<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: uthsct]]></title>
    <link>http://securityratty.com/tag/uthsct</link>
    <description></description>
    <pubDate>Tue, 29 Apr 2008 11:55:24 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[U of Texas Health Science Center takes responsibility for mailing error]]></title>
      <link>http://securityratty.com/article/3649c53d9e7389c40a0c812fcd576dc7</link>
      <guid>http://securityratty.com/article/3649c53d9e7389c40a0c812fcd576dc7</guid>
      <description><![CDATA[Technorati Tag: Security Breach


Date Reported
4/23/08
Organization
University of Texas System
Contractor/Consultant/Branch
University of Texas Health Science Center at Tyler
The CBE Group Inc...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <A href="http://technorati.com/tag/security+breach" rel=tag>Security Breach</A><BR><BR><IMG height=81 src="http://breachblog.com/images/95781-88451/uthc.jpg" width=68 align=right> 
<P><FONT size=2><STRONG>Date Reported: <BR></STRONG>4/23/08</FONT></P>
<P><FONT size=2><STRONG>Organization:</STRONG> <BR><A href="http://www.utsystem.edu/">University of Texas System</A> </FONT></P>
<P><FONT size=2><STRONG>Contractor/Consultant/Branch:<BR></STRONG><A href="http://www.uthct.edu/default.asp">University of Texas Health Science Center at Tyler</A><BR></FONT><FONT size=2><A href="http://www.cbegroup.com/">The CBE Group Inc.</A> </FONT></P>
<P><FONT size=2><STRONG>Victims:<BR></STRONG>Patients</FONT></P>
<P><FONT size=2><STRONG>Number Affected:<BR></STRONG>Unknown*</FONT></P>
<P><FONT size=1>*Roughly 2,000 medical bills were mailed, but the number of patients is not reported.&nbsp; Some patients may have received multiple bills.</FONT></P>
<P><FONT size=2><STRONG>Types of Data:<BR></STRONG>Names, addresses, and Social Security numbers</FONT></P>
<P><FONT size=2><STRONG>Breach Description:<BR></STRONG>"Some 2,000 medical bills were mailed around East Texas last week with patients' Social Security numbers visible on the envelope after a technical glitch skewed billing at the collection agency used by the University of Texas Health Science Center at Tyler. "</FONT></P>
<P><FONT size=2><STRONG>Reference URL:</STRONG><BR><A href="http://www.tylerpaper.com/article/20080423/NEWS09/804220345">Tyler Morning Telegraph</A> </FONT></P>
<P><FONT size=2><STRONG>Report Credit:</STRONG><BR>Lauren Grover, Tyler Morning Telegraph with a special thanks to <A href="http://attrition.org/dataloss/2008/04/uthsc01.html">Attrition.org</A> </FONT></P>
<P><FONT size=2><STRONG>Response:</STRONG><BR>From the online source cited above:</FONT></P>
<P><FONT size=2>Some 2,000 medical bills were mailed around East Texas last week with patients' Social Security numbers visible on the envelope after a technical glitch skewed billing at the collection agency used by the University of Texas Health Science Center at Tyler.<BR><EM>[Evan] Why is it necessary to send someone a piece of mail with their Social Security number on it?&nbsp; The person receiving the bill probably already knows their Social Security number.</EM></FONT></P>
<P><FONT size=2>Chief Operating Officer Rob Marshall at UTHSCT said the problem was quickly addressed and fixed, but his disappointment in collection agency CBE Group Inc. might not be repairable.</FONT></P>
<P><FONT size=2>"We're in negotiations ... I can't confirm or deny that we'll be with (CBE) in the future," he said Tuesday evening. "But we do have a different set of rules on handling issues like this and have already said how to safeguard this in the future."<BR><EM>[Evan] Is UTHSCT planning on sending a separate notification mailing to the people affected?&nbsp; No mention in the article.</EM></FONT></P>
<P><FONT size=2>The number of area residents whose numbers were exposed isn't known because multiple bills could have gone to one patient, said spokeswoman Rhonda Scoby.</FONT></P>
<P><FONT size=2>The Social Security numbers were never floating around the public, but were sent from secure sites at UTHSCT to CBE and then straight to the post office and to the patient's home, she said.<BR><EM>[Evan] There are a few more steps along the way, such as post office routing and delivery.&nbsp; It used to be safer to send confidential information in the mail.&nbsp; Not so anymore.</EM></FONT></P>
<P><FONT size=2>The hospital is taking full responsibility for the error and asking all affected patients to contact their business office, Marshall said.<BR><EM>[Evan] The </EM><A href="http://www.uthct.edu/resources/directory/phone.asp"><EM>UTHSCT business office</EM></A><EM>&nbsp;</EM></FONT><FONT size=2><EM>can be contacted by calling (903) 877-7172.</EM></FONT></P>
<P><FONT size=2>"It was a small glitch that we absolutely own up to and want to be able to take care of anyone who has issue as a result," he said.<BR><EM>[Evan] Then at the very least, put something on the UTHSCT web site for affected people to refer to (I couldn't find anything).</EM></FONT></P>
<P><FONT size=2>While CBE officials are still investigating the cause of the error, added software and quality control is in place to catch any further malfunction, Marshall said.</FONT></P>
<P><FONT size=2><STRONG>Commentary:<BR></STRONG>The one burning question is why are Social Security numbers present on billing statements to begin with?&nbsp; Or was this the problem all along, they were never supposed to be anywhere on the billing statement? </FONT></P>
<P><FONT size=2><STRONG>Past Breaches:</STRONG><BR>October, 2007 - <A href="http://breachblog.com/2007/10/16/utexas.aspx">University of Texas students exposed on FTP site</A></FONT></P><BR>
<SCRIPT src="http://feeds.feedburner.com/~s/breachblog?i=http://breachblog.com/2008/04/29/uthc1.aspx" type=text/javascript charset=utf-8></SCRIPT>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 11:55:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/uthsct">uthsct</category>
      <category domain="http://securityratty.com/tag/uthsct web site">uthsct web site</category>
      <category domain="http://securityratty.com/tag/collection agency">collection agency</category>
      <category domain="http://securityratty.com/tag/collection agency cbe">collection agency cbe</category>
      <category domain="http://securityratty.com/tag/cbe">cbe</category>
      <category domain="http://securityratty.com/tag/cbe officials">cbe officials</category>
      <category domain="http://securityratty.com/tag/uthsct business office">uthsct business office</category>
      <category domain="http://securityratty.com/tag/patients">patients</category>
      <source url="http://breachblog.com/2008/04/29/uthc1.aspx">U of Texas Health Science Center takes responsibility for mailing error</source>
    </item>
  </channel>
</rss>
