<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Pfizer: 17,000 Employees Suffer Privacy Breach</title>
	<atom:link href="http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/feed" rel="self" type="application/rss+xml" />
	<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/</link>
	<description>News, Comment and Conversation</description>
	<pubDate>Fri, 10 Feb 2012 22:19:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: On Pharma</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-77699</link>
		<dc:creator>On Pharma</dc:creator>
		<pubDate>Thu, 03 Jan 2008 20:47:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-77699</guid>
		<description>[...] Pharmalot reported that the personal data of 17,000 Pfizer employees (including social security numbers) was exposed, [...]</description>
		<content:encoded><![CDATA[<p>[...] Pharmalot reported that the personal data of 17,000 Pfizer employees (including social security numbers) was exposed, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lamparita</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-21028</link>
		<dc:creator>Lamparita</dc:creator>
		<pubDate>Mon, 01 Oct 2007 23:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-21028</guid>
		<description>Did anyone receive a second letter dated September 19 with updated information?</description>
		<content:encoded><![CDATA[<p>Did anyone receive a second letter dated September 19 with updated information?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trustedtoolkit</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-15359</link>
		<dc:creator>Trustedtoolkit</dc:creator>
		<pubDate>Tue, 17 Jul 2007 20:57:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-15359</guid>
		<description>Jim Kerr said:
"If they had our vault on the laptop this would not have occured. We have a product that safeguards sensitive information on any portable device. A fingerprint is required to access the data so even if the laptop was stolen the chances of getting at the data would be 7 to the tenth power."

Tell me how your "Vault" encryption solution would protect against the unauthorized transfer of data via a P2P application?</description>
		<content:encoded><![CDATA[<p>Jim Kerr said:<br />
&#8220;If they had our vault on the laptop this would not have occured. We have a product that safeguards sensitive information on any portable device. A fingerprint is required to access the data so even if the laptop was stolen the chances of getting at the data would be 7 to the tenth power.&#8221;</p>
<p>Tell me how your &#8220;Vault&#8221; encryption solution would protect against the unauthorized transfer of data via a P2P application?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Kerr</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-15241</link>
		<dc:creator>Jim Kerr</dc:creator>
		<pubDate>Fri, 13 Jul 2007 20:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-15241</guid>
		<description>If they had our vault on the laptop this would not have occured. We have a product that safeguards sensitive information on any portable device. A fingerprint is required to access the data so even if the laptop was stolen the chances of getting at the data would be 7 to the tenth power.</description>
		<content:encoded><![CDATA[<p>If they had our vault on the laptop this would not have occured. We have a product that safeguards sensitive information on any portable device. A fingerprint is required to access the data so even if the laptop was stolen the chances of getting at the data would be 7 to the tenth power.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack E. Dunning</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-10914</link>
		<dc:creator>Jack E. Dunning</dc:creator>
		<pubDate>Wed, 20 Jun 2007 19:18:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-10914</guid>
		<description>I would like to know what consumer personal medical data Pfizer has and from what sources they collected it.  Especially after the recent breach, and the fact a laptop computer with employee sensitive data "...was provided to a Pfizer colleague for use in her home."  This is nuts!  Not too long ago I was involved in a lawsuit by Privacy Rights Clearinghouse against Albertson's/OSCO for selling my prescription information to drug companies.  If the pharmaceutical industry is manipulating our private information for profit, the individual should at least have control, and be compensated when it is sold.  You can read more in my blog, "The Dunning Letter" at: http://thedunningletter.blogspot.com/search?q=hipaa

Jack E. Dunning
Cave Creek, AZ</description>
		<content:encoded><![CDATA[<p>I would like to know what consumer personal medical data Pfizer has and from what sources they collected it.  Especially after the recent breach, and the fact a laptop computer with employee sensitive data &#8220;&#8230;was provided to a Pfizer colleague for use in her home.&#8221;  This is nuts!  Not too long ago I was involved in a lawsuit by Privacy Rights Clearinghouse against Albertson&#8217;s/OSCO for selling my prescription information to drug companies.  If the pharmaceutical industry is manipulating our private information for profit, the individual should at least have control, and be compensated when it is sold.  You can read more in my blog, &#8220;The Dunning Letter&#8221; at: <a href="http://thedunningletter.blogspot.com/search?q=hipaa" rel="nofollow">http://thedunningletter.blogspot.com/search?q=hipaa</a></p>
<p>Jack E. Dunning<br />
Cave Creek, AZ</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-10256</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Tue, 19 Jun 2007 14:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-10256</guid>
		<description>What can we do as individuals or corporations to keep personal information safe?  We need to come up with some kind of solution or we may all become a victim some day.  In our recent post we ask if anybody is truely safe from a data breach.

http://www.ecorablog.com/the_compliance_and_securi/2007/06/is_it_inevitabl.html</description>
		<content:encoded><![CDATA[<p>What can we do as individuals or corporations to keep personal information safe?  We need to come up with some kind of solution or we may all become a victim some day.  In our recent post we ask if anybody is truely safe from a data breach.</p>
<p><a href="http://www.ecorablog.com/the_compliance_and_securi/2007/06/is_it_inevitabl.html" rel="nofollow">http://www.ecorablog.com/the_compliance_and_securi/2007/06/is_it_inevitabl.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Herberg</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-9090</link>
		<dc:creator>Craig Herberg</dc:creator>
		<pubDate>Mon, 18 Jun 2007 00:23:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-9090</guid>
		<description>This problem is probably much more widespread than most people think.  Employees have far too much confidential data on laptop computers.  Regardless how tightly controlled internal systems are maintained by proactive IT units, compromised remote computers accessing any internal systems -- such as email -- can compromise the entire enterprise, including its employees and clients.  Unfortunately, keyloggers and remote access trojans are commonplace on computers in the field.  Organizations that allow employees to possess or access confidential or proprietary data need to have policies and practices to reduce the risk of breach.  These P &#38; Ps must include remote computers, including those not owned by the company.</description>
		<content:encoded><![CDATA[<p>This problem is probably much more widespread than most people think.  Employees have far too much confidential data on laptop computers.  Regardless how tightly controlled internal systems are maintained by proactive IT units, compromised remote computers accessing any internal systems &#8212; such as email &#8212; can compromise the entire enterprise, including its employees and clients.  Unfortunately, keyloggers and remote access trojans are commonplace on computers in the field.  Organizations that allow employees to possess or access confidential or proprietary data need to have policies and practices to reduce the risk of breach.  These P &amp; Ps must include remote computers, including those not owned by the company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-7243</link>
		<dc:creator>me</dc:creator>
		<pubDate>Fri, 15 Jun 2007 14:43:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-7243</guid>
		<description>Once the laptop is logged into, with or w/out encryption s/w, the data is available.  Encryption is primarily for unauthorized access such as when the laptop/workstation is lost or stolen to prevent access.  

The other comment is correct - why are employees allowed Administrative Access to install whatever they want?  Pfizer should fire the IT Executive who allowed this.</description>
		<content:encoded><![CDATA[<p>Once the laptop is logged into, with or w/out encryption s/w, the data is available.  Encryption is primarily for unauthorized access such as when the laptop/workstation is lost or stolen to prevent access.  </p>
<p>The other comment is correct - why are employees allowed Administrative Access to install whatever they want?  Pfizer should fire the IT Executive who allowed this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jcr</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-6085</link>
		<dc:creator>jcr</dc:creator>
		<pubDate>Wed, 13 Jun 2007 13:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-6085</guid>
		<description>So, why would a company allow employees to log into laptops/desktops with sufficient authority/credentials to install software (which could/would include mailware as well, BTW)?  Why would a company not have hard drive encryption deployed on all laptops as a standard?  Sounds like change management practices are lacking, not just data security!</description>
		<content:encoded><![CDATA[<p>So, why would a company allow employees to log into laptops/desktops with sufficient authority/credentials to install software (which could/would include mailware as well, BTW)?  Why would a company not have hard drive encryption deployed on all laptops as a standard?  Sounds like change management practices are lacking, not just data security!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Former_PNU_Geek</title>
		<link>http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-6084</link>
		<dc:creator>Former_PNU_Geek</dc:creator>
		<pubDate>Wed, 13 Jun 2007 13:08:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.pharmalot.com/2007/06/pfizer-17000-employees-suffer-privacy-breach/#comment-6084</guid>
		<description>Although I'm sure some improvements have been made, expect it to happen again. -- I've spent years working for IT in and around its largest manufacturing base (in the US) and I've seen many areas where it's needed to improve on data security.

I wonder Dorothy Jeter (mother to Derek Jeter) had her info in that mix.. - That alone would probably do well to rack up the sale rate on this batch of stolen data.</description>
		<content:encoded><![CDATA[<p>Although I&#8217;m sure some improvements have been made, expect it to happen again. &#8212; I&#8217;ve spent years working for IT in and around its largest manufacturing base (in the US) and I&#8217;ve seen many areas where it&#8217;s needed to improve on data security.</p>
<p>I wonder Dorothy Jeter (mother to Derek Jeter) had her info in that mix.. - That alone would probably do well to rack up the sale rate on this batch of stolen data.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.160 seconds -->

