Stolen tape puts Bristol-Myers employee data at risk
Thieves seize tape containing personal data during stopover by third-party vendor
Computerworld - Bristol-Myers Squibb Co. officials last week confirmed that a nonencrypted backup tape containing the personal data of current and former employees and their dependents was stolen on June 4 from a delivery truck carrying the device.
Bristol-Myers spokeswoman Laura Hortas said the New York-based pharmaceutical company began notifying current, former and retired employees by mail on July 12 about the missing backup tape. Bristol-Myers would not disclose how many people are affected by the breach.
However, according to a security breach notification letter (download PDF) sent by the company to the New Hampshire Attorney General's office, the personal data of 458 residents of that state was stored on the stolen tape.
Hortas declined to disclose where the theft occurred or any other circumstances regarding the incident, citing an ongoing investigation by Bristol-Myers and law enforcement authorities. She also would not identify the third-party storage vendor hired by Bristol-Myers to transport the sensitive data.
She did say that thieves broke into the delivery truck during a stopover at an undisclosed facility. Bristol-Myers is currently in the process of ensuring that all data tapes maintained by its third-party storage vendor are encrypted going forward.
"Bristol-Myers Squibb regrets that the incident occurred and is committed to providing appropriate assistance for affected individuals who had their personal information on the data tape," said Hortas, reading from a prepared company statement. "We are committed to protecting the privacy and security of employee and dependent information. Maintaining the trust and confidence of our employees is paramount to Bristol-Myers Squibb."
The stolen computer tape included the names, addresses, birthdays, Social Security numbers, marital status, bank account numbers, salaries, and hiring and termination/retirement dates of the affected employees. In addition, the tape has Social Security and address information about dependents of former and current employees.
Hortas said that data on the missing backup tape is protected by a 12-character password and a jumbled text format that can only be read through "pricey" specialized software. "The tape is not something your average person could just pick up and know how to access," she added.
Bristol-Myers said it has no reason to believe that any data on the tape has been inappropriately accessed or that identity fraud has been committed. The company is offering one year of free credit monitoring and identity theft insurance to all individuals and dependents affected by the data breach.
Read more about Applications in Computerworld's Applications Topic Center.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Red Hat JBoss Fuse Compared with Oracle Service Bus Competitive Brief Read this paper to learn how to start more projects, deploy technology more pervasively within the enterprise, and apply more of your budget...
- Red Hat JBoss BRMS Best Practices Guide Learn the technical best practices for development with Red Hat JBoss Enterprise BRMS. Following the best practices outlined in these guides will result...
- Red Hat JBoss Enterprise Application Platform and IBM WebSphere Application Server Network Deployment Edition This competitive brief outlines the differences in the economies of the competing application platforms, the implementation of the JEE specification, open standards support...
- Red Hat JBoss Enterprise Application Platform and Oracle WebLogic Server Edition Competitive Brief This competitive brief outlines the differences in the economies of the competing application platforms, the implementation of the JEE specification, open standards support...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
On-Demand Webcast: 7 Reasons to Choose VoIP - Thinking about a new phone system for your business?
Be sure to watch this informative webcast. Steve Strauss, small business columnist for USA... - Live Webcast
Unified Communications 101 - Learn more!
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Applications White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!