Educause Security Discussion mailing list archives

Re: Bare Social Social Security Numbers


From: Joel Rosenblatt <joel () COLUMBIA EDU>
Date: Mon, 27 Mar 2006 12:19:57 -0500

In NY, the new privacy law ....

Law applies to electronic data only

"Private Information"

Any personally identifying data (name, number,...) in conjunction with

SSN
Driver's license (or non-driver ID card) number
Account/Credit/Debit card number  with access code

Encrypted with encryption key that also has been acquired or unencrypted data

This would be that just a list of SSN's would not count as a breach

Check with your GC office, but that is the way we read the law.

YMMV.

Thanks,
Joel Rosenblatt

Joel Rosenblatt, Senior Security Officer & Windows Specialist, CUIT
Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033
http://www.columbia.edu/~joel - You can't spell seCUrITy without CUIT


--On Monday, March 27, 2006 11:39 AM -0500 "Geoffrey S. Nathan" <geoffnathan () wayne edu> wrote:

Quick poll (apologies for cross-posting..)

Suppose a file was stolen/accessed containing only social security
numbers with no names attached.  Would this constitute a security breach
necessitating notification of those whose numbers were compromised?
(Leaving aside the question of whether the theft/access itself is a breach).

Geoff



Joel Rosenblatt, Senior Security Officer & Windows Specialist, CUIT
Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033
http://www.columbia.edu/~joel - You can't spell seCUrITy without CUIT

Current thread: