We Could Learn From the Czechs
I learned a few lessons over the weekend about financial sec…
Eligible |
![]() |
A Congressman is citing the recent theft of an unencrypted laptop containing "VA medical center data" on more than 600 veterans as evidence that the Department of Veterans Affairs is not doing enough to protect information.
U.S. Rep. Steve Buyer, R-Ind., wrote a letter to VA Secretary Eric Shinseki May 12, citing "great concern about VA's continuing material weakness in protecting veterans' personal information from data breaches."
Buyer's letter states, "The VA lacks focus on its primary responsibility of protecting veterans' personal information." He asks the secretary to provide information on "your plan to decrease and eventually eliminate the use of unencrypted devices within the VA, particularly in the healthcare business line."
The VA was in the spotlight back in 2006, when an employee's unencrypted laptop, containing information on 26.5 million veterans, was stolen. The VA then required encryption for all its laptops and desktops and those of its contractors
Despite the encryption policy, the VA acknowledges that one of its contractors, which it declined to name, reported that an unencrypted laptop was stolen from an employee's vehicle on April 22. The device contained personal health information, including the names and Social Security numbers of 616 veterans, who have been notified of the breach as required under the HITECH Act breach notification rule, the VA says.
"The access codes specific to the stolen laptop have been deleted from servers, and no further access from this laptop is possible," the VA contended in a statement sent to HealthcareInfoSecurity.com. The laptop has not been recovered.
Responding to the Congressman's letter, the VA noted in its statement that it has instructed security analysts to:
In addition, the VA notes:
NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems..Next Topic
DoJ: Report to Congress on Implementation of Section 1001 of the USA PATRIOT Act..Next Topic
NIST SP 800-41 Revision 1: Guidelines on Firewalls and Firewall Policy..Next Topic
NIST Guide to Security for WiMAX Technologies (Draft)..Next Topic
OMB Memorandum: New Reporting Instructions for FISMA..Next Topic
NIST IR 709: Cryptographic Key Management Workshop Summary (Draft)..Next Topic