The Privacy Commissioner says a culture change starting at the top of ACC is vital if further data security breaches are to be prevented.http://www.scoop.co.nz/stories/PO1208/S00359/privacy-commissioner-urges-acc-culture-change.htm
Marie Shroff is commenting on the findings and recommendations of the Independent Review of ACC Privacy and Security of Information that were released today.
The report was commissioned jointly by the Office of the Privacy Commissioner (OPC) and the ACC Board following the unauthorized disclosure of details of 6,748 clients.
"The review has found the breach was a genuine error and I accept that. But it also shows the error happened because of systemic weaknesses within ACC's culture, systems and processes," says Ms Shroff.
"The reviewers noted a good level of privacy awareness especially at branch level. But the review also highlights a culture that, according to stakeholder feedback to the reviewers, has at times "an almost cavalier" attitude towards its clients and to the protection of their private information.
"The review shows that information stewardship is low level and defensive and focuses on breaches and complaints rather than taking strong leadership that emphasises respect for clients and their information.
"That is not good enough particularly in this digital age. Personal information is the lifeblood of ACC and it is vital that ACC treats that information with respect - the trust of its clients and, in many respects, the success of its operations depends on it."
Ms Shroff says the report shows that ACC lacks a comprehensive strategy for protecting and managing its client information.
"This sort of data is a major business asset with associated risks that have to be managed.
"While ACC has elements of privacy protection and security, these are not up to the standard expected of a responsible public sector agency that holds highly sensitive information on a large number of people.
"Changing that is essential. And the changes, which must include a culture change, have to start right at the top."
The review recommends that an independent audit of how ACC has implemented the changes is undertaken every two years and provided to the Privacy Commissioner.
Marie Shroff welcomes the recommendation.
"It's evident from the report that a lot needs to change before public confidence in ACC can be restored. I believe it can be done, but only if ACC takes the review's findings and recommendations seriously and gives its many good and committed staff the support they need to implement the necessary changes.
"The review provides a strong set of proposals. I will closely monitor ACC's progress as it implements these changes."
Ms Shroff says the data security breach at ACC has provided a timely warning to both public and private sector organisations.
"Agencies that hold large amounts of personal information should be taking note of what has happened at ACC and learn from its mistakes. Many organisations will recognise it could just as easily be them in the headlines."
Showing posts with label Marie Shroff. Show all posts
Showing posts with label Marie Shroff. Show all posts
23 August 2012
Privacy Commissioner urges ACC culture change
A press release from the Office of the Privacy Commissioner
Labels:
ACC board,
Marie Shroff,
press release,
privacy,
Privacy Commissioner,
review
04 April 2012
Privacy Commissioner late to ACC leaks
An article from the Dominion Post by Kate Chapman
http://www.stuff.co.nz/national/politics/6693862/Privacy-Commissioner-late-to-ACC-leaks
The first the Privacy Commissioner knew of an alleged privacy breach by ACC was when media contacted her.© 2012 Fairfax New Zealand Ltd
Commissioner Marie Shroff is investigating how the personal details of thousands of claimants were accidentally sent to claimant Bronwyn Pullar. That investigation may also look at how Pullar's own personal information, in an email by former National Party president Michelle Boag, was leaked to a Sunday newspaper.
Pullar had contacted the Commissioner about a separate issue late last year, but the first they knew of the leaked spreadsheet containing information about thousands of claims, was when a journalist rang her office.
Assistant Commissioner legal and policy Katrine Evans said it would be normal practice for ACC to contact the Commissioner if they were aware of the breach.
"What I understand, when we first got the media inquiry, we had no knowledge."
The inquiry would look at what happened with ACC, when they became aware, and what they should have done once the knew of the breach, she said.
ACC became aware of the breach in December during a meeting with Pullar. The information was also sent as an attachment in one of many emails from Pullar to the State Services Commission last year but they did not realise they had the information until a review was conducted recently.
ACC Minister Judith Collins is threatening to take defamation action against Labour MPs Trevor Mallard and Andrew Little and Radio New Zealand, over suggestions she was the source of the leaked email about Pullar - something Collins vehemently denies.
Prime Minister John Key said that if and when Collins took defamation action was a matter for her.
