Korean Hospital Videos Spread on Overseas Porn Sites as Police Investigate Camera Security Gaps

11 Min Read
Korean Hospital Videos Spread on Overseas Porn Sites as Police Investigate Camera Security Gaps

80 videos expose patients during treatment and changing

South Korean police are investigating the renewed circulation of hospital surveillance footage on overseas pornography websites after a lawmaker identified 80 videos showing patients receiving treatment, undergoing procedures and changing clothes. Twenty-one videos were traced to a single obstetrics and gynecology clinic in Seoul, while the number of people affected has been estimated at about 100.

Contents
  1. 80 videos expose patients during treatment and changing
  2. What the recordings reveal
  3. Earlier arrests did not stop redistribution
  4. Why internet connected cameras are under scrutiny
  5. What the operating room law requires
  6. Reports differ on whether operating rooms were involved
  7. Why the Health Ministry had no CCTV incident record
  8. The audit exposed wider security weaknesses
  9. What the government has promised
  10. Key Points

The recordings displayed dates ranging from February 2022 to November 2025. Some had been edited to follow individual patients through waiting rooms, consultation rooms, ultrasound rooms and examination rooms, exposing faces and bodies without concealment. The footage also covered plastic surgery clinics, traditional Korean medicine clinics and rehabilitation facilities.

The National Police Agency received an investigation request from Rep. Heo Jong-sik of the Democratic Party of Korea on September 29, 2026, and assigned the case to the Chungbuk Provincial Police Agency. Four suspects accused of originally hacking, selling and distributing recordings were apprehended in 2025. Investigators are now pursuing people who posted the material again on other websites.

The case reached the National Assembly's Health and Welfare Committee audit on October 7, 2026, where Health and Welfare Minister Jeong Eun-kyeong acknowledged weaknesses in medical information security and promised measures developed with the medical sector. Internet connected cameras are the suspected route of the leaks, but the precise method and responsibility have not been established.

A central distinction is already shaping the response: the Medical Service Act sets specific security requirements for mandatory operating room cameras, while surveillance in other hospital spaces falls outside those particular rules. Installation compliance alone therefore does not establish whether patients are protected throughout a medical facility.

Advertisement

What the recordings reveal

Heo's office compared the clinic name and interiors visible in the footage with an operating obstetrics and gynecology clinic in Seoul. The 21 videos associated with that facility account for just over 26% of the 80 identified recordings, making it the largest concentration disclosed.

The editing appears to have turned surveillance recordings into sequences organized around patients and medical institutions. Images followed patients between rooms rather than showing only a single treatment encounter. Other videos showed injections, changing into hospital gowns, plastic surgery consultations and procedures, acupuncture and manual therapy.

The distinction between recordings and victims matters. Eighty videos do not necessarily mean 80 people, 80 clinics or 80 separate breaches. Heo told the parliamentary audit that 80 cases had been referred to police, with about 100 victims. Other reporting described at least about 100 people as affected. No final victim count or complete list of affected institutions has been announced.

Rep. Heo Jong-sik, a member of the National Assembly's Health and Welfare Committee, described the threat to patient confidence:

How can people feel safe going to a hospital when even footage of them receiving treatment and changing clothes is circulating online?

Earlier arrests did not stop redistribution

Police previously requested that access to a website carrying the recordings be blocked and took steps to protect victims. The subsequent appearance of the footage elsewhere shows that restricting access to one destination did not prevent copies from circulating.

The four suspects apprehended in 2025 were accused of the initial hacking, sale and distribution. Their apprehension does not establish who uploaded the later copies or whether every video now circulating came from the same intrusion. The current investigation is intended to identify those responsible for redistribution and clarify the leak route.

One affected hospital said it had undergone an investigation the previous year and subsequently conducted a broad security review. That account does not establish whether the newly discovered posts contain older stolen recordings or material obtained through a later breach. Heo has called for international cooperation because the websites distributing the footage are overseas.

The main dates disclosed so far are:

  • 2021: An amendment to the Medical Service Act introduced the operating room camera requirement.
  • February 2022 to November 2025: Dates displayed on the identified recordings.
  • September 2023: The operating room CCTV requirement took effect.
  • 2025: Police apprehended four suspects accused of hacking, selling and distributing footage.
  • September 29, 2026: The National Police Agency received Heo's investigation request.
  • October 7, 2026: Lawmakers questioned the health minister about the leaks and medical cybersecurity.
Advertisement

Why internet connected cameras are under scrutiny

Most of the leaked footage is believed to have been recorded using internet protocol cameras, commonly called IP cameras. These devices can send video to other equipment over wired or wireless networks. When their services are accessible through the internet, weaknesses in passwords or configuration can create a route for unauthorized access.

Reporting on the case described some imported products with widely known factory passwords and cameras that transmit footage through web servers reachable online. These are possible security weaknesses, not a confirmed explanation for how the recordings in this case were obtained. No specific manufacturer, password failure or server breach has been established as the cause.

At the parliamentary audit, Health and Welfare Minister Jeong Eun-kyeong identified IP cameras as the immediate concern while stressing the need for police to confirm the route:

At this point, IP cameras are being identified as the problem, so that area needs to be addressed.

The minister distinguished these devices from the closed circuit cameras required for operating rooms, whose recordings are intended to be kept on a closed network. Network separation limits direct exposure to the public internet, but it does not settle questions about who can view, copy or export footage. Those management questions are part of the inspection Heo is seeking.

What the operating room law requires

The Medical Service Act requires cameras in operating rooms at institutions that perform surgery on patients rendered unconscious, including through general anesthesia or sedation. Recording is required when a patient or guardian requests it, subject to legal exceptions. The measure was introduced to deter illegal conduct, including operations performed by unqualified people, and preserve evidence for investigations and medical disputes.

The operating room rules require safeguards against leaks, including password protection, access logs and restrictions on access privileges. Health Ministry requirements specify closed circuit cameras rather than internet connected network cameras for this purpose.

According to ministry figures submitted to Heo's office, 2,528 of the 2,529 institutions subject to the installation requirement had installed cameras by the end of June 2026. The remaining institution was temporarily closed. That means all operating institutions in the stated total had completed installation, but the figure measures installation rather than the security of every camera in every hospital room.

Heo's office said the identified recordings were made in examination rooms, consultation rooms, waiting rooms and patient rooms, outside the spaces covered by the specific operating room management provisions. This does not establish that other surveillance is exempt from every privacy obligation. It identifies a gap in the particular safeguards imposed under the Medical Service Act.

Advertisement

Reports differ on whether operating rooms were involved

Some accounts described the leaked footage as including operating room scenes. Heo's findings, however, placed the identified recordings outside operating rooms, and the ministry said the suspected route involved IP cameras rather than the mandatory closed network camera systems.

A direct connection between the leaks and cameras installed under the operating room mandate has therefore not been confirmed. Reporting also described hospitals using IP cameras to monitor operating rooms and other internal spaces. Whether any particular institution used an IP camera instead of the equipment required by law needs inspection; it cannot be established from the national installation total.

The Seoul Medical Association called for an investigation into the circumstances, scale and redistribution of the recordings, alongside a full review of the operating room camera policy, including possible repeal. It argued that intimate medical images can cause exceptional harm and become difficult to recover once copied and distributed.

The policy dispute turns on facts investigators have yet to resolve. A leak from cameras installed outside the mandate would point toward broader hospital surveillance controls. Evidence that a mandatory operating room system was compromised, or that unsuitable equipment was used in its place, would raise a different set of compliance questions. Neither conclusion should be assumed before the equipment and access routes are identified.

Why the Health Ministry had no CCTV incident record

Ministry data presented to Heo's office recorded 109 cybersecurity incidents at medical institutions from 2021 through August 2026. Private institutions accounted for 106 and public institutions for three. Ransomware accounted for 98 incidents, almost 90% of the total, while none was identified as involving CCTV footage.

