Title: Curves Leaves Working Computer Full Of Personal Information In An Office Dumpster - Alex Chasick- The Consumerist
Date: 08/03/08
Business Activities: Breach Response, Security - Technical Safeguards
Impact to Subscriber: A blogger posts online the discovery of a computer containing personal information after being unable to reach the manager of the affected organization.
Authority:
Risk Guidance:
Control Guidance:

Relevance:
Background Facts:
  • a blogger reported a security breach at a Curves franchise in Vancouver, Washington.

Relevance to Business Activities:

  • security - physical and technical safeguards considerations:
    • a blogger's relative found a working computer in a dumpster, containing:
      • employees' phone numbers; and
      • customers' addresses.
    • no billing information, if any existed, was exposed;
    • the Curves database, potentially containing credit card information, was encrypted; however:
      • the blogger claimed that extracting the information from the database would be trivial.

 

  •  breach response considerations:
    • the blogger contacted:
      • Curves corporate office:
        • said that although each franchise is responsible for its own IT and privacy policies:
          • the franchise's actions were inappropriate; and
          • they would get in touch with the franchise.
        • asked the blogger to wipe the hard drive.
      • the manager of the franchise:
        • who was busy or not available:
          • left a message inviting him to read his online post of the incident.

Additional Consideration:

  • the blogger returned the computer and hard drive to its owner.

Source Documents:

http://consumerist.com/tag/curves/?i=5022090&t=curves-leaves-working-computer-full-of-personal-information-in-an-office-dumpster

http://awaitinginspiration.com/dear-curves-respect-your-client-and-employee-data/

Privacy Statement · Legal notice