Computer Stolen from Insurance Provider Has Personal Information About 1,200 Villanova University students and staff members

And yes…still another example of a laptop with clear text personally identifiable information (PII) being stolen.
Villanova University confirmed on 11/2 that a laptop with information about 1,200 of their students and staff members, along with other individuals not part of Villanova, was stolen from their auto insurer, Hilb, Rogal & Hobbs in September. Notifications went out to the involved individuals on October 26.


The insurer is providing the impacted indivuals with credit monitoring, which is appropriate. However, the story did not say for how long they would get the monitoring.
It is interesting that the school was criticized for contacting the parents instead of the students directly. However, the school made a point that the notifications went to the impacted individuals’ permanent addresses. Without knowing all the details on the surface this seems to be a prudent decision; sending notifications to temporary addresses would increase the risk that the individuals may never get the notifications.
When creating your privacy breach respsonse plan, be sure to consider such issues; where do you send the notifications along with how soon following the incident following procedures to validate the breach along with the individuals impacted and their associated PII, and any necessary lag time (as little as possible) for law investigation.

Tags: , , , , , , , ,

Leave a Reply