The latest bad news from the Department of Health and Human Services is that a bored, unhappy patient at the state psychiatric hospital copied the protected health data and personal information of some 15,000 DHHS clients off a computer in the hospital library in October 2015. A year later, he posted some of it – including medical records and Social Security numbers– on Facebook.
This stunning revelation came just a week after the release of a hard-hitting report from an independent consultant who said the Division for Children Youth and Families, which like the hospital is part of DHHS, cannot do its job to protect kids because, among other serious problems, the staff at DCYF is overworked and stressed out.
Twice in the final days of U.S. Sen. Maggie Hassan’s tenure as governor, we have learned of different, but troubling concerns about HHS and the security of the state’s computer network, both of which had placed vulnerable citizens at risk.
We applaud our new governor, Chris Sununu, who in his inaugural address yesterday forcefully called on lawmakers “to act without delay” to make sure kids are safe. We urge the governor to insist on the same urgency in getting to the bottom of the DHHS data breach.
Here’s what we know. In October 2015, a staffer at the hospital library noticed that the patient had accessed “unauthorized” but not confidential DHHS files and reported that to a supervisor. His computer use was suspended; records show staff from the Department of Information Technology was called in. But no one higher up, at the hospital, DHHS or even DoIT was alerted to this obvious red flag. In an age of fear about cybersecurity and identity theft, that was inexcusable negligence.
The following August, a hospital security official reported that the same individual had posted some DHHS training material on Facebook. State police, DoIT and DHHS were notified; the conclusion was no confidential information had been breached.
A month later, investigators were told that they didn’t have enough evidence to obtain a search warrant; attempts to locate the former patient were unsuccessful. Two more months passed.
Late on Friday, Nov. 4, 2016, DHHS learned the same individual posted confidential DHHS data on Facebook. State officials took it down in 24 hours and the attorney general’s office began a criminal investigation. But the breach was not disclosed to the public by state officials until Dec. 27, 53 days later. DHHS says it took that long to determine the extent of the breach; a private cyber security expert had to help.
We don’t believe that justifies the long delay in warning DHHS clients of the risk of identity fraud or theft.
It seems to us that responsibility also falls on the state Department of Information Technology, which is charged with maintaining the security of the state’s computer network. We agree with a reader who noted the seemingly nonchalant attitude of DIT Commissioner Denis Goulet. He told reporters that a “subtle configuration change” made by someone in the library made it possible for a person with average computer skills and “a good dose of inquisitiveness” to access confidential files. Is this possible elsewhere in state government?
As was the case in high-visibility child abuse cases, state officials say they cannot discuss details of the data breach because it is an active criminal case. To us, that is too often an excuse for shutting down access to information important to public protection and government oversight and could be released without compromising an ongoing investigation.
Gov. Sununu and the Legislature need to hold those responsible accountable for these failings. They need to make the necessary corrections and, in the case of DCYF, institute reforms, and supply long-overdue financial support. “Let’s get it done, guys,” Sununu said closing out his remarks yesterday.
We couldn’t agree more.
