<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Because I am Here &#187; Data Breaches</title>
	<atom:link href="http://www.aarontitus.net/blog/category/privacy/breaches/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aarontitus.net/blog</link>
	<description>Aaron Titus' Personal Blog</description>
	<lastBuildDate>Tue, 13 Jul 2010 20:45:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>HIPPA Breach Notification Requirements Effective September 23, 2009</title>
		<link>http://www.aarontitus.net/blog/2009/09/22/hippa-breach-notification-requirements-effective-september-23-2009/</link>
		<comments>http://www.aarontitus.net/blog/2009/09/22/hippa-breach-notification-requirements-effective-september-23-2009/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 13:17:01 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Medical Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=100</guid>
		<description><![CDATA[The department of Health and Human Services (HHS) and the FTC have issued a new interim final rule governing health information breach notification requirements.  I blogged on this issue back in March 2009, just after the stimulus package, American Recovery and Reinvestment Act of 2009 (ARRA), passed.
This rule, issued in response to ARRA, goes [...]]]></description>
			<content:encoded><![CDATA[<p>The department of Health and Human Services (HHS) and the FTC have issued a new <a href="http://edocket.access.gpo.gov/2009/E9-20169.htm">interim final rule</a> governing health information breach notification requirements.  I <a href="http://jeffreyneu.com/20090318184/how-to-write-an-arra-breach-notification-letter.html">blogged on this issue</a> back in March 2009, just after the stimulus package, <em>American Recovery and Reinvestment Act of 2009</em> (ARRA), passed.</p>
<p>This rule, issued in response to <em>ARRA</em>, goes into effect on Wednesday. At that point, all HIPPA-covered entities and their business associates must notify individuals and HHS when personal health information has been breached. HIPPA-covered entities include health plans, health care clearinghouses, or health care providers. The rule also covers &#8220;business associates&#8221; which include billing companies, transaction companies, lawyers, accountants, managers, administrators, or anyone who handles health information on behalf of a HIPPA-covered entity.</p>
<p>A breach is when individually identifiable health information is acquired, used, accessed, or disclosed to an unauthorized party, in a way that compromises its security or privacy. A &#8220;breach&#8221; does not include inadvertent disclosures among employees who are normally authorized to view protected health information. A breach also does not include exposure of encrypted personal health information, for example.</p>
<p>When a breach occurs, the covered entity must notify victims and the Secretary of Human Services &ldquo;without unreasonable delay,&rdquo; and within 60 days of the discovery of the breach. The covered entity must notify the individual directly if possible (ie, by mail), and must also post a notice on its website if the breach involves 10 or more victims who are not directly reachable. If the breach involves more than 500 residents of a single state, the covered entity must also notify statewide media.</p>
<p>In certain limited circumstances a vendor might be subject to HHS and FTC notification rules. In this case, a vendor which serves the public <em>and</em> HIPPA-covered entities may comply with both rules by providing notice to individuals and the HIPPA-covered entity. In many instances, entities covered by this rule must also comply with applicable State notification laws. The test for pre-emption is whether the State law is &#8220;contrary,&#8221; to the federal law or whether &#8220;a covered entity could find it impossible to comply with both the State and federal requirements.&#8221;</p>
<h1>Compliance</h1>
<p>Of course, the best way to comply with the law is to avoiding breaches altogether. The most straightforward way to avoid having a breach is to encrypt personal health information. But if a breach does occur, complying with the law is straightforward. In addition to the requirements above, the notification must include a brief description of the incident, including the following information:</p>
<ul>
<li>Date of the breach;</li>
<li>Date of discovery;</li>
<li>Description of the types of protected health information breached;</li>
<li>Steps individuals should take to protect themselves from potential harm resulting from the breach;</li>
<li>A brief description of the investigation, efforts to minimize losses and prevent future breaches;</li>
<li>Contact information for individuals who wish to ask questions or learn more information, including a toll-free phone number, e-mail address, website, or postal address.</li>
</ul>
<p>Beyond that, you&#8217;ll have to <a href="http://jeffreyneu.com/20090318184/how-to-write-an-arra-breach-notification-letter.html#image">minimize your losses</a> by repairing your company&rsquo;s public image, regaining your customers&rsquo; trust, and mitigating civil liability.</p>
<p><em>References: 45 CFR parts 160, 162, and 164.</em></p>
<p><em>Note: This article was originally published on the <a href="http://jeffreyneu.com/20090919229/HIPPA-Breach-Notification-Requirements-Effective-September-23-2009.html">J.C. Neu &amp; Associates Blog</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/09/22/hippa-breach-notification-requirements-effective-september-23-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Write an ARRA Breach Notification Letter</title>
		<link>http://www.aarontitus.net/blog/2009/04/01/how-to-write-an-arra-breach-notification-letter/</link>
		<comments>http://www.aarontitus.net/blog/2009/04/01/how-to-write-an-arra-breach-notification-letter/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 21:48:08 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Medical Privacy]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2009/04/01/how-to-write-an-arra-breach-notification-letter/</guid>
		<description><![CDATA[Note:This article originally appeared on the Jeffrey Neu Blog.
&#8220;We&#8217;ve had a breach.&#8221; It&#8217;s a sentence nobody wants to hear, but when it happens to you, what to you do? If you&#8217;re in the healthcare industry, new federal regulations probably require you write a letter to the victims of the breach, or more. When and how [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note:This article originally appeared on the <a href="http://www.jeffreyneu.com/184-How-to-Write-an-ARRA-Breach-Notification-Letter.html">Jeffrey Neu Blog</a>.</em></p>
<p>&ldquo;We&rsquo;ve had a breach.&rdquo; It&rsquo;s a sentence nobody wants to hear, but when it happens to you, what to you do? If you&rsquo;re in the healthcare industry, new federal regulations probably require you write a letter to the victims of the breach, or more. When and how quickly do you have to send a HIPAA/ ARRA notification? And what does it have to say?</p>
<p><a name="readmore"></a>
<p>The <em>American Recovery and Reinvestment Act of 2009</em> (ARRA) requires HIPAA-covered entities to notify breach victims when protected health information has been disclosed to an unauthorized person. The legislation gives liberal exceptions for good faith and inadvertent disclosure. Redaction or encryption is an absolute defense to a breach.</p>
<p>&ldquo;Protected Health Information&rdquo; is any stored or transmitted health information which can be tied to an individual. It may include information not directly related to health, such as a full name, social security number, date of birth, home address, account number, or disability code. The law also requires third-party contractors or &ldquo;business associates&rdquo; to report breaches to the covered entity.</p>
<p>When a breach occurs, the covered entity must notify victims and the Secretary of Human Services &ldquo;without unreasonable delay,&rdquo; and within 60 days of the discovery of the breach. The covered entity must notify the individual directly if possible (ie, by mail), and must also post a notice on its website if the breach involves 10 or more victims who are not directly reachable. If the breach involves more than 500 residents of a single state, the covered entity must also notify statewide media.</p>
<p>A breach notification letter must meet differing but complementary legal and economic goals. They include:</p>
<p> <strong>
<ol>
<li><a href="#comply">Complying with law</a></li>
<li>Minimizing Losses
<ul>
<li><a href="#image">Repairing your company&rsquo;s public image</a></li>
<li><a href="#trust">Regaining your customers&rsquo; trust</a></li>
<li><a href="#liability">Mitigating civil liability </a></li>
</ul>
</li>
</ol>
<p></strong><a name="comply" title="comply"></a><br />
<h2>Compliance with Law</h2>
<p>Complying with the law is straightforward. In addition to the requirements above, the notification must include a brief description of the incident, including the following information:</p>
<ul>
<li>Date of the breach;</li>
<li>Date of discovery;</li>
<li>Description of the types of protected health information breached;</li>
<li>Steps individuals should take to protect themselves from potential harm resulting from the breach;</li>
<li>A brief description of the investigation, efforts to minimize losses and prevent future breaches;</li>
<li>Contact information for individuals who wish to ask questions or learn more information, including a toll-free phone number, e-mail address, website, or postal address.</li>
</ul>
<p> <a name="image" title="image"></a><br />
<h2>Repairing your Company&rsquo;s Image</h2>
<p>Avoid the natural tendency to clamp up. Of course, the best way to protect your company&rsquo;s image is to keep bad news out of the public eye. But once the cat&rsquo;s out of the bag, several studies indicate that more than two-thirds of economic losses arising from a data breach are due to brand diminishment and lost customer trust, rather than litigation or identity theft expenses.</p>
<p>Above all, your company must maintain credibility. Be honest, open, and share enough detail to convince an educated person that you know what you&rsquo;re talking about, and that you&rsquo;ve actually fixed the problem. Consider hiring an outside security consultant who can 1. Give you genuine feedback on your security practices, and 2. Vouch for your credibility when you say that your customers are safe.</p>
<p> <a name="trust" title="trust"></a><br />
<h2>Rebuilding Customer Trust</h2>
<p>Consider your last trip to the Department of Motor Vehicles. It probably consisted of waiting for hours in multiple serpentine lines without any direction, followed by more waiting, followed by spending money. The best part is riding away in your car when you&rsquo;re done. Surprisingly, Disneyland and the DMV have a lot in common: Long lines, spending money, and rides. What sets the DMV apart from the happiest place on earth? One important ingredient is Customer Empowerment.</p>
<p>One way the Disney folks empower customers is by posting periodic signs in long lines: &ldquo;<em>Wait Time: 45 minutes from this point</em>.&rdquo; Though the sign does not decrease wait time, it informs and empowers customers. And as Disney knows, empowered customers are happy customers. Frustrated, angry customers are far more likely to cause trouble or leave altogether.</p>
<p>The best way to rebuild your customers&rsquo; trust is to empower them. Too many breach notifications include the unhelpful statement, &ldquo;We have no reason to believe that anyone has accessed or misused your information.&rdquo; The statement is faulty because it does not empower the customer to take action. Also, if the statement isn&rsquo;t completely true, or if it changes in the future, it may inadvertently induce liability under certain circumstances. Further, these types of statements tend to frustrate rather than empower customers, causing some to conclude that the notification is incomplete or disingenuous.</p>
<p>Instead, consider these options:</p>
<ul>
<li>Say, &ldquo;Although we have no reason to believe that anyone has accessed or misused your information, if you think your personal information has been misused as a result of this breach, please call 1-800-XXX-XXXX so we can investigate&hellip;&rdquo;</li>
<li>Include statistics on typical rates of harm for similar breaches, where possible.</li>
<li>Actually investigate the breach.</li>
<li>Create a website where customers can get up-to-the minute updates on the investigation directly from you, rather than from the media (and update it after the media buzz has subsided). </li>
</ul>
<p> <a name="liability" title="liability"></a><br />
<h2>Mitigating Civil Liability</h2>
<p>ARRA does not expressly create a private right of action for a HIPAA breach. Other theoretical sources of liability exist, though. For example, an individual may be able to rely upon a notification statute as the basis for a suit alleging negligence <em>per se</em>, where the breach of the duty to notify causes proximate harm to the plaintiff. Next, failure to correct statements (such as privacy policies) which have become false or misleading in light of new events, may create a tortious cause of action if the company fails to warn customers about foreseeable risks to personal information.</p>
<p>In contrast, most breaches are not likely to create privacy liability. Privacy tort actions usually require the breached information to cause extreme emotional distress, or a dilution of the property value of reputation or prestige. In addition, most courts have consistently failed to force companies to pay for credit monitoring services unless:</p>
<ol>
<li>A person has become an actual victim of identity theft.</li>
<li>The person has found the thief</li>
<li>The person can prove that the thief&rsquo;s copy of their SSN or other personal information came from the breaching entity, and</li>
<li>The person proves that the entity had a legal obligation to keep that information private.</li>
</ol>
<p>Instead, it&rsquo;s important to remember that businesses stand to loose more money from brand diminishment and lost customer trust than from litigation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/04/01/how-to-write-an-arra-breach-notification-letter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stimulus Package Federalizes Health Information Breach Notifications</title>
		<link>http://www.aarontitus.net/blog/2009/03/06/stimulus-package-federalizes-health-information-breach-notifications/</link>
		<comments>http://www.aarontitus.net/blog/2009/03/06/stimulus-package-federalizes-health-information-breach-notifications/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 14:49:23 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2009/03/06/stimulus-package-federalizes-health-information-breach-notifications/</guid>
		<description><![CDATA[Note: This article was originally posted on JeffreyNeu.com.
Streamlining medical records has been a recurring theme of the Obama administration. Tucked away in the pending economic stimulus legislation, known as the American Recovery and Reinvestment Act (ARRA), is a provision which would create a breach notification requirement for health information breaches.
Starting in Subtitle D, ARRA takes [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article was originally posted on <a href="http://www.jeffreyneu.com/169-Stimulus-Package-Federalizes-Health-Information-Breach-Notifications.html">JeffreyNeu.com</a></em>.</p>
<p>Streamlining medical records has been a recurring theme of the Obama administration. Tucked away in the pending economic stimulus legislation, known as the <a href="http://www.opencongress.org/bill/111-h1/text">American Recovery and Reinvestment Act</a> (ARRA), is a provision which would create a breach notification requirement for health information breaches.</p>
<p>Starting in Subtitle D, ARRA takes an unprecedented foray into federalizing data breach notifications.  Although ARRA regulates breaches of health information, this legislation will no doubt be front and center of future debates about creating a Federal Breach Notification Law.</p>
<h2>Synopsis</h2>
<p>Here is a quick analysis: ARRA mirrors most state breach notification laws, in that it requires &#8220;covered entities&#8221; (ie, Health Plans, Health Care Providers, and Health Care Clearinghouses) to notify each individual if their &#8220;unsecured protected health information has been, or is reasonably believed by the covered entity to have been, accessed, acquired, or disclosed as a result of [a] breach.&#8221; Business Associates, or subcontractors, must alert the Health Care Provider of a breach.  The statute also places additional limits on how health information can be sold and shared.<br />
The statute dramatically broadens the ambiguous state-law concept of &#8220;data owners,&#8221; and applies to any HIPPA-covered entity that &#8220;accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured protected health information.&#8221;</p>
<p>As expected, the Federal law takes a lowest-common-denominator approach to duties.  For example, although notifications must be made &#8220;without reasonable delay,&#8221; the statute allows up to 60 calendar days to comply.  This is substantially longer than the longest state requirement, which requires notification within 45 days.<br />
Each state notification law requires direct (ie mail) notification to affected individuals unless the person can&#8217;t be found, and allows &#8220;Substitute Notice&#8221; in cases of large breaches.  &#8220;Substitute Notice&#8221; usually comprises posting an announcement on the organization&#8217;s website and notifying the media.  Some states do not permit Substitute Notice unless the breach is extremely large (250,000+ in some cases).  But ARRA allows substitute notice if the breach involves just 500 people in a single state.</p>
<p>The statute also reaches well beyond traditional &#8220;covered entities&#8221; to any service provider or vendor of personal health records.  Presumably, this would include data warehouses like Google or Microsoft, each of which has or has announced plans to create online consumer health records warehouses.  However, these vendors need only report the breach to the FTC, which will treat it as a deceptive trade practice. Individuals should not expect a letter from Google or Microsoft if their health care records are breached.</p>
<p>On one hand, this federal legislation will plug holes in several states statutes by regulating health information.  Arizona, California, Hawaii, Michigan, Oregon, and Rhode Island, for example, regulate health care providers and insurers differently from other companies, and may even completely exempt them from notification requirements.</p>
<p>This bill will no doubt spur the national discussion about breach notification laws.  But because they mimic existing state laws, the bill comes up short.  Breach Notification Laws were a step in the right direction when California passed the first one almost seven years ago.  But since that time, they have displayed several shortcomings, which I <a href="http://www.securitycatalyst.com/in-defense-of-breach-notification-laws-sort-of/">critique here</a>. Instead of fixing these problems, ARRA will exacerbate many of them. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/03/06/stimulus-package-federalizes-health-information-breach-notifications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cost of Data Breaches Rise</title>
		<link>http://www.aarontitus.net/blog/2009/02/04/cost-of-data-breaches-rise/</link>
		<comments>http://www.aarontitus.net/blog/2009/02/04/cost-of-data-breaches-rise/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 14:37:37 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2009/02/04/cost-of-data-breaches-rise/</guid>
		<description><![CDATA[Note: This post originally appeared on JeffreyNeu.com.
ZD Net reports that the cost of a data breach has gone up 2.5% from 2007, according to research published by the Ponemon Institute.
After comparing data from 43 companies (including several repeat offenders), companies loose just over $200 per compromised record.  Significantly, lost business due to a lack [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This post originally appeared on <a href="http://www.jeffreyneu.com/170-Cost-of-Data-Breaches-Rise.html">JeffreyNeu.com</a></em>.<br />
ZD Net reports that the cost of a data breach has gone up 2.5% from 2007, according to research published by the Ponemon Institute.</p>
<p>After comparing data from 43 companies (including several repeat offenders), companies loose just over $200 per compromised record.  Significantly, lost business due to a lack of customer trust and brand diminishment comprises 69% of the cost.</p>
<p>Forget about the cost of postage&#8230; businesses stand to loose much more in sales from customers who read, &#8220;We regret to inform you&#8230;&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/02/04/cost-of-data-breaches-rise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Top 5 Reasons You Won&#8217;t Hear About a Breach</title>
		<link>http://www.aarontitus.net/blog/2009/02/02/the-top-5-reasons-you-wont-hear-about-a-breach/</link>
		<comments>http://www.aarontitus.net/blog/2009/02/02/the-top-5-reasons-you-wont-hear-about-a-breach/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 15:11:02 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2009/02/02/the-top-5-reasons-you-wont-hear-about-a-breach/</guid>
		<description><![CDATA[Note: This article originally appeared on the Security Catalyst Blog.
I have personally discovered more than a hundred data breaches by schools, companies, doctors&#8217; offices, tax professionals, government agencies, and individuals over the past several years. Unfortunately, very few of the breaching entities proactively announce an average breach, regardless of the law.  Here are the [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.securitycatalyst.com/the-top-5-reasons-you-wont-hear-about-a-breach/">Security Catalyst Blog</a>.</em></p>
<p>I have personally discovered more than a hundred data breaches by schools, companies, doctors&#8217; offices, tax professionals, government agencies, and individuals over the past several years. Unfortunately, very few of the breaching entities proactively announce an average breach, regardless of the law.  Here are the most common reasons:</p>
<ol>
<li><strong>Failure to Detect</strong></li>
<li><strong>Market Devaluation of Privacy</strong></li>
<li><strong>Poor Communication</strong></li>
<li><strong>Ignorance of Law</strong></li>
<li><strong>Notification Difficulty</strong></li>
</ol>
<h3>Failure to Detect</h3>
<p>Many organizations do not have proper diagnostic processes to detect breaches when they occur, and many do not keep proper logs. Thus, when a press releases reads, &#8220;we have no evidence that the sensitive information was accessed…&#8221; it may simply mean that they did not keep any records, and thus literally have &#8220;no evidence.&#8221;</p>
<h3>Market Devaluation of Privacy</h3>
<p>The market does not value privacy. Ensuring privacy is expensive, but the costs of violating privacy are small. Doing a simple cost/benefit analysis, organizations often come to the logical conclusion that the PR ‘costs&#8217; of announcing a breach (especially when no hard proof of access exists) far outweigh any benefits.</p>
<p>In addition, most data breach notifications laws only require an organization to say, &#8220;Oops.&#8221; If the organization is feeling nice, they&#8217;ll say, &#8220;Oops, sorry.&#8221; And if they&#8217;re feeling gregarious, they&#8217;ll say, &#8220;Oops, sorry, and here&#8217;s a free report of how much damage has been done to your credit. You&#8217;ll still be at risk for years to come, though, so stay vigilant. Good luck.&#8221; But they have no responsibility to help you recover from financial identity theft, medical identity theft, or criminal identity theft. Merely getting a credit report does not protect against any of these risks.</p>
<h3>Poor Communication</h3>
<p>A cruel irony of data breaches is that the only source of information about a breach is filtered, packaged, and presented by the organization with the most incentive to skew the details. The breaching entity&#8217;s concern is to minimize perceived liability; therefore it is in their best interest to restrict the flow of information about the breach as far as possible.</p>
<p>I have read dozens of breach announcements, and they almost write themselves: &#8220;On X date, we discovered that some personal information was compromised. We acted immediately to make the information unavailable, and we have no evidence that anyone accessed it for inappropriate reasons. You should get a credit report as a precaution.&#8221;  Keeping a victim in the dark about the details protects only the breaching entity.</p>
<h3>Ignorance of Law</h3>
<p>Even in states where breach notification laws exist, smaller organizations often assume that the law only applies in limited circumstances, to larger companies, or to particularly large breaches.</p>
<h3>Notification Difficulty</h3>
<p>For the most part, organizations which choose not to report breaches get away with it.  But even under good circumstances, 100% victim notification is impossible. People move, phone numbers change, or addresses are incomplete or not on file. Letters that do arrive at the proper address may be ignored. Multiple contact strategies should be applied over long periods of time to reasonably ensure that most victims are notified.</p>
<p>I have suggested solutions to some of these problems <a href="http://www.securitycatalyst.com/in-defense-of-breach-notification-laws-sort-of/">here</a> and with the creation of <a href="http://www.nationalidwatch.org">National ID Watch</a></p>
<p><em>Aaron Titus is the Privacy Director for the <a href="http://www.libertycoalition.net">Liberty Coalition</a>, and runs <a href="http://www.nationalidwatch.org">National ID Watch</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/02/02/the-top-5-reasons-you-wont-hear-about-a-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>In Defense of Breach Notification Laws (sort of)</title>
		<link>http://www.aarontitus.net/blog/2009/01/17/in-defense-of-breach-notification-laws-sort-of/</link>
		<comments>http://www.aarontitus.net/blog/2009/01/17/in-defense-of-breach-notification-laws-sort-of/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 19:53:27 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2009/01/17/in-defense-of-breach-notification-laws-sort-of/</guid>
		<description><![CDATA[Note: This article was originally published on the Security Catalyst Blog.
Starting with California&#8217;s 2003 law, all but a hand full of states have now enacted breach notification laws (BNLs).  Though each is subtly different, all notification laws recognize that a if your identity, or Data Self, is treated as mere chattel, it is subject [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article was originally published on the <a href="http://www.securitycatalyst.com/in-defense-of-breach-notification-laws-sort-of/">Security Catalyst Blog</a>.</em></p>
<p>Starting with California&#8217;s 2003 law,<a name="note1"></a> all but a hand full of states have now enacted breach notification laws (BNLs).  Though each is subtly different, all notification laws recognize that a if your identity, or <a href="http://www.securitycatalyst.com/when-did-my-personal-information-become-your-property/">Data Self</a>, is treated as mere chattel, it is subject to fraud and abuse.  These laws require data stewards to notify an individual when his identity has been lost or kidnapped.</p>
<p>Your identity or Data Self is a digital alter-ego: a collection of personal facts which has its own life, fallacies, and mortality. Data is Self, but data is also treated like property.  <strong>If Self is data, and data is property, then Self is property</strong>.  If your Self is the property of others, then it can be bought, sold, traded, lost, stolen, or damaged like any other form of property.  <em>Identity Theft</em> is just that:  Where a person&#8217;s Data Self is stolen and abused.</p>
<h2>Measures of BNL Success</h2>
<p>With five years of breach notification law experience, it is essential to ask, &#8220;<a href="http://www.securitycatalyst.com/selective-notification/#comments" target="_blank">Are they working?</a>&#8221; My shorthand answer is &#8220;yes, sort of.&#8221;</p>
<p>I&#8217;ll be the first to admit that breach notifications are noisy, and contain a strong element of political theater.  Some contend that notification laws may even be harmful, distracting and confusing consumers into thinking they aren&#8217;t at risk if they don&#8217;t receive a notice. I agree that as currently written, breach notification laws have several shortcomings.  But their success or failure should be measured in several ways:</p>
<ol>
<li>Decreased Incidence of Identity Theft</li>
<li>Increased Awareness and Identity Control</li>
<li>Decreased Risk Behaviors and Incidence of Breach</li>
<li>Increased Victims&#8217; Rights</li>
</ol>
<p><a name="idtheft"></a></p>
<h3>1. Decreased Incidence of Identity Theft</h3>
<p><strong>Q: Do breach notification laws decrease identity theft?</strong></p>
<p><strong>A: Probably not.</strong> Several breach notification laws emphasize the need to protect consumers from identity theft and other misuse of a person&#8217;s Data Self.<a name="note3"></a> However, researchers <a href="http://www.romanosky.net/"> Sasha Romanosky</a>, <a href="http://www.heinz.cmu.edu/~rtelang/rahul_res.html">Professor Rahul Telang</a>, and <a href="http://www.heinz.cmu.edu/~acquisti/index.html">Professor Alessandro Acquisti</a> presented a <a href="http://weis2008.econinfosec.org/papers/Romanosky.pdf">well-reviewed paper</a> which measured the change in the rate of reported identity thefts before and after data breach laws went on the books. Though drawn from incomplete FTC data, the paper convincingly demonstrates that breach notification laws have a negligible effect on reported identity theft rates.  Instead, they suggest that a state&#8217;s gross domestic product and general fraud rate has a much stronger correlation with ID theft.</p>
<p><a name="control"></a></p>
<h3>2. Increased Awareness and Identity Control</h3>
<p><strong>Q: Do breach notification laws increase identity risk awareness?  How about consumers&#8217; control over their identities?</strong><br />
<strong>A: Yes, to varying degrees.</strong> A cruel irony of data breaches is that the responsible organization is the only one who knows exactly what happened, and they have the strongest incentive to hide or skew the details.  Many breaches go under- or unreported, regardless of law.  Even well-intentioned organizations issue vague, incomplete, blame-shifting or liability-reducing press releases that leave victims in the dark.  In order to effectively empower consumers to conduct their own risk analysis, breach notifications must contain the following elements:</p>
<ul>
<li><strong>Who</strong>: The class of victims affected by the breach.</li>
<li><strong>What</strong>: A complete list of exposed information, not just the ones required by law.</li>
<li><strong>Where</strong>: Exposing entity&#8217;s contact information.</li>
<li><strong>How and When</strong>: Sufficiently detailed information about the how and when the breach occurred.</li>
<li><strong>How Much</strong>: Total number affected, Sensitivity of information exposed, Duration of exposure, and Distribution method (ie, stolen laptop, online exposure, or dumpster).</li>
<li><strong>What Now</strong>: A clear statement of consumer&#8217;s legal rights (or lack of rights); Concrete actions taken by the organization to fix problems, mitigate risk, or remedy harm; Suggested actions for the victim.</li>
</ul>
<p>Of course, breach notification laws have much more lax reporting requirements than these.  And although I agree that the average breach announcement is &#8220;noisy,&#8221; I think it would be a mischaracterization to label them as nothing more than &#8220;noise.&#8221;  Even the least specific notifications build public awareness.  For better or worse, most public awareness of identity risks come from news bulletins about data breaches.  Although none of the announcements may put any particular individual on notice of a personal risk, these &#8220;noisy&#8221; notifications have a net positive effect of educating the population at large.</p>
<p><a name="risk"></a></p>
<h3>3. Decreased Risk Behaviors and Incidence of Breach</h3>
<p><strong>Q: Do breach notification laws decrease individual risk behavior?</strong><br />
<strong>A: Probably Not</strong>, but they have the potential to.  An effective notification must contain <em>actionable intelligence</em>, which means Intelligence plus Action.  For example, imagine that you are in a life raft in the middle of the ocean, with no hope of immediate rescue.  You see bubbles.  What do you do? You sink. You were able to gather intelligence, but had no way to act upon it. Intelligence without action breeds inaction.</p>
<p>However, imagine you&#8217;re on the same raft, and you see bubbles.  But this time you have a patch kit and a hand pump. This time you have actionable intelligence, and you will likely attempt to patch the raft and pump it up.</p>
<p>An alert is only effective when it empowers a person to act.  Typical breach announcements usually do nothing to empower individuals.  Effective breach notifications require both <em>intelligence</em> and <em>action</em>.  If either one of these elements is missing (as is often the case), it will fail to empower victims, and may even engender apathy.</p>
<p>Some suggest that in the current environment of data insecurity, consumers should be on constant high alert for identity theft, even without notice of a breach.  After all, your Data Self is constantly being traded without your knowledge or consent in IT and business environments of questionable reputes.</p>
<p>It&#8217;s a nice thought, but not very helpful. Being on high alert all the time is essentially the same as not being on alert any of the time.</p>
<p><strong>Q: Do breach notification laws encourage organizations to improve behavior?</strong><br />
