Posts Tagged ‘privacy breach’

Sanctions For Ohio Breach: Lost Vacation Time, Terminations, and a “Resignation”

Sunday, October 14th, 2007

The Ohio Department of Administrative Services (DAS) has determined that the appropriate sanction for inadequate security practices by the Ohio Department of Administrative Services’ Administrative Knowledge System (OAKS) ERP project system team leader, that resulted in the theft of an un-encrypted backup tape containing the personally identifiable information (PII) of 1.3 million individuals, is the loss of 40 hours of vacation time.

(more…)

Iowa Universities Provide Examples of Good and Bad Information Security and Privacy

Wednesday, October 10th, 2007

In the past week the two largest universities in Iowa provided examples of both great and poor security practices. Let’s see…how about the bad example first?

(more…)

ABN Amro PII Breached Through P2P: Lessons Learned

Monday, October 1st, 2007

Much is written about the risks P2P presents to organizations, but many organizations continue to implement P2P technologies, or more accurately allow their personnel to implement them on computers used for business, because they are willing to risk that the threat theories will not materialize within their own organizations.

(more…)

Canadian Privacy Commissioners Release TJX Investigation Report

Tuesday, September 25th, 2007

Yesterday the Office of the Privacy Commissioner of Canada and the Office of the Information and Prrivacy Commissioner of Alberta released their “Report of an Investigation into the Security, Collection and Retention of Personal Information” concerning the TJX breach. The investigation was performed to determine if, and if so to what extent, the incident was a violation of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and/or the Personal Information Protection Act (PIPA).

(more…)

New FTC Report Provides Organizations Good Guidance For Protecting PII

Tuesday, September 18th, 2007

Today the U.S. Federal Trade Commission (FTC) released a report, “Combating Identity Theft: Implementing a Coordinated Plan.”

(more…)

Would You Be More Inclined To Work For A Company That Gave You Identity Theft Insurance As A Benefit?

Monday, September 17th, 2007

Last year I had a couple of different identity theft insurance vendors contact me wanting me to endorse their products as they were trying to sell the packages to employers to offer to their employees as part of their total benefits packages.

(more…)

Jailtime: for Teen Who Posted Nude Photo of His Ex-Girlfriend on MySpace & for Employee Caught with Illegal Porn

Friday, August 31st, 2007

I’ve talked several times about some of the risks of using the social networking sites, such as here and here.
Here is an example of how others can post information about you on these sites that will continue to haunt you for years to come.

(more…)

Compliance and Information Security: Common Sense Confirmed

Thursday, July 26th, 2007

So many times I’ve heard business leaders complain that the data protection requirements within the multiple laws and regulations only hurt business; that they are not necessary and have no true impact on really protecting data…they are just bureaucratic hoops forced upon businesses to placate the politicians’ constituents by lawmakers who know nothing about the nuts and bolts of implementing information security…and that the cost of compliance is only hurts the business’ bottom line.
Hmm…

(more…)

On The Internet, If It Looks, Quacks and Walks Like a Duck, Is It *REALLY* a Duck?

Wednesday, June 20th, 2007

I am a great believer of performing due diligence to ensure potential new hires have no deceptive or malicious skeletons in their past that may be reincarnated after they have been hired and entrusted with access to sensitive information and supporting resources. There are appropriate times organizations should do criminal background checks, education checks, and other checks as appropriate and legal for the position being filled and the location of the facility.

(more…)

Medical Identity Theft and Bill Requiring Criminal Background Checks In LTC Facilities

Tuesday, June 19th, 2007

I have had relatives very close to me who, because of degenerative diseases and medical problems, have had to go to long term care (LTC) facilities. I always worried about the care they were receiving when I was not around. I worried that others would not be caring for them in a truly caring and kind way. I worried that people who had been convicted of violent crimes and financial fraud might try to take advantage of them and the others in the facility. I tried to keep a close watch on them.

(more…)