Patient data exposed in two separate security breaches

News
Nov 29, 20062 mins

Protected health information belonging to more than 45,000 people has been compromised in two separate incidents disclosed this week.

Kaiser Permanente Colorado Wednesday confirmed that a laptop containing information such as the name, gender, date of birth, member identification numbers and physician information of approximately 38,000 members was stolen from the car of an employee in California.

“The data included on the laptop was part of a review of an internal health quality project and is limited to two Kaiser Permanente Colorado medical offices: Skyline and Southwest,” the company said in a statement.

Though the theft occurred on Oct. 4, Kaiser began notifying affected members of the incident only this week. The reason for the delay: Kaiser’s IT staff needed time to go through “hundreds of thousands of files” to figure out exactly what information was on the stolen laptop and how many people might be affected, said Jacque Montgomery, a Kaiser spokeswoman.

All of the information on the laptop was password-protected, and at least some of it was encrypted, she said. “Everything indicates that the laptop was stolen for its value and not for the information in it.”

The letters sent out by Kaiser explains the security breach and advises members on what to do if they believe their information was being misused in some way, she said. The company has also set up a special phone line to answer questions related to the incident.

This is the second time this year that Kaiser has had to send out letters to members informing them of a potential data compromise. In August, the company sent letters to more than 160,000 members alerting them of potential ID theft concerns after a laptop containing their data was stolen.

Meanwhile, in a similar incident, two computers containing health records on more than 7,000 people in the Indiana Breast and Cervical Cancer Program were stolen earlier this month. The computers were taken from a health center in Jeffersonville, Ind., that manages the state program, said Erik Deckers, a spokesman for the Indiana Department of Health.

The compromised information includes the names, Social Security numbers and medical histories of the affected individuals, Deckers said. So far, there is no indication that any of the data has been misused, he said, adding that letters have been sent out to 7,070 people informing them of the potential compromise of personal information.

jvijayan

Jaikumar Vijayan is a freelance technology writer specializing in computer security and privacy topics. He writes for CSO Online, Dark Reading and Security Boulevard, among other outlets. He has also written for eWEEK, InformationWeek, TechTarget, Security Intelligence, Government Computer News, Datamation, and Information Security Magazine.

Jai was previously as senior editor at Computerworld, where he covered information security topics targeted at an enterprise IT audience. In addition to breaking news stories, he wrote features and analysis based on commentary and interviews with technical experts, security executives and other IT leaders. While at Computerworld, he won several awards for excellence in technology journalism.

Prior to Computerworld, Jai covered technology issues for The Economic Times in Bangalore, India. He has a Master's degree in Statistics and lives in Naperville, Ill.

More from this author