NIH Laptop Theft: How Safe Is Your Data?

By Salvatore Salamone

March 26, 2008 | On Sunday, The Washington Post reported on a laptop stolen from the National Institutes of Health (NIH) that contained clinical trial data of 2,500 patients.

The article noted that the laptop “was stolen in February, potentially exposing seven years’ worth of clinical trial data, including names, medical diagnoses, and details of the patients' heart scans. The information was not encrypted, in violation of the government's data-security policy.”

There are so many things troubling about this theft and they should all serve as a reminder about the risk inherent when data is on laptops and the responsibilities organizations have to protect that data.

First, even though the laptop was stolen in February, the NIH delayed notifying patients about the breach until last week -- roughly a month later -- for fear of this would "provoke undue alarm." Duh. If the data was compromised (and there is no indication that it has been), waiting a month would give thieves an incredible head start during which they could potentially use the information to do damage. Fortunately, while the data in this incident contained names and birthdays, it did not have Social Security Numbers, phone numbers, or patient addresses.

Second, the laptop was in the locked trunk of a car, which just goes to show the increased risk to data in our more mobile workforce. The laptop theft problem is pervasive. The FBI, Gartner, and others peg laptop theft rates at between three to seven percent. And 50 percent of the 403 senior managers surveyed in the Computer Security Institute’s 2007 Computer Crime and Security Survey said their organization experienced laptop or mobile device theft within the last 12 months.

Third, related to the mobility factor, the data should have been encrypted. This case appears to be an example of people simply bypassing existing rules. The article notes that an initial attempt to encrypt the data failed, and no further attempt was made.

And let’s hope the data was at least backed up. Even if it had not been stolen, laptops have a higher failure rate relative to most desktop systems because of the way they are handled.

This incident, and others like it, should be used by life sciences IT managers to justify more stringent data protection policies. While this case involves personally identifiable and medial information, other data -- such as research that comprises an organization’s intellectual property -- is also at risk and needs protection.

At a minimum, every life sciences organization that handles, collects, stores, and analyzes such data must put into place ironclad policies and procedures that do not let employees intentionally or accidentally avert rules about protecting data.

The data should automatically be backed up and encrypted.

Those who want to go a step further can certainly do more to protect the data. For instance, new online services automate backup whenever a user connects to the Internet. Since trial data is often collected in the field, such services help ensure more of the collected data is backed up (rather than waiting for the device be brought into the lab or office).

For protection of another type, there are software packages and systems for laptops and mobile devices that wipe a drive clean if the device is stolen or an unauthorized user attempts to access data. (There are also services that help locate a stolen laptop.)

The bottom line is that IT must take a more commanding role in protecting data associated with intellectual property and clinical trial data whose exposure could result in HIPAA violations and identity theft problems for the trial participants.

How do you protect your data? Do you have any tricks of the trade that make the processes easier on your users? Drop me a note at s.salamone@att.net and share your thoughts on the subject.



White Papers & Special Reports

sgi whp 2
Managing the Modern Genomics Data Flood
Sponsored by SGI

Managing and storing the perfect storm of multi-disciplined data pouring from next generation sequencers and other omics instruments is a central challenge in life sciences. Discover in this paper how the SGI ArcFiniti storage solution, optimized for unstructured genomics and life sciences data can: 

  • Reduce costs, proactively protect data integrity, and deliver the high performance I/O required for genomics data processing and analysis.  
  • Effectively manage capacities from 156TB to 1.4PB as a disk based, integrated hardware and software platform 


sgi - whp 1
Turning Genomics Data into Practical Insight
Sponsored by SGI

With worldwide sequencing capacity approaching 13 quadrillion DNA bases annually turning genomics data into knowledge is a true computational challenge. Read this paper and learn how the SGI UV coherent shared memory platform can:  

  • Speed results time while cost competitively tackling the most difficult computational problems across all omics disciplines. 
  • Push performance by scaling to extraordinary levels, up to 256 sockets (2,560 cores, 4,096 threads) per single system (one OS image). 

Provide support for up to 16TB of coherent shared memory in a single system image enabling extreme efficiency across a wide range of compute demands. 



accerlys-logo_2012_wh
New Complimentary Market Survey…
Collaborations and Communications Within Drug Discovery Research
Sponsored by Accelrys
This survey was conducted by the Cambridge Healthtech Media Group in January, 2012. It was sponsored by Accelrys related to their HEOS initiative to gather valid information around externalizing collaborative research while improving communications in the cloud. With 310 qualified industry respondents the survey findings reveal useful usage and trends patterns.  An insightful follow-on discussion and webinar related to this survey, and the HEOS by Scynexis SaaS portal is also available on the Bio-IT World website for complementary viewing.
 


Job Openings

tessella logo 
Scientific Software Engineer
Boston MA
$70,000 to $95,000
 
Apply at http://jobs.tessella.com   

 

 

oxford nanopore logo 


 Early Access Collaborations Managers -  Click here to find out more and apply   

Oxford Nanopore's GridION technology, VP, Sales and Marketing  -   Click to  Apply  


 

 

For reprints and/or copyright permission, please contact  Tim McLucas, (781) 972-1342, tmclucas@healthtech.com .