Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

BLUE CROSS BLUE SHIELD DATA BREACH: MORE THAN 800,000 DOCTOR RECORDS

October 12, 2009

Blue Cross Blue Shield is now reviewing its polices after confirming that a stolen employee laptop contained unencrypted personal information (including name, address, tax ID, and physician identifier number) on almost every doctor that accepts Blue Cross Blue Shield.

And that's a lot of doctors, between 800,000-850,000 of them according to a company spokesman. The spokesman said that the employee, in violation of company policy, moved the data from an encrypted company laptop to an unencrypted personal laptop.

Now, reviewing policies is always a good idea. But geez guys, is data this important only protected by a policy? Your security folks should know every time this data is accessed or copied. It should be logged and alerts transmitted to the appropriate personnel. Companies that think policies will protect their data need to understand human frailty. It's technology that will secure the data – not policies.

E-mail:   Phone: 703-359-0700

www.senseient.com

http://twitter.com/sharonnelsonesq