<strong>A: Probably yes.</strong> The <a href="http://weis2008.econinfosec.org/papers/Romanosky.pdf">Romanosky paper</a> found that notification laws likely encourage businesses to take more stringent safety precautions with personal information, because of the economic incentive to avoid breaches.  However, the incentives to secure data do not appear to outweigh the market forces which devalue privacy.  Both the <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm">Privacy Rights Clearinghouse</a> and the <a href="http://datalossdb.org/">OSF Data Loss Database</a> show a steady, and perhaps even increasing number of breach incidents and lost records each year. While part of this increase may be attributable to better reporting, there is no solid indication that data breach incidents are decreasing.</p>
<p><a name="rights"></a></p>
<h3>4. Increased Victims&#8217; Rights</h3>
<p><strong>Q: Do Breach Notification Laws Create New Rights for Consumers? </strong><br />
<strong>A: Absolutely yes.</strong> While not the silver bullet to cure all ails, breach notification laws are an important first step at creating rights for victims of breaches.  Before BNLs, nobody had the right to know whether their Data Self had been compromised.  Additional legislation will be necessary to address existing and emerging identity threats.  Especially as Data Selves are treated as property, our society runs a risk that the unregulated trade of personal information could morph into a new form of <a href="http://www.securitycatalyst.com/when-did-my-personal-information-become-your-property/">digital human trafficking</a>.</p>
<h3>Legislative Improvements</h3>
<p>Breach notification laws are a first step in regulating the trade of Data Selves. The right information at the right time, given to the right people, coupled with a clear course of action will empower people and catalyze change. Here are six legislative suggestions to effectively protect and empower consumers:</p>
<ol>
<li><strong>&#8220;Stewards,&#8221; not &#8220;Owners&#8221;</strong>: Given the tenuous and dangerous legal basis for &#8220;owning&#8221; personal information, notification laws should replace the concept of &#8220;personal information owners&#8221; with &#8220;personal information stewards.&#8221; This change would help sharpen the distinction between Data as Self versus Data as Property, and emphasize that third parties can&#8217;t &#8220;own&#8221; a Data Self.  When Self is Data and Data is Property, then we run the risk that Self becomes Property.</li>
<li><strong>Expand Reporting Requirements</strong>: Breach notifications should provide actionable intelligence, including <em>who, what, when, how, how much, and &#8220;what now?&#8221;</em> of each breach.</li>
<li><strong>Standard Measures of Risk</strong>:  I suggest using Size, Sensitivity, Duration, and Distribution.</li>
<li><strong>Presumptive Loss</strong>: In order to successfully sue for a breach, a consumer must 1. Become an actual victim of identity theft, 2. Find the identity thief, 3. Prove that the thief&#8217;s copy of their SSN or other personal information came from the breaching entity, and 4. Prove that the entity had a legal obligation to keep that information private (a rare duty).  This is an unreasonable and often insurmountable burden of proof.  Instead, Tennessee has adopted  a small presumptive &#8220;ascertainable loss&#8221;<a name="note5"></a> whenever a breach occurs. These nominal damages would recognize harm to reputation, apprehension, emotional distress, and violation of selfhood. They would also  help counteract the market&#8217;s failure to value privacy</li>
<li><strong>Require a Data Audit Trail</strong>:  Stewards of personal information should maintain standard inventory controls on personal information, recording with whom and when the personal information was shared.  This data trail would be used for data audits and could help establish causation in the case of a breach.</li>
<li><strong>Automatic Credit Reporting</strong>: Consumers should get an automatic notification at any activity on their credit.</li>
</ol>
<p><em>Aaron Titus is the Privacy Director for the <a href="http://www.libertycoalition.net">Liberty Coalition</a> and runs <a href="http://www.nationalidwatch.org">National ID Watch</a>, and welcomes feedback.</em></p>
<hr />
<h3>Footnotes</h3>
<p><a name="footnote1"></a> Cal. Civ. Code §§ 1798.82-84.<br />
<a name="footnote2"></a> <em>See, e.g.</em> N.H. Rev. Stat. § 359-C:2.<br />
<a name="footnote3"></a> <em>See, e.g.</em> Ga. Code § 10-1-910(4),(7).<br />
<a name="footnote4"></a> <em>See, e.g.</em> Cal. Civ. Code § 1798.81.5.(a).</p>
<p><a name="footnote5"></a> <em>Tenn. Code</em> § 47-18-2102(1).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/01/17/in-defense-of-breach-notification-laws-sort-of/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DC Dentist, Tax Professional, and Chiropractor Expose 16,790 Patient, Client Information on Hot Spots</title>
		<link>http://www.aarontitus.net/blog/2008/04/09/dc-dentist-tax-professional-and-chiropractor-expose-16790-patient-client-information-on-hot-spots/</link>
		<comments>http://www.aarontitus.net/blog/2008/04/09/dc-dentist-tax-professional-and-chiropractor-expose-16790-patient-client-information-on-hot-spots/#comments</comments>
		<pubDate>Wed, 09 Apr 2008 15:06:23 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/04/09/dc-dentist-tax-professional-and-chiropractor-expose-16790-patient-client-information-on-hot-spots/</guid>
		<description><![CDATA[Washington, DC.  In three separate breaches, a Maryland Dentist, Virginia Tax Professional, and a Maryland Chiropractor have exposed the personal client and patient information of 16,970 Washington DC-area residents, including 3,270 social security numbers over public wireless networks or &#8220;Hot Spots.&#8221;
Dentist Dr. Michell Burdine-Merai&#8217;s office in Oxon Hill, Maryland exposed private information about 9,911 [...]]]></description>
			<content:encoded><![CDATA[<p>Washington, DC.  In three separate breaches, a Maryland Dentist, Virginia Tax Professional, and a Maryland Chiropractor have exposed the personal client and patient information of 16,970 Washington DC-area residents, including 3,270 social security numbers over public wireless networks or &#8220;Hot Spots.&#8221;</p>
<p>Dentist Dr. Michell Burdine-Merai&#8217;s office in Oxon Hill, Maryland exposed private information about 9,911 patients, former patients, and their families to the public through an unsecured public wireless network, including roughly 2,569 social security numbers. The information also included appointments, dental treatments, and phone numbers.</p>
<p>In Alexandria, Virginia, the office of Martha Yungk, EA accidentally exposed the private information of 7,003 of her clients, former clients and their families on a public wireless network after an IT professional replaced a broken router with a wireless router, without her permission.  The information includes more than 700 social security numbers, 400 addresses and phone numbers, and detailed tax information for 2,796 people. Letters to the IRS about criminal tax actions, state tax information, and notes about health and alimony were among the more than 300 sensitive documents exposed on the hot spot.  The wireless network was available to any member of the public with a laptop, who came within 150 feet of the office (including the parking lot).</p>
<p>Maryland chiropractor Prime Care exposed private information about 56 patients over its public wireless network.   Most of the individuals affected are patients of Dr. Steven Boesche, though Dr. Boesche was not responsible for the posting.   The Hot Spot exposed 29 files with sensitive patient information, including patient account numbers, blood pressure, date of accident, diagnoses, examination results, patient history, pulse, prognosis, and treatments.</p>
<p>&#8220;This is an indemic problem among independent professionals. There&#8217;s an insecure wireless network in almost every office park,&#8221; says Aaron Titus, Privacy Director of the Liberty Coalition and SSNBreach.org.  &#8220;This trend is predictable if regrettable, because independent practitioners have small staffs and often outsource IT functions to people of varying skill.  When they outsource it to a non-professional, it can have a devastating effect on patient and client privacy.&#8221;</p>
<p>Individuals affected by this exposure should immediately visit <a href="http://www.ssnbreach.org">www.ssnbreach.org </a> and search for their names, to confirm what types of personal information were exposed.</p>
<p>About SSNBreach.org</p>
<p>Sponsored by the Washington, DC non-profit Liberty Coalition, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports™ as a public service.<br />
Each Identity Exposure Report (IXR) documents what types of personal information were exposed (such as Social Security Numbers, Birth Dates, Addresses, etc.), without revealing them. Each IXR also details the situation surrounding each exposure, and contact information of those responsible for the breach. Armed with this information, victims can further investigate, take action, or correct harm.</p>
<p>Sources:<br />
<a href="https://www.ssnbreach.org/release.php?g=79">https://www.ssnbreach.org/release.php?g=79</a><br />
<a href="https://www.ssnbreach.org/release.php?g=82">https://www.ssnbreach.org/release.php?g=82</a><br />
<a href="https://www.ssnbreach.org/release.php?g=85">https://www.ssnbreach.org/release.php?g=85</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/04/09/dc-dentist-tax-professional-and-chiropractor-expose-16790-patient-client-information-on-hot-spots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Florida State University Prof Posts 33 Students&#8217; SSNs Online</title>
		<link>http://www.aarontitus.net/blog/2008/04/01/florida-state-university-prof-posts-33-students-ssns-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/04/01/florida-state-university-prof-posts-33-students-ssns-online/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 14:02:16 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/04/01/florida-state-university-prof-posts-33-students-ssns-online/</guid>
		<description><![CDATA[TALLAHASSEE, Florida.  The personal information of 66 Florida State University students sat on a public FSU Chemistry Department server for more than five years.  Several files included names, 33 social security numbers, grades, homework and exam scores. All of the individuals affected by this breach appear to be former students of Dr. Steinbock, [...]]]></description>
			<content:encoded><![CDATA[<p>TALLAHASSEE, Florida.  The personal information of 66 Florida State University students sat on a public <a href="http://www.chem.fsu.edu">FSU Chemistry Department</a> server for more than five years.  Several files included names, 33 social security numbers, grades, homework and exam scores. All of the individuals affected by this breach appear to be former students of Dr. Steinbock, an FSU professor.</p>
<p>The Liberty Coalition discovered the files in late January, 2008 and notified the university.  FSU quickly removed the files from the server, but they remained available through search engine caches until late March, 2008.</p>
<p>This incident falls into a nationwide pattern where university professors use public university servers to back up sensitive student personal information, either unaware of the sensitive information, or unaware that the information would be available to the public.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.</p>
<p>				Each Identity Exposure Report (IXR) documents what types of personal information were exposed (such as Social Security Numbers, Birth Dates, Addresses, etc.), without revealing them.  Each IXR also details the situation surrounding each exposure, and contact information of those responsible for the breach.  Armed with this information, victims can further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=73">https://www.ssnbreach.org/release.php?g=73</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/04/01/florida-state-university-prof-posts-33-students-ssns-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Texas A&amp;M Prof Posts Partial SSNs, Grades of Former Students Online</title>
		<link>http://www.aarontitus.net/blog/2008/04/01/texas-am-prof-posts-partial-ssns-grades-of-former-students-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/04/01/texas-am-prof-posts-partial-ssns-grades-of-former-students-online/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 13:58:57 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/04/01/texas-am-prof-posts-partial-ssns-grades-of-former-students-online/</guid>
		<description><![CDATA[COLLEGE STATION, Texas. On November 21, 2000, someone posted the names, scores, Grades, and last five digits of 44 students&#8217; social security numbers on a Texas A&#038;M server.  All affected students attended Dr. Clyde Munster&#8217;s Fall 1998 Hydrologic Principles in Agriculture class (AGEN 350). The Liberty Coalition discovered the files in late November, 2007. [...]]]></description>
			<content:encoded><![CDATA[<p>COLLEGE STATION, Texas. On November 21, 2000, someone posted the names, scores, Grades, and last five digits of 44 students&#8217; social security numbers on a <a href="http://baen.tamu.edu/">Texas A&#038;M</a> server.  All affected students attended Dr. Clyde Munster&#8217;s Fall 1998 Hydrologic Principles in Agriculture class (AGEN 350). The Liberty Coalition discovered the files in late November, 2007. Though the university quickly removed the files from public access after notification, copies remained online through late March, 2008 in search engine caches.</p>
<p>This breach fits within a common pattern where university faculty or staff use university servers to store backed-up files, assuming that since the system requires a password to upload files, that the servers are private.  Unfortunately, in this instance, some of Dr. Munster&#8217;s backed-up files contained sensitive information which was made available online and picked up by search engines.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.<br />
				Each Identity Exposure Report (IXR) documents what types of personal information were exposed (such as Social Security Numbers, Birth Dates, Addresses, etc.), without revealing them.  Each IXR also details the situation surrounding each exposure, and contact information of those responsible for the breach.  Armed with this information, victims can further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=80">https://www.ssnbreach.org/release.php?g=80</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/04/01/texas-am-prof-posts-partial-ssns-grades-of-former-students-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UConn Prof Posts 14 Student SSNs Online</title>
		<link>http://www.aarontitus.net/blog/2008/03/31/uconn-prof-posts-14-student-ssns-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/03/31/uconn-prof-posts-14-student-ssns-online/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 11:55:03 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/03/31/uconn-prof-posts-14-student-ssns-online/</guid>
		<description><![CDATA[STORRS, Connecticut.  On or before July 24, 2003 former UConn Economics Professor, Dr. Stiver, loaded an Excel file to his University of Connecticut home page which contained the names, last 8 social security number digits, scores, and grades of 14 students.  All of the affected individuals appeared to be Dr. Stiver&#8217;s former Economics [...]]]></description>
			<content:encoded><![CDATA[<p>STORRS, Connecticut.  On or before July 24, 2003 former UConn Economics Professor, Dr. Stiver, loaded an Excel file to his <a href="http://www.econ.uconn.edu/">University of Connecticut</a> home page which contained the names, last 8 social security number digits, scores, and grades of 14 students.  All of the affected individuals appeared to be Dr. Stiver&#8217;s former Economics 242 students.</p>
<p>University officials had already discovered the file during an internal audit in early February, 2008, before the Liberty Coalition was able to notify them of the exposure.  By the time the Liberty Coalition contacted the University of Connecticut, they had already deleted the file, worked with all major search engines to clear their caches, and notified each affected student.  To its credit, the University also offered each student two free years of credit checking, which is not technically required by law.</p>
<p>This exposure falls into a national pattern where professor will use university public servers to store sensitive personal information.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.</p>
<p>				Each Identity Exposure Report (IXR) documents what types of personal information were exposed (such as Social Security Numbers, Birth Dates, Addresses, etc.), without revealing them.  Each IXR also details the situation surrounding each exposure, and contact information of those responsible for the breach.  Armed with this information, victims can further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=81">https://www.ssnbreach.org/release.php?g=81</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/03/31/uconn-prof-posts-14-student-ssns-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stevens Institute of Technology Posts 9 Student SSNs Online</title>
		<link>http://www.aarontitus.net/blog/2008/03/26/stevens-institute-of-technology-posts-9-student-ssns-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/03/26/stevens-institute-of-technology-posts-9-student-ssns-online/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 11:24:31 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/03/26/stevens-institute-of-technology-posts-9-student-ssns-online/</guid>
		<description><![CDATA[HOBOKEN, New Jersey.  Stevens Institute of Technology professor L.E. Levine posted a file with names, Social Security Numbers and Homework scores for 7 students who apparently took his course &#8220;MA681&#8243; in the Fall of 1999.  According to the server personal.stevens.edu, the files were posted on or before April, 2001.  Though Dr. Levine [...]]]></description>
			<content:encoded><![CDATA[<p>HOBOKEN, New Jersey.  <a href="redir.php?url=http://www.stevens.edu/">Stevens Institute of Technology</a> professor L.E. Levine posted a file with names, Social Security Numbers and Homework scores for 7 students who apparently took his course &#8220;MA681&#8243; in the Fall of 1999.  According to the server personal.stevens.edu, the files were posted on or before April, 2001.  Though Dr. Levine deleted them immediately after he was notified of the exposure, the information continued to be available through March, 2008 through search engine caches.</p>
<p>By placing this information online, Stevens Institute of Technology has put these students at increased risk of identity theft and other forms of fraud.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.<br />
				SSNBreach.org <em>documents the types of information exposed, but does NOT contain sensitive data</em>, such as Social Security Numbers, Birth Dates, Addresses, etc.  Consequently, there is no way to search for your SSN or any other type of sensitive data on SSNBreach.org.  Once we document the <em>types</em> of exposed information and the situation surrounding the exposure, we include the information in personalized Identity Exposure Reports.  This information allows victims to further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=71">https://www.ssnbreach.org/release.php?g=71</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/03/26/stevens-institute-of-technology-posts-9-student-ssns-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>University of Iowa has Another Breach</title>
		<link>http://www.aarontitus.net/blog/2008/03/25/university-of-iowa-has-another-breach/</link>
		<comments>http://www.aarontitus.net/blog/2008/03/25/university-of-iowa-has-another-breach/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 11:05:29 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/03/25/university-of-iowa-has-another-breach/</guid>
		<description><![CDATA[IOWA CITY, Iowa. In the second exposure of sensitive information in as many months, the University of Iowa posted sensitive student information online.  Two files were discovered in January, 2008 which appear to contain the names, grades, and last four digits of nine students&#8217; social security number were posted on the Computer Sciences Department [...]]]></description>
			<content:encoded><![CDATA[<p>IOWA CITY, Iowa. In the second exposure of sensitive information in as many months, the University of Iowa posted sensitive student information online.  Two files were discovered in January, 2008 which appear to contain the names, grades, and last four digits of nine students&#8217; social security number were posted on the <a href="redir.php?url=http:///www.cs.uiowa.edu/">Computer Sciences Department</a> website.  All of the students appear to have attended the Summer 2001 22c-112 course, taught by Aditya Kumar Sehgal, Ph.D.</p>
<p>According to the server, the information was posted online since at least November, 2004.  Though the university acted quickly to delete the files from their servers, copies remained available through major search engine caches through late March, 2008.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.</p>
<p>				SSNBreach.org <em>documents the types of information exposed, but does NOT contain sensitive data</em>, such as Social Security Numbers, Birth Dates, Addresses, etc.  Consequently, there is no way to search for your SSN or any other type of sensitive data on SSNBreach.org.  Once we document the <em>types</em> of exposed information and the situation surrounding the exposure, we include the information in personalized Identity Exposure Reports.  This information allows victims to further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=70">https://www.ssnbreach.org/release.php?g=70</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/03/25/university-of-iowa-has-another-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shabazz Academy Posts K-5 Student Addresses Online</title>
		<link>http://www.aarontitus.net/blog/2008/03/24/shabazz-academy-posts-k-5-student-addresses-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/03/24/shabazz-academy-posts-k-5-student-addresses-online/#comments</comments>
		<pubDate>Mon, 24 Mar 2008 11:46:01 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/03/24/shabazz-academy-posts-k-5-student-addresses-online/</guid>
		<description><![CDATA[LANSING, Michigan.  In late December, 2007 the Liberty Coalition discovered an excel file with the names, addresses, phone numbers, and emergency contact information for 125 students, parents, and others for Shabazz Public School Academy on their website.  69 of those affected are Pre-K through fifth grade students.  Though no social security numbers [...]]]></description>
