Advertisement
*
Reproduction permitted for personal use only. For reprints and reprint permission, contact reprints@wistechnology.com.

DHFS to end practice of using Social Security numbers for ID

Kevin Hayden
Madison, Wis. - Kevin Hayden, secretary of the Wisconsin Department of Health and Family Services, has told a State Assembly committee that his department is working with Electronic Data Systems to change identification numbers to a unique 10 digit number that does not include the Social Security numbers of Wisconsin residents enrolled in state healthcare programs.

Hayden and Roger Ervin, secretary of the Department of Revenue, testified on recent security breaches Thursday before the Assembly Committee on Consumer Protection and Personal Privacy. They were on hand to explain what their respective departments are doing to prevent future release of Social Security numbers and other sensitive information.

Their testimony came after the Social Security numbers of hundreds of thousands of state residents were exposed in recent mailings. The breaches include the visible mailing of more than 260,000 Social Security numbers along with an informational booklet about Senior Care, and the mailing of as many as 5,000 new tax mailings from the DOR that went out with Social Security numbers in full view. It was the second data breach associated with DOR in the past 13 months; in late 2006, a DOR contractor took the blame for sending 171,000 tax booklets with the recipients' Social Security numbers on the cover.

Both secretaries described the steps that have been taken to prevent future mistakes. “We recognize the need for ongoing vigilance in this area,” Hayden said.

Hayden said the current 10-digit number system, which includes Social Security numbers, will be replaced with a "pseudo" identifying number that is not based on the Social Security numbers.

According to an incident report, Hayden said an EDS employee failed to follow privacy procedures as part of a mail merge. The employee, who has been fired, failed to review the contents of that file to ensure that sensitive information was not included in the mailing. Hayden said the error was detected before an additional 237,000 mailings were sent out.

After the emailing went out, DHFS directed EDS to put free credit monitoring in place to protect affected residents from identity theft, and the company has agreed to offer of free credit monitoring and cover all expenses associated with the error.

Hayden also has asked Wisconsin Attorney General J.B. Van Hollen to consider legal action against EDS.

“Confidential information should never have been printed,” Hayden said, “and this failure has exposed our [program] members to identity theft."

DOA/DOR

Michael Morgan, secretary of the Department of Administration, could not attend the hearing due to the death of his father in law. In his stead, Deputy Secretary Dan Schooff told the committee he is confident the department has systems in place to monitor security, including a scanning technology that does 8,000 scans an hour and is connected to law enforcement agencies.

Across state agencies, he said employees with access to confidential information are required to sign confidentiality agreements, “but clearly more has to be done.”

Schooff noted that Gov. Jim Doyle has asked Metavante, Inc., to review state security practices and procedures, and the company has agreed to do so free of charge by the first week of April and share what it learns with the committee.

Wisconsin is the only Midwestern state that still uses Social Security numbers as personal identifiers, a practice that many believe has outlived its usefulness - especially in the electronic age. Schooff said policy makers have used Social Security numbers because they were the unique identifier provided by the federal governmnt, which still uses them in some cases.

Ultimately, Ervin said the best way to ensure security is to disaggregate Social Security numbers across government and make them worthless in terms of market value. That entails a specific identifier for the Department of Revenue, an underlying password, and then linking these identifiers to individual Social Security numbers to create multiple layers of security.

Ervin said DOR looks forward to working with Metavante to assess its security weaknesses. He said the DOR has completed an audit of its entire security profile, and has already made changes and will make more in the future with respect to its practices, policies, and infrastructure improvement.

Prior to holidays, Ervin said the DOR began an assessment of its security plan. “We can never give up understanding where we can improve," he said. "We will focus on physical security, employee policies, education, and training. Each employee in DOR has to under go security training and sign confidentiality contracts.”

Related stories

Department of Health and Family Services cancels technology-related Request for Proposal

Extracting and redacting: Is solution to state's privacy fumbles right in its own back yard?

Doyle asks Metavante to investigate state data breaches

Comments

TopsyTurvey responded 5 months ago: #1

According to the IRS, social security numbers are solely for tax reporting purposes. Yet, organizations continue to misuse this data as a personal identity number; which was ironically the main reason SSN numbers were bitterly opposed by many thoughtful people when first suggested. I've been learning to just "SAY NO" when people ask for my SSN for no other reason than laziness in managing their databases. I've never had to give it out once I've refused on grounds that it's an unauthorized use of social security numbers. Glad the Wisconsin government is finally getting smart, but you were certainly slow learners. Those third parties cannot abuse SSN data and expose people to ID-Theft if you do not give them the data!!! Sadly, the only reason you likely responded at all, is that it started costing you money to pay for credit watches.

numbers?! responded 4 months ago: #2

Nice of the state to finally take some action. I am currently a victim of the states blunder in the printing of social security numbers and they are paying for my credit to be monitored. What is even more interesting is that in order to receive benfits I have to make monthly payments. No big deal right? I did not think so until I had to print my ID number on my check. That ID number happens to be my social security number! The state is telling me I have to give someone, part-time data entry employee, my bank routing number, and my checking account number with my social security number. What a nice, neat little package. I'm sure the issue will be resolved in some 3 years though!

-Add Your Comment

Name:
E-mail:

Comment Policy: WTN News accepts comments that are on-topic and do not contain advertisements, profanity or personal attacks. Comments represent the views of the individuals who post them and do not necessarily represent the views of WTN Media or our partners, advertisers, or sources.

WTN Media cannot accept liability for the content of comments posted here or verify their accuracy. If you believe this comment section is being abused, contact edit@wistechnology.com.

Advertisement
Advertisement
WTN Media Presents