addresses computer-related offences committed dishonestly or fraudulently, while Section 66B deals with dishonestly receiving or retaining stolen computer resources or communication devices while knowing, or having reason to believe, that they are stolen.

Vitraya has argued that the provisions used in the FIR do not adequately reflect the scale and complexity of the alleged incident. The company has also questioned why the FIR continued to identify the suspects as unknown despite the technical material it says had already been provided to police.


Company questions progress of investigation

The petition alleges that the investigation has not involved sufficient forensic examination or preservation of the digital evidence relevant to the alleged attack.

Vitraya claims that investigators have not undertaken substantial measures such as examining or seizing relevant digital infrastructure, preserving electronic evidence or conducting custodial interrogation of suspected individuals.

The company argues that these alleged shortcomings are particularly important because the incident involves systems and entities operating across multiple jurisdictions.

According to Vitraya, the alleged breach spans six states, involves multiple corporate entities and includes digital infrastructure located outside India. The company has specifically referred to a Singapore-based server where it alleges that the compromised medical information was transferred.

The cross-border element could complicate an investigation because digital evidence may be distributed across different jurisdictions, requiring investigators to establish where systems and data were located, identify the parties controlling those systems and preserve evidence before it can be deleted, altered or moved.

The company therefore argues that the investigation requires an agency with the technical capacity and jurisdictional reach to examine the alleged attack.


Privacy concerns form central part of petition

Vitraya has also framed the alleged breach as a constitutional privacy issue rather than solely a dispute between competing businesses.

The petition relies on the Supreme Court's 2017 judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, in which a nine-judge Constitution Bench recognised privacy as a fundamental right protected under Article 21. The court held that privacy is intrinsic to the protection of life and personal liberty.

That constitutional framework is relevant to a case involving medical information because the alleged data does not merely concern commercial records. It potentially connects individuals with information about their health, treatment and insurance claims.

The petition consequently argues that the alleged unauthorised disclosure of such information affects citizens' informational privacy and digital autonomy.


India's data protection framework adds another layer

The case also arrives as India moves toward implementing its newer personal-data protection regime.

The Digital Personal Data Protection Act, 2023 establishes a framework governing the processing of digital personal data and creates obligations for organisations handling such information. The Act also provides for a Data Protection Board of India and includes provisions addressing data-fiduciary obligations, individual rights, grievance redressal and penalties.

However, the timing matters. The DPDP framework is being implemented in phases. The government notified the DPDP Rules in November 2025, while several substantive provisions of the Act and Rules are scheduled to take effect 18 months after the notification.

The alleged Vitraya intrusion was identified in February 2025, before those later implementation stages. The investigation therefore cannot simply be described as a test of the fully operational DPDP regime. Instead, the case sits at the intersection of India's existing cybercrime laws, constitutional privacy protections and the country's transition toward a dedicated personal-data protection framework.

Separately, CERT-In's directions under the Information Technology Act identify unauthorised access to IT systems or data, data breaches and data leaks among cybersecurity incidents that covered organisations are required to report.


Supreme Court seeks response on proposed CBI investigation

The Supreme Court's immediate action is limited to issuing notice on the petition. The court has not made a finding that the alleged breach occurred in the manner claimed by Vitraya, nor has it established the involvement of the companies named in the petition.

The petitioner is asking the court to transfer the investigation to the CBI because it considers the existing police investigation inadequate.

Alternatively, Vitraya has proposed a court-monitored SIT involving agencies with relevant cybersecurity expertise, including the CBI and CERT-In.

The company's argument is that the combination of alleged cross-state activity, foreign-hosted infrastructure, sensitive medical information, multiple corporate entities and digital forensic evidence makes the case unsuitable for a routine investigation.

The Supreme Court's notice now places the investigation and the requested transfer before the respondents, including the Union government, the CBI and the Punjab government.

The case could therefore become an important test of how Indian authorities investigate alleged large-scale breaches involving healthcare data, cross-border infrastructure and competing corporate entities, particularly when the affected information includes medical records and government-linked identifiers.

For now, however, the allegations remain subject to investigation and judicial consideration.

Supreme Court Weighs Shareholder Lawsuit Against Meta Over Data Disclosure

 

The U.S. Supreme Court is deliberating on a high-stakes shareholder lawsuit involving Meta (formerly Facebook), where investors claim the tech giant misled them by omitting crucial data breach information from its risk disclosures. The case, Facebook v. Amalgamated Bank, centers around the Cambridge Analytica scandal, where a British firm accessed data on millions of users to influence U.S. elections. While Meta had warned of potential misuse of data in its annual filings, it did not disclose that a significant breach had already occurred, potentially impacting investors’ trust. During oral arguments, liberal justices voiced concerns over the omission. 

Justice Elena Kagan likened the situation to a company that warns about fire risks but withholds that a recent fire already caused severe damage. Such a lack of disclosure, she argued, could be misleading to “reasonable investors.” The plaintiffs’ attorney, Kevin Russell, echoed this sentiment, asserting that Facebook’s omission misrepresented the severity of risks investors faced. On the other hand, conservative justices expressed concerns about expanding disclosure requirements. Chief Justice John Roberts questioned whether mandating disclosures of all past events might lead to over-disclosure, which could overwhelm investors with excessive details. Justice Brett Kavanaugh suggested the SEC, rather than the courts, might be better positioned to clarify standards for corporate disclosures. 

