Friday, September 7, 2007

OOPS, They Did It Again! Third Breach for Pfizer, Inc.

Perhaps the pharmaceutical giant’s single-minded goal - your health - would explain why they’ve had three security breaches in the past three months and unfortunately this is becoming all too common for companies.

This isn’t to say that Pfizer isn’t cooperating with authorities, but like so many other companies, they’re just too busy with the work at hand; they don’t prioritize their time to ensuring there are processes in place to protecting and securing what they’ve worked so hard to build. First and foremost, training of employees, particularly sales reps, who are constantly on the road and most susceptible to the loss of data, need to know how to handle the data they obtain and have access to.

Connecticut’s Attorney General, Richard Blumenthal, made this statement in a phone interview with one of the state’s newspapers, The Day:

"This is part of a pattern that is unacceptable and which the company should find intolerable," Blumenthal said in a phone interview Tuesday. "We are alerting criminal authorities, specifically the U.S. Attorney's Office, as to the possibilities of criminal wrongdoing."

This latest breach has exposed 34,000 to possible identity theft and the previous breach exposed 17,000 current and former employees, as well as, healthcare workers and other individuals when confidential information was “wrongfully removed…from a Pfizer computer system”.

It wasn’t until this latest breach, which appears to be an apparent and intentional abuse by a now former employee, that a Pfizer spokesperson said that the company has now turned its focus to protecting the security of employees' personal information and that various policies and procedures are currently under review. Although it’s unknown, at this time, whether this potential for criminal activity has affected anyone who’s personal information was stolen, the company has voluntarily provided an identity theft solution for those involved in hopes of avoiding federal charges.


Sunday, August 26, 2007

Indentity Theft Through County Public Records

Though I would agree that sometimes access to county public records helps to locate vital information, such as the name and address of a landlord, for which a property manager may refuse to provide, but is this access an open market to identity thieves?

I recently did some research to see what kind of personal data I could get from a search on the Bexar County Clerk's website, as a result of a news story that aired in Illinois about a man who is convinced that his identity was stolen based on personal data that was posted to his county clerk's website. As it turned out, I was able to get names, addresses, date of births, digital signatures, marriage certificates, employer IDs, and Social Security numbers just by putting in a date range and specific documents to review. Examples of documents that are scanned and posted are Land Records, Assumed Names, UCC Records, Marriage Licenses, and Foreclosure Notices. What I found most appalling was the release of social security numbers for those individuals who owed back child support. In addition, it seems ironic that there are state and federal laws that are supposed to protect us from having such personal data accessible by the public and yet most cities have government websites where this information is publicly attainable. However, you do have the right to require them to remove social security numbers and driver’s license numbers from any document where the original document includes this information. Unfortunately, in this day and age, that might not be enough.