<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cbiz]]></title>
    <link>http://securityratty.com/tag/cbiz</link>
    <description></description>
    <pubDate>Tue, 29 Jan 2008 09:51:35 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[35,000 T. Rowe price plan participants alerted]]></title>
      <link>http://securityratty.com/article/eeaa57364e7dfa30a2ef24d6c7ffa570</link>
      <guid>http://securityratty.com/article/eeaa57364e7dfa30a2ef24d6c7ffa570</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/28/07

Organization
T. Rowe Price

Contractor/Consultant/Branch
T. Rowe Price Retirement Plan Services
CBIZ Benefits and Insurance Services Inc
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/trowe.jpg" align="right" height="48" width="131"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/28/07<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.troweprice.com" target="_blank"> T. Rowe Price</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www2.troweprice.com/rps/scm/consultant/public/index/0,,,00.html" target="_blank"> T. Rowe Price Retirement Plan Services</a> <br><a href="http://www.cbiz.com/benefits/" target="_blank"> CBIZ Benefits and Insurance Services Inc.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Participants in various T. Rowe Price retirement plans<br><br><span style="font-weight: bold;">Number Affected:</span><br>35,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computers were stolen from the office of CBIZ Benefits and Insurance that contained sensitive personal information belonging to participants in “several hundred” T. Rowe Price retirement plans.&nbsp; CBIZ is a vendor for T. Rowe Price that was helping the company to prepare <a href="http://www.irs.gov/instructions/i5500/index.html" target="_blank"> IRS Form 5500's</a>.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.investmentnews.com/apps/pbcs.dll/article?AID=/20080128/REG/672979544" target="_blank"> Investment News online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Investment News<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>T. Rowe Price Retirement Plan Services alerted 35,000 current and former participants in “several hundred” plans that their names and Social Security numbers were contained in files on computers that were stolen, said Brian Lewbart, spokesman.<br><br>taken from the office of CBIZ Benefits and Insurance Services Inc., which prepares the 5500s for T. Rowe Price<br><br>The data were kept on the computers to help complete filing of Form 5500<br><span style="font-style: italic;">[Evan] I have a feeling that the information was only meant to be kept on the computers temporarily until the Form 5500's were complete.&nbsp; This breach demonstrates the importance in protecting confidential information no matter where it resides, no matter how long.&nbsp; Confidential information must remain protected in-transit and at-rest, even if temporary.&nbsp; Obviously, encryption could have been an effective defensive layer.</span><br><br>Other personal information, such as addresses, and birth dates, was not on the computers.<br><span style="font-style: italic;">[Evan] This information can be obtained publicly anyway, so no help here.</span><br><br>The company offered those affected a free one-year subscription to an online credit monitoring service and up to $25,000 of identity theft insurance, as well as tips on protection from identity theft.<br><br><span style="font-weight: bold;">Commentary:</span><br>Not much is known about this breach yet.&nbsp; I am sure that there is more to come.<br><br>This is yet another case of a lost or stolen computer containing sensitive personal information without encryption (assuming there is no encryption). <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/29/trowe.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 29 Jan 2008 09:51:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/rowe price">rowe price</category>
      <category domain="http://securityratty.com/tag/insurance">insurance</category>
      <category domain="http://securityratty.com/tag/identity theft insurance">identity theft insurance</category>
      <category domain="http://securityratty.com/tag/cbiz benefits">cbiz benefits</category>
      <category domain="http://securityratty.com/tag/cbiz">cbiz</category>
      <source url="http://breachblog.com/2008/01/29/trowe.aspx">35,000 T. Rowe price plan participants alerted</source>
    </item>
  </channel>
</rss>