"I support her action, she wants to clear her name, she feels very strongly that she was impugned and on that basis she's taken her own action, it's her own money, her own resources, she's free to do that."
http://www.stuff.co.nz/national/politics/6693862/Privacy-Commissioner-late-to-ACC-leaks
Labels:
Bronwyn Pullar,
Dominion Post,
inquiry,
Judith Collins,
Marie Shroff,
Michelle Boag,
Privacy Commissioner
15 March 2012
Collins backs manager on ACC privacy breach
An article from the New Zealand Herald by Adam Bennett
http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&objectid=10792157
ACC Minister Judith Collins has gone into bat for the senior manager who was told of a potentially massive breach of client privacy in December but didn't do enough to investigate it.© 2012 APN Holdings NZ Ltd
ACC chief executive Ralph Stewart this week confirmed reports that in August last year a case manager accidentally emailed a spreadsheet with information about other clients to a long-term claimant. About 9000 records were sent relating to about 6700 individuals giving information including their names and claim numbers.
He revealed that Philip Murch, ACC's national manager of Recover Independent Services, first learned of the potential breach during a routine meeting with the claimant in December but didn't inform his superiors. "We didn't do enough at that point," said Mr Stewart.
Yesterday, following a meeting with Mr Stewart and ACC chairman John Judge, Ms Collins said she was expecting a report from the corporation and how it was handled as early as tomorrow.
Ms Collins said said Mr Murch "obviously didn't handle the matter as well as it should have been handled". However she understood that during his December meeting with the recipient of the information, Mr Murch was not told "what the nature was of that confidential information" and was "not fully aware of what was happening".
"That's what I expect will no doubt be reflected in the report to me."
By yesterday about 2200 clients affected by the breach had been contacted.
Ms Shroff said it appeared the breach involved only ACC claims that were under review in August last year.
http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&objectid=10792157
Labels:
claimants,
Herald,
Judith Collins,
Marie Shroff,
privacy
14 March 2012
ACC filing systems under investigation
An article from the Dominion Post by Phil Kitchen
http://www.stuff.co.nz/dominion-post/news/politics/6569694/ACC-to-send-mountain-of-apologies
The number of inquiries into ACC’s mass privacy blunder widened today with the Office for the Privacy Commissioner announcing it would investigate not just the huge breach of privacy but also the corporation’s standards for securing personal information.© 2012 Fairfax New Zealand Ltd
ACC clients were concerned about the breach and could either wait for ACC to contact them or call 0800 101 996 to ask if they were among the thousands of clients on files the corporation sent to someone who should not have received them, a spokeswoman for the office said.
People concerned their privacy had been breached should complain first to ACC then to the commission if they are not satisfied with the response. The office has opened an investigation into the breach but also into ACC’s standards for securing personal information, she said.
The Privacy Commissioner’s inquiry follows calls by ACC Minister Judith Collins for an urgent internal report on the breach from ACC which has been criticised by Green Party ACC spokesman Kevin Hague.
Mr Hague said today that ACC’s regular breaching of people’s privacy suggested it was a cultural and systemic issue which must be investigated independently. "If we want to fix the problems at ACC, an investigation needs to be conducted by an independent body," he said.
ACC will telephone or mail an apology to 6748 clients whose privacy had been breached and deal with compensation claims case by case.
The corporation was deluged with complaints yesterday after revelations that a staff member sent a spreadsheet containing the names and nature of at least 9000 claims, including some by those who say they have been the victims of sexual abuse and violent crimes. The details - some featuring well-known people - were emailed to a person who should not have received them, in what may be one of New Zealand's worst privacy breaches. The revelations led to "please explain" calls to the corporation from ACC Minister Judith Collins and Privacy Commissioner Marie Shroff.
ACC chief executive Ralph Stewart apologised yesterday and said "frankly" the breach had been poorly handled. "Clearly we must review our internal processes to ensure this type of event doesn't happen again."
An ACC spokeswoman later said it wished it had done more to investigate.
Senior management were told three months ago that they had possibly made the biggest privacy breach in New Zealand history but, apart from asking for the information back, no further investigation was done. The details revealed included full names, the nature of each claim and dispute, and individual claim numbers, as well as personal information on nearly 250 claims from ACC's most secure unit, the sensitive claims unit.
The recipient of the information spoke to The Dominion Post after repeatedly raising issues of systemic privacy failures by ACC in handling how it collected, used and disclosed claimants' information. "This was only one example," the recipient said yesterday. "Many ACC claimants have received numerous letters of apology from ACC in relation to breaches of their privacy only for further breaches to occur.
"These issues of systemic failure were raised at the highest level within ACC, along with a request for these matters to be investigated.
"The ACC management's team response to the ACC board was that there was no validity to the prior privacy issues raised.
"It is now up to appropriate authorities to investigate."
The information provided to the recipient has now been destroyed.
The breach led to multiple calls from politicians and advocacy groups for an independent inquiry into how it occurred and into ACC's privacy practices. There were also calls for ACC to compensate those involved but the corporation may have dodged a bullet on that issue because the recipient did not publish the details on the internet.
Privacy lawyer John Edwards said it would be difficult for claimants to prove distress or humiliation had been suffered as a result of the file being sent to one member of the public.
However, it was significant and of considerable concern that details about ACC sensitive claims unit clients were being distributed outside the unit, Mr Edwards said. The fact that the unit existed should mean "extra special care" should be taken about the privacy of those clients but ACC had failed to protect those clients' privacy, he said.
ACC yesterday invited clients seeking a settlement or compensation to write to the corporation's privacy officer and said the issue would be dealt with on a case by case basis.
SLOPPY PRIVACY PROTECTION, SAYS CLIENT
A man who was paid $12,000 by ACC for breaching his privacy was later sent sensitive information by the corporation relating to fraud investigations. Even after being ordered by the privacy commissioner to pay Bruce Van Essen $12,000, ACC then sent him a document identifying six people, and their case details, who were under investigation.
Mr Van Essen said the privacy breach last year was yet another example of a sloppy culture of privacy protection at ACC. "Regardless if they are under investigation for fraud or not these people still have privacy rights yet ACC couldn't care less."
The fraud details were wrongly sent to him last year and he said it took three phone calls to ACC over several days before a member of ACC's fraud unit finally contacted him. ACC asked him to return the information and Mr Van Essen agreed, on the condition that the corporation tell the six people their privacy had been breached.
Mr Van Essen, who lives in Dunedin, said ACC has repeatedly flouted his privacy. "Just before Christmas ACC paid me $12,000 for a privacy breach that the privacy commissioner upheld in 2007."
He said it had taken him nearly five years to settle that breach and he has also had several other privacy breaches upheld by ACC.
The Dominion Post was also provided with an edited document yesterday containing another nine privacy breaches of ACC clients' details. The details included names, occupations, diagnosis of injuries and duration of compensation to the clients. The details were sent to an ACC client who should not have received them.
http://www.stuff.co.nz/dominion-post/news/politics/6569694/ACC-to-send-mountain-of-apologies
Labels:
article,
claimants,
Dominion Post,
Green Party,
Judith Collins,
Kevin Hague,
Marie Shroff,
privacy,
Privacy Commissioner
Green Party asks Privacy Commissioner to step in on ACC
A press release from the Green Party
The Green Party is calling on the Privacy Commissioner to investigate systemic issues relating to the privacy of individuals’ information at ACC. Green Party ACC spokesperson Kevin Hague said ACC’s regular breaching of people’s privacy suggested it was a cultural and systemic issue which must be investigated independently.http://www.scoop.co.nz/stories/PA1203/S00195/green-party-asks-privacy-commissioner-to-step-in-on-acc.htm
“ACC has proposed to investigate itself but, given its history of mishandling people’s sensitive information, this would be highly inappropriate.
“ACC’s management and board and the Minister of ACC were all aware of repeated previous privacy breaches at the organisation, but failed to act to protect the public.
“The public can’t be expected to trust the organisation won’t perform a white wash. If we want to fix the problems at ACC, an investigation needs to be conducted by an independent body.”
Mr Hague this morning wrote to the Privacy Commissioner Marie Shroff requesting she investigate ACC’s processes and systemic mishandling of people’s private and sensitive data.
“I’ve been approached by many people, some of whom are being supported by the sensitive claims unit, seeking an investigation into the privacy breach,” Mr Hague said. “This is a serious issue that the Government was aware of and failed to act on — it requires public scrutiny.
“Government organisations can’t play with people lives like this. People need to know their private and sensitive information is safe.”
ACC failed to comply with its obligations under Privacy Principle 5: Storage and Security of Personal Information, and could therefore be dealt with by the Privacy Commissioner.
Note: Other high profile privacy breaches include the Ports of Auckland this week allegedly supplying right wing blogger Cameron Slater with a staff member’s personal information, and Paula Bennett supplying media with personal details of a beneficiary she had a public spat with.
Systemic issues at ACC include but are not limited to:
1. Reports that up to 50 ACC staff outside of the sensitive claims unit had access to information about individuals within the sensitive claims unit that they should not have had access to.
2. Reports that ACC was aware of the breach of privacy for over three months but did not inform any individual affected until the issue became public via the media.
