BreachExchange mailing list archives

KY: University of Louisville kidney patient data was available to public


From: kirniki <kirniki () gmail com>
Date: Wed, 2 Jun 2010 20:38:26 -0400

http://www.courier-journal.com/article/20100602/BUSINESS/6020403/1003/University+of+Louisville+kidney+patient+data+was+available+to+public

A University of Louisville database of 708 names that included social
security numbers and dialysis details was available on the Internet
without password protection for nearly 1 ½ years, university officials
said Wednesday .

The Web site was disabled on May 17 when the university discovered the
flaw. University officials said in a statement that accessing the
database would not have been easy, and no direct links to the database
were discovered.
[..]
_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/

Get business, compliance, IT and security staff on the same page with
CREDANT Technologies: The Shortcut Guide to Understanding Data Protection
from Four Critical Perspectives. The eBook begins with considerations
important to executives and business leaders.
http://www.credant.com/campaigns/ebook-chpt-one-web.php


Current thread: