Showing posts with label security breach. Show all posts
Showing posts with label security breach. Show all posts

Thursday, September 25, 2008

Security Breach: Nearly 50,000 Patient Records Compromised

According to news sources, patient information from nearly 50,000 patients of New York-Presbyterian Hospital/Weill Cornell Medical Center was jeopardized in a data security breach announced on April 11, 2008. The breach included names, phone numbers, addresses and social security numbers. The Wall Street Journal reported on its health care blog that postal officials searching an identity theft ring in Atlanta have identified 221 documents which came from the hospital.

According to a spokesperson hospital officials are in the process of contacting thousands of patients and New York Presbyterian is offering affected patients credit monitoring services. IdentityTruth is reaching out to hospital patients to provide them the option of comprehensive identity theft prevention coverage at a discounted rate, since credit monitoring alone does not prevent identity theft. IdentityTruth’s technology helps to predict possible fraud and delivers ongoing alerts about any changes to the individual’s credit and identity profile. IdentityTruth’s comprehensive service is especially important to protect consumers in cases such as this, where social security numbers were compromised.

Data Breaches a Growing Problem for Consumers

The New York Presbyterian Hospital breach is part of a growing wave of data breaches which are putting consumers at risk for identity theft. In the case of the Presbyterian Hospital case news reports are highlighting a possible link to an organized identity theft ring. Incidents such as these highlight a disturbing truth for consumers: even if you are careful, you are not safe since businesses, health care organizations and government agencies which hold your sensitive data are increasingly at risk of data breaches.

IdentityTruth invites consumers to learn more by viewing the identity theft timeline—which shows that identity theft starts long before something shows up on your credit report.

Data Breach: Pfizer - 13,000 Employee Records Compromised

According to news sources preliminary reports indicate that in May 2008 pharmaceutical giant Pfizer suffered a data security breach involving a stolen laptop that contained 13,000 employee records. While it appears that social security numbers were not involved, names, home addresses, telephone numbers, employee ID numbers, job titles and salary information may have been compromised in this security breach.

Pfizer has reported a number of breaches over the past year, including a breach earlier this year also affecting employees. According to news sources Pfizer has sent more than 65,000 data breach notifications over the past twelve months.

If you are a Pfizer employee and suspect that your information was stolen during this or another security breach, you need to take action now to prevent identity theft. Whether the breach occurred last week or last year, your personal information is in criminal hands and could be used at any time for identity theft. Typical credit monitoring only reports theft after damage has been done. Only through proactive, preventative identity monitoring can you be sure that your identity, assets, and credit are safe.

At the IdentityTruth website, you can learn about the latest advancements in identity theft prevention and use online tools to instantly check to see if your identity has been compromised.

Don't wait – take action today and stop identity theft before damage occurs!

Data Security Breach: State Street Bank - 45,000 Records Compromised

According to news sources, a division of State Street Corporation suffered a security data breach involving 45,000 customer and employee records. The loss occurred when a laptop storing the information was stolen from a vendor hired by Investors Financial Services, which was acquired by State Street in 2007.

The data contained on the stolen laptop included names, addresses, dates of birth and, in some cases, Social Security numbers. State Street claims that there is no evidence that the stolen data has been misused and noted that this is the first case of data theft in its history.

However, this security breach does highlight vulnerabilities associated with the loss of physical equipment — which is still a risk, no matter how stringent a firm’s online security protocols.

Data Breaches a Growing Problem for Consumers

Financial services breaches are of particular concern to consumers given the sensitive nature of the information stored by these institutions. Connecticut Attorney General Richard Blumenthal recently noted that the Social Security and account numbers of as many as 4.5 million customers were compromised when a vendor working for Bank of New York Mellon lost unencrypted backup storage tapes.

The loss of physical assets, as highlighted in these cases, is a reminder that consumers may be at risk for identity theft—even if they are careful with management of their own statements and documents.

Learn more about how identity theft actually happens: view the identity theft timeline. In this brief overview, you’ll learn that identity scams usually start long before something shows up on your credit card statements.

Security Data Breach: Stanford University - 72,000 Identities at Risk

In June, 2008 Stanford University reported a data security breach involving a stolen laptop containing the personal information of university employees.

The theft is believed to affect only those employees hired on, or before, September 28, 2007 but the total number of individuals affected could be as high as 72,000, given the size of the university.

Details of the crime are still under investigation, but officials suspect this was a case of property theft — that the data contained on the laptop was not the primary target. Nonetheless, the university has issued a statement to all current and past employees acknowledging the potential impact of the crime, and implications relating to identity theft.