The Biden administration supports the plaintiffs, with Assistant Solicitor General Kevin Barber describing the case as an example of a misleading “half-truth.” Meta’s attorney, Kannon Shanmugam, argued that such broad requirements could dissuade companies from sharing forward-looking risk factors, fearing potential lawsuits for any past incident. Previously, the Ninth Circuit found Meta’s general warnings about potential risks misleading, given the company’s awareness of the Cambridge Analytica breach. The Court held that such omissions could harm investors by implying that no significant misuse had occurred. 

If the Supreme Court sides with the plaintiffs, companies could face new expectations to disclose known incidents, particularly those affecting data security or reputational risk. Such a ruling could reshape corporate disclosure practices, particularly for tech firms managing sensitive data. Alternatively, a ruling in favor of Meta may uphold the existing regulatory framework, granting companies more discretion in defining disclosure content. This decision will likely set a significant precedent for how companies balance transparency with investors and risk management.

Supreme Court Directive Mandates Self-Declaration Certificates for Advertisements

 

In a landmark ruling, the Supreme Court of India recently directed every advertiser and advertising agency to submit a self-declaration certificate confirming that their advertisements do not make misleading claims and comply with all relevant regulatory guidelines before broadcasting or publishing. This directive stems from the case of Indian Medical Association vs Union of India. 

To enforce this directive, the Ministry of Information and Broadcasting has issued comprehensive guidelines outlining the procedure for obtaining these certificates, which became mandatory from June 18, 2024, onwards. This move is expected to significantly impact advertisers, especially those using deepfakes generated by Generative AI (GenAI) on social media platforms like Instagram, Facebook, and YouTube. The use of deepfakes in advertisements has been a growing concern. 

In a previous op-ed titled “Urgently needed: A law to protect consumers from deepfake ads,” the rising menace of deepfake ads making misleading or fraudulent claims was highlighted, emphasizing the adverse effects on consumer rights and public figures. A survey conducted by McAfee revealed that 75% of Indians encountered deepfake content, with 38% falling victim to deepfake scams, and 18% directly affected by such fraudulent schemes. Alarmingly, 57% of those targeted mistook celebrity deepfakes for genuine content. The new guidelines aim to address these issues by requiring advertisers to provide bona fide details and final versions of advertisements to support their declarations. This measure is expected to aid in identifying and locating advertisers, thus facilitating tracking once complaints are filed. 

Additionally, it empowers courts to impose substantial fines on offenders. Despite the potential benefits, industry bodies such as the Indian Internet and Mobile Association of India (IAMAI), Indian Newspaper Association (INS), and the Indian Society of Advertisers (ISA) have expressed concerns over the additional compliance burden, particularly for smaller advertisers. These bodies argue that while self-certification has merit, the process needs to be streamlined to avoid hampering legitimate advertising activities. The challenge of regulating AI-enabled deepfake ads is further complicated by the sheer volume of digital advertisements, making it difficult for regulators to review each one. 

Therefore, it is suggested that online platforms be obligated to filter out deepfake ads, leveraging their technology and resources for efficient detection. The Ministry of Electronics and Information Technology highlighted the negligence of social media intermediaries in fulfilling their due diligence obligations under the IT Rules in a March 2024 advisory. 

Although non-binding, the advisory stipulates that intermediaries must not allow unlawful content on their platforms. The Supreme Court is set to hear the matter again on July 9, 2024, when industry bodies are expected to present their views on the new guidelines. This intervention could address the shortcomings of current regulatory approaches and set a precedent for robust measures against deceptive advertising practices. 

As the country grapples with the growing threat of dark patterns in online ads, the apex court’s involvement is crucial in ensuring consumer protection and the integrity of advertising practices in India.

LiveLaw and Bar & Bench, Two Websites Which Revolutionized Legal Readings

Last year in November, Supreme Court of India Justice DY Chandrachud commented during a case hearing, he said "I will tell you something in a lighter vein, instead of wading through the pleadings before us, I thought I will check LiveLaw or other platforms for the documents. Justice Chandrachud's remark comes as an acknowledgment of the significant impact that law/legal news websites have over Indian court hearings in recent years. Especially two websites, 'LiveLaw' and 'Bar and Bench' have done great work for their in-depth coverage of court hearings.  

Despite Television Coverage being banned in court proceedings, the coverage from these two websites gives information about real-time ground coverage via a live Twitter tweet about proceedings. Besides this, the legal websites are appreciated for their speedy coverage of news upload of not only judgments and court orders, but also about pleadings and petitions related to cases. It comes as a good initiative because until now, the legal resources were available only from lawyers pertaining to specific issues. "LiveLaw’ and ‘Bar & Bench’ have revolutionized legal reporting by tweeting about proceedings in real-time, bringing them to the screens of general readers," reports Scroll.  

LiveLaw and Bar and Bench's readership are not limited to only judges and lawyers. The two websites have millions of readers and hundreds of thousands of followers on social media, they have revolutionized common people's access to law proceedings. The extensive coverage of court proceedings comes with criticism, that much is obvious. Few people think that real-time ground coverage of legal proceedings has undermined the court's integrity among the general public. 

The Scroll reports "While India’s various courts started uploading their judgments online around 2010, the exchanges between the lawyer and the judge were rarely available to people beyond the courtroom. Litigants struggled to understand the trajectory even of their own cases." "Lay readers now follow the intricacies of important matters as they unfold. Many have realized that even if the functioning of real-life courts isn’t quite as dramatic as the way they are depicted in the movies, the proceedings can often be very compelling," it says.