So it appears I missed a third-party vendor/business associate leak that affected at least two covered entities and possibly more. Great thanks to Humana for sending along the vendor’s press release when I inquired about a breach report Humana had made to HHS as affecting 5,764 members or potential members. It turns out that the…
Category: Subcontractor
July Systems data leak: Massive trove of sensitive information exposed online via unsecured database
India Ashok reports: A massive trove of sensitive data was left freely exposed online by San Francisco-based July Systems. The company’s cloud-based location intelligence and engagement platform called “Proximity MX”, which contains proprietary information belonging to the firm and its clients, were exposed via unsecured Amazon S3 databases. […] According to security researchers at Kromtech,…
AU: Data breach hits Department of Social Services credit card system
For more than one year, employee data of approximately 8,500 Department of Social Services employees was exposed online due to an error by contractor Business Information Services. Paul Karp reports that the compromised data included: credit card information, employees’ names, user names, work phone numbers, work emails, system passwords, Australian government services number, public service classification…
Social Security numbers of 2,100 Maine foster care participants posted online
J. Craig Anderson reports: The names, addresses and Social Security numbers of roughly 2,100 Mainers who receive foster care benefits were accidentally posted to a public website in September, the Maine Office of Information Technology said Monday. The incident was the responsibility of an employee of a contractor, Knowledge Services, who still has a contract…
Cook County Health and Hospitals System Patients Impacted by Experian Health Breach
HIPAA Journal reports: Cook County Health and Hospitals System, a health system comprising two hospitals and more than a dozen community health centers in Cook County Illinois, has alerted patients to a breach of their protected health information. The breach occurred at Experian Health, a business associate of Cook County Health and Hospitals System. Experian…
Security flaw may have exposed personal info on 21,000 Utah Express Pass users
Oops? Art Raymond reports: A vigilant UDOT Express Pass customer discovered a glaring security breach in the third-party website that manages pass accounts, but state officials don’t yet know if the personal information of approximately 21,000 current and former customers has been compromised. That information on customers who have purchased passes for accessing HOV lanes…