in

This Blog

Syndication

Tags

News

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Archives

AlertBoot Endpoint Security

AlertBoot offers a cloud-based full disk encryption and mobile device security service for companies of any size who want a scalable and easy-to-deploy solution. Centrally managed through a web based console, AlertBoot offers mobile device management, mobile antivirus, remote wipe & lock, device auditing, USB drive and hard disk encryption managed services.

Data Encryption Software: South Shore Hospital Update

A couple of months back, South Shore Hospital had announced the breach of patient information for 800,000 people.  At the time, I had wondered whether data encryption like AlertBoot had been used to protect the data.  Seeing how it involved close to a million people, the use of encryption software would have been advisable.

Data Breach: Little to No Risk

Today, South Shore has reported to the Massachusetts AG's Office that there is "little to no risk that information on the files has been or could be acquired, accessed or misused," per the Boston Herald.

If you'll recall, three boxes of tapes were sent away for destruction via a commercial courier.  When South Shore did not receive certificates of destruction, it pressed its contractors for an answer.  Eventually, word got back to the hospital that only one box arrived at the data destruction facility, which was destroyed.

Since then, an investigation into the two boxes has revealed that the contents of the two boxes probably ended up in a landfill, and that there was no reason for anyone to steal the boxes for the data within them since they were unmarked.  More specifically,

All available evidence indicates that the three boxes of computer tapes were likely separated from each other during transport. Once separated [Ed. - the three boxes were placed together on a shipping pallet], two of the three boxes were unidentifiable because they were unmarked and appeared to be of no value. As a result, those two boxes of computer tapes are believed to have been disposed of in a secure commercial landfill that [the carriers] uses to dispose of unclaimed materials and are therefore unrecoverable. [bostonherald.com]

Outside data forensic experts have concluded that it would nearly impossible for someone to access the information on the backup tapes.

In all, all signs point towards the risk of breach being minimal.  Not only will a potential data thief need some advanced skills to read the information on the tapes, he or she'd also need the not-so-advanced skills of digging and shoveling (and the clairvoyance to know where the tapes are currently buried).

What About the Next Time?

Unfortunately, this is not a case of "all's well that ends well."  After all, just because South Shore had its breach doesn't mean it couldn't have another one tomorrow.  It continually needs to make sure that its data security policies reflect the realities of the potential threats they are facing.  In fact, one might say it's more of case of "whew, we got lucky this time!"

South Shore will have to assess whether the use of backup tape encryption is warranted as well as other security measures, including physical ones (perhaps better tape so boxes on their pallets don't come apart?)


Related Articles and Sites:
http://news.bostonherald.com/jobfind/news/healthcare/view/20100908south_shore_hospital_statement/srvc=home&position=also
http://www.southshorehospital.org/news/notice/news_statement.htm

 
<Previous Next>

Disk Encryption Software: Not Used in CUNY Breach Affecting 7,000

Data Security Programs: E-Mail Addresses Are Not As Benign A Data As They Appear

Comments

No Comments

About sang_lee

Sang Lee is a Senior Account Manager and Security Analyst with AlertBoot, Inc., the leading provider of managed endpoint security services, based in Las Vegas, NV. Mr. Lee helps with the deployment and ongoing support of the AlertBoot disk encryption managed service. Prior to working at AlertBoot, Mr. Lee served in the South Korean Navy. He holds both a B.S. and an M.S. from Tufts University in Medford, Massachusetts, U.S.A.