3. The failures in the systems and processes that permitted such a significant breach of privacy to occur.
4. The actions of the CEO and the board of ACC once they were made aware of the privacy breach.
5. The fact that there have been other significant breaches of privacy at ACC within the last few years.
Labels:
Green Party,
Kevin Hague,
Marie Shroff,
press release,
privacy
Apology meaningless
An editorial from the Marlborough Express
http://www.stuff.co.nz/marlborough-express/news/opinion/6571581/Editorial-Apology-meaningless
There's an old saying that it's too late to be sorry. ACC needs to remember that.© 2012 Fairfax New Zealand Ltd
Chief executive Ralph Stewart yesterday apologised for the latest gaffe by his staff and said they would be calling or writing to 6748 clients with an apology after their privacy was breached when a spreadsheet containing the names and details of at least 9000 claims was emailed to a client. This is not the first time this sort of thing has happened.
The corporation handles some of the most personally sensitive information of any government department and has said before that it does everything to ensure its processes are robust and secure.
Clearly they are not.
The most worrying aspect of the latest security breach, however, is that senior ACC managers were told about it in December. A staffer asked for the information back but did nothing more to follow through.
The client also sent alerts to more than 50 ACC managers raising concerns about the security of information held by the sensitive claims unit, which deals with cases including claims of rape and sexual assault. Details on 250 clients of that unit were included in the mailout.
But it wasn't until the client talked to a Fairfax journalist that ACC started taking the situation seriously.
A spokeswoman said they wished they had done more to investigate and Mr Stewart said the breach had been poorly handled. He has bought into the philosophy that there is no point defending the indefensible, but he's too late and the apology is meaningless without an explanation of how the internal processes were breached and why nothing was done sooner.
ACC Minister Judith Collins and Privacy Commissioner Marie Shroff have asked Mr Stewart to provide an explanation, and these details should also be made public.
It is accepted that ACC deals with a huge number of cases each year, with claims involving contacts with multiple parties such as the claimant, the employer, medical organisations and care providers. Cases are handled by staff who are human and can add the wrong address to an outgoing email.
An organisation that operates in this environment will have appropriate checks and balances in place.
So it is a struggle to understand how a spreadsheet on 9000 claims can be attached to an email and find its way through that checking system to the wrong inbox.
http://www.stuff.co.nz/marlborough-express/news/opinion/6571581/Editorial-Apology-meaningless
Labels:
ACC board,
claimants,
editorial,
Judith Collins,
Marie Shroff,
Marlborough Express,
privacy
ACC breach 'poorly handled': Collins
An article from the Otago Daily Times by Hayden Donnell
http://www.odt.co.nz/news/national/201340/acc-breach-poorly-handled-collins
Minister for ACC Judith Collins has criticised her agency's "poorly handled'' response to a massive breach of claimants' information.© Allied Press Ltd 2012
ACC chief executive Ralph Stewart yesterday (Tue) confirmed an Auckland worker had accidentally attached a spreadsheet containing thousands of private records in an email to another client. About 9000 records were sent relating to about 6000 people, including 137 who had suffered injuries from sexual abuse or assault. The client told ACC in December about the information breach.
However, Ms Collins was only informed about the breach through media reports yesterday. She admitted the response had been "poorly handled" in an interview on Radio Live this morning.
"It has been poorly handled and I think the chief executive has confirmed that ... They need to improve their work in relation to privacy and they need to do that straight away."
When asked whether "heads will roll'' over the incident, Ms Collins said the agency would go through employment processes. She said the staff member who accidentally leaked the details was "extraordinarily distraught".
"It's a bit difficult to have people's heads rolling when the chief executive's pretty new, in there a couple of months.
"I understand there are obviously employment processes that they have to go through.
"But they're also saying to me there's no way the staff member meant to do anything wrong."
Ms Collins criticised the client who received the confidential records. The client allegedly used the information as leverage to make demands of ACC, Ms Collins said. "I'm certainly extremely disappointed.
"But I also have to look at the poor people who thought that their details might be published or were available. All of those claimants ... I feel incredibly sorry for them and it beggars belief that someone who had confidential details didn't give it straight back to ACC."
Privacy Commissioner Marie Shroff earlier said she was investigating the breach. "We've indicated to ACC that this is a 'please explain' situation," she said. "There are various criteria for seriousness, one is the numbers of people involved, one is how sensitive the information is, another is whether it puts people directly at risk ... This one is serious if it's proved to be correct because it involves extremely sensitive personal information, particularly around the sensitive claims area."
Ms Shroff said she could launch an investigation if she received a complaint about the breach, but could also launch her own inquiry if she felt the situation warranted it. "We've taken the obvious first steps to go to ACC ... once we get their response we'll make a call about how to proceed."
http://www.odt.co.nz/news/national/201340/acc-breach-poorly-handled-collins
Labels:
ACC board,
article,
claimants,
Judith Collins,
Marie Shroff,
ODT,
privacy
Subscribe to:
Posts (Atom)