<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tenet]]></title>
    <link>http://securityratty.com/tag/tenet</link>
    <description></description>
    <pubDate>Mon, 18 Feb 2008 07:26:45 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Tenet Healthcare warns 37,000 patients of data compromise]]></title>
      <link>http://securityratty.com/article/73f4e01b5ebef5ac9d71b7bda7e81462</link>
      <guid>http://securityratty.com/article/73f4e01b5ebef5ac9d71b7bda7e81462</guid>
      <description><![CDATA[Dallas-based Tenet Healthcare Corp. last week sent out notices to about 37,000 patients informing them about the potential compromise of their personal and financial...]]></description>
      <content:encoded><![CDATA[Dallas-based Tenet Healthcare Corp. last week sent out notices to about 37,000 patients informing them about the potential compromise of their personal and financial data.]]></content:encoded>
      <pubDate>Thu, 21 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tenet healthcare corp">tenet healthcare corp</category>
      <category domain="http://securityratty.com/tag/financial data">financial data</category>
      <category domain="http://securityratty.com/tag/patients">patients</category>
      <category domain="http://securityratty.com/tag/potential compromise">potential compromise</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/notices">notices</category>
      <source url="http://www.networkworld.com/news/2008/022208-tenet-healthcare-warns-37000-patients.html?fsrc=rss-security">Tenet Healthcare warns 37,000 patients of data compromise</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud at Tenet Healthcare affects 37,000]]></title>
      <link>http://securityratty.com/article/3354deb2261c2960edeefc322fb21ebf</link>
      <guid>http://securityratty.com/article/3354deb2261c2960edeefc322fb21ebf</guid>
      <description><![CDATA[Technorati Tag: Security Breach


Date Reported
2/13/08
Organization
Tenet Healthcare Corporation
Contractor/Consultant/Branch
None
Victims
Patients
Tenet Healthcare Corp. owns 54 hospitals in a dozen...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <A href="http://technorati.com/tag/security+breach" rel=tag>Security Breach</A><BR><BR><IMG height=54 src="http://breachblog.com/images/95781-88451/tenet.jpg" width=115 align=right> 
<P><FONT size=2><STRONG>Date Reported: </STRONG><BR>2/13/08</FONT></P>
<P><FONT size=2><STRONG>Organization:</STRONG> <BR><A href="http://www.tenethealth.com/TenetHealth" target=_blank>Tenet Healthcare Corporation</A> </FONT></P>
<P><FONT size=2><STRONG>Contractor/Consultant/Branch:</STRONG><BR>None</FONT></P>
<P><FONT size=2><STRONG>Victims:</STRONG><BR>Patients*</FONT></P>
<P><FONT size=1>*Tenet Healthcare Corp. owns 54 hospitals in a dozen states, including Hilton Head Regional Medical Center and Coastal Carolina Medical Center.</FONT></P>
<P><FONT size=2><STRONG>Number Affected:<BR></STRONG>37,000</FONT></P>
<P><FONT size=2><STRONG>Types of Data:</STRONG><BR>Social Security numbers and other personal information.</FONT></P>
<P><FONT size=2><STRONG>Breach Description:<BR></STRONG>A former employee working in the Tenet Healthcare Corporation billing center in Frisco, Texas has been convicted of identity theft.&nbsp; Terrence Brooks worked for the company for less than two years and stole names, Social Security numbers and other personal information belonging to at least 90 patients, but also had access to 37,000.</FONT></P>
<P><FONT size=2><STRONG>Reference URL:</STRONG><BR><A href="http://www.beaufortgazette.com/local/story/190720.html" target=_blank>The Beaufort Gazette online story</A> </FONT><BR><FONT size=2><A href="http://www.sun-sentinel.com/news/local/palmbeach/sfl-flpfraud0214sbfeb14,0,42801.story" target=_blank>The Sun-Sentinel online story</A><BR></FONT><FONT size=2><BR><STRONG>Report Credit:</STRONG><BR>Daniel Brownstein, The Beaufort Gazette</FONT></P>
<P><FONT size=2><STRONG>Response:</STRONG><BR>From the online sources cited above:</FONT></P>
<P><FONT size=2>A former employee of a locally connected national hospital chain who was convicted of identity theft had access to the personal information of about 37,000 patients, according to a company spokesman.</FONT></P>
<P><FONT size=2>Terrance Brooks, 30, of Fort Worth, was arrested Nov. 25 when he tried to open a Costco credit card using a state ID with fraudulent information, police said.</FONT></P>
<P><FONT size=2>The company mailed letters last week announcing the security breach to anyone who could have been affected, said spokesman Steven Campanini.</FONT></P>
<P><FONT size=2>Tenet also informed victims how to set up free fraud alerts at the nation's three major credit bureaus.</FONT></P>
<P><FONT size=2>"There's an annoyance factor and we apologize for that," Campanini said. "We recognize consumer privacy is very important and take it very seriously."<BR><EM>[Evan] I am not personally a victim, but I am pretty sure that this surpasses "an annoyance factor" for some people.</EM></FONT></P>
<P><FONT size=2>The ex-employee worked at a Frisco, Texas, billing center for less than two years, and is confirmed to have stolen the names, Social Security numbers and other personal information of about 90 patients, Campanini said. The company has paid to monitor the credit reports of those victims.</FONT></P>
<P><FONT size=2>Terrence Brooks, 30, had access to 37,000 other accounts</FONT></P>
<P><FONT size=2>He pleaded guilty last month to five counts of fraudulent use and possession of identification information and was sentenced to nine months in prison.<BR><EM>[Evan] Only nine months in prison.&nbsp; In 2006, the average time it took victims to recover from identity theft was 607 hours.</EM></FONT></P>
<P><FONT size=2>He had passed a background check to get the Tenet job. Brooks was immediately fired when the company learned of his arrest.</FONT></P>
<P><FONT size=2>"What's challenging in this situation is there was an employee intent on committing fraud," Campanini said. "No company can prevent that, but we can have practices in place to immediately address it when it does occur, and that's what we did."<BR><EM>[Evan] I agree that preventing employee fraud is challenging, but reducing risk is very impossible.&nbsp; There are several things that companies can do to reduce the risk significantly (segregation of duties, job rotation, cross-training, etc.).&nbsp; Access to Social Security numbers should require an additional level of clearance and this clearance should be closely scrutinized.&nbsp; The normal "run of the mill" billing work does not require Social Security number access.</EM></FONT></P>
<P><FONT size=2>"I'm more concerned with what could happen than what has happened," Ashley Latzer a person that received one of the Tenet notification letters.<BR><EM>[Evan] More than an "annoyance"?</EM></FONT></P>
<P><FONT size=2>Tenet patients concerned about the security of their personal information may call a company hotline at 1-800-553-6101 between 8 a.m. and 6 p.m. weekdays.</FONT></P>
<P><FONT size=2><STRONG>Commentary:</STRONG><BR>I am concerned with how many people in companies have unnecessary access to confidential information.&nbsp; One of the first steps in reduding risk of employee fraud is to limit access to confidential information to only when it is absolutely required.&nbsp; The resolution of most customer service, help desk, and billing calls don't require Social Security numbers, credit card numbers (including CVV2), and other sensitive information.&nbsp; </FONT></P>
<P><FONT size=2>I don't know enough about how Tenet manages its data and billing center, but I am sure that creative information security solutions could reduce the risk of this happening again. </FONT></P>
<P><FONT size=2><STRONG>Past Breaches:</STRONG><BR>Unknown</FONT></P><BR>
<SCRIPT src="http://feeds.feedburner.com/~s/breachblog?i=http://breachblog.com/2008/02/18/tenet.aspx" type=text/javascript charset=utf-8></SCRIPT>]]></content:encoded>
      <pubDate>Mon, 18 Feb 2008 07:26:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tenet">tenet</category>
      <category domain="http://securityratty.com/tag/require">require</category>
      <category domain="http://securityratty.com/tag/require social security">require social security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/tenet healthcare corp">tenet healthcare corp</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/letters">letters</category>
      <category domain="http://securityratty.com/tag/tenet notification letters">tenet notification letters</category>
      <source url="http://breachblog.com/2008/02/18/tenet.aspx">Employee fraud at Tenet Healthcare affects 37,000</source>
    </item>
  </channel>
</rss>
