BreachExchange mailing list archives

Re: [Follow-up] Vassar Brothers Medical Center


From: Chris Walsh <cwalsh () cwalsh org>
Date: Thu, 8 Feb 2007 13:32:18 -0600

Additionally -

Materials filed by VBMC with the NY State Consumer Protection Board and obtained via
a freedom of information request are available at 

http://www.cwalsh.org/BreachInfo/primary_sources/pdfs/VassarBros-20060625.PDF



On Thu, Feb 08, 2007 at 02:13:16PM -0500, Dissent wrote:
In August 2006, DL reported that Vassar Brothers Medical Center had 
reported a stolen laptop containing PII on almost 260k patients.
Original story:  http://attrition.org/dataloss/2006/08/vbmc01.html

Vassar Brothers issued two letters to patients following that breach:
http://www.poughkeepsiejournal.com/assets/pdf/BK3538482.PDF
http://www.poughkeepsiejournal.com/assets/pdf/BK6060427.PDF

Subsequently, Vassar Brothers retained Kroll to investigate the theft 
and missing data.  They then issued a press release saying that based 
on Kroll's investigation of network server logs, the stolen laptop 
did not contain any identifying patient information.

The Poughkeepsie Journal has been all over this breach and just 
published two more articles today, which dispute some of VBMC's 
reported statements:

Official: Data installed as part of drills
http://www.poughkeepsiejournal.com/apps/pbcs.dll/article?AID=/20070208/BUSINESS/70207069/1003

and:

Documents show patient data on stolen laptop
http://www.poughkeepsiejournal.com/apps/pbcs.dll/article?AID=/20070208/BUSINESS/70207079




--
Main site: http://www.pogowasright.org
Main RSS feed: http://www.pogowasright.org/backend/pogowasright.rss
Breaches RSS feed: http://www.pogowasright.org/backend/breaches.rss 

_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss
Tracking more than 146 million compromised records in 566 incidents over 7 years.

_______________________________________________
Dataloss Mailing List (dataloss () attrition org)
http://attrition.org/dataloss
Tracking more than 146 million compromised records in 566 incidents over 7 years.



Current thread: