<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: centocor]]></title>
    <link>http://securityratty.com/tag/centocor</link>
    <description></description>
    <pubDate>Tue, 29 Jan 2008 08:08:47 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Stolen laptop contained Centocor speaker-consultant information]]></title>
      <link>http://securityratty.com/article/d0443c7844bc4096a8b34f900750e688</link>
      <guid>http://securityratty.com/article/d0443c7844bc4096a8b34f900750e688</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/29/08

Organization
Johnson and Johnson

Contractor/Consultant/Branch
Centocor, Inc
Unnamed IT Vendor

Centocor, Inc. is a wholly owned subsidiary of...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/centocor.jpg" align="right" height="53" width="190"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.jnj.com/home.htm"> Johnson and Johnson</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.centocor.com/centocor/index.html" target="_blank"> Centocor, Inc.</a>* <br>Unnamed IT Vendor<br><br><font size="1">*Centocor, Inc. is a wholly owned subsidiary of Johnson &amp; Johnson, a worldwide manufacturer of healthcare products.</font><br><br><span style="font-weight: bold;">Victims:</span><br>People participating in National Faculty and Rounds on the Road Speakers programs<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name, home of business city and state, and Social Security number/Tax Identification Number<br><br><span style="font-weight: bold;">Breach Description:</span><br>Several computers are missing from Centocor facilities in Horsham, Pennsylvania, of which one contained sensitive personal information belonging to speaker-consultants engaged by Centocor for the National Faculty and Rounds on the Road speakers programs.&nbsp; Centocor was notified by their IT vendor of the missing computers in early October, 2007, and was provided additional details on November 29th, 2007. <br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/Centicor.pdf" target="_blank"> New Hampshire Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>I am writing to inform you about a recent security incident affecting a number of<br>speaker-consultants engaged by Centocor, Inc.<br><br>a number of computers cannot be accounted for at Centocor's Horsham campus and are believed to have been stolen.<br><br>Centocor was initially notified by its IT vendor of the incident in early October 2007 and was provided specific details On Nov. 29, 2007.<br><span style="font-style: italic;">[Evan] The letter to the New Hampshire Attorney General is dated January 2nd, 2008. This equates to 34 days between the time Centocor knew about the "specific details" and the time of notification.&nbsp; The unnamed IT vendor took more than a month to conduct their investigation.&nbsp; This is longer than I would have expected on both accounts.&nbsp; I wonder if this slowness is attributed to Centocor, the IT vendor or law enforcement.</span><br><br>Based on the subsequent investigation conducted by Centocor, one of the missing computers likely contained a file which included the name, city/state and social security/tax identification numbers of a number of people engaged by Centocor<br><br>one of the laptops likely contained a file with information that was intended for management of our National Faculty and Rounds on the Road Speakers program<br><span style="font-style: italic;">[Evan] Why purpose does storing this file on a unsecure laptop serve?</span><br><br>Based on our investigation, Centocor believes that a former, contracted employee of the vendor removed the computers from our facilities<br><span style="font-style: italic;">[Evan] It's good to know that they have a suspect in the theft.</span><br><br>Centocor reported this event to local law enforcement and they are currently investigating with full cooperation from Centocor and the vendor.<br><br>Centocor does not have any evidence that your infonnation has been misused, and<br>we believe that the likelihood of such misuse is low.<br><span style="font-style: italic;">[Evan] I think the likelihood is higher than it would be in the case most "run of the mill" laptop thefts.&nbsp; In this case, the suspect is a contracted employee of the IT vendor which implies that this person may have IT skills.</span><br><br>we have arranged for a credit-monitoring product at no cost to you, which also includes unlimited access to your credit report<br><span style="font-style: italic;">[Evan] Centocor has arranged for 1 year of credit monitoring with ConsumerInfo.com.&nbsp; Permanent information protected with one year of monitoring doesn't do much to reduce the risk to the affected individual.&nbsp; Monitoring is after the fact, and one year is 365 days.</span><br><br>Centocor is committed to working with the local law enforcement to try and recover the missing assets and your information<br><span style="font-style: italic;">[Evan] It is important to remember that information is not like most physical assets.&nbsp; Once information confidentiality has been compromised, you can't "recover" it.&nbsp; You can't disclose a secret and then make it secret again.&nbsp; Nonsense.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>I know for a fact that Johnson &amp; Johnson runs a well-respected information security program, but even the well-respected companies experience breaches.&nbsp; I don't know too much about Centocor, and for all I know they may be an independently run IT organization.<br><br>Questions:<br>Why was this information on the laptop to begin with?<br>Why are Centocor laptops not encrypted? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>September, 2007 - <a href="http://breachblog.com/2007/09/08/thousands-of-patients-affected-by-mckesson-stolen-computers.aspx" target="_blank"> 68,767 Patients Affected by McKesson Stolen Computers</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/29/centocor.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 29 Jan 2008 08:08:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/centocor">centocor</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/evan centocor">evan centocor</category>
      <category domain="http://securityratty.com/tag/evan">evan</category>
      <category domain="http://securityratty.com/tag/time centocor">time centocor</category>
      <category domain="http://securityratty.com/tag/centocor facilities">centocor facilities</category>
      <category domain="http://securityratty.com/tag/facilities">facilities</category>
      <category domain="http://securityratty.com/tag/centocor laptops">centocor laptops</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <source url="http://breachblog.com/2008/01/29/centocor.aspx">Stolen laptop contained Centocor speaker-consultant information</source>
    </item>
  </channel>
</rss>
