Breach report · Government

Nearly 750,000 Citizens' Data Improperly Accessed

A software misconfiguration let a third-party security firm improperly access data from nearly 750,000 Indiana residents' COVID-19 contact tracing survey.

Exploit: Misconfiguration Company: Indiana Department of Health Industry: Government, Healthcare Sources: wowo.com

In what state officials are deeming to have been a low-risk data breach, the Indiana Department of Health is notifying affected individuals that data from the state’s COVID-19 online contact tracing survey was improperly accessed.

The incident occurred when a 3rd party company, who was looking to provide security-based services to the agency, accessed the information. The Department was immediately informed, and a “certificate of destruction” was signed to confirm the data had not been copied or downloaded.

In a statement, Tracy Barnes, the state’s Chief Information Officer had this to say, “We take the security and integrity of our data very seriously. The company that accessed the data is one that intentionally looks for software vulnerabilities, then reaches out to seek business. We have corrected the software configuration and will aggressively follow up to ensure no records were transferred.”

In the wrong hands, any amount of compromised data can be costly. Fortunately for the Department, their software vulnerabilities were exposed with good intentions and have seemingly been addressed.

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.