<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: waukesha]]></title>
    <link>http://securityratty.com/tag/waukesha</link>
    <description></description>
    <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Waukesha County job applicant data exposed in mailing]]></title>
      <link>http://securityratty.com/article/6efea251f53508bced1039830009ef31</link>
      <guid>http://securityratty.com/article/6efea251f53508bced1039830009ef31</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/13/08

Organization
Waukesha County, Wisconsin

Contractor/Consultant/Branch
Crivello Carlson, S.C

Victims
Job applicants from the year 2006

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/waukesha.jpg" width="149" align="right" height="200"><font size="2"><b>Date Reported: </b><br>7/13/08<br><br><b>Organization: </b><br><a href="http://www.waukeshacounty.gov/">Waukesha County, Wisconsin</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.milwlaw.com/index.aspx">Crivello Carlson, S.C.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Job applicants from the year 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 130"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Job applications including, names, addresses, job and education history, salary, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"More than 130 people who applied for a job with Waukesha County in 2006 had their Social Security numbers, employment and salary information, addresses and phone numbers and other personal information released to one of the women who applied for the job. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.jsonline.com/story/index.aspx?id=772046">Milwaukee Journal Sentinel</a> <br><a href="http://www.newrichmond-news.com/articles/index.cfm?id=87905&amp;section=Wisconsin%20News&amp;property_id=19">New Richmond News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Raquel Rutledge, Milwaukee Journal Sentinel<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Taunya Thomas was horrified when she got a call from a stranger who knew almost everything about her.<br><br>The woman on the phone told Thomas she knew her Social Security number, where she lived and worked, how much money she made and where she went to high school and college. She rattled them off, not missing a single digit or fact.<br><br>She promised she wasn't going to use the information.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; The government body that exposed the information made the promise that "your Social Security number will remain confidential".&nbsp; So much for promises</span>.<br><br>She was calling, she said, because she wanted Thomas and others to know where she had gotten it.<br><br>She hadn't stolen it. <br><br>Waukesha County sent it to her in the mail, along with the same personal information for more than 130 other people who had all applied for a job with the county in 2006.<br><span style="font-style: italic;">[Evan] What's with Wisconsin and mailing confidential information (in error)?&nbsp; This is the third mailing error reported on The Breach Blog coming out of Wisconsin this year.</span><br><br>The woman on the phone, Bernadine Matthews, too had applied for the position as an economic support specialist.<br><br><img src="http://images.quickblogcast.com/95781-88451/matthews.jpg" width="324" border="0"><br><font size="1">This is Matthews displayed holding the applications.&nbsp; Source: Milwaukee Journal Sentinel</font><br><br>When she didn't get it, she filed a complaint with the Equal Employment Opportunity Commission.<br><br>As part of the complaint and the investigation, the EEOC requested copies of all the applications.<br><br>The law firm representing the county, Crivello Carlson, sent the applications to Matthews.<br><span style="font-style: italic;">[Evan] Really?&nbsp; Any second thoughts about the fact that this may put innocent people at risk?</span><br><br>Waukesha County tried to reclaim the documents sent to Matthews, threatening to get a search warrant and send a lawyer to her house, Matthews said.<br><br>When Matthews refused, they insisted she bring the documents to the law firm so they could white-out the private information in the applications.<br><br>Again, Matthews refused.<br><span style="font-style: italic;">[Evan] At what point does Matthews cross a line.&nbsp; The confidential information on those job applications does NOT belong to her.&nbsp; In my opinion, she has no right to maintain possession of the information.&nbsp; For Matthews to knowingly maintain information that does not belong to her almost seems criminal to me.</span><br><br>The applications would be critical to her discrimination suit, she thought.<br><span style="font-style: italic;">[Evan] So risk the disclosure of senstive information belonging to 130 people for your own benefit?&nbsp; If not criminal, it is certainly selfish.</span><br><br>She quickly hired an attorney, copied the documents and sent a set back to the county. She keeps her copies in an oversize safe-deposit box at her bank, she said.<br><span style="font-style: italic;">[Evan] Who authorized her to make copies?&nbsp; The data owners (victims) certainly did not.</span><br><br>"I'm not going to be like the county," Matthews said. "I'm going to protect the privacy of the information in this box. Obviously they didn't give a darn about the applicants' privacy."<br><br>The Waukesha County employment application specifically states it will protect Social Security numbers.<br><br>"Your Social Security Number will remain confidential and will not be copied or released but is required for applicant tracking purposes," the application reads.<br><br><a href="http://www.milwlaw.com/ourpeople/profile.aspx?id=285&amp;name=Raymond%20J.%20Pollen">Ray Pollen</a>, an attorney with Crivello Carlson, at first said it was no mistake that Matthews received the uncensored applications.<br><span style="font-style: italic;">[Evan] So Mr. Pollen sent the information on purpose.&nbsp; Did he stop to think that there might be a problem here?&nbsp; Did it occur to anyone that they should redact the most sensitive information such as Social Security numbers, or names?</span><br><br>He said it was required under federal law that all parties in an EEOC discrimination complaint receive copies of information requested by the agency investigating. He couldn't point to the specific provision.<br><span style="font-style: italic;">[Evan] Does a specific provision exist?&nbsp; I cannot think of a single purpose that a Social Security number would serve in this case.</span><br><br>Several days later, Pollen said the EEOC had no such requirement.<br><br>"The EEOC is silent on the issue," he said.<br><br>Instead it's the state's Equal Rights Division that requires all parties be copied on information requested by the division but even that provision doesn't mandate that attachments - such as the applications - be included. And, Matthew's case was not filed with the state.<br><br>"We followed the state's protocol," Pollen said.<br><br>P.I. asked: So anyone who applies for a job with Waukesha County could have their private information disclosed to a non-governmental third-party?<br>&nbsp;<br>Pollen answered: "We responded to a federal agency's request for information. . . . In my opinion there was no violation of any law or procedure."<br><span style="font-style: italic;">[Evan] Let's give Mr. Pollen the benefit of the doubt.&nbsp; Let's say that there was no violation of any law or procedure here.&nbsp; There certainly seems to be a violation of trust, a violation of good judgment, and a violation of privacy.&nbsp; The "if the law don't state it, then I must be able to do it" mentality is one of the reasons we have so many laws.&nbsp; Maybe if we used a little more common sense.</span><br><br>Taunya Thomas called the release of her information to a stranger shocking. She said at a minimum the county should have notified her that her information had been compromised.<br><br>"I'm devastated that it's that easy for my information to be disclosed," she said. "For someone to call me and tell me where I worked, where I went to school, recite my Social Security number verbatim to me, that's scary."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very frustrating breach to read about.&nbsp; It is frustrating when someone knowingly discloses confidential information and then tries to justify it.&nbsp; Equally frustrating is when a person that has no right to the information refuses to part with it.&nbsp; In the middle of all of this are 130 innocent people.<br><br>I do not claim to know half as much about the law as Mr. Pollen does.&nbsp; His actions may be well within his legal rights for all I know. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/waukesha.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/waukesha county">waukesha county</category>
      <category domain="http://securityratty.com/tag/senstive information">senstive information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/salary information">salary information</category>
      <source url="http://breachblog.com/2008/07/15/waukesha.aspx">Waukesha County job applicant data exposed in mailing</source>
    </item>
  </channel>
</rss>
