Originally published April 10, 2006 in MeetingNews
Paradise Island, Bahamas — The burgeoning scourge of identity theft is not sparing the hospitality industry.
Kerzner International, owner and operator of the Atlantis Resort here, recently revealed that personal information — credit card data, bank account numbers and even some social security numbers — of about approximately 55,000 guests had been stolen.
Also, on Jan. 20, a hacker invaded the computer system of the University Place Conference Center and Hotel at Indiana University in Indianapolis, according to Privacy Rights Clearinghouse (PRC), a nonprofit consumer information organization based in San Diego. Reservation information, including credit card data, was compromised for an unknown number of people.
And on Dec. 28, a Marriott Vacation Club back-up tape was lost that held social security numbers and credit card data for 206,000 people.
In the Atlantis case, most details, including the dates when affected guests stayed at the property and when the breach was discovered, have not been released publicly because of a continuing investigation into the matter.
Kerzner sent a letter to each guest whose information was stolen and offered credit monitoring for a year. For legal reasons, Kerzner officials were unable to comment for this article, said spokeswoman Lauren Snyder.
Questions for Hotels
The idea of identity theft produces in many people a feeling of resigned helplessness: If they're going to get me, what can I do about it?
But is there, in fact, anything meeting planners can do to safeguard their attendees' information?
"Merely asking questions is the first big step," said Brad Utter, president of Global Security Services in Davenport, Iowa, who noted that security is especially complicated at hotels that are owned and managed by different entities.
"Are [properties] cognizant that identity theft is a growing problem, and are they taking steps to make sure that information doesn't get into the wrong hands? Are they throwing information in the garbage, or are they contracting with a company to dispose of it? They do that for their proprietary information, but what about consumer information?"
Planners should ask hotels for a copy of their security policies, Utter said. They won't provide detailed information on security maintenance, which would be counterproductive, but they should offer general information on how they hold and destroy sensitive information and assure planners that they "don't throw it out in the trash with the food prep."
Pressing hotels on data security should be considered a best practice for meeting planners, said Tom Fragala, CEO of Santa Barbara, Calif.-based Truston Corp., an online service that helps victims of identity theft, and CEO of Vistera Systems, which handles systems integration for owners and managers of multiple hotels.
"If anybody's going to push the lodging industry in this direction, it's going to be the market, and meeting planners are a big part of that," Fragala said. "If we can raise the awareness of everyone involved, I think some good will come of it."
Agreed Utter, "Even if these places don't have appropriate security plans in place, if enough planners ask the questions and if the hotels start losing business, sooner or later they will get a procedure in place."
Fragala noted that "most salespeople will probably be surprised to be asked these questions, but every property should have an IT person who can answer."
In the Know
Twenty-two states have security-breach notification laws, whereby residents must be made aware if their information has been compromised.
California, the first state to enact such a law, made headlines when the security of ChoicePoint Inc., a broker of consumer data, was breached in February 2005. The company first notified only affected California residents, although stolen information affected more than 163,000 people in all 50 states. Eventually ChoicePoint notified all affected parties, but the matter sparked nationwide interest in notification laws.
Fragala said planners should consider holding meetings in states with a security-breach notification law, or ask the hotel to agree in writing to notify attendees in the event of a breach.
"It's totally reasonable for any planner to add a contract clause or stipulation about this," Fragala said, adding, "Whether you like it or not, this is now part of your job — what are you going to do to protect your people?"
He also recommended that planners be aware of other possible sources of security breaches, such as a conference registration desk, where attendee information might be lying in plain sight on a table. "Remember that these are public places and there are people other than the attendees milling about," he said.
Planners should consider hotels to be partners, not adversaries, in maintaining security, according to Drew Friedrich, worldwide market manager for IBM's Entity Analytic Solutions in Las Vegas.
"I think [hospitality companies] probably spend as much if not more on security as other organizations," said Friedrich. "It's a reputational risk. A hotel may have spent 30 years building up its brand; they don't want to mess that up. Even if it's not their fault, they don't want to be associated with it."
A Matter of Trust
Nan Edmunds, meeting coordinator for the Pennsylvania Orthopaedic Society, has a group of 100 going to the Atlantis in May. She said she's confident the property is doing everything possible to prevent a recurrence of the security breach.
"They seemed very careful," she said, adding, "It may be less likely to happen a second time since they're on guard."
Julie Schrader, president of Schrader Events & Marketing in Ludington, Mich., is considering the Atlantis for an upcoming program.
"I'll be researching the facts and will be questioning Kerzner about what steps it's now taking to safeguard its database," Schrader said. "I realize that sometimes it takes a major problem to occur in order for the right procedures to be put in place, and once Kerzner implements a new system, it may have one of the most secure databases in the industry.
"Hopefully that's its goal, and hopefully incidents like this will serve as wake-up calls to other hotels, even small ones."
But even with a technologically superior system, Fragala observed, "There are critical elements like how many people have passwords, how often they are changed and how many people have those passwords on Post-It Notes next to their computer."
Said Schrader, "Identity theft is a reality today, and although security breaches can happen anytime, anywhere outside of meeting planners' control, we obviously need to take into account how well a property handles computer and ground security when selecting a site.
"I've never felt the need to Google 'database security at xyz hotel' in the past. Now that I have, I'm surprised at the extent of the inadequacies."