<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fallon]]></title>
    <link>http://securityratty.com/tag/fallon</link>
    <description></description>
    <pubDate>Fri, 25 Jan 2008 08:54:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Stolen laptop contained unencrypted Fallon Community Health Plan information]]></title>
      <link>http://securityratty.com/article/fef649699bab3bfa56860edca6af847d</link>
      <guid>http://securityratty.com/article/fef649699bab3bfa56860edca6af847d</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/24/08

Organization
Fallon Community Health Plan

Contractor/Consultant/Branch
Unknown vendor

Victims
Fallon Senior Plan and Summit ElderCare...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/fallon.jpg" align="right" height="102" width="151"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/24/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.fchp.org/" target="_blank"> Fallon Community Health Plan</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unknown vendor<br><br><span style="font-weight: bold;">Victims:</span><br>Fallon Senior Plan and Summit ElderCare customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>29,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, dates of birth and Medicare identification numbers*<br><br><font size="1">*"Medicare identification number" is the generic term for any number, other than the National Provider Identifier, used by a provider or supplier to bill the Medicare program, which usually consists of the person's or his or her spouse's Social Security number.</font><br><br><span style="font-weight: bold;">Breach Description:</span><br>Three laptops were stolen from a Boston office used by an unnamed Fallon Community Health Plan vendor.&nbsp; One of the three laptops contained sensitive personal information belonging to Fallon Senior Plan and Summit ElderCare customers.&nbsp; The computer was originally though to be encrypted, but a subsequent investigation has proven this to be false.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.telegram.com/article/20080124/ALERT01/769284629" target="_blank"> Worcester Telegram</a> <br><a href="http://www.bostonherald.com/business/general/view.bg?articleid=1068943&amp;srvc=rss" target="_blank"> Boston Herald story</a> <br><a href="http://boston.bizjournals.com/boston/stories/2008/01/21/daily65.html" target="_blank"> Boston Business Journal story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Bob Kievra, Worcester Telegram &amp; Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Fallon Community Health Plan said this afternoon the names, dates of birth and Medicare identification numbers of approximately 30,000 Senior Plan members was on a laptop computer stolen earlier this month from a Boston-based vendor of the HMO.<br><span style="font-style: italic;">[Evan] I have been unable to determine the vendor from the 4 or 5 news reports I have read.&nbsp; If you know for certain, please comment.</span><br><br>members with Fallon Senior Plan and Summit ElderCare coverage<br><br>"I deeply regret that this incident occurred,'' said President and Chief Executive Officer Eric H. Schultz. "I sincerely apologize for the inconvenience and trouble this theft may cause our members.''<br><br>Mr. Schultz said the laptop containing Fallon's information was one of three computers stolen from a Boston office on either Dec. 31 or Jan. 1.<br><br>The vendor discovered the theft Jan. 2 and originally said the material had been encrypted. But the health plan, with the assistance of a forensic technologist, came to the conclusion Jan. 14 that the information was not protected.<br><span style="font-style: italic;">[Evan] I wonder why the vendor thought that the information had been encrypted.&nbsp; Do they encrypt some laptops, and not others?&nbsp; It is a good idea to encrypt all laptops (and mobile devices) rather than try to determine which ones may have confidential information on them and which ones do not.</span><br><br>the data was not password protected or encrypted, in violation of the company's policies<br><span style="font-style: italic;">[Evan] I assume that we are talking about FCHP's policies.&nbsp; Kudos to FCHP for including password protection and encryption in policy.&nbsp; Does FCHP have Vendor/Third-Party access policy and/or regularly audit their vendors for compliance?</span><br><br>The vendor was using the data to ensure that Medicare claims were being appropriately processed<br><br>The HMO said Thursday it will offer a year’s free credit monitoring to those affected.<br><br>Those individuals have also been mailed letters notifying them of the incident, and FCHP has alerted regulatory authorities to the theft.<br><br><span style="font-weight: bold;">Commentary:</span><br>A vendor that accesses confidential information and stores it on mobile media without proper protection is inexcusable.&nbsp; I am perplexed.&nbsp; Doing business with a vendor that won't (or can't) provide evidence supporting how they will protect confidential information is taking unnecessary risk. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/25/fallon.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 25 Jan 2008 08:54:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/fallon">fallon</category>
      <category domain="http://securityratty.com/tag/protect confidential information">protect confidential information</category>
      <category domain="http://securityratty.com/tag/accesses confidential information">accesses confidential information</category>
      <category domain="http://securityratty.com/tag/fallon senior plan">fallon senior plan</category>
      <category domain="http://securityratty.com/tag/senior plan">senior plan</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/unknown vendor">unknown vendor</category>
      <source url="http://breachblog.com/2008/01/25/fallon.aspx">Stolen laptop contained unencrypted Fallon Community Health Plan information</source>
    </item>
  </channel>
</rss>
