Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Unencrypted Laptop Stolen From Home Health Monitoring Firm Puts 116,000 At Risk

Just days after NASA warned that a laptop containing unencrypted sensitive employee information was stolen from the space agency, another large organization has come forward and acknowledged a similar incident, also involving a stolen laptop loaded with sensitive personal information, and resulting in many individuals being put at risk.

Just days after NASA warned that a laptop containing unencrypted sensitive employee information was stolen from the space agency, another large organization has come forward and acknowledged a similar incident, also involving a stolen laptop loaded with sensitive personal information, and resulting in many individuals being put at risk.

Late Tuesday, Alere Home Monitoring, a Waltham, Massachusetts-based provider of anticoagulation monitoring and management services, said that a company-owned laptop containing sensitive individual information, including names, addresses, dates of birth, Social Security numbers, and diagnosis codes had been stolen.

The company said that it has notified approximately 116,000 individuals about the data loss incident, and is now reaching out to the media.

According to Alere, the laptop was taken from a locked vehicle belonging to an Alere employee.

In typical post-breach fashion, the company is offering impacted individuals free credit monitoring service for one year, but said they see no reason to believe that the information on the stolen computer has actually been accessed or inappropriately used. Unfortunately, that’s impossible to tell, and if it did fall into the hands of a savvy criminal, many could be at risk of ID theft.

While Alere may be unfamiliar to many, it’s no small company. Publically traded Alere (NYSE:ALR) currently supports a market cap of nearly $1.5 billion and announced earlier this month that it had net revenue of $691.4 million for the third quarter of 2012.The company claims that it has helped over 10,000 clinicians track 450,000 patients and 30 million INR tests.

The company said that in response to the incident, it has bolstered its information security program by deploying encryption to laptops that connect to its corporate network. In addition to other measures, the company said it would provide additional education to its staff.

“CIOs need to remember that just encrypting a laptop solves only a fraction of data breach risk,” Mark Bower, data protection expert and VP at Voltage Security told SecurityWeek recently.

Advertisement. Scroll to continue reading.

“Data moves to and from laptops – in emails, files, and as data to and from applications and servers. So while encrypting a laptop might be a first reaction, with attackers going after data in flight and the risk of accidental breach through multiple channels (whether its data at rest, in use or in motion), wherever there’s a security gap with data in the clear, it’s vulnerable to compromise,” Bower explained. “It’s important for CIOs to consider new and more effective ways of preventing breaches – for example, data-centric security.”

An Alere Home Monitoring spokesperson did not immediately respond to SecurityWeek’s request for comment.

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...