DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Two Iowa Dept. of Human Services employees blamed for security breaches of more than 2,000 Iowans’ personal information

Posted on March 7, 2014 by Dissent

The Iowa Department of Human Services announced Friday that there was a breach in personal information related to some Polk County social work assessments.

There are 2,042 individuals whose information was included in the breach, which happened during the assessment period of some child and dependent adult abuse cases. Letters were mailed this week notifying these Iowans of the breach.

This occurred when two workers used personal email accounts, personal online storage accounts and personal electronic devices for work purposes. That caused confidential data to be transmitted outside the DHS secure network. The incidents happened over a 5-year period starting in 2008.

“There are no reports that any of the information was misused before it was deleted,” said Pat Penning, service area manager for the region including Polk County. “We’ve sent notification to individuals whose information was transmitted outside the secure network.”

The types of information involved included name, mailing address, Social Security number, state identification number, date of birth, health information and incident information.

The department began an internal investigation on January 17, 2014, once the issue was identified by a social work supervisor. Officials found that the workers did not follow DHS policy, which prohibits use of personal devices and transmitting information outside of the agency’s network. Appropriate personnel action was taken.

“The chance that this information was accessed through these password-protected accounts and devices was small,” said Penning, “but we realize the Iowans involved in these cases may wish to take steps to be sure their information wasn’t misused.”

Individuals who receive a letter notifying them of the breach can get more information if they are concerned their identity may be compromised, and they can sign up for free credit monitoring. They can call the Iowa Concern Hotline at 1-800-447-1985.

DHS is taking further action including blocking access to online file storage sites, providing updated materials to staff on the department’s information technology policy and standard operating procedures, and continuing to require yearly cyber-security training for all employees.

For more information, please visit http://www.dhs.state.ia.us or contact Amy Lorentzen McCoy at 515-281-4848 or at [email protected]

SOURCE: Iowa Department of Human Services

A Q&A on the breach has been posted here (pdf).


Related:

  • Kaufman County's data breach was their second one in three weeks
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Romanian prisoner hacks prison IT system in plot made for a Netflix movie
  • John Bolton Indictment Provides Interesting Details About Hack of His AOL Account and Extortion Attempt
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
  • Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches
Category: ExposureGovernment Sector

Post navigation

← Leader Of Identity Theft Ring Targeting Government Employees And Others Sentenced To 12 Years
Two Iowa Dept. of Human Services employees blamed for security breaches of more than 2,000 Iowans' personal information →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.