How Little Data Breaches Cause Big Problems

Justin Bathon · T.H.E. Journal Technological Horizons in Education · 2013

Strict state laws leave little room for error when it comes to securing student information. Fortunately, beefing up data security policies does more than safeguard students. Outside a typical American middle school, papers were blowing around in the wind be side a garbage container. A student, seeing the papers, grabbed some and read about the special needs assessment for a seventh-grader named Kevin, including his IQ score, psychological assessment data, behavioral information, and family history. Some time later, the prying student and his friends were passing Kevin's private information around the school. It doesn't take a career educator to guess what happened next Over the next few weeks, students relentlessly taunted Kevin, calling him stupid, dumb, and retarded. They might just as well have applied the first of those adjectives to their school. In one careless stroke, the school's poor data security practices had led to the direct harm of one of its students. [ILLUSTRATION OMITTED] Unfortunately, this cautionary tale isn't apocryphal. Part of a very real case out of Minnesota, it not only points out the ethical need to secure student data, but highlights the legal implications of failing to do so. Kevin's family sued the school district, and at the trial court, the jury returned a verdict that found the district liable for $60,000 in past damages and $80,000 in future damages--and also awarded more than $45,000 in legal fees to the family (although the legal fees were later reduced on appeal). [ILLUSTRATION OMITTED] Breaches Big and Small These days, schools across the country are being held to a rigorous legal standard for data security--one that leaves little room for error, but substantial room for legal It's an age where a missent e-mail with student data can represent enormous liabilities, and a lost laptop can cause concern and dramatic newspaper headlines. Of course, such accidental breaches are only part of the story. Students also actively try to hack into school networks. The number and scope of data breaches in schools can be alarming, and the examples are plentiful. In fact, there is so much data to secure, and so much room for error in securing it, that the US Department of Education has stepped in and created the Privacy Technical Assistance Center to help educational institutions with data privacy, confidentiality, and security practices. Among the center's resources is the Data Breach Response Checklist, an exhaustive document developed in part to help protect schools and districts, because, as the ED readily admits in the checklist, efficient incident handling will also help reduce organizational liability. In some cases, the data that puts schools at risk in the first place is not entirely under their control. A report out of the Fordham University School of Law found that states collect far more data than is required under federal law, often storing it in robust student information systems maintained at the state level. The data systems themselves were also poorly regulated because the states lacked policies on retention and purging. Overall, the study found that many states provide obscure, incomplete, or difficult to decipher information about their data practices and programs. While the study mostly examined state-level data systems, local data systems rely on these state student information data contracts, and information is often shared between local and state datasets. Furthermore, local officials are mostly responsible for data input into these vast systems, which makes them accountable for any future breach that may occur as a result of improper data sharing. Policy in Place The existing law governing data security in schools begins with the federal Family Educational Rights and Privacy Act (FERPA), which requires schools to keep student records private, only sharing them with parents or guardians. …

Read the paper · More papers on PaperTik