Breach Report 2012.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Identity Theft Resource Center Report Date: 1/4/2013 2012 Breach List: Breaches: 470 Exposed: 17,491,690 Page 1 of 95 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-22 Humana KY 7/12/2012 Paper Data Medical/Healthcare Yes - Unknown # 0 A Humana office in the Tampa, Florida area moved to a new location on July 12, 2012. On November 28, due to a business need to pull information from the 2011 files that were boxed for storage during the move, it was discovered that one box of paper files containing member appeals regarding discharge from a skilled nursing facility and/or hospital was lost during the move. The files contained member name, demographic information, date of birth, Medicare identification number, and possibly clinical information. Humana has no information to date indicating that the information has been inappropriately used. Attribution 1 Publication: NH AG's office Author: Date Published: Article Title: Humana Article URL: http://doj.nh.gov/consumer/security-breaches/documents/humana-20121217.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-21 Irvine Scientific CA Electronic Business Yes - Unknown # 0 This letter is being sent in accordance with New Hampshire law to inform your office that our company recently suffered the theft of credit card information which potentially exposed the name and credit card number of one (1) New Hampshire resident. We have enclosed a copy of the notice letter that we will be sending to potentially affected individuals on a nationwide basis on or before December 18, 2012. Attribution 1 Publication: NH AG's office Author: Date Published: Article Title: Irvine Scientific Article URL: http://doj.nh.gov/consumer/security-breaches/documents/irvine-scientific-20121218.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-20 Montana State University MT Electronic Educational Yes - Unknown # 0 On September 16, 2012, our client, Montana State University ("MSU"), discovered that certain documents on a network storage device were inadvertently left unencrypted and available on MSU's network between August 1, 2012 and September 15, 2012. During this time period, the device had been decrypted and reset to factory settings in order to troubleshoot performance issues. After conducting a thorough investigation, MSU does not believe anyone viewed the documents as the information could only be accessed from MSU's network by a user with specialized knowledge. The device contained certain student loan documents from students who attended MSU in 2006. The information involved included names, dates of birth, and Social Security numbers. No financial or bank account information was involved. Attribution 1 Publication: NH AG's office Author: Date Published: Article Title: Montana State University Article URL: http://doj.nh.gov/consumer/security-breaches/documents/montana-state-university-20121221.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-19 LexisNexis FL Electronic Business Yes - Unknown # 0 We are writing in accordance with your state's information security breach notification statute to inform you that we are notifying consumers of an incident in which a technical error led to sensitive personally identifiable information, including Social Security numbers and drivers ' license numbers, about them being displayed in full in reports sent to other consumers. Typically, the Social Security numbers and drivers' license numbers would have been redacted. The issue began on October 30, 2012, was discovered on November 5, 2012 and was corrected by November 6, 2012. Attribution 1 Publication: NH AG's office Author: Date Published: Article Title: LexisNexis Article URL: http://doj.nh.gov/consumer/security-breaches/documents/lexisnexis-20121206.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-18 Valpak FL Electronic Business Yes - Unknown # 0 On November 14, 2012, our client, Valpak, learned from an investigator at the United States Postal Inspection Services (USPS) that a temporary independent contractor used by Valpak was indicted and charged with mail fraud. When the individual was arrested in November 2012, law enforcement found a file in his possession that contained the names, Social Security numbers, and employment start and end dates for employees of Valpak franchises. Because the contractor only performed work for Valpak from June through September 2011 , only individuals hired before September 2011 were in the file. Valpak was informed by the USPS that the contractor opened a post office box in a limited number of individuals' names. Copyright 2012 Identity Theft Resource Center Identity Theft Resource Center Report Date: 1/4/2013 2012 Breach List: Breaches: 470 Exposed: 17,491,690 Page 2 of 95 How is this report produced? What are the rules? See last page of report for details. Attribution 1 Publication: NH AG's office Author: Date Published: Article Title: Valpak Article URL: http://doj.nh.gov/consumer/security-breaches/documents/valpak-20121214.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-17 Sunview Vineyards CA Electronic Business Yes - Unknown # 0 We are writing to inform you that on or about the 15th of December 2012, we believe that a company laptop computer was stolen from one of our facilities as part of a burglary. We have reason to believe that personal information concerning you was or may have been on the laptop computer and that information may be in the possession of the thief. While the laptop computer was password protected, the files were not encrypted, so it is unclear if the thief has or can access any of your personal information. Regardless, we wanted to make sure that you were aware of this issue. Attribution 1 Publication: CA AG's office Author: Date Published: Article Title: Sunview Vineyards Article URL: https://oag.ca.gov/system/files/SampleLetterforSecurityBreachNotification%2801126564%29%20%283%29_0.pdf? ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-16 Yale University CT Electronic Educational Yes - Published # 450 The hacker group NullCrew claimed it had obtained 1,200 accounts on Yale databases, but the University said only 450 accounts were affected by the breach. Photo by NullCrew. A hacker group known as NullCrew claims it obtained the personal information of 1,200 Yale students and staff members from University databases. Attribution 1 Publication: yaledailynews.com Author: Date Published: Article Title: Hacker group breaches Yale databases Article URL: http://yaledailynews.com/crosscampus/2012/07/30/hacker-group-breaches-yale-databases/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-15 Westside Park Elementary CA Paper Data Medical/Healthcare Yes - Published # 1,370 School Based Health Center Medical records at the Westside Park Elementary School Based Health Center may have been accessed when the county clinic was burglarized, San Bernardino County officials said Tuesday. Attribution 1 Publication: phiprivacy.net Author: Date Published: Article Title: Patient records accessed after county clinic burglary Article URL: http://www.phiprivacy.net/?s=westside ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-14 San Jose State University CA Electronic Educational Yes - Published # 10,000 Associated Students On June 26, SJSU learned a hacker breached an Associated Students of SJSU server. Please note the breach affected Associated Students only. SJSU employee data and MySJSU are completely separate and were not affected. Therefore, the breach will not impact fall 2012 registration and did not result in the release of thousands of student Social Security numbers or student ID passwords as suggested by the media. Attribution 1 Publication: SJSU Today website Author: Date Published: Article Title: Update: Associated Students Server Security Breach Article URL: http://blogs.sjsu.edu/today/2012/update-associated-students-server-security-breach/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20121231-13 Rhinebeck Health Center - NY Electronic Medical/Healthcare Yes - Published # 6,745 Center for Progressive Rhinebeck Health Center and the Center for Progressive Medicine (“the Centers”) are attempting to notify patients of a potential breach to their personal and protected health information. Unauthorized access to patient information may have occurred between approximately November 15, 2011 and December 14, 2011. Rhinebeck was notified of the hacking/IT incident by their computer vendor on February 15, 2012. Copyright 2012 Identity Theft Resource Center Identity Theft Resource Center Report Date: 1/4/2013 2012 Breach List: Breaches: 470 Exposed: 17,491,690 Page 3 of 95 How is this report produced? What are the rules? See last page of report for details. Attribution 1 Publication: RHC/CPM Company Press Release Author: Date Published: Article Title: Rhinebeck