B次元官网网址

Skip to content

UVic had policies in place to secure confidential data

Greater Victoria employers using data breach as a learning opportunity

Stolen information affecting the bank accounts of thousands of people would never have ended up in the hands of thieves if an existing policy was followed at the University of Victoria.

Before assigning blame, the school wants to wait for two reviews looking into whether an employee failed to follow policy by backing up confidential employee information to a device stolen 10 days ago.

According to UVicB次元官网网址檚 Information Security Policy, data such as social insurance numbers and financial information must be stored within a controlled-access system with the file being password protected or encrypted. The device must also be locked away.

The university has said the information on the stolen device was not encrypted or password protected, though it was locked up.

Regardless, UVicB次元官网网址檚 vice-president of finance and operations says sheB次元官网网址檚 waiting on the reviews before determining if policy was breached.

B次元官网网址淚 think what weB次元官网网址檙e going to be looking at is: whatB次元官网网址檚 in the policy? What are the specific procedures? And to what extent did this fit in with what was in that policy?B次元官网网址 said Gayle Gorrill.

Employees at the university receive periodic training on how to properly handle private information, she added.

In 2009, more than 400 employees that have access to secure information went through a three-hour session on information security and privacy.

B次元官网网址淲eB次元官网网址檒l be re-looking at this and asking, B次元官网网址榙o we need to do a refresher?B次元官网网址 I expect we will,B次元官网网址 Gorrill said.

Ryan Berger, an executive in the Canadian Bar AssociationB次元官网网址檚 freedom of information and privacy subsection, says he anticipates UVic isnB次元官网网址檛 the only employer reviewing its security policies.

B次元官网网址淲hen you see significant breaches that affect so many people, and itB次元官网网址檚 a well known public institution, it will raise the privacy profile and the importance of encrypting sensitive information and ensuring that organizations are appropriately protecting privacy,B次元官网网址 said Berger, a partner with the Vancouver law firm Bull, Housser & Tupper.

ThatB次元官网网址檚 exactly whatB次元官网网址檚 happening at the Vancouver Island Health Authority, which has nearly 18,000 employees and almost 2,000 physicians on its payroll.

B次元官网网址淲eB次元官网网址檙e really using this unfortunate situation as an opportunity for learning,B次元官网网址 said Cathy Yaskow, director of information access and privacy.

Yaskow, whose department focuses much of its work on the protection of confidential patient information, said VIHAB次元官网网址檚 current system to protect its employees is secure and thorough.

B次元官网网址淭he majority of our information, including employee and banking information, is stored (in an encrypted network),B次元官网网址 she said.

Any data that is saved to an external device is fully encrypted and stored in a locked safe, she said.

Camosun College, with slightly more than 1,000 employees, is also taking heed of the UVic breach.

B次元官网网址淲e have a database where this (similar type of) information is and itB次元官网网址檚 encrypted. We are not feeling like weB次元官网网址檙e in jeopardy,B次元官网网址 said Denis Powers, executive director of human resources.

B次元官网网址淲e have not stored anybodyB次元官网网址檚 personal, confidential information on devices or in modems that could be easily stolen.B次元官网网址

Unlike at UVic, there doesnB次元官网网址檛 exist any unencrypted (or encrypted, for that matter) file at Camosun that contains employee banking information and social insurance numbers.

Each individual piece of confidential information at Camosun is encrypted and stored separately on large, internal servers, Powers said.

Saanich police are continuing an investigation into a fraud, which stems from a break-in and theft at UVic on either Jan. 7 or 8.

The university is also conducting internal and external reviews into its policies. Additionally, the Office of the Information and Privacy Commissioner is looking into the release of information.

kslavin@saanichnews.com





(or

B次元官网网址

) document.head.appendChild(flippScript); window.flippxp = window.flippxp || {run: []}; window.flippxp.run.push(function() { window.flippxp.registerSlot("#flipp-ux-slot-ssdaw212", "Black Press Media Standard", 1281409, [312035]); }); }