Skip the navigation

Update: California lawmakers rip handling of data theft at university

Instead of a broad media advisory, they want potential victims to be notified directly

By Todd R. Weiss
October 29, 2004 12:00 PM ET

Computerworld - Four members of the California state assembly are pressuring the state's Department of Social Services (DSS) to immediately improve its attempts to notify 1.4 million state residents that their personal information may have been stolen by hackers in August.
In a letter Wednesday to Kim Belshe, secretary of the state's Health and Human Services Agency, which oversees the DSS, the lawmakers were critical of the department's decision to "only issue a media advisory about the 'unauthorized access.' " The media advisory "is not the most effective way to communicate with the workers and affected elderly and disabled clients," the letter stated.
Instead, the legislators wrote, "we believe it is imperative and well worth the cost to individually inform every affected party so each client and worker can personally check and see if they have been a victim of identify theft."
Under a California privacy law that went into effect last year, businesses and public agencies are required to inform individuals when their names -- in combination with either their Social Security numbers, driver's license numbers or credit/debit card numbers with personal identification numbers -- have been accessed by an unauthorized person (see story).
Last week, the state announced the apparent security breach and warned affected state residents of the incident through a media advisory (see story). The personal data was being used with the department's consent by a researcher working at the University of California, Berkeley, in August when it was apparently infiltrated by hackers. The DSS is working with the FBI to investigate the case.
The incident involved a computer that contained personal information on about 1.4 million recipients and providers participating in DSS's In-Home Supportive Services (IHSS) program, which provides home care services to low-income elderly and disabled Californians. Names, addresses, telephone and Social Security numbers, and the birth dates of IHSS participants may have been stolen, according to the DSS.

"We respectfully request that you require the Department of Social Services to individually notify In-Home Supportive Services recipients and providers that the privacy of their personal information may have been compromised due to the breach of security suffered at UC-Berkeley," the letter stated.
Hans Hemann, chief of staff for assembly member Loni Hancock, said the DSS response of sending out a media advisory was "underwhelming."
"We believe that the efforts of the department have not reached a sufficient number of the IHSS clients so far," Hemann said. The media advisory was sent to about 500 newspapers, television and radio stations, he said, and the DSS set up



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Privacy White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Privacy White Papers
Privacy Webcasts
A Road Map for Best Practice Social Media Acceptable Use Policy
Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Privacy Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs