Technology
e-Newsletter
Intelligence Unit Special Reports Special Events Subscribe Sponsored Departments Follow Us

Twitter Facebook LinkedIn RSS

CDPH Reports 'Big' Data Security Breach

Cheryl Clark, for HealthLeaders Media, December 16, 2010

A magnetic tape containing sensitive personal and medical information for up to 2,550 residents and employees of 600 Southern California skilled nursing facilities has gone missing in the mail, state officials said Wednesday.

Kevin Reilly, the California Department of Public Health's chief deputy director for policy and programs, described the breach as "a big and unusual event for us," which resulted from a violation of protocol at the West Covina office. Protocol requires the state to use a private courier instead of the U.S. Postal Service for such sensitive material, but that protocol was sometimes not followed at that office. While individual employees have lost laptops containing small amounts of information, Reilly said, "This is definitely the largest breach of confidential and private information we've had at the Department of Public Health."

The tape contains e-mail addresses, investigative reports and background information on healthcare workers, names of health care facility residents, some medical diagnoses and social security numbers of CDPH employees, facility residents and healthcare workers dating from 2003, state officials said. The information was created or sent to the state Division of Licensing and Certification's West Covina office. "Everything we do out of that office was on the tapes," including potentially sensitive investigative documents regarding health facility violation investigations which may not have included personal information or health records, Reilly said.

Spokesman Mike Sicilia explained that the office primarily deals with investigations of certified nursing assistants at skilled nursing facilities in Southern California but that documents involving a few other types of health facilities may also be on the tape.

The material is unencrypted, but uses a specific magnetic tape system that's not largely available, state officials said.

While there was no evidence to date that unauthorized parties have acquired or accessed the information, "the California Department of Public Health is currently notifying affected individuals," and will "advise each individual about how to protect themselves from identity theft," state officials said in a news release.

The incident occurred when a CDPH office in West Covina, near Los Angeles, sent the tape by way of the U.S. Postal Service 400 miles to the Sacramento central office for backup. CDPH's Sacramento office on Sept. 27 received the mailed envelope "which was reported to be unsealed and empty. CDPH immediately reported the breach of the information Security Office and began an investigation," the state said.

Comments are moderated. Please be patient.

2 comments on "CDPH Reports 'Big' Data Security Breach"


Sang (12/30/2010 at 5:15 PM)
Dave, The story notes that the tape was UNencrypted. What I'm curious to know is, why is it protocol to use a private courier over the USPS? Couriers have plenty of instances of losing stuff, too. Maybe they're better at not losing mail, but it still happens. If the CDPH was serious about protecting the information, they should have a protocol calling for the use of cryptographic solutions for any digital data that is mailed.

dave (12/16/2010 at 12:56 PM)
I'm confused. If the tape was enctrypted and cannot be read, then how was there a breach??