Canada: Hospital’s Unprotected External Hard Drive Missing.

According to cbc.com and other media outlets, 650 Canadians have been affected by the theft of an external hard drive that contained medical information. The Mazankowski Alberta Heart Institute announced that the HDD “went missing” from an outpatient lab. Its disappearance is linked, most probably, to a theft that occurred on August 5 of this […] read more

Laptop With Medical Info Missing From University of Hong Kong.

According to scmp.com, the University of Hong Kong has lost a laptop computer containing medical information on more than 3,600 people. Apparently, the laptop computer was not secured with full disk encryption software; and yet, 901 patients’ data was cryptographically protected independently. Police are currently investigating the situation. Massive Data Breach This latest episode has […] read more

Seattle University Alerts Over 2000 Faculty & Staff Of Lost Laptop.

Seattle University announced a couple of weeks ago that an unencrypted laptop was lost while an employee was “commuting on the bus.” An IT investigation drew the conclusion that “an offline email cache file” contained Social Security numbers and other personal information for 2,102 current and former faculty, staff, and dependents. The story feels like […] read more

UK’s National Cyber Security Centre Publishes List of Commonly Used Passwords.

A blast from the past, from the 1990s to the early noughts to be more specific, made the news this week, courtesy of the National Cyber Security Centre in the United Kingdom. According to an analysis by the government organization, blink182 is among the most commonly used passwords in the world. This means that it’s […] read more

Canada NWT Laptop Not Encrypted Because It’s “Very Difficult To Encrypt”.

Approximately two weeks ago, Canada’s cbc.com reported on the theft of a government laptop with promises of more articles on the same in the weeks to come. Earlier this week, the last article was posted. The story is a doozy. To summarize, an employee with the Department of Health and Social Services (Northwest Territories, Canada) […] read more

Leading Self-Encrypting Drives Compromised, Patched.

Earlier this week, security researchers revealed that certain SEDs (self-encrypting drives) sold by some of the leading brands in the consumer data storage industry had flaws in its full disk encryption.   Bad Implementation One of the easiest ways to protect one’s data is to use full disk encryption (FDE). As the name implies, FDE […] read more

Fresno State Hard Drive Stolen, 15000 Affected.

At least 15,000 California State University, Fresno “student athletes, sports-camp attendees, and Athletic Corporation employees” were affected by a data breach earlier in the year, according to kmph.com and other news sites. A hard drive, 18 laptops, and other items were reported missing on January 12 from the university’s North Gym building. On the face […] read more

HIPAA Security Trickle-down? Notifications State Sensitive Information Not Contained In Stolen Devices.

According to databreaches.net, two medical entities recently alerted patients of a data breach: Eastern Maine Medical Center (EMMC) and Nevro Corporation. In the case of EMMC, an external hard drive went missing. For Nevro, a number of laptops were stolen during a break-in. Information contained in these devices was not protected with data encryption in […] read more

Penn Medicine Sending Breach Notifications To 1000 Patients Over Stolen Laptop.

Penn Medicine has revealed this past week that a laptop computer with protected health information (PHI) was stolen on November 30. While the details are meager (aside from a short entry at philly.com, which is referenced by databreaches.net, an online search comes up empty), the following was revealed: About 1000 people were affected. The laptop […] read more

Children’s Medical Center of Dallas Pays $3.2 Million To Settle HIPAA Violations.

The Children’s Medical Center of Dallas (Children’s) recently settled with the US Department of Health and Human Services (HHS) over multiple failures to encrypt sensitive data in mobile devices. The settlement – $3.2 million dollars – is quite the figure, as is the timeline involved: It looks like an investigation could have been started as […] read more