Shoppers are turning to stronger cyber hygiene: as health and social services move online, UNAIDS is pressing for digital privacy that doesn’t leave people behind , especially those living with HIV, LGBTQI communities, sex workers and people who use drugs. Here’s what’s changed, why it matters and how organisations can keep clients safe.
Essential Takeaways
- Digital leap: COVID‑19 pushed HIV services online quickly, revealing gaps in access and skills for many people.
- Concrete threats: Cyberattacks, phishing and fake profiles have moved from theoretical risks to real harms for activists and organisations.
- Privacy can be life‑or‑death: Leaked records or a chatbot notification can expose someone to stigma, blackmail or arrest in hostile settings.
- Community solutions work: UNAIDS backs tools built by and for communities, plus regular security reviews and dedicated budgets.
- Practical musts: Use secure devices, update protocols, train staff and secure legal support to reduce risk.
Why the pandemic made digital security urgent
Lockdowns forced clinics and support groups to offer testing, counselling and medication guidance online, and that sudden shift made a few things painfully obvious: connectivity varies, devices are shared and assumptions about access don’t hold up. According to UNAIDS, some patients in Zimbabwe could only reach services via social apps on capped data plans, while others in Kazakhstan needed help just to get QR codes for entry to clinics. That mismatch turned convenience into a barrier for the most vulnerable and showed how quickly privacy risks escalate when services go digital.
Practical tip: map the ways people access services before moving them online , SMS and low‑data options often work better than full websites for many users.
When theoretical risks became real attacks
Organisations that once treated cyberthreats as hypothetical are now responding to repeated intrusions. A 2025 survey of LGBTI groups found cyberattacks were common, and UNAIDS teams have documented fake dating profiles, unlawful phone searches and disinformation campaigns. In one troubling case from Central Asia, hacked contact lists and exposed office addresses led to blackmail and closure. The takeaway is simple: digital violence is an extension of real‑world harm, and community groups need resilience, not just awareness.
Practical tip: start with basic protections , enforce strong passwords, enable two‑factor authentication and run phishing drills with staff and volunteers.
Why data breaches can literally cost lives
In places where same‑sex relationships, sex work or drug use are criminalised, a leaked record isn't just embarrassing , it's dangerous. Even a seemingly mundane chatbot question about medication side effects can reveal someone’s status. Shared phones make accidental disclosure more likely, too: browsing history, notifications or message previews can out someone to housemates or family. Organisations must treat client data as a high‑risk asset and plan accordingly.
Practical tip: configure apps to hide notifications and use ephemeral chat or anonymous hotlines where possible; avoid collecting unnecessary personally identifiable information.
New tech helps but also introduces fresh risks
AI, chatbots and automated tools can widen reach and offer discreet support , a Brazilian chatbot, for example, built trust with young trans users who sometimes shared more with it than a counsellor. But advanced tools often come with better security only for well‑funded groups. UNAIDS recommends scaling community‑designed solutions and resisting one‑size‑fits‑all tech that ignores local realities. Funding models need to include ongoing maintenance and secure licences, not just one‑off set‑ups.
Practical tip: when choosing digital tools, ask vendors about data storage, encryption, access controls and whether the tool supports local anonymisation practices.
How organisations can build practical defences today
UNAIDS suggests a combination of policy, practice and pockets of funding: review digital and physical security risks regularly, keep protocols current, secure access to legal counsel and ring‑fence a budget for security measures and device replacement. Training matters , not as a one‑off course but as repeated, scenario‑based preparation. And where possible, support community development of tools that fit local connectivity, language and privacy needs.
Practical tip: create an incident playbook that covers immediate steps, communication templates and legal contacts , rehearse it annually.
It's a small change that can make every interaction safer for people who already face so much risk.
Source Reference Map
Story idea inspired by: [1]
Sources by paragraph: