It seems that Columbia University Medical Center inadvertently exposed the Social Security numbers of 138 medical students from the graduating class of 2013 in an Excel spreadsheet sent to faculty, students, and staff. CUMC became aware of the breach on March 15. The breach occurred because the Excel spreadsheet with residency match lists for the graduating…
Category: Exposure
Errors by both Sentry Life Insurance and the Department of Labor expose 401k participants’ information online
Sentry Life Insurance is a service provider for many companies’ 401k plans. In that capacity, they assist clients in the preparation of, and submission of, the plans’ Form 5500 to the Department of Labor. On July 2, Sentry discovered that some plans’ Form 5500 submissions to DOL contained an attachment with the individuals’ names, Social Security numbers,…
MNsure employee responsible for e-mail attachment breach no longer employed at MNsure
The MNsure employee who erroneously attached a spread sheet with 1,587 insurance agents’ names and Social Security numbers to an e-mail to one insurance agent is no longer working for MNsure. The Associated Press’s coverage adds that the employee violated internal policy by storing unencrypted personal information about Minnesota insurance agents on a computer desktop. The agency…
Audit of State University of New York at Albany reveals to-be-surplussed devices certified as “clean” still contained PII
I periodically post audits from the NYS Comptroller Thomas DiNapoli’s office pertaining to data protection. A recently released audit of SUNY-Albany reminds us that we need to continue to be concerned about inadequately wiped devices or drives that are to be surplussed. The audit period covered January – May 2012, and during that time, SUNY-Albany…
LabMD Responds to FTC Complaint: Claims Agency Lacks Enforcement Jurisdiction
Just received this press release from Cause of Action with LabMD’s response to FTC’s complaint: Cause of Action (CoA), a government accountability organization, filed an answer to an aggressive and arbitrary enforcement action brought by the Federal Trade Commission (FTC) against LabMD, a small cancer diagnosis company. CoA is defending LabMD against a complaint brought by the FTC in…
AZ: Job applications with personal information found in dumpster
Kristine Harrington reports that someone using the dumpster behind Denny’s in Phoenix discovered approximately 200 unshredded job applications. The manager says it never should have happened.