ECONOMY

National Health Insurance Service employees caught accessing, leaking personal data for private use

by
Lee Tae-hyung
Published : Sept. 14, 2026 - 10:14:41
    • Copy Completed!

View Korean Original

Disciplinary records reveal repeated privacy breaches at NHIS and HIRA; lawmaker calls for full internal audit

[123RF]
[123RF]

A series of unauthorized access and data-leak incidents involving personal health and insurance records have been confirmed at the National Health Insurance Service and the Health Insurance Review and Assessment Service.

Disciplinary records obtained from both agencies by Rep. Heo Jong-sik of the Democratic Party of Korea, a member of the National Assembly's Health and Welfare Committee, show that multiple employees accessed or removed personal data without authorization.

Employee A, a grade-5 staff member at the NHIS, used the agency's computer system to access personal information — including records of family members, a former girlfriend and a counterparty in an apartment sale — without authorization on 62 occasions between December 2020 and November 2023. The NHIS suspended A for three months on May 3, 2024.

Employee B, a grade-4 section chief at the NHIS, looked up the names, resident registration numbers and monthly salaries of numerous colleagues for non-work purposes between December 2023 and June 2025. B told investigators that some of the searches were intended to help a spouse prepare for a job application at the agency. B was also found to have accessed a colleague's personal data at a sister's request and passed the information on to her, and was dismissed on Nov. 4, 2025.

There were also cases in which personal data files were taken outside the agency under the pretext of health screening performance targets or work convenience.

Employee C, a grade-3 team leader, downloaded files containing personal and sensitive data onto a computer belonging to an employee without access clearance during a campaign to encourage unscreened individuals to get checkups in early 2025, then had the files decrypted and sent to a personal email account to work on from home. The NHIS docked C two months' pay on May 1, 2026, citing, among other things, a failure to verify the accuracy of the files.

Employee D at HIRA was arrested and referred to prosecutors on fraud charges after a report was filed alleging that D had leaked colleagues' personal data to borrow money from a loan company. The report was received by HIRA's integrity reporting center on April 9, 2025, and D stopped showing up for work without notice from April 28. Police arrested and referred D to prosecutors on May 20, and HIRA suspended D from duties on May 24.

"At agencies that handle highly sensitive personal information — including health and medical records — employees keep looking up data and taking it outside out of curiosity, personal favors or private convenience," Rep. Heo said. "Access to information granted for public duties must not be treated as a personal entitlement."

Heo added that the agencies must conduct a comprehensive review of how access, inquiry and export privileges are managed and how internal controls are structured. "Use of information beyond its intended work purpose must be thoroughly blocked to protect the data entrusted to us by the public," he said.


thlee@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