One of the benefits of a software like Alertsec is that many governments do not require notifications of security breaches when the data in question was encrypted. However, in the United States of the exceptions to this is the tiny state of New Hampshire. In New Hampshire a company is required to report a data breach notification even if sensitive information was encrypted.
Normandeau Associates Reports Stolen Laptop
So just recently, Normandeau Associates filed a letter with the Attorney General when a laptop was stolen. According to the letter filed with the AG, a computer with personal information of 277 NH residents (who knows how many more people living in other states were affected) was stolen from an employee’s home in November 2008. The laptop theft was recovered in February 2009. However, somehow the fact that the laptop was stolen did not come to light until June 2009.
According to a copy of the letter sent to affected residents, the laptop contained a database of past and current Normandeau employees, including SSNs, names, and bank account numbers.
Confidential Data on the Laptop
So, why was this database on the laptop computer? The official letter explained:
Normandeau has policies that prohibit personal information from being downloaded onto its laptop computers. In this instance, the database was temporarily stored on the laptop during restorative maintenance to the company’s network, and contrary to company policy, not thereafter removed. The company took action against the responsible person for unintentionally failing to remove the database containing the personal information as required by company policy. No further precautionary actions were required to prevent similar breaches.
But the letter also noted:
The perpetrator required specific computer software to access the encrypted database in its existing format on the laptop, and it is unknown if access was actually made.
Levels Of Encryption
That last note explains why states like New Hampshire require reporting even when data is encrypted. There are different levels of encryption, and depending on how strong (or weak) the database’s encryption happens to be, there could have been a data breach.
The most common example of encryption is password protection used in Microsoft Office Products like Word and Excel. However, the encryption used is primitive at best. A simple search on the Internet will yield software that is inexpensive and often free that will allow for the breaking of this basic encryption.
While the letter from Normandeau does not identify the encryption that was used, it does say “required specific computer software to access the encrypted database” which points out that the encyrption was not on the entire laptop – but just on this database.
Hard drive encryption is used in order to encrypt all data stored on a hard drive. With a program like Alertsec all installed programs, files and system settings are encrypted. This makes it impossible for an unauthorized person to read your files.
All encryption is not equal – but Alertsec will provide a high level of encryption for minimal cost and expenditure of time.

This month the United States Naval Hospital in Pensacola, Florida began
A Spring 2009
This leads to any number of questions. Why is a government contractor collecting SSNs? Why didn’t the government contractor
Let’s compare:
