Archive for the ‘Privacy Incidents’ Category

FEMA Records Of 16,000 Katrina Victims Posted Online

Tuesday, December 23rd, 2008

How did the following happen…there are many options…insider threat? Poor IT storage controls? Poor applications development controls? Perhaps using real personally identifiable information (PII) for test purposes? Hacker break-in? Through an outsourced company with access to the PII, but who also had poor controls? There are so many possibilities…

(more…)

Blackberry Disposal Lessons From McCain & Palin

Tuesday, December 16th, 2008

Another real-life example to show the importance of having effective policies and procedures in place for not only information disposal, but also for the disposal of computers and storage media…

(more…)

HIPAA Violation: Healthcare Worker Writes About Patients On MySpace

Thursday, December 4th, 2008

What was this worker for a healthcare provider thinking…didn’t/doesn’t the provider provide any kind of information security or privacy training or awareness communications…?

(more…)

Cybercriminals Threaten To Post Millions Of PII Records For Express Scripts Customers

Friday, November 7th, 2008

Just last month I blogged about the new Identity Theft Enforcement and Restitution Act of 2008. It covers extortion. I’m interested to see if it gets used for the latest extortion attempt…

(more…)

Email “Hack” Tells University Students & Staff That U.S. President Vote Is “Tomorrow”

Wednesday, November 5th, 2008

Here’s another email incident example to add to your files…

(more…)

Hackers Are “Rattlesnakes Without the Rattles”

Saturday, October 25th, 2008

Research into the psychology of hackers has been going on ever since Cap’n Crunch cereal whistles were used to make free phone calls to anywhere in the world.
I saw the ABC News article…

(more…)

Two Great Sites About Privacy Breaches and Privacy Studies

Thursday, October 16th, 2008

A friend (thanks Terry!) just pointed me to a couple of really great sites that Nymity provides without needing to register, and they have no ads or marketing…

(more…)

Iowa Land Records Association Posts SSNs…Including The Governor’s…On Their Internet Site

Wednesday, September 3rd, 2008

Okay, here’s another example of a ridiculously dumb privacy breach that occurred, in Iowa this time, through a government agency posting information on the Internet…

(more…)

Laptop Containing PII of 1 Million+ People Sold On eBay for $141

Saturday, August 30th, 2008

I’ve been doing a lot of work with data retention and disposal policies and procedures lately, remembering the silly things I have read about with regard to organizations getting rid of their computers, such as selling their computers on eBay when they no longer need them…without removing the information! This is certainly not a phenomenon that is confined to the U.S.
Lo and behold, another situation has happened where an organization sold their old computer on eBay…for a bargain at £77 ($141), and it contained a a huge amount of personally identifiable information (PII), including credit card applications, on what is reported to be as many as over 1 million customers. Here are a few excerpts from the report in Forbes…

(more…)

Insider Threat Examples & 7th HIPAA Criminal Conviction

Monday, August 25th, 2008

Yesterday I read about the 7th criminal conviction and sentencing that has been given under HIPAA, “Woman gets 14 months in ID theft case.”

(more…)