De La Rosa on Illuminate Education breach and vendor accountability
De La Rosa details the Illuminate breach where 380,000 families were not informed for over two years. Doyle explains the timeline of forensic investigations and notifications. De La Rosa asks if DOE drops vendors who fail to report breaches; Doyle confirms DOE stopped doing business with Illuminate Education after the breach.
Have we before?
Yeah, have you, would you, did you?
Yeah.
Yeah, in the case of Illuminate Education, for example, that was a data breach that happened about four years ago.
There was a pretty wide-scale breach that happened, and New York City public schools decided that we're no longer going to be doing business with that vendor.
Okay.
Good.
So they failed to report for two years.
And then once you found out about the breach, how long did it take?
Take the DOE to report to the state the data breach.
I'm sorry, but what was the...
You just said that...
The two years?
How long did it take for Illuminate to report to you after the data breach that there was a data breach?
I think what happened with Illuminate, and this precedes my tenure and my current role, but
Illuminate informed us of an incident, but they didn't completely categorize it as a data breach until several weeks afterwards.
I think it was a few months before they officially deemed it a data breach.
And so it was a matter of a few months from the time of the incident to the time that we were officially notified of a data breach.
Well, in the Illuminate incident, 380,000 families were not informed.
This is what the contract you brought up, 380,000 families were not informed until May of 2024, more than two years after the incident.
And seven months after Illuminate had informed the DOE.
Of the additional students involved, according to the DOE website.
Delays in informing families can have devastating consequences because children are a top target for identity theft since they don't have credit ratings.
What's the explanation?
I mean, these are inordinate delays.
So what I'm asking about is the delays with the DOE.
What explains the delays between the DOE and the reporting of this information according to the controller's report?
Well, for the Illuminate case, there was actually, so there was the initial incident.
We eventually received the information necessary to make the notifications, which is often part of the difficulty and the delay in getting the notifications out as we rely on the vendors to get us that data as soon as possible.
That can often take months.
Forensic investigations have to be completed before we get that information.
As soon as we got that information, which was about four or five months after the initial incident, we sent out the notifications.
I think it was about a year and a half later, Illuminate came back to us and informed us that they had actually discovered that additional students had been impacted
and that they had not initially informed us of.
Again, we had to go through that process of obtaining the data from them, the whole forensic investigation, and go through our process of matching that with our own records so we can send out notifications, translate letters, all of that, get that done as soon as we could.
The controller found the DOE failed to report breaches to families within the required 60-day time frame.
Obviously, parents kind of act to protect their children's information or work to mitigate damage from a breach if they're not told in a timely fashion that their child's information was disclosed.
So what steps has the DOE taken to fix these lapses?
Yeah, that's a good question, too.
I mean, I think, again, a lot of this goes back to our training and awareness programs, making sure that our staff are completing the training is very important, and we're pushing to get that, like I said before, to a much higher number.
No, no, I know.
Sorry.
I'm talking about when the DOE, not when like an individual teacher or school, I'm talking about when DOE Central gets this sort of information.
Unless it's the policy that an individual teacher or principal submits this information to the state.
We would consider the date of discovery to be the date that the principal at the school learns of an incident.
And then sometimes there can be a gap between them reporting that back up to the student privacy office so that we can then turn around and send the notifications.
And when we do send the notifications, when it is a cybersecurity incident like in the case of Illuminate, we also do extend free credit monitoring and identity theft protections to students, which is...
Sorry, you do that or the vendor does?
We do that.
Why do you...
Well, the vendor reimburses us for it.
Okay.