Home > U Miami: Stolen Back-up Data 'Unlikely' To Be Misused

News

U Miami: Stolen Back-up Data 'Unlikely' To Be Misused

4/17/2008

The University of Miami reported Thursday that computer back-up tapes containing personal information from some 2.1 million patients were stolen from a third-party storage facility in March. The university said it's confident that the information on those tapes is inaccessible to the thieves but is notifying patients anyway.

The data on the tapes had been encrypted, and the university contracted with an outside firm to test the strength of that encryption, finding that "misuse of the information on the tapes is unlikely," according to U Miami. Nevertheless, the university is in the process of notifying all 47,000 people whose financial information could have been exposed by the theft. U Miami said anyone who has been a patient of a U Miami physician or has visited a U Miami facility since 1999 could have their data on those tapes. The 47,000 figure includes only those whose financial information may have been in the back-up data. The total number of individuals whose information was on those tapes was 2.1 million, a U Miami representative told Campus Technology.

"Shortly after learning of the incident," U Miami reported, "the university determined it would be unlikely that a thief would be able to access the backup tapes because of the complex and proprietary format in which they were written. Even so, the university engaged leading computer security experts at Terremark Worldwide to independently ascertain the feasibility of accessing and extracting data from a similar set of backup tapes."

According to Terremark, the security firm spent a week trying to break the encryption on the tapes and could not come up with any usable data. According to Christopher Day, senior vice president of the Secure Information Services group at Terremark, breaking the encryption would "require certain key data which is not stored on the tapes...."

Included on the tapes were patient records that contained names, addresses, Social Security numbers, health information, and/or credit card and other financial information.

"Even though I am confident that our patients' data is safe, we felt that in the best interest of the physician-patient relationship we should be transparent in this matter," said Pascal J. Goldschmidt, senior vice president for medical affairs and dean of the University of Miami Miller School of Medicine, in a statement released today.

Further information about the incident can be found here.



About the author: Dave Nagel is the executive editor for 1105 Media's educational technology online publications and electronic newsletters. He can be reached at dnagel@1105media.com.

Have any additional questions? Want to share your story? Want to pass along a news tip? Contact Dave Nagel, executive editor, at dnagel@1105media.com.

Cite this Site

David Nagel, "U Miami: Stolen Back-up Data 'Unlikely' To Be Misused," Campus Technology, 4/17/2008, http://www.campustechnology.com/article.aspx?aid=61064

copy text (above) for proper citation



Recommended Reading
  • Cedarville U Sets Up SonicWall Firewalls

    Cedarville University in southwestern Ohio has implemented SonicWALL firewalls to provide high-speed gateway firewall protection for its 3,000 students.

  • Data Breach Strikes U North Dakota Alumni Association

    The alumni association for the University of North Dakota has gone public with a data breach that occurred when a laptop belonging to a software vendor was stolen from a vehicle. The computer contained the names of 84,000 university alumni, donors, and others, according to coverage by the Grand Forks Herald.

  • Tips for Selecting a Campus CRM tool

    As competition for students increases, colleges and universities are looking more and more to customer (or constituent) relationship management software for help in remaining competitive.

  • Intercast Networks Goes into Beta with Kazam Video Service at Internet2 Universities

    Intercast Networks has redesigned Kazam, its student Internet TV and video service based on the company's VideoXpress platform. Following a spring semester alpha trial at Columbia and Purdue University, the company redesigned Kazam's interface based on student feedback and added additional content that caters to a student audience.

  • Michigan State Managing MRI Images from Africa with Acuo Tech DICOM Services Grid

    Doctors at Michigan State University have begun using the Digital Imaging and Communications in Medicine (DICOM) Services Grid from Acuo Technologies to transport and manage magnetic resonance imaging (MRI) results from a hospital in Malawi, Africa in order to monitor the impact of malaria on children.

  • IIT Delhi Delivers Services with Ingres Open Source

    Administrators at the Indian Institute of Technology Delhi (IIT Delhi) have gone public with their installation of open source database management software from Ingres. IIT Delhi, one of seven leading institutes of technology in India, adopted Ingres Database to support administration functions such as grading, finance, human resources, procurement, and hospital administration.