State Department, VA disclose two new data breaches
One affects passport applicants, the other, VA patients
Computerworld - Two federal agencies that have already drawn attention this year for data security breaches are back in the spotlight again -- for the same reason.
One of them is the U.S. Department of State, which last week disclosed that it had notified close to 400 individuals that the data they had submitted with their passport applications had been stolen in a database intrusion (download PDF).
And last Saturday, the U.S. Department of Veteran's Affairs (VA) said that one of its medical centers in Oregon had accidentally posted personal data on about 1,600 patients on its public Web site.
The breach at the State Department occurred in March at around the same time the agency disclosed that some of its contractors had illegally snooped on passport records belonging to Sen. Barack Obama (D-Ill.), Sen. John McCain (R-Ariz.) and other high-profile citizens, according to a spokeswoman.
That disclosure triggered a review of the security controls protecting the State Department's Passport Information Electronic Records System (PIERS), which contains records on 192 million passports for 127 million people. An Inspector General's report (download PDF) was released in July and identified "many control weaknesses" -- including a general lack of policies, procedures and training for protecting passport data at the State Department. The report noted that there were about 20,500 users with active PIERS accounts as of May, with about 12,200 of them being employees or contractors at the department.
According to a State Department spokeswoman, 383 records were illegally accessed by a State Department employee. That worker has since been terminated, the spokeswoman said. All of those who were affected by the incident have been notified by the department and have been offered one year's worth of free credit monitoring. The notifications were sent out in two batches, with the first set going out on July 10 and the second on Oct. 6.
When asked how the agency discovered the breach and why it took so long to notify affected individuals, the spokeswoman cited a previous explanation of the events by Sean McCormack, another spokesman at the agency. McCormack said the department learned of the breach at around the same time the snooping incidents were disclosed publicly, but offered no further details.
According to The Washington Post, the State Department was tipped off to the intrusion in March by police officers in Washington who discovered nearly two-dozen credit cards and printouts of eight passport applications during the search of a car that was stopped for having excessively tinted windows. Four of the names on the credit cards matched four of the names on the passport applications, leading police to conclude the passport information had been stolen for identity theft purposes.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Pay-as-you-Grow Data Protection: IBM Tivoli's Full-featured Data Protection Suite for Small to Medium Businesses IBM Tivoli Storage Manager Suite for Unified Recovery gives small and medium businesses the opportunity to start out with only the individual solutions...
- Streamline Data Protection with IBM Tivoli Storage Manager Operations Center IBM Tivoli Storage Manager (TSM) has been an industry-standard data protection solution for two decades. But, where most competitors focus exclusively on Backup...
- Simplify and Consolidate Data Protection for Better Business Results Learn about IBM® Tivoli® Storage Manager Operations Center, which provides advanced visualization, built-in analytics and integrated workflow automation features that leapfrog traditional backup...
- HP HAVEn: See the big picture in Big Data HP HAVEn is the industry's first comprehensive, scalable, open, and secure platform for Big Data. Enterprises are drowning in a sea of data...
- Data Protection and Disaster Recovery with iSCSI and VMware Get this on demand webcast now
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Privacy White Papers | Webcasts