You are here: silicon.com > Software > Security Strategy

Security Strategy

185,000 people's medical data stolen

Among the largest data thefts in the US...

Tags: data theft, san jose medical group, california

By Dawn Kawamoto

Published: 11 April 2005 08:00 BST

A California medical group is telling nearly 185,000 current and former patients that their financial and medical records may have been exposed following the theft of computers containing personal data.

Given the number of people affected, the theft from the San Jose Medical Group ranks among the largest in the nation. It follows a rash of other breaches that have raised concerns about the security of sensitive information.

The theft occurred after the San Jose Medical Group had copied patient and financial information from its secured servers to two local PCs, said Mike Patel, vice president of information technology for the San Jose Medical Group.

The data, some of which was encrypted, was part of a patient billing project and also part of the medical group's 2004 year-end audit, Patel noted.

On 28 March, during the early morning hours, the building was broken into and the medical group's two new Dell computers were stolen.

"We believe they were stolen because of the kind of computers they were and not because of the information," Patel said, noting that there have been no reports of patients' personal or financial information having been compromised.

Ironically, the medical group earlier this year began the process of encrypting its patient and financial information. It had not completed the process when the two PCs were stolen.

"We started to encrypt things this year because of [medical regulations], ID theft reports and security regulations," Patel said.

As a security measure, the medical group has historically stored its information only on the secured servers, where employees have only limited access to the computers and the information can only be accessed via the network.

Under the Security Breach Information Act of California, companies and organizations are required to notify people when their personal information may have been stolen.

The San Jose Medical Group began notifying patients on Tuesday, nine days after the break-in, Patel said. He noted that it took some time to gather the necessary information for notices and then distribute them to the thousands of patients who were affected.

Since the burglary, the medical group has taken steps to shore up the physical security of the building with surveillance cameras and other measures, Patel said.

The incident is certainly not the first of its kind. Last month, the University of California, Berkeley, warned 98,000 people that their personal information may have been exposed following the theft of a laptop from its admissions office.

That theft, however, paled in comparison to an incident at the university in August, when an attacker gained access to 1.4 million database records containing personal information in a social researcher's computer.

Other recent scares over data security include one at the Bank of America, which misplaced backup tapes containing the records of 1.2 million people, the bank said in February. Additionally, hackers broke into the databases of Seisint, a subsidiary of LexisNexis, gaining access to the records of 32,000 people, the company said last month.

Also in March, data warehousing company ChoicePoint confirmed that it had sold data to scammers, resulting in at least 750 cases of identity theft.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Technical Support Consultant, Product Support Engineer, Product Development

Adobe at a Glance Headquarters: San Jose, CA Founded: 1982 IPO Date: 1986 Employees: Approximately 7,000 Offices: 60+ offices worldwide Fiscal 2008 ...

Senior Network Administrator

Our focus is on innovative solutions that reduce cycle times for our customers and accelerate the delivery of life-enhancing drugs to market for the ...

Housekeeping Services Manager

Show a positive and caring attitude to patients, visitors and fellow employees at all times. To maintain appropriate staff records i.e.training ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: