This middle-aged computer geek has been in love with the idea of going high tech for everything since I was in high school. Except for one area -- good old fashioned paper and fountain pens for taking notes and keeping a calendar.
My favorite thing about Bank of America is that I don't need an envelope or deposit slip at the ATM. I rarely write checks by hand and I don't use check registers. I check my balances online and download my statements each month. I'm holding off on buying an iPad because I don't want to pay for a subscription to the hard copy of a magazine. I don't want the paper clutter and I want a discount for not consuming the paper.
But calendars and notes are different. During one of my stints of being unemployed, I listened to a recruiter complain that his computer was down and, therefore, he couldn't check his calendar about setting up an interview for me. I told him that I preferred to use a paper calendar for that so that I can check it immediately. I can't imagine having to fire up my computer or futz with my smartphone to check a date and time on an electronic calendar. Once upon a time smart families and efficient small offices would hot sync Palm Pilots so that everyone would know everyone's schedule, but Palm Pilots are rarely used today.
As for notes, it's much easier for to take a pad and jot down notes, especially at meetings. At work, I've often just typed out details, contacts and notes on what needed to be followed up to update the higher ups on the status of projects. Recently, I discovered a way to combine both an agenda and meeting and project notes. It's called the Rhodia Meeting Book, a complimentary copy of which I was sent to me by Exaclair, which is well-known for high quality paper goods. Other lines include Excompta, Quo Vadis, Clairefontaine and G. Lalo. Fountain pen lovers are probably also familiar with it the inks from its division, J. Herbin. All their paper is thick enough to be fountain-pen friendly. I'm a southpaw, and I find that fountain pens are easier to write with and make my handwriting more legible.

What I love about the Rhodia Meeting Book is its well-thought out layout. There's ample room for writing the goal of the project or a synopsis of a meeting, contacts, notes and steps to be taken and by whom. Color code additional note, such as for follow-up, and it's a lot more efficient and easier to read than a black and white print out of a Word document or Excel spreadsheet. Of course, you can do that and tape it onto one of the pages. Rhodia paper is heavy enough to withstanding tugging.
My wife, a fully participating member of the Sandwich Generation, introduced me to Rhodia products, and she has a sizable collection of their various notepads. She says she cannot be "tethered" to her computer for calendars, articles she's writing, even correspondence. Paper "liberates" her. And, trust me, she's no slouch when it comes to using technology.
No doubt computers have changed the way we do work and the way we live. My paper calendar and Rhodia Meeting Book make all that better, even with up-to-date technology. My biggest problem? The temptation to buy more is too easy. I work just a few blocks from Art Brown, which sells a wide variety of Rhodia products as well as fountain pens and inks.
At home, I'm the nag. I am always nagging my wife to back up her computer. She claims she's busy with our son, working, doing laundry, yadda, yadda, yadda. Guess what happened? She nearly lost all her data, including ad copy write-ups she is contractually obligated to keep for two years. She admitted that she hadn't backed up since October 2010.
How this happened is beyond me. We have anti-virus software running on all the computers in the house. For the record, we really thought CA, which we got through Cablevision at no extra charge, was the best. Unfortunately, it didn't work with Windows 7. I should really look into that now since Windows 7 has been around for a long time. I read recently that Windows 7 is pretty resistant to malware, but here's what happened to my wife's computer. A virus and a Trojan horse crept through Microsoft's own anti-virus program and hid her data files. We used malwarebytes.com to detect, quarantine and destroy the culprits. She's back in business. But she learned one valuable lesson:
My current job involves preparing for disaster recovery, going beyond just preventing issues with firewalls and other security measures. I recently read an article about the Veterans Affairs Department’s low priority of documenting a detailed view of its IT architecture.
This came out in the testimony Roger Baker, the VA’s CIO on May 11. Baker told Congress that the VA has 62 data centers and approximately 37,000 servers, but admitted that some of those servers could be “virtual instances running on a single physical server.”
How big an issue is this? Beyond the obvious of not having standard up-to-date hardware and software for security, there is another potential problem. The VAD is supposed to work with the Department of Defense to implement joint systems as well as to developing and securing information systems.
The irony is that from a medical records standpoint, the VA hospitals have their system right. A VA hospital in Florida can access a patient’s records in a VA hospital in Connecticut. This is something that computer savvy doctors understand. (Note: many doctors are still not committed to electronic medical records. Sometimes it’s because they don’t want to spend the money, but sometimes it’s because of the lack of standards outside VA hospitals.)
Back to the VAD's architecture, Baker's concern is because things are not being handled as they would in a private company. Joel Willemssen, managing director for IT at the Government Accountability Office, said it’s absolutely critical to get a picture of the VA’s architecture. Baker is planning to cancel failing programs and restructure the way VA's IT department operates instead of focusing on the broader architecture. Willemssen admits that Baker is going to have to cut up the problem like a sausage and deal with it in chunks. Realistically, it's the only thing that can be done for now.
Learn more from: http://veterans.house.gov/hearings/hearing.aspx?NewsID=2325
Californians, take note. If your health insurer is Health Net, watch your credit report. Somehow, Health Net cannot account for nine of its server drives which contains the personal information needed for identity theft. Almost 900,000 Health Net "subscribers" may be at risk.
It gets worse. Health Net failed to encrypt the data.
Now two state agencies are investigating what happened (or, in this case, what didn't happen). Beth Givens, director of Privacy Rights Clearinghouse, said Health Net didn't even go through the basic steps of security.
Of course, Health Net will now offer its "members" free credit monitoring and identity theft insurance. What does that cost? Last year I blogged that someone assigned a cost to each case of a security breach -- $204.00 per lost record. This is not actual money being spent, but if that is indeed an accurate number, Health Net's security breach is valued at $172,380,000 - thousands of times more than the salary someone with my expertise earns. Some of this cost is real. Depending on the outcome of the investigations, Health Net could face fines to the tune of millions of dollars. There's precedence for this. Hospitals in Massachusetts and Arizona were fined for HIPAA violations. The people who steal identities are not interested in your health, just your wealth.
http://www.kpbs.org/news/2011/mar/15/state-regulators-launch-investigations-health-net-/
In my earlier post today, I blogged about the loss of memory cards at an Arizona hospital that had information on some 2,200 patients who had endoscopies. Now the California Department of Public Health reported that it lost data for more than 2,500 facility residents, department employees and other healthcare workers. How viral is that?
This past year the CDPH fined hospitals guilty of losing patient records. It was supposed to beef up its efforts to protect this from happening again, but that hasn't happened. In this case, the information that was lost was stored on magnetic tape that was not encrypted. The data on this tape contained more information than the memory cards in the Arizona health center. Names, Social Security numbers, e-mail addresses, background and medical health information -- all you need, and then some, for identity theft.
Two things happened to compromise the safety of this data. First, the field office, where the tape originated, failed to encrypt the files, as per normal procedure. Then they sent it to the central office via USPS instead of by courier. The envelope arrived, but it was unsealed and empty.
When there is vulnerability in security, it's often because a company doesn't want to spend the money on upgrades. As everyone knows, California is in dire financial straits. But this time lack of sufficient funding wasn't the culprit. It was just a lack of following proper procedures. All that's really required are reminders everywhere -- on posters and on every computer monitor:
MIND THE SECURITY GAP
Call me paranoid, but I believe that people have to be alert 24/7 about their personal data. Recently I posted a blog about how information stolen in Fort Hood, Texas about 20 soldiers led to more than 2,000 attempts to use their identities to make money. Here's a more staggering statistic: 2,284 endoscopy patients' information is missing because two data cards were lost or misplaced at the Mountain Vista Medical Center in Meza, Arizona two months ago.
People tend to think in a linear fashion. Health care workers concentrate on their patients, as they should, but they need to be trained to think of every component in their workplace as cash to be guarded. No doubt they are careful about the equipment they use insofar as they try to avoid physical damage. But, like every worker I've dealt with in offices, they don't think too much about the IT part. If there's a problem, they just call IT to fix it. In this case, the issue is the privacy of the patients' medical information (names, dates of birth, ages and genders), not their addresses, Social Security numbers and credit card information. Still, it was enough for the medical center to notify patients of the incident and to offer them the standard patch -- one year of free credit monitoring services.
Fortunately, the hospital has revised security procedures for storing compact memory cards and are retraining employees on procedures related to confidentiality and security. That said, there is reason to be concerned about other security vulnerabilities at the hospital. Hackers don't give up. Just yesterday, my wife was at a small credit union in Stamford and one of the top employees said, "You can't simply throw out papers anymore. You have to shred them." She went on to explain that if a hacker isn't successful right away, he or she will wait a few months to use the information he has. Time is on the side of the hackers.
Loss of savings is a daily concern for many people since the economic meltdown more than two years ago. Lately, there have been more threats of loss of savings due to security vulnerabilities in the U.S. government. A new report by the Government Accountability Office states that the Federal Deposit Insurance Corporation lacks adequate encryption of "sensitive information transmitted over its network." It also found that the FDIC has "inconsistent identification and authentication user controls" and needs to beef up its internal monitoring and auditing practices. One example the GAO cited was the existence of default installation user ideas on some of its UNIX servers. Another is that the data network and voice network are both on the same network.
I'm not a heavy duty UNIX administrator, but I know enough about UNIX. It's an open system that is widely used in servers, on workstations and in mobile devices. It's critical that companies have policies and firewalls in place to avoid unauthorized penetration of their systems.
It's ironic that after all these years, the FDIC increased its insurance protection in case banks went under. Now people have to worry that their savings might be lost because of inadequate data security.