Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Deja vu all over again at Veterans Administration

Another breach for an agency that's prone to them
 

Sign up to receive Security Resource Alerts

November 16, 2007 (Computerworld) -- In what's become a fairly familiar routine for them of late, the U.S. Department of Veterans Affairs is investigating a potential data breach -- the theft of three computers containing personal data on potentially 12,000 individuals.

Two desktop PCs and one laptop containing that data were stolen from a VA medical facility in Indianapolis -- ironically enough, on Veterans Day. The records belong to patients who were treated at the hospital and include Social Security numbers and other personally identifiable information.

"It appears from this most recent breach that there are still some in the VA, even some responsible for the security of such data, who don't realize the importance of the security of the names and data of our veterans," U.S. Rep. Steve Buyer (R-Ind.) said in a prepared statement.

According to Buyer, the VA notified his office of the breach on Thursday and is working to ascertain the names and data of the people who might have been affected by the theft.

Buyer was the chairman of the House Committee on Veterans' Affairs until the Democrats took control of Congress last year. As chairman, he held 16 hearings on IT issues at the VA, eight of which were specifically on security. The hearings were designed to identity the issues that led to the loss of a laptop and hard disk containing personal data on more than 26.5 million veterans in May 2006.

That incident led to a sweeping overhaul of the VA's IT organization and more direct power being bestowed on the office of the CIO to make needed security changes.

"It is inexcusable that the VA repeatedly fails to comply with its own policy to safeguard veterans' personal information," Buyer said in his statement. He added that the agency needs to provide full credit monitoring to all those affected by the latest breach.

The theft at the Richard L. Roudebush VA Medical Center in Indianapolis is the latest in a string of similar incidents that have occurred at the VA before and after the massive data breach brought the agency's security shortcomings to light.

Last January, an IT specialist at a VA medical center in Birmingham, Alabama, reported as missing (download PDF) a hard disk containing personal data on more than 250,000 veterans and an additional 1.3 million medical providers.

In August of last year, at the height of the uproar over the May breach, the VA disclosed that Unisys Corp., a subcontractor hired to assist in insurance collections for VA medical centers in Pittsburgh, had reported a missing computer containing personal data on over 16,000 veterans.

During a Buyer hearing into the May 2006 breach, VA officials disclosed several other prior security incidents that had happened at the department, including the loss of a back-up tape containing legal and case related information on 16,500 veterans from Indianapolis. Also disclosed during the hearing was another breach, this one involving the loss of SSNs and other personal data on 66 veterans; their data was compromised when a VA auditor put the papers with the data in the trunk of a rental car that was later stolen.

(Editor's note: This story originally misidentified the location of the VA medical center where the latest computer theft took place. The story was updated at about 1:30 EST on Nov. 20 to include the facility's correct location in Indianapolis.)




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"Angelina Jolie pregnancy was not a hoax; John McCain is not going to Vietnam as part of his presidential campaign;..." Read more...
"A school district in Philadelphia has approved the position of Chief Technology Officer because they were hacked by a student...." Read more...
Read more Security posts or See all Blogs
Microsoft to buy up to $100M in Novell SUSE Linux support vouchers
Apple: iPhone update improves 3G; users disagree
Opera patches 7 bugs, but keeps one secret
Gag order against MIT students dissolved by judge
Wi-Fi tweaks for speed freaks
Apple offers MobileMe users a second extension
Move over quad-cores, Intel's ready to ship 6-core chips
Opinion: So you want to be a network manager, Part 2
Intel shows off PC, server solid-state drive road maps
Intel chairman kicks off IDF with call for social-minded innovation
More top stories...
Wi-Fi in-flight comes to some American routes
Yahoo Buzz poses serious threat to Digg, some users say
IBM pumps $300M into business continuity centers
EBay moves further from auction roots with pricing, payment changes
Minding online store a case of 'Not my job' for eBay, legal foes
IPv6 adoption moving at glacial pace
Salesforce buys InStranet for call center tech
Mac, Windows clipboards poisoned by URL attacks
Apple blames scorching iPods on battery problem
Update: Microsoft to alpha-test Office 14 before end of year
The x86's lineage can be traced back to 1968, to a design on a napkin drawn by Austin O. "Gus" Roche, an all-but-forgotten engineer in Texas who was obsessed with creating a personal computer.
Are you using the latest version of Mac OS X efficiently? Try our tips and watch your productivity soar.
Just because Microsoft's done with XP doesn't mean you have to be. Keep XP in the game with these downloads, tweaks and hacks.
Apple's new iPhone software is more significant for IT than the new iPhone itself, says Michael Gartenberg.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
Identity & Security Management Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this free webcast, for a limited time, compilments of Webroot Software!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Eliminate SPAM, Gain Productivity
Get this white paper now!
(Source: MessageLabs) Learn all about the dangers and the costs of spam in all its forms - from stock-touting to spreadsheet. Also, understand the drawbacks of traditional hardware- and software-based defenses - and the unique benefits of MessageLabs multi-layered, managed Anti-Spam solution; as illustrated by a real-world case study where MessageLabs stopped spam cold.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Leading Analyst Firm: Penetration Testing is a Requirement
Gartner Paper: US Data Centers - The Calm Before the Storm
How Much Will an Office 2007 and Vista Migration Hurt?
View more whitepapers