Most VA Privacy Breaches Trace To Paper, Not PCs

  /     /     /  
Publicated : 22/11/2024   Category : security


Most VA Privacy Breaches Trace To Paper, Not PCs


Majority of data breaches at the Veterans Administration result from mislaid paper documents, official says, not stolen PCs.



5 Helpful Online Services From Uncle Sam (click image for larger view)
Most data breaches at the Veterans Affairs Department involve mishandled paper documents, not information technology assets, proving that the agency is doing a good job of protecting its computer systems, a VA IT leader told
InformationWeek Government
recently.
Between 96 and 98 percent of our [data breach] incidents -- it varies from month to month -- deal with physical paper where … people are not thinking about the fact that that piece of paper theyre carrying around making benefits determinations has sensitive information and they need to protect it, said Stephen Warren, VA acting assistant secretary for information and technology. Its an area that we spend a lot of time and training on. We are constantly updating our campaign to inform the staff that they have to take this seriously. We are constantly reinforcing the message that it matters.
The central point that Warren makes to VA employees who handle sensitive information is that patients cant get critical services if their identity has been stolen. It has huge impact on an individual, he said.
[ The Veterans Administration leads in telemedicine. Read
Why The Private Sector Lags VA In Telehealth
. ]
Most of these data breach incidents are cited as mishandled or misused physical or verbal information in the departments monthly reports to Congress of
data incidents
, which are assembled by the VA Office of Information Securitys Incident Resolution Team.
In one case involving the VAs Milwaukee, Wis., facility last April, a paper notification letter was inadvertently sent to the wrong beneficiary. The letter contained the beneficiarys name, address, home phone number, Social Security number and bank account information. The beneficiary who erroneously received the document called VA to report the incident and returned it to the facility.
The VA employees involved in the Milwaukee incident were counseled on the importance of handling personally identifiable information, according to the April report.
In another April case, documents containing the full names and the last four digits of the Social Security numbers of 270 veterans were found on two separate occasions in mens restrooms in a Nashville, Tenn., VA office. The veterans were notified of the incident and investigators concluded that the documents were inadvertently left in the restrooms by unidentified employees who had attended morning meetings in the building.
According to the
April report
, there were 227 incidents of data breaches across the VA between April 1 and April 28 in which information was manually mishandled in one way or another. In comparison, only eight cases of stolen or missing PCs or laptops were reported and investigated in the same month.
Missing laptop or PC cases often involve inventory mixups, Warren said. For example, in an April incident at a Coatsville, Pa., VA facility, four desktops PCs were reported missing from the inventory; three of them were later found. No personally identifiable information or protected health information was stored on any of the PCs, the response team found.
If you consider the fact the VA has about 440,000 people that we service and that the department over 900,000 devices on the network, [a data breach count relating to IT assets] of somewhere between one and 10 in a month is pretty good, Warren said. And many of those are things disappearing in inventory. Many are found subsequently because they got moved somewhere.

Last News

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Most VA Privacy Breaches Trace To Paper, Not PCs