Laptop stolen from billing vendor contained unencrypted data on 3,500 students

Share this article:

About 3,500 students in Massachusetts and Vermont who receive Medicaid reimbursements are being notified that their unencrypted personal information – including Social Security numbers – was on a password protected laptop stolen from the vehicle of a Multi-State Billing Services employee.

How many victims? Nearly 3,000 students in Central and Eastern Massachusetts and 446 students in Vermont. 

What type of personal information? Medicaid identification numbers and Social Security numbers were among the information.

What happened? A password protected laptop containing the unencrypted student data was stolen from the vehicle of a Multi-State Billing Services employee.

What was the response? Multi-State Billing Services is enhancing security, including encrypting all relevant data on portable computers. All impacted individuals are being notified, and Multi-State Billing Services will reimburse costs related to security freezes for the next three years.

Details: The laptop was stolen in May. The letter sent to parents of impacted students was dated June 25.

Quote: “We believe that the likelihood of exposure of the student records is low,” Daniel Courter, general counsel for Multi-State Billing Services, said in a statement. “The nature of the theft suggests that the perpetrator had no interest in, or awareness of, this data.”

Source: milforddailynews.com, The Milford Daily News, “Milford schools: Info compromised due to security breach,” July 1, 2014.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

POLL

More in The Data Breach Blog

Florida medical center hit with breach for third time in two years

Aventura Hospital and Medical Center has reported a data breach for the third time in two years.

Tampa General Hospital breach impacts hundreds of patients

Tampa General Hospital is notifying 675 patients that their personal information may have been accessed, without authorization, by a former employee.

George Mason University travel system targeted for malware attack

The incident could have exposed the names and Social Security numbers of users, although no evidence has surfaced to suggest that's the case.