Skip the navigation

E-mail glitch exposes private data in California

The incident could be the first major test of the state's privacy law

By Dan Verton
July 6, 2004 12:00 PM ET

Computerworld - IT officials in Contra Costa County, Calif., today launched a countywide investigation into how hundreds of internal e-mails containing private employee data were sent out inadvertently to a Swedish company.
The investigation was launched after Computerworld notified the county that Robert Carlesten, a 26-year-old managing director of Internet company Ord&Bild, based in Karlstad, Sweden, could produce dozens of e-mails he said have been arriving at his Internet.ac domain regularly for the past two years.
Carlesten said he tried to contact the senders of the e-mails on numerous occasions but received no reply.
In addition to a deluge of administrative communications from the county's Department of Information Technology and human resources director, the e-mails contain detailed discussions and attachments related to the payroll files for the county's Superior Court as well as current and former employee benefits. Many of the e-mails, obtained by Computerworld, contained the names, employee numbers and benefits of Superior Court commissioners and other workers.
Tom Whittington, CIO of Contra Costa County, said the county became aware of the problem only after receiving calls from Computerworld. A preliminary investigation, he said, revealed that the problem was the result of some county employees using erroneous e-mail address books and wasn't caused by a virus or worm infection.
"We've started to take action to stop this, and I believe we have stopped it," said Whittington. "We shut off and blocked the Internet.ac domain so our employees can't send any e-mails to that address."
Part of the problem, said Whittington, is that the county's naming structure includes ".ac" for the auditor controller's office. "Now we need to research who has the bad address book that has this address."
But that move poses a potential challenge for Whittington's IT administrators: Many employees have personal address books that are stored only on their PCs, making it impossible for the county's IT department to centrally update all address books.
Although Whittington said he has been advised by the county's chief information security officer that counties and cities are exempt from California's landmark identity-theft law, known as SB 1386, some legal analysts said the county may be required to notify those whose personal information was compromised.
SB 1386, which went into effect July 1, 2003, requires companies that do business with California residents to inform customers when their names, in combination with personally identifiable information, have been accessed by an unauthorized person. If Contra Costa County is required to follow the statute, it would be the first major test of the law.
Jeff Matsuura, aprofessor at the University of Dayton School of Law, said that on face value, the e-mails appear to contain personally identifiable information that is covered by SB 1386. "It seems to me that such an incident would gut the statute if this kind of disclosure did not fall within it," said Matsuura.
He added that there might be other federal legal issues that come into play, such as whether the incidents violate the Electronic Communications Privacy Act.
"If I were advising the county, I'd tell them to notify everybody whose personal data was compromised," said Matsuura.

Read more about Privacy in Computerworld's Privacy Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Privacy White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Privacy White Papers
Privacy Webcasts
A Road Map for Best Practice Social Media Acceptable Use Policy
Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Privacy Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs