NIH Laptop Theft: How Safe Is Your Data?

By Salvatore Salamone

March 26, 2008 | On Sunday, The Washington Post reported on a laptop stolen from the National Institutes of Health (NIH) that contained clinical trial data of 2,500 patients.

The article noted that the laptop “was stolen in February, potentially exposing seven years’ worth of clinical trial data, including names, medical diagnoses, and details of the patients' heart scans. The information was not encrypted, in violation of the government's data-security policy.”

There are so many things troubling about this theft and they should all serve as a reminder about the risk inherent when data is on laptops and the responsibilities organizations have to protect that data.

First, even though the laptop was stolen in February, the NIH delayed notifying patients about the breach until last week -- roughly a month later -- for fear of this would "provoke undue alarm." Duh. If the data was compromised (and there is no indication that it has been), waiting a month would give thieves an incredible head start during which they could potentially use the information to do damage. Fortunately, while the data in this incident contained names and birthdays, it did not have Social Security Numbers, phone numbers, or patient addresses.

Second, the laptop was in the locked trunk of a car, which just goes to show the increased risk to data in our more mobile workforce. The laptop theft problem is pervasive. The FBI, Gartner, and others peg laptop theft rates at between three to seven percent. And 50 percent of the 403 senior managers surveyed in the Computer Security Institute’s 2007 Computer Crime and Security Survey said their organization experienced laptop or mobile device theft within the last 12 months.

Third, related to the mobility factor, the data should have been encrypted. This case appears to be an example of people simply bypassing existing rules. The article notes that an initial attempt to encrypt the data failed, and no further attempt was made.

And let’s hope the data was at least backed up. Even if it had not been stolen, laptops have a higher failure rate relative to most desktop systems because of the way they are handled.

This incident, and others like it, should be used by life sciences IT managers to justify more stringent data protection policies. While this case involves personally identifiable and medial information, other data -- such as research that comprises an organization’s intellectual property -- is also at risk and needs protection.

At a minimum, every life sciences organization that handles, collects, stores, and analyzes such data must put into place ironclad policies and procedures that do not let employees intentionally or accidentally avert rules about protecting data.

The data should automatically be backed up and encrypted.

Those who want to go a step further can certainly do more to protect the data. For instance, new online services automate backup whenever a user connects to the Internet. Since trial data is often collected in the field, such services help ensure more of the collected data is backed up (rather than waiting for the device be brought into the lab or office).

For protection of another type, there are software packages and systems for laptops and mobile devices that wipe a drive clean if the device is stolen or an unauthorized user attempts to access data. (There are also services that help locate a stolen laptop.)

The bottom line is that IT must take a more commanding role in protecting data associated with intellectual property and clinical trial data whose exposure could result in HIPAA violations and identity theft problems for the trial participants.

How do you protect your data? Do you have any tricks of the trade that make the processes easier on your users? Drop me a note at [email protected] and share your thoughts on the subject.

White Papers & Special Reports

This Bio•IT World Briefing On “Next-Generation Sequencing,” underwritten by GenomeQuest, Inc.,
presents a selection of feature stories, interviews,commentaries, conference reports, and editorials on the emergence, opportunities, and challenges posed by high-throughput sequencing. Covered in this collection: the launch of new platforms from Applied Biosystems and Helicos; new applications of nextgen sequencing; the rise of personal genomics; and informatics solutions to vexing problem of managing the vast volumes of next-gen data. Download now



SGI's Meeting Today’s Computational Needs for Science

The quest to better understand disease mechanisms and find new treatments is driven by new laboratory technologies and ever-more sophisticated modeling and simulation efforts. As such, life sciences R&D investigations increasingly are relying on more powerful computing resources. The challenge is how to accommodate the broad mix of applications.

Addressing this issue, this paper produced by the Bio-IT World Custom Publishing Group discusses a new SGI Hybrid Computing Environment approach. It optimally uses shared memory systems, multi-processor clusters, and FPGAs to accelerate computational workflows.



sgi_protm

SGI's Supercharging Proteomics Discovery

The deeper study of proteins and their interactions can reveal scientific information once considered nearly untouchable to scientists and researchers. Today, unprecedented advancements in computing power are enabling the creation of mounds of proteomic based data along with the accompanying bottlenecks data can create.

Rather than just “simplify the experiment” to fit the computational resources an alternative is now available with the SGI Proteomics Appliance. This complimentary white paper, produced by the Bio-IT World Custom Publishing Group, looks at ways to use the Proteomic Appliance to handle the most intensive proteomics computing tasks facing science today.



Life Science Webcasts & Podcasts

Trade Commission of Spain

Spain’s Emerging Biotech Revolution

The biotechnology sector is growing 10 percent faster in Spain than it is in the U.S. Driven by a culture, government and private sector that are open-minded and optimistic, Spain-based companies are emerging as leaders in this dynamic field. Discover how your business can capitalize on creative solutions from Spain-based enterprises by learning about:

  • Trends and factors driving the growth of Spain’s biotechnology sector.
  • The Spanish government’s aggressive policies and incentive programs for biotechnology research.
  • Biotechnology spin-offs, bio-clusters and new research centers in Spain that are combining entrepreneurial spirit with larger-than-ever resources.
  • The strength of Spain’s biomedicine community, and how U.S. pharmaceutical companies are capitalizing on it.

Download Now


More Podcasts

Job Openings

Friedrich Miescher Institute for Biomedical Research - Part of the Novartis Research Foundation
Basel, Switzerland is looking for a Head of IT Systems & Infrastructure. You will manage a cutting-edge core server and network infrastructure, comprising Linux and Solaris, as well as a robust Windows and Macintosh environment. We look forward to receiving your application: [email protected]. click for more information

Lilly Singapore Center for Drug Discovery (LSCDD) - Associate Director of Informatics
Lead and mentor a strong team for the Bioinformatics group at the Integrative Computational Sciences (ICS) department at LSCDD towards the development of novel algorithms, data analysis methods and software tools for drug discovery. Work closely with the Software Engineering group at ICS, and collaborate with the Discovery IT organization in Europe and USA. For additional information, or to apply visit: LSCDD

Related Resources & Products

Biodefense & Enabling POC Diagnostics & Microarray Data Analysis 2007
Biodefense & Enabling POC Diagnostics & Microarray Data Analysis 2007
Principled, Effective Data Mining for Systems Biology




For reprints and/or copyright permission, please contact RMS, 1808 Colonial Village Lane, Lancaster, PA;

(717) 399-1900 ext 100 or via email to [email protected].