The Macrosite for News, Analysis and Opinion about the Future of the Internet
Mary Jander

CIO's Head Rolls After Utah Data Breach

Written by Mary Jander
5/17/2012 15 comments
no ratings
DISCUSS     Email This

It was an IT nightmare: On April 2, 2012, technicians working for the State of Utah's Department of Technology Services (DTS) discovered that hackers were downloading sensitive personal information about healthcare claimants from a state-run server.

Included in the stolen data were 280,000 records containing Social Security numbers, as well as 500,000 additional records without SSNs but containing other sensitive personal information, such as name, address, or date of birth.

If that wasn't bad enough, the hackers, who appeared to hail from Eastern Europe, had been at their nefarious task since March 30. And their initial contact with the server had taken place on March 10.

After immediately shutting down the server, DTS staff investigated the breach over the next month, while state officials underwent a lengthy process of public apology and education, trying to ensure that people whose data went missing weren't further victimized by imposters phoning them with phony "help."

The state government has offered victims free credit monitoring service, but according to the Deseret News, just 10 percent of the 280,000 whose SSNs were breached are taking the state up on the offer. Still, at a cost of $16 per person per year, the state has already spent at least $448,000 on the service and could potentially end up shelling out $4.5 million.

The second shoe dropped on Tuesday this week, when Utah governor Gary Herbert fired executive director of DTS Stephen Fletcher; replaced him with a new acting director and former colleague, Mark VanOrden; and instituted a new position of Health Data Security Ombudsman, hiring Utah healthcare advocate Sheila Walsh-McDonald for the job.

Stephen Fletcher
Stephen Fletcher

Harsh, yes; but according to a statement in yesterday's Deseret News, Stephen Fletcher approved of the governor's action because he was ultimately in charge when the breach took place.

Fletcher also cited the difficulties of keeping data safe these days. "There has been a huge increase in the number of attacks against state systems -- about a 600 percent increase in the last four months -- and it is always a difficult challenge to make sure that you have adequate resources there to make sure the attacks are turned away," he told the press.

[Pssst! Do you think CIOs should take the fall when enterprise data breaches occur? Weigh in on our new poll here.]

Interestingly, Fletcher was slated to appear today as a guest on Internet Evolution Radio. A request for comment from him for this blog was unanswered at press time.

Meanwhile, the new director of DTS has released a more detailed summation of the "multiple mistakes" that put the red carpet down for data thieves to enter Utah's Medicaid Management Information System.

"Ninety-nine percent of the state's data is behind two firewalls, this information was not. It was not encrypted and it did not have hardened passwords," VanOrden told legislators in a meeting yesterday. Default passwords installed at the factory were still in the system when it was shut down, he noted.

There were other problems: The server had been installed months ago by a contractor, not a staffer as department protocol demands. Also, DTS policy calls for servers like this one to undergo monitoring and a risk assessment -- steps that also weren't taken.

Despite the furor this breach has caused, it is far from unique. According to information posted by the Privacy Rights Clearinghouse, of the 203 data breaches reported so far this year in the US, 103 involved either government or healthcare information. Of that subset, 16 cases were the result of hacking.

The largest hacking of a government or healthcare information source this year in the US occurred in January 2012 at Indiana University, when the online records of 650,000 nationwide participants in a President's Challenge fitness program were breached. It seems no CIOs were harmed, however, in the resolution of that case.

Related posts:

— Mary Jander Follow me on TwitterVisit my LinkedIn pageFriend me on Facebook, Managing Editor, Internet Evolution

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
Mary Jander
Thinkernetter
Friday May 18, 2012 10:08:45 AM
no ratings

Great points, tech_ed. Indeed, this situation points to the fact that in house isn't always more secure, and therefore not cheaper.

tech_ed
Rank: Cyborg
Thursday May 17, 2012 11:25:23 PM
no ratings

I guess what's an important lesson to take away from this, if I may blow my own horn...is that companies think that they can save money by taking server hosting inhouse. They see what it costs to co-locate or have managed hosting from a hosting provider and they think that they can do it cheaper...well, sometimes they can. But issues like this show that you may not be considering all the costs of bringing your servers inhouse. Like I said in my previous statement, in the 20 years of being in the managed, colocated and network ISP/ASP business, I have never witnessed a breach where customer data was compromised. Not once! And why is that? We have rules, policies and proceedures. Plus we are professionals...it's all we do...we don't fix printers, we don't troubleshoot PowerPoint, we don't do any of the things an inhouse IT does....hosting, that's it...*THAT'S* what you're paying for when you purchased managed hosting. Just because the nephew of the CEO built his first webpage at age 5 doesn't make him an expert. You can't imagine how many so-called professionals don't understand cross-site scripting, or how to prevent SQL injecting...or how to even harden a server! It's not that difficult, but it's  not childs play either. You *HAVE* to know what you're doing and you have to have the experience to prepare for *EVERY* contingency. 

I've witnessed major customers who think they can bring their stuff inhouse so they leave thinking they're going to save money...the smart ones come back...the arrogant ones end up like these people...

That's why I always say, when money and security is at stake, leave it to the experts...

cjon316
IQ Crew
Thursday May 17, 2012 5:48:10 PM
no ratings

Wow, that is even better. Put the bill to the taxpayers. How will they recoup the losses. Will this mean Utah tax increases?

What a mess.

Mary Jander
Thinkernetter
Thursday May 17, 2012 5:05:51 PM
no ratings

The damage will unfold as it becomes apparent whose data was taken and what was done with it. And the taxpayers will foot the bill, because this is a government agency.

cjon316
IQ Crew
Thursday May 17, 2012 5:02:16 PM
no ratings

This is really a terrible situation isn't it.

How does one gauge the actual damage done? And who is responsible to meet those damages?

Mary Jander
Thinkernetter
Thursday May 17, 2012 5:00:46 PM
no ratings

Great points, tech_ed. I believe that when the new acting IT director faced legislators today he mentioned that it has been tough to get the technicians to understand many pages of policy rules.

But that just illustrates how it's the job of the CIO to make the rules and regulations easier to follow.

Mary Jander
Thinkernetter
Thursday May 17, 2012 4:58:50 PM
no ratings

Agreed, chuckgregory, that scapegoating is counterproductive. But sadly, I think the governor had to "make an arrest" and deliver someone's head on a platter. As I said in an earlier message, it was high theater designed to appease angry constituents. And no, it won't fix the problem. But surely, it got DTS smacked into shape.

Mary Jander
Thinkernetter
Thursday May 17, 2012 4:55:58 PM

It is too bad that the state prohibits any official for being dismissed. I am not saying that Utah's governor should have fired its CIO. But the law should not shield IT personnel who are truly negligent.

tech_ed
Rank: Cyborg
Thursday May 17, 2012 4:55:41 PM
no ratings

"There were other problems: The server had been installed months ago by a contractor, not a staffer as department protocol demands. Also, DTS policy calls for servers like this one to undergo monitoring and a risk assessment -- steps that also weren't taken."


I've worked for two of the worlds largest tier-1 hosting providers over the past 20 years! I've been involved with both sides of the computer security world for over 35 years! Breaches like this are inexcusable!
Regardless of the number of attacks you get on your system, there really is no excuse for not hardening your equipment! As an experiment back in the 90s, we stood up a Windows server with no patches or updates on a public facing network. It took less than 20 minutes for it to be owned by hackers!

It is clear that policy and proceedures were ignored in this case. And since policy and proceedures come from the top down, the highest head must be sacrificed for not ensuring that not only these policies and proceedures be followed, but that the management staff he put in place were not compitant enough to make sure that the employees followed proceedure!

Following simple hardening steps is all it takes to keep the baddies away from your data....it really shouldn't be that hard!

Mary Jander
Thinkernetter
Thursday May 17, 2012 4:54:21 PM
no ratings

It seems that the ripple effects are still to play out, cjon316. Those whose personal information was breached have been told they must track their online credit activity very closely for the next while, since their SSNs etc. are likely to wind up in the wrong hands, having been sold by the hackers.

