Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

PIIssed off yet?

A letter from the Department of Veterans Affairs on PII data breach
Security Strategies Alert By M. E. Kabay, Network World
June 12, 2007 09:16 AM ET
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

  • Share/Email
  • Tweet This
  • Comment
  • Print

In March 2007, Network World writer Jon Brodkin wrote an excellent analysis of 10 letters informing victims of data theft or loss of control of personally identifiable information (PII) that their data might be compromised.

He pointed out that almost all of the letters failed to express any responsibility for the loss of control over data stored on unencrypted disks that were lost or stolen, or for poorly secured Web sites that posted PII without protection or with poor protection. My guess is that staff attorneys warned the public relations officials to avoid any implication of responsibility to avoid contributing anything that would exacerbate their liability in potential lawsuits. Passive voice is great for shifting responsibility from specific agents to the great gaseous cloud of the unnamable and unblamable.

“Mistakes were made,” indeed.

My wife is a neuropsychiatrist; she recently received a letter from the Veterans Affairs (VA) office in Austin, Texas, informing her of loss of control over her PII. I am starting this series of articles about the VA’s handing of PII with a verbatim transcript of the letter she received. I think readers will be interested in seeing the contents in detail - and there is actually some generally useful information that everyone can store away in case it’s needed. In particular, I recommend that all of us save the contact information for the three credit bureaus and the phone number for the FTC service.

So here’s part one of the series. In the following parts, I’ll go back to the theft of computer disks containing unauthorized copies of PII on May 3, 2006. Then I’ll continue the series with summaries of later cases of data theft and loss from the VA, U.S. government reports and congressional testimony about these problems, VA assurances of planned improvement, and the status of VA assurances. I’ll wind up with analysis of the underlying issues and provide recommendations for improvement.

* * *

DEPARTMENT OF VETERANS AFFAIRS
1615 Woodward St.
Austin, TX 78772

-----, MD

Dear -----, MD:

I am writing to you, as the Director of the Veterans Integrated Service Network (VISN) 7 in Atlanta, Georgia, to inform you that I have been notified that a portable computer hard drive used by an employee of the Birmingham Veterans Affairs (VA) Medical Center is missing. This portable hard drive was used to back-up information contained on a VA employee’s office computer, related to research projects with which the employee was involved. A file on the portable hard drive included information from the Unique Physician Identification Number (UPIN) Directory dated 2004, which includes demographic information and identifiers, such as the UPIN, dates of birth, state license numbers, business addresses, and employer identification numbers (EIN). In the case of your information, we believe the EIN was your Social Security Number. This file was obtained by VA from the Centers for Medicare & Medicaid Services (CMS) for the purpose of conducting research on veterans’ health care.

M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services and teaching. He is Chief Technical Officer of Adaptive Cyber Security Instruments, Inc. and Associate Professor of Information Assurance in the School of Business and Management at Norwich University. Visit his Web site for white papers and course materials.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (5)
Login
Forgot your account info?

Veterans Administration should be ashamed of the way it's dealing with that data breachBy Anonymous on June 12, 2007, 11:14 amIt's interesting that the letter states, in so many words, that (a) we (the VA) lost your data, and (b) the victim (recipient of the letter) whose personal data...

Reply | Read entire comment

VA Loss of DataBy Anonymous on June 13, 2007, 8:41 amI notice the letter stated that the PII was being used for research. Canada's Protection of Privacy Act requires that personal data may only be used for what it...

Reply | Read entire comment

In CanadaBy Anonymous on June 21, 2007, 2:26 pmFortunately, in Canada, the vast majority of the population (including hackers & thieves) are too stupid to understand IT security or even how to breach it (if it...

Reply | Read entire comment

As a US Army Veteran am very, very gratefulBy Brad Reese on June 21, 2007, 6:45 pmAs a US Army Veteran, I thank the US Department of Veterans Affairs every single day for the superb and excellent medical care they provide me and my fellow veterans. There...

Reply | Read entire comment

Automated harassmentBy Anonymous on June 29, 2007, 3:21 pmI was subjected to this kind of harrasement for well over a decade by Verizon in conjuction with another corporation. The only way out, for me was, to drop my landline...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed