news-record.com

NEWS

Advertisement | Advertise with Us

Hacker hits UNC-Chapel Hill study data on 236,000 women

Friday, September 25, 2009
(Updated 8:03 am)

CHAPEL HILL (MCT) — A hacker has infiltrated a computer server housing the personal data of 236,000 women enrolled in a UNC-Chapel Hill research study.

Among the information exposed: the Social Security numbers of 163,000 study participants.

Though the intrusion was detected in late July, computer forensics experts say it may have happened two years ago, said Matthew Mauro, chairman of the UNC-CH Department of Radiology.

And though UNC-CH officials and a private computer forensic expert have spent two months investigating, they still don't know who did the hacking, where the attack originated, or even whether data was downloaded.

''There's no direct evidence that any information has been removed," Mauro said. "But we can't say for sure."

The compromised server had all required security measures, Mauro said. It was one of two servers housing data on more than 662,000 women. The data are part of the Carolina Mammography Registry, a 14-year-old project that compiles and analyzes mammography results submitted by radiologists across the state.

The data are submitted to UNC-CH electronically; that process will now be tightened up, Mauro said.

Until several years ago, Social Security numbers were used as patient identification codes, which is why that information was part of some, but not all, patient files.

The project is funded by a five-year National Institutes of Health grant worth more than $2 million. Mauro and the project's chief researcher, Bonnie Yankaskas, say they hope the security breach doesn't affect future federal funding.

A spokeswoman for the NIH declined to comment Thursday.

''This is the worst thing that could possibly happen," said Yankaskas, who has led the project since its inception. "It's the kind of thing that, in 1995, we didn't even think about. We go through all these measures to make everything secure, and then a hacker comes along and turns it upside down. I'm devastated."

Universities are popular targets for hackers because, unlike private corporations, their computing systems are largely decentralized, said Karen McCall, a UNC Health Care spokeswoman. Thus, security breaches aren't always detected quickly.

While they didn't find evidence that files were downloaded, investigators did find traces of viruses dating to 2007, Mauro said, an indication that the registry had been compromised for that long.

''Once they gain access to a system, they are often just taking a peek," said John Snyder of Net Friends, a Durham security firm. "They may have accessed many systems, and they'll get to you when they get to you."

Snyder cautioned that information may have been taken even if there were no traces of that happening.

''It's pretty easy to make a copy of something to an external source and cover your tracks," he said.

The hacked server has been taken down, its data removed, and the intrusion has prompted a broad examination of computer server security across the medical school, Mauro said. The medical school alone has about 580 servers housing research and clinical data. That does not include UNC Hospitals' patient files, which are maintained separately.

In coming days, the medical school will send letters to all 236,000 study participants about the security breach. School officials said they held off on notifying participants until they had completed their investigation and would be able to field questions.

For 14 years, the research project has studied the practice of mammography and helped identify breast cancer risk factors and improve early detection.

''I know women will be upset by this," said Yankaskas, the lead researcher. "I'm hoping they will appreciate the good this project is doing and let us continue."

Comments

This article has been closed to new comments. Comments are generally closed after 14 days. However, comments may be closed earlier at the discretion of the News & Record.

Inappropriate content? Please report abuse.

frustrated

September 27, 2009 - 10:50 am EDT

I hope no one is really surprised. There was probably no anti-virus software, email and server passwords would not meet State Auditor recommendations. State Auditors do there job by auditing Universities; however, UNC Universities have a tendency to say we do not concur with State Auditor Findings. If students, faculty and staff realized how insecure there data was they would be absolutely livid. Security Managers at Universities do not have the credentials to manage the sensitive data of students, faculty, staff and alumni.

IT CEO do not have the credentials to be IT CEOs. In other words how much sense does it make to make a Biology Major a IT CEO??? Technology is becoming more complex everyday. People are under the impression that technology experts have the expertise to track who sent and email by IP address. WRONG its only tracked to the ISP provider! ISP IP address are roaming which means they change everytime you open a new IE Browser. The software tools that state that they can do this can only identify the city and state of the person.

IT staff that work with Federal and State are working short handed therefore it is necessary that they work from home sometimes using there own personal computers because there is no money to supply necessary equipment for them to work from home. But yet HR has not put any policies in place to re-coop this information when the employee retires, layed off or fired. So the secure data remains on personal desktops and laptops that belong to the retiree or dismissed employee.

University IT employees normally understand and make recommendations but Administrations refuse to listen and normally look at the employees as troublemakers and start the retaliation process. So problems like this eventually occur. Yes you are correct all systems have some vulnerability including banks. But preventions must be put in place.

Did anyone notice that this article did not explain how the hacker got in. If this happened 2 years ago where is the State Auditors IT Security Audit findings that is public information. I sure would like to see it and I would like to know why hasn't it been made available to the public.

frustrated

September 27, 2009 - 10:54 am EDT

And why were they using Social Security numbers this is against State Policy??

eMail Updates

Advertisement | Advertise with Us

Featured Ads

Search

Advertisement | Advertise with Us
Advertisement | Advertise with Us
Advertisement | Advertise with Us

News & Record Network Sites

Triad Weather

  • Current Condition: FAIR
  • Current Temperature: 67°
  • UV Idx: 0
  • Forecast High/Low: H: 85° L: 62°

User Tools

  • Social Networking
  • RSS
  • Share
  • Sign in to MyNR

Search