in

This Blog

Syndication

Tags

News

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Archives

AlertBoot Endpoint Security

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Laptop Encryption Software Not Used In Missing Chicago Ambulance Laptop?

Update (3/25/09): It's official: the stolen laptop was encrypted. I just found out a letter from The Dezonia Group that was filed with the Attorney General of New Hampshire.  What can I say?  Kudos to The Dezonia Group for having data protection in place, and for taking that extra step.
Update (3/19/09): I guess I lose my bet below.  According to WBBM's site (link at the bottom), spokesman Ed Walsh from the Chicago Revenue Department has confirmed that the laptop computer was encrypted, and had information on 60,000 people.  However, this does not mesh with current Illinois legal exemptions, as I pointed out below as well.  Why would a company subject itself to such public humiliation and ill will when they've got the correct protection in place?

Databreaches.net has a link to a report on how anyone who's used the Chicago Fire Department ambulances may be at an increased chance of identity theft and related ills.  And if what I'm reading about Illinois is correct, it looks like laptop encryption software like AlertBoot was not used to protect sensitive data.

The Story

According to CBS 2 in Chicago, the city bills at least $600 per ambulance ride.  The collection, though, is outsourced to The Dezonia Group, which has mailed letters stating that an employee's laptop computer was stolen six weeks ago.

The information on the laptop included patient names, addresses, and Social Security numbers.  The laptop was never recovered, and the company is offering one year of free credit-reporting.

I'd Bet The Laptop Was Not Encrypted

Illinois is a state where data breach notifications are mandatory.  However, they do provide exemptions, one of them being the use of encryption.

Seeing how no company wants to go around stating they've had a data breach (it's a sure invitation for lawsuits...which the company will probably end up winning, but is still a huge distraction and costly), I take The Dezonia Group's letter as an indirect disclosure that the missing laptop didn't use encryption software.

In this day and age, if you're constantly dealing with SSNs, data encryption should be considered very carefully, with a bias towards encrypting.

In fact, if you're dealing with sensitive information, your main question should be "why shouldn't I use encryption?" rather than "why should I use encryption?"  If you can't find an adequate answer to the first question and still don't encrypt your data...well, chances are that nothing will happen.

But if something does happen--after all, there is no effective way to completely stop theft...or forgetfulness, for that matter--you'd be wishing that you had acted otherwise.

Related Articles:
http://cbs2chicago.com/topstories/Laptop.Dezonia.ID.2.958082.html
http://www.databreaches.net/?p=2220
http://datalossdb.org/organizations/1758-dezonia-group-inc

Updated: http://www.wbbm780.com/Been-In-An-Ambulance-Lately--Your-Identity-May-Be-/4051123

 
<Previous Next>

What Is Data At Rest Encryption? (Updated)

Data Security: University of Florida A Natural Target For ID Theft?

Comments

No Comments

About sang_lee

Sang Lee is a Senior Account Manager and Security Analyst with AlertBoot, Inc., the leading provider of managed endpoint security services, based in Las Vegas, NV. Mr. Lee helps with the deployment and ongoing support of the AlertBoot disk encryption managed service. Prior to working at AlertBoot, Mr. Lee served in the South Korean Navy. He holds both a B.S. and an M.S. from Tufts University in Medford, Massachusetts, U.S.A.