Computerworld
CPA group says drive with member data missing
Jaikumar Vijayan  08 June, 2006 08:28

Adding to the lengthening list of organizations reporting data compromises, the American Institute of Certified Public Accountants (AICPA) Wednesday confirmed that a computer hard drive containing the unencrypted names, addresses and Social Security numbers of nearly all of its 330,000 members has been missing since February.

The hard drive had been accidentally damaged by an AICPA employee and was sent out for repair to an external data-recovery service in violation of the AICPA's policies, said Joel Allegretti, a spokesman for the New York-based organization. It was on its way back to the AICPA via FedEx but failed to arrive. Allegretti did not say when exactly the drive went missing except to note that the package containing it was due back at the AICPA "towards the end of February."

It took the organization until March 31 to "recreate the drive" and determine what data it contained. The AICPA began notifying affected members of the potential compromise of their personal data on May 8 and has since completed the task, Allegretti said.

Jim McClusky, a spokesman for FedEx, said it is unclear what exactly happened to the drive. But he stressed that it is a mistake to characterize the package as being lost.

"We did handle the shipment, and we are working closely and cooperatively with our customer to determine where the package might be," he said. "It is still being investigated. At this point, we are looking at it as a missing shipment; that doesn't mean it's lost."

Based on investigations so far, it does not appear that information on the hard drive has been misused, Allegretti said.

Following the loss, the AICPA is offering affected members a year's worth of free credit-monitoring services. The incident has also prompted the group to begin deleting all Social Security numbers from its member database.

While a note posted on the organization's Web site says the collection of Social Security numbers has been a long-standing procedure, it added that "we will cease collecting and maintaining them, except in limited circumstances. And even for those, we are accelerating our efforts to develop other means of uniquely identifying our members."

News of the AICPA breach comes amid a flurry of similar disclosures in recent days. By far, the biggest was the May 22 disclosure by the U.S. Department of Veterans Affairs that it had lost personal data on more than 26.5 million veterans discharged since 1975. Since then, the agency has admitted that the breach may have exposed personal information on about 2.2 million active-duty National Guard and Reserve troops as well.

Since then, there have been similar disclosures elsewhere, including Texas Guaranteed Student Loan Corp, a nonprofit organization. TG said that an outside contractor lost an unspecified piece of equipment containing the names and Social Security numbers of approximately 1.3 million borrowers.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about VIA, FedEx, CPA

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

5 steps to getting started with data loss prevention

Lost and leaked data from stolen laptops, compromised networks, and malware-infected client devices all affect Australian businesses. Read on to discover the five critical steps to prevent data loss within your organisation.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.