This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 319 To_xml

SUMMARY

Social Security numbers, names, and medical records for 930,000 on stolen server
Records 969,000
Record Types SSN NAA DOB
Breach Type Stolen Computer
Data Family Electronic
Source Outside
Organization Medical Excess, LLC
Other Affected/Involved Organizations American International Group (AIG)
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: Anonymous

TIMELINE

DateEvent
2006-03-31 Incident Occurred
2006-04-01 Incident Discovered By Organization
2006-06-14 Organization Reports Incident
2006-06-22 Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
1,400,000 2006-10-26 Affiliated Computer Services (ACS), Colorado Department of Human Services
550,000 2007-12-29 Administrative Systems, Milwaukee Public School, The Baltimore Life Insurance Companies
700,000 2008-04-19 Central Collection Bureau

MAP OF INCIDENT LOCATION

Address: USA
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $58,140,000.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

PRIMARY SOURCES

Primary Source ID: 383

add details to this primary source Description
American International Group, Inc (AIG) breach notification - A server stolen from a locked room contained personal data, including names, addresses and DOB for 28,798 residents of New York. Total affected were 969,000
FilenameSourceResearcher Incident IDs
AIG-20060401.PDFNew York State Consumer Protection Boardcwalsh 319
RecordsFile DateUploadedUpdated
28798 2006-06-21 2008-12-04 23 Sep 15:58
Excerpt
383

Jun-2l-ZD06 03:35pm From-AIG MEDlCAL EXCESS +Tl4—dZ·lE-363l T-QAZ P.U0l/007 F-385 Medical Excess ` . . ` One MacArthur Place, Suite 520 South Coast Metro, CA 92727 Phone: (714) 436-3609 Toll Free; (B...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 367

add details to this primary source Description
Breach notification of Medical Excess LLC, server and computers stolen containing sensitive information.
FilenameSourceResearcher Incident IDs
AIG-20060401-NC.PDFNorth Carolina Department of Justice, Consumer Protection Divisioncwalsh 319
RecordsFile DateUploadedUpdated
21381 2006-03-31 2008-12-04 23 Sep 15:52
Excerpt
367

North ('aruliuu Security Breach Reporting Form Pursuuiit to thc Identity Thcft Protection Act oI`2Ui)5 \;t:i;c of Busiiacss O ming or Liccztsing Iuiigtuzitiou ;·'\I`I`cclctl hy the I’I.PZAi5E SI¥B§\I...

Click here for the Full Details | Download Raw PDF

Primary Source ID: 606

add details to this primary source Description
Social Security numbers, names, and medical records for 969,000 on stolen Medical Excess server, including 28,798 New York residents
FilenameSourceResearcher Incident IDs
MedExcess-20060401.PDFNew York State Consumer Protection Boardcwalsh 319
RecordsFile DateUploadedUpdated
28798 2006-06-21 2008-12-04 23 Sep 17:20
Excerpt
606

Jun—2(-ZDUB 03:35pm Fr¤m—AlG MEDICAL EXCESS +Tl4-435-3E3l T-842 Prin)/007 F-386 Medical Excess " . , ` One MacArthur Place, Suite 520 South Coast Metro, CA 92727 Phone: (714) 436-3609 Toll Free; (BOO...

Click here for the Full Details | Download Raw PDF

COMMENTS

New Comment

simple_captcha.jpg
(type the code from the image)

Sponsored By: Credant_200x51 Tenable Pgp_logo Zecurion
Permission is granted to use this database in non-profit works and research. Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation for commercial interests requires authorization and licensing arrangements. For more information, please e-mail curators@datalossdb.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2010, Open Security Foundation, All Rights Reserved.