INFOSEC Year in Review 1997 M. E. Kabay, PhD, CISSP Assoc. Prof. Information Assurance Dept. of Computer Information Systems, Division of Business Norwich University
[email protected] Copyright © 2003 M. E. Kabay. All rights reserved. Page 1 INFOSEC Year in Review 1997 11 Breaches of confidentiality Category 11 Breaches of confidentiality 1997-02-23 medical data confidentiality PA News In Sheffield, England, a hospital handed over 50,000 confidential gynecological records to a data processing firm that hired people off the street and set them to work transcribing the unprotected data. The scandal resulted in withdrawal of the contract, but thousands of records were exposed to a wide variety of people with no background checking to ascertain their reliability. Category 11 Breaches of confidentiality 1997-04-08 QA operations security confidentiality AP, Reuters The General Accounting Office lambasted the IRS for improper operations security, saying that the IRS "misplaced" 6,000 computer tapes and cartridges. Sen. John Glenn (D-OH), who released the report, also introduced a bill to define criminal penalties against IRS employees who snoop into taxpayer records without cause. Glenn said that out of 1,515 cases of unauthorized browsing identified in the 1994 and 1995 fiscal years at the IRS, only 23 employees were fired for the activity. Category 11 Breaches of confidentiality 1997-04-30 medical confidentiality AIDS database UPI Greg Wentz was found guilty of anonymously mailing a list of 4,000 names of people with AIDS to two Florida newspapers. It turned out that he was acting vindictively to punish his ex-lover, William Calvert III.