PDA

View Full Version : After laptop theft, Baylor Health warns of possible data compromise



OMEN
11-06-2008, 04:16 PM
About 7,400 patients in the HealthTexas Provider Network could be affected
HealthTexas Provider Network Inc., a subsidiary of Dallas-based Baylor Health Care System, is notifying about 7,400 patients of the potential compromise of their Social Security numbers and other personal information after a laptop containing the data was stolen in September.

It is also contacting an additional 100,000 people whose records on the laptop contained a "limited amount" of health information -- though not Social Security numbers, Baylor said in a statement yesterday.

The laptop was left overnight by an employee in her car, from which it was stolen sometime in mid-September. The computer was used mainly for administrative purposes and therefore did not contain comprehensive patient histories, Baylor said. The employee from whom the laptop was stolen has been fired, a Baylor spokeswoman added today.

Individuals whose Social Security numbers were compromised in the incident will receive a year's worth of free credit monitoring, the spokeswoman said.

Ironically, the theft comes as Baylor is rolling out new technology aimed at helping it track laptops and remotely erase sensitive information on them in the event of a loss or theft.

The incident highlights yet again why security analysts have for a long time now advocated the use of encryption or other measures for protecting sensitive data on laptops and other mobile devices.

The Privacy Rights Clearinghouse, which maintains a data breach log, lists dozens of incidents this year involving data compromises stemming from lost laptops, PCs and storage devices.

For example, the National Heart, Lung and Blood Institute (NHLBI) in March disclosed that a laptop containing sensitive data on about 2,500 individuals had been stolen. In another incident the same month, Agilent Technologies Inc. disclosed the theft of a laptop containing confidential information on more than 50,000 current and former employees.

In January, Horizon Blue Cross Blue Shield of New Jersey and Georgetown University, both announced data compromises resulting from the loss of a laptop and a storage device, respectively. In Horizon's case, the stolen laptop contained sensitive data on 300,000 people. A security feature on the stolen computer later erased that data.

In the Georgetown University incident, the stolen disk contained personal data on about 38,000 current and former students, faculty members and staffers.

Compworld