That absence does not demonstrate that no camera breaches occurred. Police had already apprehended suspects over hospital recordings in 2025, while the ministry's records contained no corresponding CCTV incident. The difference points to a gap between police activity and the information reaching the body responsible for medical policy.

Heo said private medical institutions report breaches involving electronic medical records to the Health and Welfare Ministry, while incidents affecting other systems go to the Ministry of Science and ICT or the Korea Internet & Security Agency. Under that arrangement, a hospital camera breach may not appear in the Health Ministry's incident records.

Jeong said she learned of the footage through news coverage. Heo has asked for a comprehensive inspection covering camera locations, footage storage, access management and responsibility for security, rather than a check limited to whether required operating room cameras have been installed.

Advertisement

The audit exposed wider security weaknesses

The camera investigation was discussed alongside attacks that interrupted care and exposed other patient information. Hospital internal network ransomware cases reached 14 in the first eight months of 2026, compared with eight in 2025. The partial year total was already six cases higher, a 75% increase, although the figures cover different lengths of time.

Ransomware typically locks or disrupts computer systems to pressure an organization into paying. At Kangwon National University Hospital, an attack interrupted treatment for four hours and 50 minutes. At Hwasun Chonnam National University Hospital, 298 records of personal information were reported leaked.

The national emergency medical information network suffered three disruptions in 2026. One outage involving the National Medical Center took up to 32 hours to restore. The disruptions illustrate a separate risk to the continuity of care, but the audit accounts did not establish that all three resulted from cyberattacks.

Rep. Han Ji-a of the People Power Party presented figures showing that 16.7% of 263 general hospitals, including tertiary hospitals, had no information security budget. Institutions averaged 0.9 security workers each. She also cited the 2021 intrusion by a North Korean hacking group at Seoul National University Hospital, which exposed health information concerning about 830,000 people.

These incidents involve different systems and cannot be treated as one breach. Together, they show why the ministry's response is expanding beyond cameras to staffing, budgets, hospital networks and the protection of medical information.

What the government has promised

Jeong pledged a security plan developed jointly with private medical institutions and said the ministry had asked the Korean Medical Association and Korean Hospital Association to strengthen internal checks. She acknowledged that hospitals cite costs and shortages of specialist staff as obstacles to stronger protection.

Health and Welfare Minister Jeong Eun-kyeong described the pace of the threat at the audit:

We are not keeping up with the speed of the attackers.

The planned response includes consideration of offensive cybersecurity, meaning authorized tests that imitate attackers to find weaknesses before criminals exploit them. Han proposed introducing that approach first at national university hospitals, the National Health Insurance Service and the Health Insurance Review and Assessment Service. The ministry also said it would examine ways to secure specialist personnel and funding.

For victims of the footage leaks, the immediate priorities are removal, blocking further distribution and protection from additional exposure. Heo has also sought institutional security standards and inspection duties covering all hospital video equipment, not just mandatory operating room cameras.

No date has been announced for a completed police investigation, a final victim count, publication of the comprehensive security plan or a decision on changing the camera rules. The promises remain measures to be developed, rather than a completed reform. Establishing whether recordings are newly stolen or repeatedly copied will be essential to assessing both the breach and the effectiveness of the response.

Advertisement

Key Points

  • Heo's office identified 80 videos from Korean medical facilities, including 21 linked to one Seoul obstetrics and gynecology clinic.
  • About 100 people have been identified as victims; the final total is not established.
  • Chungbuk police are investigating renewed distribution after four suspects were apprehended in 2025.
  • IP cameras are the suspected leak route. A connection to mandatory operating room CCTV remains unconfirmed.
  • Health Ministry records listed 109 medical cybersecurity incidents through August 2026, but none involving CCTV.
  • The government has promised joint security measures, stronger internal checks and consideration of authorized attack testing.
  • The leak method, full scale of exposure and timetable for reforms remain unresolved.
Share This Article

You May also Like