Rian from RedTeam Protection, a division of Tony Josephs and Sons Investigations Inc., just sent me another batch of p2p cockups that exposed personal — and in some cases — sensitive medical — information. In each case, RedTeam advised the entity and/or helped ensure removal of the filesharing application. Some of these breaches are more…
VA suspends contractor over patient data security
Adam Levine reports: The Department of Veterans Affairs has suspended a contractor for failing to follow the department’s policies for securing sensitive data about patients, the department said. A routine inspection revealed that a transcription contractor, with access to information including name, Social Security number and diagnosis, was using computers that did not follow guidelines…
Privacy Trumps Profit in Obama’s $19 Billion Health Stimulus
Nicole Gaouette reports: Patients’ advocates claimed victory in a battle over the privacy of health records as the U.S. Congress prepares to vote on the economic stimulus bill, which contains $19 billion for health-care information. U.S. House and Senate negotiators’ compromise reflects stricter standards that privacy advocates wanted for marketing, selling and disclosing health data….
UK: ICO takes enforcement action against Hastings and Rother PCT for data loss
From the press release (pdf) from the Information Commissioner’s Office (ICO): The Information Commissioner’s Office (ICO) has taken enforcement action against Hastings and Rother Primary Care Trust (PCT) following a breach of the Data Protection Act. This is the eighth time the ICO has taken enforcement action against an NHS organisation for breaching the Data…
Ca: Privacy commissioner may investigate City of Regina privacy breach
Joe Couture reports: Contrary to statements made by a City of Regina executive, the Office of the Saskatchewan Information and Privacy Commissioner has not yet decided whether or not to undertake a formal investigation into the breach of privacy announced by the city yesterday. Read more in the Leader-Post
UK: Busy Bees childcare voucher data leak plugged – Update
A UK child care voucher scheme has been taken off line after user Nick Gibbins found that the “web” application was exposing personal data for over one hundred thousand users. Gibbins found that the Busy Bees childcare voucher system was actually implemented using Citrix Metaframe, exporting the user interface from a Windows 2000 application to…