The stolen laptop contained a wealth of information including employee's names, dates of birth, Social Security numbers, addresses, phone numbers, and more. The scope of information compromised arms identity thieves to perpetrate credit card fraud and other identity-related crimes.

Security data breaches at educational facilities continue to pose a large threat to consumers even as security measures are beginning to increase. Other well-known institutions suffering security breaches this year include Harvard University, New York University, the University of California at San Francisco, and Oklahoma State University.

If you suspect that you are a victim of this security breach, you need to take action now to protect yourself from identity theft. Whether this breach occurred yesterday or last year, your personal information is in criminal hands and could be used at any time to steal your identity. Traditional credit monitoring only reports on theft after damage has been done. Only through proactive, preventative identity monitoring can you be sure that your identity, assets, and credit are safe.

At the IdentityTruth website, you can learn about the latest advancements in identity theft prevention and use online tools to instantly check to see if your identity has been compromised.

Don't wait - take action today and stop identity theft before damage occurs!

Monday, June 30, 2008

Security Breach - Oklahoma State University

IdentityTruth Reaches Out To The 70,000 Oklahoma State University Students, Staff And Faculty Impacted By Server Breach

Waltham, MA - May 19, 2008 - A breach in an Oklahoma State University computer server exposed the names, addresses and Social Security numbers (SSNs) of approximately 70,000 students, staff and faculty who purchased parking and transit service permits in the past six years. According to news sources, the discovery of the breach originally occurred in March; the University began notifying permit holders as of May 14. On discovery of the breach, OSU contacted federal law enforcement about the incident and immediately took down all access to the server.

After a stolen laptop exposed the records and personal data of 37,000 students, faculty and staff, OSU transitioned most of its services to random 8-digit identifying numbers for students instead of using SSNs. However, the server used for the parking and transit services had not been transitioned. The OSU website offers resources for helping to manage potential risks stemming from this data breach. It specifically urges individuals to look closely at their credit information.

Because credit monitoring alone does not help to prevent identity theft, IdentityTruth is also reaching out to affected individuals to offer special pricing on its comprehensive identity theft prevention technology. IdentityTruth detects real-time suspicious activities, fraud schemes, credit requests and related data breaches. IdentityTruth uses this information to build an individual identity profile offering a complete picture of a consumer’s identity risk - from credit information to SSN tracking.

“The process of protecting all forms of personal data is extremely complex, and is by no means infallible,” said Steven Domenikos, CEO of IdentityTruth. “While most institutions and organizations are aware of the risk that data exposure causes, exposure can and will happen because of human error, technology failings or malicious hackers targeting data. The only way to really control the process is to clearly understand where your data resides and the active level of risk at any given time. This can only be achieved with proactive, comprehensive management services like those provided by IdentityTruth.”

IdentityTruth is offering a one-month special subscription rate of $1 for more than 70,000 people reportedly impacted by the breach. IdentityTruth is a unique service that provides more complete protection than other, credit-based services. IdentityTruth offers all of the standard identity protections, such as fraud alerts, but goes far beyond standard identity theft prevention services to provide the most comprehensive protection available in the market--all for the same price as other companies charge for fraud alerts alone. IdentityTruth services are also backed by a $2 million service guarantee.

IdentityTruth's comprehensive identity theft prevention service:


  • Reports suspicious events in the past, such as unrecognized addresses or phone numbers;
  • Ensures that free fraud alerts are properly activated on the consumer’s credit profile with the three credit bureaus;
  • Helps to predict possible fraud actions that could impact the individual in the future;
  • Delivers ongoing alerts about any changes to the individual’s credit and identity profile; and
  • Reports on any related regionalized data breach that could have impacted the individual’s identity.
IdentityTruth provides subscribers the most complete identity theft prevention service available today for the same price as other companies charge for fraud alerts alone.

Individuals who believe their information may have been compromised as part of the OSU data breach are invited to contact IdentityTruth at 800-684-1336. IdentityTruth service will be offered to any impacted individuals for $1 for the first month’s service. For more information about IdentityTruth’s offering go to http://www.identitytruth.com/databreaches.


About IdentityTruth Inc.
IdentityTruth, is the leading provider of a new breed of service to help consumers safeguard their privacy and identity. Through innovative technology, individuals receive the earliest possible notificationTM in advance of potential misuses of their identities so they can take better control. Early detection is the best protection. IdentityTruth is a privately held, VC- funded company headquartered in Waltham, Massachusetts. Investors include Argonaut Ventures and Stata Venture Partners. For more information, go to www.identitytruth.com or call 781-684-1300.

# # #

Oklahoma State University is not affiliated in any way with IdentityTruth and this press release should not be viewed as an endorsement by Oklahoma State University of IdentityTruth or its Service.