Delaware retirees' personal information posted on state website

The personal information of Delaware state retirees was included in a request for proposal (RFP) that made its way onto the state's website for five days before it was discovered and removed.

How many victims? 22,000.

What type of personal information? Social Security numbers, genders and dates of birth.

What happened? The RFP, which contained sensitive state retirees' information, was prepared by Aon, a consulting company that provides services to the state of Delaware for health and benefit programs. Aon prepared the document for the state to solicit bids from insurance companies interested in providing vision benefits to state employees and retirees. The RFP was posted to the procurement section of the state website to allow interested bidders access to the proposal document.

State staff discovered and removed the document five days after it was posted.

Details: The document did not include retiree names or current state employee information.

What was the response? Letters are being sent to affected individuals who will be offered one year of free credit monitoring.

Source: http://www.newarkpostonline.com/, Newark (Del.) Post, “State employee retirees' Social Security numbers posted on website by vendor,” Aug. 30, 2010.

close

Next Article in The Data Breach Blog

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.