Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Lost Tapes at TRICARE Potentially Expose 4.9 Million Military Personnel

TRICARE Breach Potentially Puts 4.9 Million Individuals at Risk

A massive data breach that could potentially affect 4.9 million individuals who received services from TRICARE, a provider of health care services to active and retired military personnel, was disclosed this week.

TRICARE Breach Potentially Puts 4.9 Million Individuals at Risk

A massive data breach that could potentially affect 4.9 million individuals who received services from TRICARE, a provider of health care services to active and retired military personnel, was disclosed this week.

Health Care SecurityAccording to a statement from TRICARE, on September 14, 2011, Science Applications International Corporation, a third party technology contractor, reported the data breach that occurred as a result of lost backup tapes. The tapes were apparently lost during a transfer between Federal facilities and San Antonio, Texas.

A representative from SAIC’s Incident Response Call Center told SecurityWeek that the data on the tapes was encrypted, but I’m not convinced that is the case. In a public statement announcing the breach, the company said, “The risk of harm to patients is judged to be low despite the data elements involved since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure.” This statement is far from convincing that the risk level is low, and knowledge of specific hardware and software typically doesn’t matter much when it comes to encryption. If the data had been encrypted, one would think they would explicitly say so in the statement. Also, it’s typically not required to disclose an incident like this if the media had been properly encrypted.

Either way, this incident will cost TRICARE big money.

The information contained on the lost backup tapes included data from patients who received care in San Antonio area military treatment facilities from 1992 through September 7, 2011, and may include Social Security numbers, addresses and phone numbers, and some personal health data such as clinical notes, laboratory tests and prescriptions.

According to TRICARE, no financial data, such as credit card or bank account information was stored the backup tapes.

According to Howard Anderson at HealthCareInfoSecurity.Com, this could be the largest health information breach reported since the HIPAA breach notification rule which took effect in September of 2009.

Advertisement. Scroll to continue reading.
Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.