SC to examine plea for CBI probe into alleged breach of 1.5 lakh medical records

The-plea-alleges-a-major-cyber-breach-involving-me_1786030578640

SC to Examine Plea for CBI Probe into Medical Records Breach

Constitutional Bench Issues Notice in Vitraya Technologies Case

Bharatmorningnews.com – The Supreme Court has agreed to SC to examine plea for CBI probe into allegations of massive medical data theft. The apex court consented to review a legal challenge requesting that the Central Bureau of Investigation take over an inquiry concerning the unauthorized access and removal of personal and healthcare information belonging to over 150,000 individuals. The data was held by a technology enterprise operating in the digital health sector.

During the proceedings, a three-judge panel consisting of Chief Justice Surya Kant alongside Justices Joymalya Bagchi and V Mohana expressed concern regarding the matter’s gravity. The bench issued formal notice on the petition submitted by Vitraya Technologies Pvt Ltd, noting that they had previously directed Solicitor General Tushar Mehta to evaluate whether existing legislation requires strengthening.

“We understand the seriousness…that is why in the other case, we have requested the learned solicitor general (Tushar Mehta) to consider if the law should be made more stringent.”

Allegations of Widespread Cyber Intrusion

Submitted under Article 32 of the Constitution, the legal document describes a massive digital penetration affecting highly confidential citizen information. This encompasses healthcare documentation, insurance settlement records, Aadhaar-associated details, and various other identifiers capable of linking to individual identities. The petition maintains that such a violation severely impacts the constitutional right to privacy guaranteed under Article 21.

Senior advocate K Parameshwar, representing the petitioner alongside counsel Nupur Sharma, highlighted that the incident extended across six different states. They criticized law enforcement agencies for not performing a thorough investigation despite numerous complaints being lodged over time.

“I have been informing the authorities from day one. I filed my complaint in March 2025. It took them till August 2025 even to register an FIR,” Parameshwar told the court, adding that the police invoked only Sections 66 and 66B of the Information Technology Act (less stringent provisions) despite the scale of the alleged offence.

The counsel further questioned the credibility of the ongoing inquiry, pointing out that the FIR remains filed against unidentified individuals even though comprehensive information about a Singapore-based server containing records of approximately 150,000 Indian citizens had been provided. He requested either the investigation be handed over to the CBI or a special investigation team monitored by the court be established.

Timeline of Events and Technical Evidence

According to the petition drafted by advocate Abhinav Agrawal, Vitraya Technologies—which manages a real-time platform for health insurance claim settlements—identified a synchronized cyber assault in February 2025. The attack involved systematic brute-force login attempts, bulk downloading of private files, and extraction of critical customer information from the company’s digital systems.

After conducting an internal forensic review, the organization reportedly pinpointed questionable IP addresses and server behaviors connected to Remedinet Technologies Pvt Ltd and IHX Pvt Ltd. Both entities are reportedly controlled by Bessemer Venture Partners, a foreign investment company. The petition additionally claims that Bessemer orchestrated the assaults together with Medi Assist, Perfios Software Solutions Pvt Ltd, and related organizations, all of which compete directly with the petitioner.

The company approached Punjab’s cybercrime police on March 5, 2025, providing technical logs, server information, IP addresses, names of suspected individuals, and supporting documents. Despite offering complete cooperation throughout the initial inquiry and making multiple representations, the police reportedly postponed FIR registration for almost half a year.

Eventually, on August 29, 2025, an FIR was recorded at the Punjab State Cyber Crime Police Station in SAS Nagar. However, it was filed exclusively under Sections 66 and 66B of the Information Technology Act and targeted “unknown persons,” even though the petitioner had already submitted detailed technical proof identifying the responsible parties.

Call for Enhanced Investigation

The petition asserts that the investigation has proven largely inadequate. It claims that critical steps such as comprehensive forensic analysis, seizure of digital assets, preservation of electronic evidence, and custodial questioning have not been undertaken despite the nationwide impact of the alleged breach.

The legal challenge emphasizes that this situation goes beyond a typical commercial disagreement. With the Supreme Court now set to SC to examine plea for CBI probe thoroughly, stakeholders await a decisive ruling that could reshape how India handles large-scale data security violations.

Frequently Asked Questions

What is the Supreme Court examining in this case?

The Supreme Court is reviewing a petition requesting a CBI investigation into the alleged breach of 1.5 lakh medical records belonging to Indian citizens. The court has issued notice to all concerned parties.

Why is a CBI probe being sought?

The petitioner argues that the Punjab cybercrime police investigation has been inadequate, with delayed FIR registration and insufficient forensic work. A CBI probe would ensure a more comprehensive and impartial inquiry.

How many medical records were allegedly compromised?

Approximately 150,000 medical and healthcare records were reportedly accessed and extracted from Vitraya Technologies’ Singapore-based server during the cyber attack in February 2025.

What sections of the IT Act were invoked in the FIR?

The FIR was filed under Sections 66 and 66B of the Information Technology Act, which the petitioner considers less stringent provisions for such a large-scale data breach.

Which states were affected by this data breach?

The cyber intrusion reportedly extended across six different states in India, affecting citizens nationwide who had their healthcare and personal information compromised.

प्रातिक्रिया दे

आपका ईमेल पता प्रकाशित नहीं किया जाएगा. आवश्यक फ़ील्ड चिह्नित हैं *