Offshore outsourcing cited in Florida data leak
State employees are being warned that their personal data may have been compromised
March 26, 2006 12:00 PM ETIDG News Service - Florida state employees are being warned that their personal information may have been compromised after work on the state's People First payroll and human resources system was improperly subcontracted to a company in India.
Employees who worked for the state during the 18-month period between Jan. 1, 2003, and June 30, 2004, may be affected, according to an e-mail message sent to all state employees on March 16. The state's Department of Management Services (DMS), which oversees the People First system, estimates that 108,000 current and former state employees may be affected by the data breach, although that estimate could change as the department's investigation into the matter continues.
The e-mail was sent after a subcontractor of outsourcing service provider Convergys Corp. improperly allowed subcontractors in India to index state personnel files, said DMS spokeswoman Tiffany Koenigkramer. The offshoring was done as part of Convergys's nine-year, $350 million contract to manage the state's personnel work.
Convergys had subcontracted the indexing work to GDXdata Inc., in Denver, which itself turned to a subcontractor in India, a violation of the GDXdata contract with Convergys, the DMS said. Convergys has since cancelled its contract with GDXdata, the agency said.
Convergys said the offshore work was done without its knowledge. "Convergys was misled by GDX, one of several subcontractors hired to perform work for the state of Florida," the company said in a statement.
The offshore work was made public in late December, when documents were unsealed in a "whistle-blower" lawsuit brought against GDXdata by two former employees.
The DMS is investigating the matter, but it has so far detected "no known cases of credit fraud or identity fraud that resulted from this work," Koenigkramer said.
"It is common today for businesses and even government to use offshore companies," the DMS March 16 e-mail states. "However, the use of offshore services in this case was inappropriate and unacceptable."
Convergys and the DMS expect to provide affected employees with a credit-protection plan this week, Koenigkramer said.
That is not enough for one of the state's public-employee unions, which is calling for an end to the Convergys deal and saying that the People First system has been mismanaged. "We want this thing killed," said Doug Martin, communications director at the American Federation of State, County and Municipal Employees, Council 79. "This is a joke, and the sad thing is, we're paying for it."
State Sen. Walter "Skip" Campbell, a Democrat who would also like to see the contract pulled, called the outsourcing a "critical security breach," in part because it inappropriately exposed sensitive information about the state's law enforcement agents. "We don't know how far the dissemination of this information has gone," he said.
Based in Cincinnati, Convergys is a provider of billing, customer service and human resources outsourcing services. It reported $2.5 billion in revenue last year, according to the company's Web site.
A spokeswoman for GDXdata declined to comment for this story.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
