<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: utuia]]></title>
    <link>http://securityratty.com/tag/utuia</link>
    <description></description>
    <pubDate>Mon, 16 Jun 2008 05:37:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[UTUIA laptops are missing after shipment]]></title>
      <link>http://securityratty.com/article/3cca53a16c51f77342f6ce79b4c1eee9</link>
      <guid>http://securityratty.com/article/3cca53a16c51f77342f6ce79b4c1eee9</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/9/08

Organization
United Transportation Union Insurance Association (&quot;UTUIA

Contractor/Consultant/Branch
Westin Hotels and Resorts
United Parcel...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/utuia.jpg" align="right" height="81" width="140"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/9/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.utuia.org/index.htm">United Transportation Union Insurance Association ("UTUIA")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.starwoodhotels.com/westin/index.html">Westin Hotels and Resorts</a> <br><a href="http://www.ups.com/content/us/en/index.jsx">United Parcel Service</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Policyholders<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names and social security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>Two laptop computers shipped via UPS to UTUIA offices are missing.&nbsp; One of the laptops may contain sensitive personal information belonging to UTUIA policyholders.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/united_trans_union.pdf">New Hampshire State Attorney General breach notification</a><br><br>Report Credit:<br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>We are writing to inform you of a recent security incident involving UTUIA, headquartered in Ohio.<br><br>During shipment of UTUIA laptop computers to UTUIA offices, laptops have been reported missing.<br><span style="font-style: italic;">[Evan] The notification letter sent to victims mentions two laptops.</span><br><br>The laptops may have contained personal information, including names and social security numbers, about policyholders<br><br>UTUIA has reported the missing laptops to law enforcement authorities and is pursuing the return of these laptops.<br><br>United Transportation Union Insurance Association has filed police reports, is coordinating with the hotel involved (Westin San Francisco) and has notified UPS of the missing items.<br><span style="font-style: italic;">[Evan] Based on the information so far, it appears that UTUIA arranged for Westin to ship two laptops via UPS.&nbsp; One of the laptops contained sensitive personal information.&nbsp; There is no mention of encryption or any other protections in the breach notification, so we can only imagine.</span><br><br>Given the time that has passed since notification, we believe the likelihood of timely recovery is low and therefore are proceeding with notification.<br><span style="font-style: italic;">[Evan] How much time has passed since the laptops were lost/stolen?&nbsp; Neither the New Hampshire or victim notifications disclose this important piece of information.</span><br><br>Currently, there is no indication that the laptop was stolen for its content, but it is possible that there was unauthorized access to information<br><span style="font-style: italic;">[Evan] Do you think that a thief would announce his/her intentions for stealing the laptop?&nbsp; I don't think so.&nbsp; What indication an investigator look for to explain a thief's motives?</span><br><br>We regret this unfortunate situation, and although we have no evidence at this time that any personal information has been accessed or misused, we encourage you to take preventative measures.<br><span style="font-style: italic;">[Evan] What "preventative measures" did UTUIA use to protect personal information for which they were not the owners?&nbsp; Who knows?</span><br><br>We sincerely apologize for any inconvenience that this may cause you.<br><br>If you have additional questions, please call us toll-free at 866-753-3631 between 8:30 a.m. and 4:30 p.m. eastern time, or contact us by mail at 14600 Detroit Avenue, Cleveland, Ohio 44107.<br><br><span style="font-weight: bold;">Commentary:</span><br>In my opinion, there is not enough information in the breach notification sent to the New Hampshire Attorney General or victims.&nbsp; Customers deserve more information about what an organization plans to do in order to provide an adequate amount (owner's discretion) of security.&nbsp; Based on the information we've read in the breach notification, there is no basis for judgment, which is sad.<br><br>What exactly does UTUIA do to protect the confidential information belonging to policyholders?<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/16/utuia.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 05:37:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/utuia">utuia</category>
      <category domain="http://securityratty.com/tag/protect personal information">protect personal information</category>
      <category domain="http://securityratty.com/tag/laptop computers">laptop computers</category>
      <category domain="http://securityratty.com/tag/utuia laptop computers">utuia laptop computers</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/utuia offices">utuia offices</category>
      <source url="http://breachblog.com/2008/06/16/utuia.aspx">UTUIA laptops are missing after shipment</source>
    </item>
  </channel>
</rss>
