




A Recent Clinton Admin PII Breach Affects Me!
I received notice that “The National Archives Records Administration (NARA) learned in late March 2009 that an external hard drive containing a copy of Clinton Administration Executive Office of the President data is missing from a NARA processing room… The hard drive includes files that contain personally identifying information (PII.)” Specifically, this hard drive includes HR information… and I used to work at the White House… so my information was compromised.
The brochure also says what NARA is doing about the situation:
- “NARA’s Office of Inspector General, with the assistance of the US Secret Service, has launched a full-scale criminal investigation into this incident. NARA is offering a reward of up to $50,000 for information leading to the recovery of the missing hard drive.
- NARA informed the US Computer Emergency Readiness Team of the Department of Homeland Security, the White House Counsel’s Office, staff of our House and Senate Oversight Committees, and a representative of former President Clinton.
- NARA is sending notification letters to affected individuals and offering free credit monitoring services to help protect individuals from identity theft.
- NARA is revising its internal policies and procedures to ensure maximum protection of electronic and textual records containing PII. NARA is also implementing stringent physical and technical safeguards in place to protect protect personal information and prevent this type of incident from occurring in the future. Other initiatives include annual and refresher training for our employees and contractors to ensure they are familiar with privacy rules, regulations and standard operating procedures aimed at reducing the risk of breaches of PII.”
This is all pretty interesting stuff for me. My thoughts:
- I currently specialize in IT Compliance, which includes designing, implementing, and testing controls for protecting PII. I now have a new anecdote for sales meetings!
- I am annoyed that it took so long to inform me. Four months?!?! There’s time for some serious Identity damage in that amount of time!
- I am not particularly concerned, since I took Identity Theft protection measures after my computer was stolen… so much of the work is done… I’ll take up NARA on the extra protections, but it is duplicative at this point.
Labels: me, news, professional