Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Broadcasting Company Laptop With Employee Personal Information Stolen | Main | Information Assurance: Make a Perspective Adjustment; It's All About the Business »

Computer Stolen from Insurance Provider Has Personal Information About 1,200 Villanova University students and staff members

And yes...still another example of a laptop with clear text personally identifiable information (PII) being stolen.

Villanova University confirmed on 11/2 that a laptop with information about 1,200 of their students and staff members, along with other individuals not part of Villanova, was stolen from their auto insurer, Hilb, Rogal & Hobbs in September. Notifications went out to the involved individuals on October 26.

The insurer is providing the impacted indivuals with credit monitoring, which is appropriate. However, the story did not say for how long they would get the monitoring.

It is interesting that the school was criticized for contacting the parents instead of the students directly. However, the school made a point that the notifications went to the impacted individuals' permanent addresses. Without knowing all the details on the surface this seems to be a prudent decision; sending notifications to temporary addresses would increase the risk that the individuals may never get the notifications.

When creating your privacy breach respsonse plan, be sure to consider such issues; where do you send the notifications along with how soon following the incident following procedures to validate the breach along with the individuals impacted and their associated PII, and any necessary lag time (as little as possible) for law investigation.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/235

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.