<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dpw]]></title>
    <link>http://securityratty.com/tag/dpw</link>
    <description></description>
    <pubDate>Wed, 12 Dec 2007 12:10:53 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Another stolen Pennsylvania DPW computer, more victims]]></title>
      <link>http://securityratty.com/article/e8b36cb6c44070799de7b29f38f06218</link>
      <guid>http://securityratty.com/article/e8b36cb6c44070799de7b29f38f06218</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
12/6/07

Organization
State of Pennsylvania

Contractor/Consultant/Branch
Department of Public Welfare (DPW

Victims
Certain welfare clients

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/padpw.jpg" align="right" height="45" width="199"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>12/6/07<br><br><span style="font-weight: bold;">Organization: </span><br>State of Pennsylvania<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Department of Public Welfare (DPW)<br><br><span style="font-weight: bold;">Victims:</span><br>Certain welfare clients<br><br><span style="font-weight: bold;">Number Affected:</span><br>86*<br><br><font size="1">*Names and Social Security numbers of 14 clients<br>*Names and addresses of 72 clients</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and Social Security numbers (see above)<br><br><span style="font-weight: bold;">Breach Description:</span><br>On December 5th, 2007 Edward Novak from the Pennsylvania Department of Public Welfare (DPW) sent a news release announcing the theft of a DPW computer that contained sensitive personal information about a limited number of DPW clients.&nbsp; This is the second such breach of 2007 at DPW.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&amp;STORY=/www/story/12-05-2007/0004717620&amp;EDATE=" target="_blank"> The Pennsylvania Department of Public Welfare Press Release</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>State of Pennsylvania Department of Public Welfare<br><br><span style="font-weight: bold;">Response:</span><br>The official DPW news release in it's entirety:<br><br>The Department of Public Welfare today began notifying 86 clients whose personal information was contained on a computer stolen from a DPW office in Philadelphia.<br><br>While there is no indication that any of the information on the stolen computer has been used inappropriately, DPW wants to ensure that potentially affected clients are notified of the incident, and understand that the department is taking every possible precaution to<br>protect them.<br><br>"We sincerely apologize to all of those who may be affected by this regrettable incident," said Secretary of Public Welfare Estelle B. Richman. "The department is working closely with law enforcement throughout their investigation and is ready to assist every client who may be impacted."<br><span style="font-style: italic;">[Evan] I really like this statement from Estelle B. Richman.&nbsp; It feels genuine to me.</span><br><br>The information on the computers was password protected. The information contained the names and Social Security numbers of approximately 14 clients and the&nbsp; names and addresses only of another 72 clients.<br><span style="font-style: italic;">[Evan] You know my thoughts on password protection. If this breach is indicative of other computers and data-at-rest locations within the department, then there is another breach just waiting to happen.&nbsp; Encryption is a must and Password protection = momentary nuisance to a crook.&nbsp; This is the second such breach at DPW this year.</span><br><br>The department today has began mailing notification letters to all 86 individuals who could potentially be affected in order to explain what has happened and to assist them with any remediation steps they will need to take.&nbsp; <br><br>Consumers with questions or those who believe they have been affected can call the Philadelphia Change Center at (215) 560-7226 in the Philadelphia area, from 7:30 a.m. to 5 p.m.<br><br>For additional information on identify theft or to learn about steps to take if you believe you have been a victim, visit the Pennsylvania Commission on Crime and Delinquency's Web site at <a href="http://www.identitytheftactionplan.com" target="_blank"> <a href="http://www.identitytheftactionplan.com</a><br><br>CONTACT:&nbsp;&nbsp;&nbsp;">www.identitytheftactionplan.com</a><br><br>CONTACT:&nbsp;&nbsp;&nbsp;</a> Anne C. Bale (717) 787-4592<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach was relatively small in terms of numbers or people affected, but I have a hunch that it exposes a relatively large risk within the DPW.&nbsp; All confidential data at rest need to be encrypted with the keys managed securely.<br><br>The DPW should be applauded in their response and disclosure (i.e. a link to the press release is prominently displayed on the DPW home page), but admonished for not encrypting sensitive data at rest. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>September, 2007 - <a href="http://breachblog.com/2007/09/11/pa-department-of-public-welfare-computers-stolen-with-375000-citizens-affected.aspx"> Pennsylvania DPW computers stolen, exposing 375,000 citizens</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/12/12/padpw.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Wed, 12 Dec 2007 12:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dpw computer">dpw computer</category>
      <category domain="http://securityratty.com/tag/dpw">dpw</category>
      <category domain="http://securityratty.com/tag/pennsylvania">pennsylvania</category>
      <category domain="http://securityratty.com/tag/pennsylvania dpw computers">pennsylvania dpw computers</category>
      <category domain="http://securityratty.com/tag/dpw clients">dpw clients</category>
      <category domain="http://securityratty.com/tag/pennsylvania department">pennsylvania department</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <source url="http://breachblog.com/2007/12/12/padpw.aspx">Another stolen Pennsylvania DPW computer, more victims</source>
    </item>
  </channel>
</rss>
