The University of Iowa Health Care (UIHC) sent letters to 5,300-plus patients whose personal identifying data was left exposed for more than two years (May 2015 to 2017) by an unidentified employee. The UIHC has promised to tighten up their security protocols and enhance employee training with respect to data privacy. CISOs will be well served to go to school on the UIHC experience and educate their trusted insiders on the need to protect PII alwaysnot just in production, but also in development.”]

