Jump to content

When Administrators Don't Follow Their Own Policies


Recommended Posts

Posted

Sam LaGrone

The News & Observer (Raleigh, N.C.)

2008 Feb 12

RALEIGH, N.C. -- Wake County, N.C., officials are investigating whether county emergency medical services supervisors violated their own procedures when they waited eight days to report as stolen a missing laptop with the names and Social Security numbers of more than 4,600 patients, paramedics and firefighters.

According to Wake EMS standard operating procedure, if theft is suspected, "the EMS Chief and the law enforcement agency with jurisdiction should immediately be contacted."

But a timeline of the county's reactions released this week details the eight-day delay. According to the timeline, Wake EMS Chief Skip Kirkwood was notified Jan. 17, the same day the laptop was discovered missing from a battery charger at a paramedic station on WakeMed's Raleigh campus. But hospital police did not take a report until Jan. 25, after Kirkwood met with the county attorney, Scott Warren, and the head of Wake County's Information Technology Department, Lib Wanner.

Kirkwood has said the department spent those eight days doing an exhaustive search, which included help from WakeMed Police in reviewing their security tapes.

Deputy County Manager Joe Durham said whether or not EMS personnel adhered to the procedure will be part of an overall review of how the case of the missing laptop was handled.

"That's something we're going back and looking at," he said. "We have not made a determination on that yet."

The missing laptop contained names, addresses and Social Security numbers for 1,188 patients transported by Wake County paramedics and contract ambulance services -- information that is a prime target for identity thieves.

The laptop also contained the names and Social Security numbers of every person who has worked as an emergency medical responder in Wake County since the electronic patient data system began -- a list totaling more than 3,400 names. The county waited three weeks after the computer went missing to inform patients and EMS workers. Most received notification Friday, county officials said.

EMS workers, from volunteers to full-time staff, are assigned a four-digit number and password used to access the county's online patient system. But unbeknown to most employees and volunteers, every Wake EMS laptop had that code number paired to the worker's name and Social Security number. The Social Security numbers were used to verify a user's identity if he forgot his user name or password. The numbers were taken from an EMS personnel database and loaded onto the laptops.

The practice of using Social Security numbers or a mother's maiden name for password authentication is frowned upon by security experts, since the information is easier to discover than other security questions that don't have answers in the public domain. Also, the sensitive personal data on the laptop was not encrypted, making it easier for identity thieves to steal.

Durham said last week the Social Security numbers were in the process of being scrubbed from the Wake EMS network.

Carrie Bowden, a Durham paramedic who is also a part-time volunteer at the Stony Hill Rural Fire Department in Wake County, was surprised that her Social Security number and name were on the missing laptop. She was informed by county officials last week.

"There's no reason my Social Security number should be on that computer," Bowden said. "It's not even encrypted. Nice."

BE ON THE LOOKOUT

Wake County is looking for a Panasonic Toughbook CF-29 laptop believed stolen from a paramedic station at WakeMed's Raleigh campus. The laptop, which contains the names and Social Security numbers of more than 4,600 patients, paramedics and firefighters, has a Wake County identification sticker marked "DP 16096." If you have information about the laptop, call Jeff Hammerstein with Wake Emergency Medical Services at 625-3260.

Posted

Well at least they didn't lose 500K social security numbers like another governmental agency did.

will the administrator get reprimanded for not following procedure and policy, you can bet your but that a lowly employee would get reprimanded or fired but the administrator - no freakin way.

I'd be a little upset.

Posted

Once a policy leaves the adminisphere, it only applies to the underlings it is targeted at.

Jeez Dust, I thought you were familiar with this. :roll:

Posted

Sam LaGrone

The News & Observer (Raleigh, N.C.)

2008 Feb 12

The laptop, which contains the names and Social Security numbers of more than 4,600 patients, paramedics and firefighters, has a Wake County identification sticker marked "DP 16096." If you have information about the laptop, call Jeff Hammerstein with Wake Emergency Medical Services at 625-3260.

Boy.. if I stole the thing I'd make sure I left that sticker on... #-o

This thread is quite old. Please consider starting a new thread rather than reviving this one.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...