Vulnerabilities / Threats
7/9/2010
01:43 PM
50%
50%

ID Thefts Go Unreported Despite Notification Laws

The Identity Theft Resource Center says one-third of breaches appear to be malicious, but a lack of transparency and accountability may be masking true extent of problem.

The Identity Theft Resource Center (ITRC) announced Thursday that it had recorded 341 individual data breaches for the first six months of 2010.

But hundreds more went unreported, said the organization. In addition, for 46% of breaches, the number of records potentially affected weren't disclosed, and for 38%, no cause was disclosed.

Why is that?

According to the ITRC, some states now harbor a protected breach list that is not made public at all, or is only accessible by exercising the Freedom of Information Act. One state, for example, had a list of 200 breaches, but for most, little information was disseminated, at least publicly, such as the number of records affected.

In addition, for medical data breaches, the Department of Health and Human Services (HHS) has created a "risk of harm" threshold for notifications. Under HHS guidelines, if an organization determines that a data breach hasn't caused "a significant risk of financial, reputational, or other harm to individual," then it doesn't have to report the breach, either to the person whose information was breached or to law enforcement agencies.

As a result, "despite a law stating that all medical breaches involving more than 500 people must be listed on the Health and Human Services breach list, ITRC recorded medical breaches that never made the list," according to a statement issued by the group.

The "risk of harm" medical record clause has been contentious since it was first disclosed in August 2009. At that time, the Center for Democracy and Technology challenged the loophole, arguing that "the primary purpose for mandatory breach notification is to provide incentives for healthcare companies to protect data."

In other words, if healthcare companies properly invest in security, they can avoid data breaches, and the attendant cost of related fines. "However, the harm standard institutionalized in HHS's interim final rule cripples this crucial incentive," said the CDT.

In addition, allowing organizations to conduct their own risk assessment, and then determine whether or not to notify people whose records have been affected, may be contributing to an underreporting of the actual extent of data breaches today, and providing an incomplete picture of which organizations adequately safeguard people's personal information.

"Consumers want to know if they are at risk from even a small breach," according to the ITRC. "The details of a breach help determine their risk factors as well as guide them in proactive measures."

The ITRC first began maintaining a detailed list of data breaches, updated weekly, in 2005.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Five Things Every Business Executive Should Know About Cybersecurity
Don't get lost in security's technical minutiae - a clearer picture of what's at stake can help align business imperatives with technology execution.
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.