Slashdot Mirror


Backup Tapes With 2 Million Medical Records Stolen

Lucas123 writes "A vehicle used by an off-site archive company to transport patient data was broken into on March 17. The University of Miami just made the theft public last week, saying the thieves removed a transport case carrying the school's six computer backup tapes. On those tapes were more than 2 million medical records. In fact, the archive company waited 48 hours before notifying the university itself. A University spokeswoman said the school has stopped shipping backup tapes off-site for now."

12 of 173 comments (clear)

  1. Hmm. by Ethanol-fueled · · Score: 4, Interesting

    From TFA:

    After learning about the data breach, the university contacted local computer forensics companies to see if data on a similar set of backup tapes could be accessed. Menendez said security experts at Terremark Worldwide Inc. "tried for days" to decode the data but could not because of proprietary compression and encoding tools used to write data to the storage tapes.

    Proprietary compression and encoding tools? the article reeks of FUD but proprietary technologies still aren't without their faults...but eh, it's not like they used this "09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0", right?

    1. Re:Hmm. by Anonymous Coward · · Score: 5, Funny

      When questioned further, Terremark employees answered, "what's EBCDIC?"

  2. Re:yes but what's the value by Jhon · · Score: 3, Informative

    Why would someone steal the tapes? What is there value.


    What would YOU pay for 2 million social security numbers?
  3. *Still* no encryption?? by DigitAl56K · · Score: 4, Insightful
    There needs to be a law regarding data encryption. Virtually every time data is stolen, be it on CDs, laptops, backup tapes, missing hard drives, and so forth, it is not encrypted. In fact, I can think of only one case that has made press in the last 4-5 years that I can remember encryption being used to safeguard the data.

    Transporting confidential data off-site via any medium, including the Internet, without industry-recognized encryption (not something that is proprietary and untested) ought to be a criminal offense with severe penalties.

    TFA talks about proprietary compression and encoding and not about encryption. I simply do not believe that it is difficult to recover that data - whatever proprietary software wrote those files can be obtained from somewhere for a price. You can probably Google the file extension or some information in the header to determine the format and/or software.

    "The university feels confident that the person who took [the tapes] doesn't know what they have." They do now!

    "Even though I am confident that our patients' data is safe, we felt that in the best interest of the physician-patient relationship we should be transparent in this matter." That data is not safe. At best it is in an obscure, but not secure format.

    It's incredible, really. Since TrueCrypt 5.0 arrived,I don't even carry my work laptop or flash drives around without either full disk encryption or encrypted container files on them, and they do not contain anything as sensitive as 2 million medical records.
    1. Re:*Still* no encryption?? by WaltBusterkeys · · Score: 4, Interesting

      You can probably Google the file extension or some information in the header to determine the format and/or software. Not everything is on Google. If we're talking tapes, we're probably talking old mainframe-level systems. That means the problem might even be at the level of accessing the tape at all. The data coming off the tape is still just a string of ones and zeroes to them.

      This isn't a question where they've got a file sitting on their desktop called "Data.abx" and all they need to do is figure out what program creates an ".abx" file. In all likelihood, there's an old custom or semi-custom mainframe system that wrote this to the tape that didn't format in FAT32. (Nor would it make sense to even both with a filesystem on this type of backup system -- you're not backing up files, you're backing up a database.) From looking at a stream of data dump, there's no way to immediately make sense of it. If there's no file headers, there's not as much of a clue as to where to start. It just looks like an endless string of hex (2 million records is a lot of data).

      Somehow I doubt that this is just an Access file, sorry. Or even a SQL dump. They're not complete idiots.
    2. Re:*Still* no encryption?? by jimicus · · Score: 4, Informative

      Why would you still use antiquated mainframes for your backups, particularly if it's 2 million records? If something happened at your site you'd need a similarly antiquated mainframe just to get your data back. That makes very little sense. Three reasons:

      1. It works.

      2. IBM (assuming they are using IBM kit) mainframes are still being built today, and while they're totally different internally to the systems of 30 years ago, they're still compatible.

      3. This is what companies like SunGard and IBM (yes, they have a DR consultancy team) specialise in. You tell them what equipment you'll need in a disaster recovery scenario, they agree to loan it to you. In which case, who cares how old the system is?
  4. Re:yes but what's the value by WaltBusterkeys · · Score: 5, Informative

    Why would someone steal the tapes? What is there value. From TFA: The stolen backup tapes hold names, addresses, Social Security numbers and health information

    On the black market these days, a full identity (name, SSN, address, bank information, etc) can go for $14 each. If the tapes had full identities, that's 2 million x $14 = $28 million payday for a bunch of crooks. Even assume a "volume discount" for these guys and they're still in the many million dollar range. Even if it's just name, address, and SSN there's some value on the black market for these tapes.

    When you're breaking into a vehicle filled with stuff that looks like computer equipment, it's hard to know whether the data is going to be social security numbers (valuable), credit card numbers (valuable), medical records (valuable if there's addresses and SSNs), or routine corporate records (not all that valuable). Enough data brokers are sloppy enough with their security that there's a good chance to get some identity information that has value.

    These guys were either extremely lucky or knew exactly what they were doing. Or they're complete idiots who are wondering why these tapes won't play on their 8-track player.
  5. 2 million records, or people? by pclminion · · Score: 4, Insightful

    The article is very careful to phrase it as "2 million medical records." I somehow doubt that this means the medical records of 2 million separate individuals -- if it did, surely the news outlet would have said so, as it is much more dramatic. I bet a "medical record" is a single row in the database, and what was really stolen was a DB with 2 million records (as in "rows") in it. I seriously doubt the medical records of 2 million people are all collected on a single set of tapes.

  6. Even better by Psychotria · · Score: 4, Insightful

    "The university feels confident that the person who took [the tapes] doesn't know what they have. Even if they do know what's contained inside, it's very difficult to extract that information," remarked Menendez. I am sorry Menendez, but difficult for who exactly. Your school is not unique, nor is it the pinnacle of knowledge (no school is). If we could decrypt things 50 years ago, how is a "compression" method hard to work out?
  7. Old school by LoudMusic · · Score: 3, Funny

    Tape is so last millennium. Anybody who's anybody backs up to hard drives across the internet.

    --
    No sig for you. YOU GET NO SIG!
  8. In 2025 those will still be valid SS numbers by plantman-the-womb-st · · Score: 4, Insightful

    Get your most closely kept personal thought:
    put it in the Word .doc with a password lock.
    Stock it deep in the .rar with extraction precluded
    by the ludicrous length and the strength of a reputedly
    dictionary-attack-proof string of characters
    (this, imperative to thwart all the disparagers
    of privacy: the NSA and Homeland S).
    You better PGP the .rar because so far they ain't impressed.
    You better take the .pgp and print the hex of it out,
    scan that into a TIFF. Then, if you seek redoubt
    for your data, scramble up the order of the pixels
    with a one-time pad that describes the fun time had by the thick-soled-
    boot-wearing stomper who danced to produce random
    claptrap, all the intervals in between which, set in tandem
    with the stomps themselves, begat a seed of math unguessable.
    Ain't no complaint about this cipher that's redressable!
    Best of all, your secret: nothing extant could extract it.
    By 2025 a children's Speak & Spell could crack it.

    You can't hide secrets from the future with math.
    You can try, but I bet that in the future they laugh
    at the half-assed schemes and algorithms amassed
    to enforce cryptographs in the past.

    --
    Say bad words about my book, in cold oatmeal, or I shall sue!
  9. Yeah, but ... by CustomDesigned · · Score: 3, Funny

    Complete idiots don't read Slashdot. Oh, wait ...