<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: bcbsnj]]></title>
    <link>http://securityratty.com/tag/bcbsnj</link>
    <description></description>
    <pubDate>Mon, 11 Feb 2008 10:52:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Lost Horizon Blue Cross Blue Shield of New Jersey laptop]]></title>
      <link>http://securityratty.com/article/7ccb8054d47cf10d8aa3779be8085f62</link>
      <guid>http://securityratty.com/article/7ccb8054d47cf10d8aa3779be8085f62</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/29/08

Organization
Horizon Blue Cross Blue Shield of New Jersey (BCBSNJ

Horizon Blue Cross Blue Shield of New Jersey (Horizon BCBSNJ), a...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/horizon.jpg" align="right" height="58" width="159"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.horizon-bcbsnj.com/" target="_blank"> Horizon Blue Cross Blue Shield of New Jersey (BCBSNJ)</a>*<br><br><font size="1">*Horizon Blue Cross Blue Shield of New Jersey (Horizon BCBSNJ), a not-for-profit organization headquartered in Newark, is the state's largest health insurer.</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Horizon BCBSNJ members<br><br><span style="font-weight: bold;">Number Affected:</span><br>~300,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>On January 5th, 2008 a laptop used by a Horizon Blue Cross Blue Shield of New Jersey employee was stolen in Newark, NJ.&nbsp; The laptop contained sensitive personal information belonging to Horizon Blue Cross Blue Shield of New Jersey members and has not been recovered.<br><br>Reference URL:<br><a href="http://www.horizon-bcbsnj.com/newsroom_pop.asp?id=5" target="_blank"> Horizon BCBSNJ News Alert</a> <br><a href="http://www.nj.com/news/index.ssf/2008/01/horizon_blue_cross_blue_shield.html" target="_blank"> New Jersey On-Line story (many comments)</a> <br><a href="http://www.njbiz.com/weekly_article.asp?aID=29064834.2172984.951652.2303489.5422106.991&amp;aID2=73195" target="_blank"> New Jersey Business Journal report</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Horizon Blue Cross Blue Shield of New Jersey, with a special thanks to <a href="http://attrition.org/" target="_blank"> Attrition.org</a> <br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Horizon Blue Cross Blue Shield of New Jersey is notifying more than 300,000 of its members that their names, social security numbers and other personal information were contained on a laptop computer stolen in Newark<br><br>If you are a Horizon BCBSNJ member and you have not received a letter indicating that your information was on the stolen laptop, you are not affected.<br><span style="font-style: italic;">[Evan] This is a stated "fact" on the Horizon BCBSNJ News Alert site.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/horizonalert.jpg" border="0" width="193"><br><br>There was no medical data on the stolen laptop.<br><br>On January 5, 2008, a Horizon BCBSNJ employee’s laptop was stolen in the City of Newark.<br><br>Horizon BCBSNJ believes that it is highly unlikely that any personal data stored on the stolen computer has been accessed. The computer was password protected.<br><span style="font-style: italic;">[Evan] Come on.&nbsp; Password protection (likely operating system level) is NOT adequate protection for confidential data, especially on mobile media.&nbsp; Password protection is certainly not the factor that would make access "highly unlikely".</span><br><br>Those whose names were on the laptop are being offered a free year of credit-monitoring services.<br><br>Horizon BCBSNJ has sent letters to all affected members alerting them to the theft.<br><br>The laptop, which was stolen on Jan. 5, was being taken home by an employee who regularly works with member data.<br><span style="font-style: italic;">[Evan] I wonder how many other employees regularly work with member data on unencrypted laptops.</span><br><br>Thomas Rubino, director of public affairs for Horizon, said the loss of data resulted from a violation of company security practices, and was being investigated.<br><br>on January 23, 2008, a security feature was initiated that destroys all of the data on stolen computer.<br><span style="font-style: italic;">[Evan] Why would Horizon BCBSNJ invest in software to remotely destroy data and not add encryption to the mix?&nbsp; The remote data destruction in which "a security feature was initiated" requires network connectivity.&nbsp; Simply disabling the network card(s) or slaving the drive(s) to another computer easily circumvents this security "feature" and does not provide certainty that the data is safe.</span><br><br>Horizon BCBSNJ takes seriously its obligation to protect personal information. We apologize for any inconvenience this theft may have caused those affected.<br><br><span style="font-weight: bold;">Commentary:</span><br>I don't understand the reluctance of some companies to encrypt data at rest on laptops and other mobile media.&nbsp; If the laptop were encrypted and there was no reason to believe that the key had been compromised, then there would be no effective breach of data confidentiality.&nbsp; For those companies that do encrypt data at rest, be sure that users are not writing passwords (keys) down with the laptop, i.e. Post-it notes and stickers. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/11/horizon.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 11 Feb 2008 10:52:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/horizon">horizon</category>
      <category domain="http://securityratty.com/tag/horizon bcbsnj takes">horizon bcbsnj takes</category>
      <category domain="http://securityratty.com/tag/horizon bcbsnj">horizon bcbsnj</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/medical data">medical data</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/remotely destroy data">remotely destroy data</category>
      <category domain="http://securityratty.com/tag/bcbsnj">bcbsnj</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <source url="http://breachblog.com/2008/02/11/horizon.aspx">Lost Horizon Blue Cross Blue Shield of New Jersey laptop</source>
    </item>
  </channel>
</rss>
