Latest Comments
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM

Sensitive information of 140,000 new parents compromised

  • Email a Friend
  • Print Page
Sensitive information of 140,000 new parents compromised
By Dan Kaplan
May 22, 2007 10:48 AM
Tags: Sensitive | information | of | 140,000 | new | Georgia | parents | compromised
DHR, which oversees the state Division of Public Health, said in the letter mailed last week that it improperly discarded records containing the Social Security numbers and medical histories of parents whose babies were born in the state between April 2006 and March 16 of this year.

Stuart Brown, director of the division, called the incident "a tremendous mistake," but said there is no evidence any of the data has been misused, according to media reports. The records did not contain any names or addresses, but did include data about parents' race, education, pregnancy care and information about the delivery.

Lisa Moery, spokeswoman for the DHR, told SCMagazine.com today that the incident came to light after an investigative reporter for a local television station discovered the records in March in trash bins outside a facility.

"We weren't aware of it until last week," Moery said.

In a separate message posted on the agency's website, Brown advised parents to place a fraud alert with one of the three major credit-reporting agencies. He added that the state Office of Vital Records soon will contact affected people "to verify specific data and provide individuals with additional information."

Brown told the Atlanta Journal-Constitution that hospitals submit the records to the state with birth certificates. The forms are supposed to be shredded after information in them is entered into computers.

However, Brown told the paper, the information was never destroyed because of a staff turnover. He promised offenders would be disciplined.

DHR has since instituted new confidentiality policies and procedures, trained all Vital Records staff on properly disposing of personal information and implemented updated shredding machines, according to a statement.

Kevin Simzer, chief marketing officer of Entrust, told SCMagazine.com that technology doesn't matter unless organisations ensure employees understand the value of sensitive data while also having the proper policies in place.

"It sounds like they really didn't have these things in place," Simzer said.

Phil Neray, vice president at Guardium, told SCMagazine.com that organisations must establish "data-centric security cultures" to get employees thinking about safeguarding information.

This is not the first information security breakdown in Georgia state government. Last year, a contractor lost a disk containing the names, birth dates and Social Security numbers of 2.9 million health services recipients.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Access Control Whitepapers