Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/24/2008
10:05 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Medical Records For 2,500 Study Participants Are Stolen

Only after a laptop is stolen from the trunk of a car owned by a researcher at the National Heart, Lung, and Blood Institute (NHLBI) does this organization promise to do better when it comes to security. Why does it always go down this way?

Only after a laptop is stolen from the trunk of a car owned by a researcher at the National Heart, Lung, and Blood Institute (NHLBI) does this organization promise to do better when it comes to security. Why does it always go down this way?According to a statement issued by the NHLBI, a notebook was lifted from the locked trunk of an employee. The good news, as is so often the case, is that the theft appears to be random. That is, the thieves seem to have gone for the hardware, and not for the data it holds. Also, it doesn't appear as if any financial information was stolen, or data that could directly lead to identity theft, such as Social Security numbers or credit card data. What is definitely missing are the health records of roughly 2,500 hundred participants in a cardiac MRI study conducted between 2001 and 2007. The records included name, date of birth, medical record numbers, and MRI data. While this is certainly private information, it's not as bad as many of the breaches due to lax security we've recently witnessed.

I'm not familiar with any law or regulation that requires this breach to be publicly disclosed. It's certainly not covered by California SB 1386, which requires personally identifiable financial information to be exposed to trigger a notification. So kudos to the NHLBI for doing the right thing, and alerting participants who may be affected.

However, it's the promise of future security enhancements that rings hollow. It sounds like the text in so many other breach notifications that have made the news in recent years:

We want to assure the participants in this and every other NHLBI study that we are taking several steps to increase data security and ensure that similar incidents do not occur in the future.

And it continues:

The NHLBI is conducting proper follow-up procedures with those responsible for this incident and has taken several steps to increase data security and protect the privacy of current and future study participants. First, we are ensuring that all NHLBI laptop computers are encrypted, as required by policies of the DHHS and the Office of Management and Budget. Laptop computers in the possession of NHLBI research staff are being inspected by NIH CIT information security personnel to ensure that appropriate encryption software is installed.

The interesting question here is one about organizations and risk. What is it about risk that makes organizations only take these sorts of security-conscious steps after there's a breach?

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29450
PUBLISHED: 2021-04-15
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It...
CVE-2021-21405
PUBLISHED: 2021-04-15
Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library method VerifyCompressed. This method accepts signatures in 2 forms: "serialized", and "compressed", meaning that BLS signatures can be provided as either of 2 un...
CVE-2021-29430
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response size for requests it mak...
CVE-2021-29431
PUBLISHED: 2021-04-15
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform a...
CVE-2021-29432
PUBLISHED: 2021-04-15
Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This could be used to construct plausible phishing emails, for example. This issue has been fixed in 4469d1d.