PIIssed off yet?
A letter from the Department of Veterans Affairs on PII data breach
Security Strategies Alert
By
M. E. Kabay
,
Network World
, 06/12/2007
Sign up for this newsletter now!
Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.
- Share/Email
- Tweet This
- Print
In March 2007, Network World writer Jon Brodkin wrote an excellent analysis of 10 letters informing victims of data theft or loss of control of personally identifiable information (PII) that their data might be compromised.
He pointed out that almost all of the letters failed to express any responsibility for the loss of control over data stored
on unencrypted disks that were lost or stolen, or for poorly secured Web sites that posted PII without protection or with
poor protection. My guess is that staff attorneys warned the public relations officials to avoid any implication of responsibility
to avoid contributing anything that would exacerbate their liability in potential lawsuits. Passive voice is great for shifting
responsibility from specific agents to the great gaseous cloud of the unnamable and unblamable.
“Mistakes were made,” indeed.
My wife is a neuropsychiatrist; she recently received a letter from the Veterans Affairs (VA) office in Austin, Texas, informing
her of loss of control over her PII. I am starting this series of articles about the VA’s handing of PII with a verbatim transcript
of the letter she received. I think readers will be interested in seeing the contents in detail - and there is actually some
generally useful information that everyone can store away in case it’s needed. In particular, I recommend that all of us save
the contact information for the three credit bureaus and the phone number for the FTC service.
So here’s part one of the series. In the following parts, I’ll go back to the theft of computer disks containing unauthorized
copies of PII on May 3, 2006. Then I’ll continue the series with summaries of later cases of data theft and loss from the
VA, U.S. government reports and congressional testimony about these problems, VA assurances of planned improvement, and the
status of VA assurances. I’ll wind up with analysis of the underlying issues and provide recommendations for improvement.
* * *
DEPARTMENT OF VETERANS AFFAIRS
1615 Woodward St.
Austin, TX 78772
-----, MD
Dear -----, MD:
I am writing to you, as the Director of the Veterans Integrated Service Network (VISN) 7 in Atlanta, Georgia, to inform you
that I have been notified that a portable computer hard drive used by an employee of the Birmingham Veterans Affairs (VA)
Medical Center is missing. This portable hard drive was used to back-up information contained on a VA employee’s office computer,
related to research projects with which the employee was involved. A file on the portable hard drive included information
from the Unique Physician Identification Number (UPIN) Directory dated 2004, which includes demographic information and identifiers,
such as the UPIN, dates of birth, state license numbers, business addresses, and employer identification numbers (EIN). In
the case of your information, we believe the EIN was your Social Security Number. This file was obtained by VA from the Centers
for Medicare & Medicaid Services (CMS) for the purpose of conducting research on veterans’ health care.
M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services. CV online.
Comments (5)
Veterans Administration should be ashamed of the way it's dealing with that data breachBy Anonymous on June 12, 2007, 11:14 amIt's interesting that the letter states, in so many words, that (a) we (the VA) lost your data, and (b) the victim (recipient of the letter) whose personal data...
Reply | Read entire comment
VA Loss of DataBy Anonymous on June 13, 2007, 8:41 amI notice the letter stated that the PII was being used for research. Canada's Protection of Privacy Act requires that personal data may only be used for what it...
Reply | Read entire comment
In CanadaBy Anonymous on June 21, 2007, 2:26 pmFortunately, in Canada, the vast majority of the population (including hackers & thieves) are too stupid to understand IT security or even how to breach it (if it...
Reply | Read entire comment
As a US Army Veteran am very, very gratefulBy Brad Reese on June 21, 2007, 6:45 pmAs a US Army Veteran, I thank the US Department of Veterans Affairs every single day for the superb and excellent medical care they provide me and my fellow veterans. There...
Reply | Read entire comment
Automated harassmentBy Anonymous on June 29, 2007, 3:21 pmI was subjected to this kind of harrasement for well over a decade by Verizon in conjuction with another corporation. The only way out, for me was, to drop my landline...
Reply | Read entire comment
View all comments