TMCnet News

St. Louis Post-Dispatch Repps Hudson column
[June 12, 2006]

St. Louis Post-Dispatch Repps Hudson column


(St. Louis Post-Dispatch (KRT) Via Thomson Dialog NewsEdge) Jun. 11--The possibility that avian flu will sweep the United States and force many of us to telecommute from home raises this perplexing question: How can the public be assured that hospital, defense industry, government and other employees working from home will safeguard private personal information?

The dismal precedent, of course, was the Veterans Administration employee whose laptop was stolen from his home last month. The laptop contained the names and personal records of 26.5 million veterans.

It's unknown if the thief who broke into the VA employee's home has made use of the names and vital information with the potential for causing endless problems for the vets if misused.


However, if the VA's information security people were doing their jobs, the personal details on the laptop would be worthless because that data would be encrypted, password protected and therefore unavailable. That's a big "if."

During hearings before a joint hearing of two Senate committees investigating the theft and VA security, senators learned another disturbing fact: The employee had been taking the laptop home for three years, despite agency policy to the contrary.

A veterans group has sued the VA for $26.5 billion -- or $1,000 a veteran because of the harm this compromise of private information could cause.

Now let's assume that avian flu will affect millions of U.S. workers, either later this year or in a couple of years. Most experts on the flu and workplace behavior suggest that offices that can allow their workers to work from home should prepare to do so.

A big part of working from home or off-site will be using a company or agency computer -- or one the employee owns at home.

This challenge is one that Kevin Cross thought through several years ago. His solution is to keep abreast of best practices in information technology security.

"We have few laptop users, and the few will be at the executive level," said the administrative director of information technology operations for SSM Health Care.

SSM has its headquarters here, with hospital and healthcare facilities in Missouri, Illinois, Wisconsin and Oklahoma; it has 23,000 employees with 10,000 desktop computers. That's a lot of employees and computers to keep track of.

With so much highly sensitive patient and employee information in the electronic information system, Cross and others in his position have to work out tried-and-true procedures to protect sensitive information.

Solving that problem, at least in theory, gets SSM a long way toward safeguarding its prime data if avian flu should force most employees to work from home as they stay away from others and tend to their families.

"You can never do too much," Cross said. "We're always challenging ourselves."

Standard procedure at SSM is not to allow employees to store information on their hard drives -- only on its secure servers, and then in special-access sections. The data is encrypted and password protected -- with passwords changed at periodic intervals, like every 60 days.

Should avian flu hit areas where SSM operates, Cross anticipates that employees will work from home using their personal computers.

Other sectors that would have to work with more remote employees could include defense and financial.

The Boeing Co. had a computer-security problem last year when one of its laptops containing employees' Social Security numbers and bank account information was stolen. The defense contractor's security reputation took a hit.

"We now have the right tools and procedures in place, and training," said Kelly Donaghy, spokeswoman for Boeing's security operations.

At the Federal Reserve Bank of St. Louis, where highly sensitive information also resides in laptops, Vicki Kosydor, vice president of information technology, wasn't forthcoming in describing how the local Fed protects information.

"We take the role of central bank very seriously," she said. "Select employees can take laptops home."

What's on them? How are they protected?

"We can just say they are highly secured laptops," Kosydor said before cutting off the questions.

It's fair to say that many key people who are charged with ensuring their company's or agency's privileged information isn't compromised have been working diligently on this problem.

It's also fair to say we'll not know how successful their efforts have been until we're all tested by an epidemic like bird flu or a disaster of some kind, like an earthquake.

Let's hope they've done their jobs well -- and anticipated all the problems that might arise.

[ Back To TMCnet.com's Homepage ]