And yes, the server was taken offline immediately when the breach was discovered.

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from IT Clan Editor's Blog
Mitch Wagner
Mitch Wagner   5/16/2013   13 comments
Facebook and Twitter are great for posting cat pictures. But are people really using social media for life-changing communications? Like, if a hurricane comes by and blows down their house?
Kim Davis
Kim Davis   5/9/2013   18 comments
In a standout presentation at the Jefferies 2013 Global Technology, Media & Telecom Conference in New York this week, the UK government talked about becoming a "very intelligent client."
Mitch Wagner
Mitch Wagner   5/2/2013   9 comments
A consumer business would have to be crazy or desperate to change call-center software in December, the peak of the holiday season. But that was exactly Positec's position.
Mitch Wagner
Mitch Wagner   4/25/2013   10 comments
To help enterprises deploy software faster for mobile, social, big-data, and cloud applications, IBM this week acquired development tools vendor UrbanCode.
Mitch Wagner
Mitch Wagner   4/18/2013   17 comments
Internet Explorer seems like a relic of the 90s, like parachute pants and Friends. But that's just me. I'm a Chrome guy, and before that I used Firefox.
5
of
Mary E. Shacklett
Law Will Define Next-Gen Privacy

4|25|12   |   1:48   |   7 comments


The plan for unmanned police drones to patrol traffic and other city conditions in Seattle has sparked a new set of legal concerns about privacy. Law traditionally lags technology, but we can expect now to see a new round of activity in the courts as legal definitions begin to emerge on what "next-gen privacy" will look like.
Ann Cavoukian
The Need for Biometric Encryption

11|10|11   |   3:25   |   10 comments


Ontario's information privacy commissioner explains the unintended consequences of facial recognition technology and how biometric encryption can make it safer.
Ann Cavoukian
Privacy Is Everyone's Responsibility

11|1|11   |   4:01   |   17 comments


Ontario's privacy commissioner offers advice to businesses and users for protecting privacy online.
Wisdom of the Big Chair
IT Losing the Security Battle

1|7|13   |   3:15   |   No comments


ITRC found that more than 600 security breaches took place in 2012. Flaws were found in some of the nation's most respected companies: Apple, Citibank, and Wells Fargo. So, it seems the bad guys are doing better than the men in the white hats.
Second Shooter
Cisco & Linksys: A Problem at the Edge

1|4|13   |   2:15   |   No comments


Cisco's rumored sale of Linksys suggests we may have problem with innovation and profit at the edge of our Internet, and that could be critical to the evolution of many Internet-delivered services.
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
Wisdom of the Big Chair
FBI Turns Attention to Mobile Security

10|30|12   |   3:45   |   8 comments


The FBI recently issued a warning to smartphone users, highlighting two mobile malware applications: Loozfan, which steals personal information, and FinFisher, which is spyware that takes over a smartphone's functions.
Second Shooter
The Real Problem With Cloud Security

8|17|12   |   2:12   |   7 comments


All the recent hoopla about cloud security overlooks an important point, which is that it's not strictly a cloud problem. The linkage of online services into cooperative chains creates the risk, and only biometrics and federation of providers can save us.
Mary E. Shacklett
Scrum Brings Social MediaThinking to Projects

7|30|12   |   2:12   |   8 comments


The very low-tech "scrum" project technique introduces "crowd talking" to projects and also sets the entire crowd to problem solving. So far, these new social-media-style meetings appear to have supercharged project execution.
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   3 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
Alison Diana
Ushering in a new era of cognitive computing systems, IBM announced today the IBM Watson Engagement Advisor, a technology breakthrough that allows brands to crunch big data in record time to transform the way they engage clients in key functions such as customer service, marketing, and sales.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
Yahoo Needs to Break Tumblr in Order to Fix It
Joe Stanganelli
As
Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.

CLICK FOR MORE