Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Since This is Health Information Privacy and Security Week... | Main | Health Information On Computer Stolen From Vancouver Office »

Notification Delayed Months after SSNs and birthdates of 40,000 stolen in Hawaii

The Honolulu Star Bulletin reported today

"Records containing the names, Social Security numbers and birth dates of more than 40,000 individuals were illegally reproduced at a copying business sometime before January while they were waiting to be put onto a compact disc for the state.  State Attorney General Mark Bennett said federal authorities notified his office of the theft in January but asked that the information be withheld while an unrelated drug investigation was ongoing."

This illustrates one of the concerns with the loopholes in the existing and proposed breach notification laws; they allow law enforcement to delay notifications following such theft of personal information that can easily be used for identity theft and fraud, without providing any accompanying accountability to the law enforcement for the bad things that happen to the impacted individuals in the meantime. 

The information was withheld because of "an unrelated" drug investigation?  Someone, or perhaps several people, had 40,000 people's SSNs and birthdates, and law enforcement thought it was okay that they be kept in the dark because of the remote chance that an unrelated drug investigation may somehow be involved? 

Accountability to law enforcement should be written in with these loopholes.  Perhaps then it would not be such a seemingly flippant decision for law enforcement to restrict notification if they were responsible for fixing all the messes that resulted from the crimes that occurred with the stolen data during that wait time when the corresponding people were kept in the dark.

""We are taking this issue very seriously and strongly advise those affected ... to obtain and review their credit reports," state Attorney General Mark Bennett said yesterday in a news release. "Social Security numbers and other personal information can be used by thieves to obtain credit cards, to open fraudulent bank accounts, to mortgage property and purchase automobiles.""

They understand the risks, and yet they waited over four months to notify the individuals?  And now, they are advising them to obtain and review their credit reports?  They should at least be offering to pay for credit monitoring services for these people.  Again, organizations and law enforcement need to be more directly accountable for what happens to stolen personal data when they choose to delay notification.

"The records from the Voluntary Employees Benefit Association of Hawaii were set to be copied at NewTech Imaging in Honolulu when they were apparently illegally reproduced by one or more people, said Bennett's special assistant, Dana Viola."

This is another surprising risk that was taken; highly confidential data was taken to a local public copy store and left to be reproduced?  Why was such a decision made to leave highly sensitive data in the hands of an untrusted third party, in what appears to be a neighborhood copy store, where the public mills about?

"She could not say when the records were taken, but Bennett believes it was after February 2005.  Federal investigators learned in January that the records had been stolen, Bennett said. Police later found the data on a computer that had been confiscated as part of an investigation into drugs.  Russell Okata, HGEA's executive director, said the state is to blame for the theft because officials failed to "adequately protect the records" of the union's members."

The sensitive data should never have been taken to a public store and dropped off for duplication in the first place.  Organizations who collect and maintain sensitive data must be responsible for it at all times, especially when they choose to entrust it to other organizations, for whatever reasons, and they need to be accountable when bad things occur as a result of those decisions.

Technorati Tags




TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/54

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.