DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

For three years, employee data sat on a former employee's device, unbeknownst to all

Posted on November 9, 2013 by Dissent

On October 24, Rotech Healthcare, Inc. reported a data security breach to the New Hampshire Attorney General’s Office that involved some health information.

According to their letter to the state, on August 30, they learned that a former employee  took some files with her when she left the firm on November 26, 2010.

Those files contained information on employees and their dependents, including names, addresses, Social Security numbers, the names of the carrier(s) administering their healthcare coverage, and/or “limited information about certain medical or pharmacy services the resident received.”

Robin Menchen, Chief Privacy Officer for Rotech, informed the state that the former employee has deleted all information that was on the device and was returning the device to the firm.  A letter to affected employees provides additional information and makes it clear that the removal of the files was discovered by the former employee’s subsequent employer, who found evidence of the files on the employee’s non-networked computer and contacted Rotech with the files. The employee seemed genuinely surprised and assured Rotech that the files had never been accessed or used while they were on the device.

Rotech offered those affected free credit monitoring services and is reviewing their privacy and security protocols to try to prevent a similar situation from occurring in the future. Thankfully for them, the employee’s subsequent employer discovered the breach, but the fact is that they had a breach in 2010 that went undiscovered for three years, and during that time the device could have been connected to the Internet, could have been infected by malware, or could have fallen into the wrong hands. That doesn’t seem to have happened, but it was a risk. And given the increasing use of BYOD, this strikes me as a priority for all firms that store or process personal and sensitive information.


Related:

  • Maintenance Note
  • CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094
  • System Status Note
  • System Status Note
  • System Status Note
  • Fraudster's fake data breach claims should remind media to be careful what we report
Category: Uncategorized

Post navigation

← You know that blood test your doctor ran as part of your wellness check? The state can subpoena the results.
Skype in the Sights of Level 7 Crew for 15/11/2013 →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.