WHIO reports: Wright-Patterson Air Force Base officials confirm they are investigating an incident at the Department of Air Force 88th Medical Group involving a binder containing names and Social Security numbers that was misplaced from their blood donor program. The 88th Medical Group sent more than 3,000 letters notifying donors that a data binder with…
National Express print-at-home vulnerability
Paul writes: National Express are one of the biggest public transport companies in the UK with a huge fleet of coaches and trains. This vulnerability discloses customers information to a potential attacker such as the passengers names, destination, last 4 digits of the card, price the customer paid for the tickets and of course the…
Signature Systems Breach Expands
Brian Krebs reports: Signature Systems Inc., the point-of-sale vendor blamed for a credit and debit card breach involving some 216 Jimmy John’s sandwich shop locations, now says the breach also may have jeopardized customer card numbers at nearly 100 other independent restaurants across the country that use its products. Read more on KrebsOnSecurity.
G.O.P. Error Reveals Donors and the Price of Access
Jonathan Weisman reports: In politics, it is sometimes better to be lucky than good. Republicans and Democrats, and groups sympathetic to each, spend millions on sophisticated technology to gain an advantage. They do it to exploit vulnerabilities and to make their own information secure. But sometimes, a simple coding mistake can lay bare documents and…
Ca: Health records in derelict buildings 'careless privacy breach'
CBC News reports: P.E.I.’s Opposition Health Critic James Aylward is demanding the provincial government move all health and financial records to a secured location at once. Earlier this week, CBC News reported that boarded-up, abandoned buildings near the Hillsborough Hospital, currently used to store some financial records and health records, have been broken into in recent…
Delaware Joins List of States Regulating Data Disposal
Jason C. Gavejian writes: On January 1, 2015, Delaware employers who dispose of records which contain the unencrypted personal identifying information of employees must take steps to ensure the privacy of such information. The bill, H.B. 294, was recently signed by Delaware’s Governor Jack Markell. Delaware also enacted a companion bill, H.B. 295, in July which imposed the…