			<content:encoded><![CDATA[<p>LANSING, Michigan.  In late December, 2007 the Liberty Coalition discovered an excel file with the names, addresses, phone numbers, and emergency contact information for 125 students, parents, and others for <a href="redir.php?url=http://www.shabazzlearning.com">Shabazz Public School Academy</a> on their website.  69 of those affected are Pre-K through fifth grade students.  Though no social security numbers or credit card numbers were exposed, some parents may be legitimately alarmed at the release of contact information for their young children.</p>
<p>The file was created on October 9, 2006.  The school acted quickly to delete the file from their server and notify parents, but the file remained available through search engine caches until late February, 2008.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.<br />
				SSNBreach.org <em>documents the types of information exposed, but does NOT contain sensitive data</em>, such as Social Security Numbers, Birth Dates, Addresses, etc.  Consequently, there is no way to search for your SSN or any other type of sensitive data on SSNBreach.org.  Once we document the <em>types</em> of exposed information and the situation surrounding the exposure, we include the information in personalized Identity Exposure Reports.  This information allows victims to further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=78">https://www.ssnbreach.org/release.php?g=78</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/03/24/shabazz-academy-posts-k-5-student-addresses-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wright State University Prof Posts 395 Grades, 38 Partial SSNs Online</title>
		<link>http://www.aarontitus.net/blog/2008/03/21/wright-state-university-prof-posts-395-grades-38-partial-ssns-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/03/21/wright-state-university-prof-posts-395-grades-38-partial-ssns-online/#comments</comments>
		<pubDate>Fri, 21 Mar 2008 16:45:32 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/03/21/wright-state-university-prof-posts-395-grades-38-partial-ssns-online/</guid>
		<description><![CDATA[DAYTON, Ohio.  The Wright State University Computer Sciences Department has posted the names and last five digits of 38 students&#8217; social security numbers on their website.  All of the students affected seem to be former students of Dr. Junghsen Lieh, Ph.D. who took Materials Engineering courses between 1997 and 2005.  In addition [...]]]></description>
			<content:encoded><![CDATA[<p>DAYTON, Ohio.  The Wright State University <a href="redir.php?url=http://www.cs.wright.edu/">Computer Sciences Department</a> has posted the names and last five digits of 38 students&#8217; social security numbers on their website.  All of the students affected seem to be former students of Dr. Junghsen Lieh, Ph.D. who took Materials Engineering courses between 1997 and 2005.  In addition to the partial social security numbers, the individual scores and grades for roughly 395 students are also posted.</p>
<p>According to Dr. Lieh, the files were made during a large backup a corrupted and damaged PC in March 2006, though many of the files are considerably older than that.  This breach falls within a common national pattern of faculty who use online university servers to back up files, some of which may be sensitive in nature. The Liberty Coalition notified Dr. Lieh, the Wright State University General Counsel.  Though the files were deleted from the server within 24 hours, copies remained available through Yahoo&#8217;s search engine cache until late March, 2008.</p>
<p>Much of the information exposed in this incident may be protected by FERPA.  In addition, the last four or five digits of the social security number are used by some financial institutions and businesses to extend credit, or as passwords.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.</p>
<p>SSNBreach.org <em>documents the types of information exposed, but does NOT contain sensitive data</em>, such as Social Security Numbers, Birth Dates, Addresses, etc.  Consequently, there is no way to search for your SSN or any other type of sensitive data on SSNBreach.org.  Once we document the <em>types</em> of exposed information and the situation surrounding the exposure, we include the information in personalized Identity Exposure Reports.  This information allows victims to further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=77">https://www.ssnbreach.org/release.php?g=77</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/03/21/wright-state-university-prof-posts-395-grades-38-partial-ssns-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Suffolk Co., NY Posts 250 Partial SSNs Online</title>
		<link>http://www.aarontitus.net/blog/2008/02/19/suffolk-co-ny-posts-250-partial-ssns-online/</link>
		<comments>http://www.aarontitus.net/blog/2008/02/19/suffolk-co-ny-posts-250-partial-ssns-online/#comments</comments>
		<pubDate>Tue, 19 Feb 2008 11:40:47 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2008/02/19/suffolk-co-ny-posts-250-partial-ssns-online/</guid>
		<description><![CDATA[HAUPPAUGE, New York. On or before May 22, 2007 (and as early as March 22, 2007), the Suffolk County Government Civil Service posted the names and last four digits of 250 individuals&#8217; social security numbers on their website.  The file appeared to be a copy of an old database related to the &#8220;CF Police [...]]]></description>
			<content:encoded><![CDATA[<p>HAUPPAUGE, New York. On or before May 22, 2007 (and as early as March 22, 2007), the <a href="http://www.suffolkcountyny.gov/">Suffolk County Government</a> Civil Service posted the names and last four digits of 250 individuals&#8217; social security numbers on their website.  The file appeared to be a copy of an old database related to the &#8220;CF Police Lottery.&#8221; The Liberty Coalition discovered the file and notified the county government on December 14, 2007.  The file was not deleted from the county server until January 30, 2008, after a second notification by the Liberty Coalition.</p>
<p>Following the second notification, a county representative contacted the Liberty Coalition and pledged that Suffolk County plans to change its procedure, and stop using partial SSNs as an identifying number.</p>
<p>The last four digits of the social security number is used by businesses to extend credit, and financial institutions sometimes use it as a password.  By placing this information online, Suffolk County has placed these individuals at an elevated risk of identity theft.</p>
<p><strong>Individuals affected by this exposure should immediately visit <a href="https://www.ssnbreach.org">www.ssnbreach.org</a> and search for their names, to confirm what types of personal information were exposed.</strong></p>
<p><strong>About SSNBreach.org</strong></p>
<p>Sponsored by the Washington, DC non-profit <a href="redir.php?url=http://www.libertycoalition.net">Liberty Coalition</a>, SSNBreach.org provides hundreds of thousands of free personalized Identity Exposure Reports&trade; as a public service.</p>
<p>				SSNBreach.org <em>documents the types of information exposed, but does NOT contain sensitive data</em>, such as Social Security Numbers, Birth Dates, Addresses, etc.  Consequently, there is no way to search for your SSN or any other type of sensitive data on SSNBreach.org.  Once we document the <em>types</em> of exposed information and the situation surrounding the exposure, we include the information in personalized Identity Exposure Reports.  This information allows victims to further investigate, take action, or correct harm.</p>
<p><em>Source:</em> <a href="https://www.ssnbreach.org/release.php?g=76">https://www.ssnbreach.org/release.php?g=76</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2008/02/19/suffolk-co-ny-posts-250-partial-ssns-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
