FBI probes data theft blackmail scheme
Data thieves threaten to release millions of patient records
IDG News Service - Data thieves are threatening to release millions of patient records held by a U.S. prescription drug management company unless the company pays up.
Express Scripts in St. Louis said on Thursday it received a letter in early October with the names, birth dates, Social Security numbers and some prescription information for 75 patients. The company provides benefit management services to health care organizations, insurers and other businesses.
"While we are unaware at this time of any actual misuse of any members' information, we understand the concern that this situation has caused our members," Express Scripts said on a Web site set up to provide information on the breach.
The company has also included contact information for credit monitoring agencies and other resources for people who believed they may be a victim of fraud.
Express Scripts said it has a variety of security systems to protect patient data but said no system is invulnerable. Officials have identified where the data was stored and have implemented "enhanced controls," the company said.
The data breach at Express Scripts underscores the trouble enterprises and governments are having protecting their data from loss, theft and inadvertent disclosure.
Since January 2005, more than 230 million records involving the personal data of U.S. residents have been compromised due to breaches, according to the Privacy Rights Clearinghouse's Chronology of Data Breaches.
Hackers targeting an insecure wireless network at retailer The TJX Companies Inc. resulted in upward of 94 million credit and debit card accounts being compromised in 2007.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts