When National American University moved from one Rapid City campus to a new location earlier this year, the school or a contractor appears to have improperly disposed of thousands of sensitive student financial records that included names, addresses, loan numbers and Social Security numbers, according to documents reviewed by the Rapid City Journal.
The private information, which was reportedly dumped into a trash bin, was brought to the newspaper by a person who lived across the street from NAU’s old campus at 321 Kansas City St. That person observed movers loading boxes into a Dumpster during the university’s relocation. The source, sensing something wasn’t right, took a box of the discarded records for safekeeping, and later showed them to the Journal.
That single box contains hundreds of pages of financial loan data for thousands of former students, including their names, addresses and Social Security numbers that theoretically could be used to steal their identity.
Two former NAU students have confirmed that the data is theirs, though so far no identify theft has been reported. The improper disposal of student loan records may also be a violation of federal privacy laws.
In an email to the Journal, Thomas Johnson, an attorney representing NAU, said the university’s position is that financial documents were properly handled during the move, or should have been destroyed by a firm hired by NAU.
“During the re-location of the university’s Rapid City campus, documents containing private student data were either moved to the new campus or were to be destroyed in a secure manner by a third-party vendor retained by the University,” Johnson wrote.
Nonetheless, in a call Friday afternoon, Johnson said NAU is taking the allegation seriously and the university will begin investigating next week.
“Our priority is to figure whether there was a breach here, and who was involved,” Johnson said. “NAU takes seriously those responsibilities, they have protocol in place, and believed they followed protocols in place.”
Student data and the law
After seeing boxes put in a dumpster, the source was curious and looked inside and saw one box labeled in handwriting as containing bank statements and federal Perkins loan statements.
“I was surprised they’d be throwing something like that away,” the source said. The Journal is not naming the source, a former NAU student, to preserve their anonymity because the person said they only came to the newspaper to shed light on their concerns.
If that depiction is true, NAU may have violated at least one federal law governing the disclosure of student information, and possibly others. If any student loan documents were thrown into a dumpster, that would appear to violate the Family Educational Rights and Privacy Act.
Known as FERPA, the law governs the disposal of sensitive records by educational institutions that receive government funding. Jim Bradshaw, a spokesman for the U.S. Department of Education, wrote in an email that disposing of that kind of information in a trash bin would likely be covered under the law.
“The law does not generally permit the discarding of personally identifiable information from education records in a manner that would disclose students’ [information],” wrote Bradshaw. “While there is no specific provision in FERPA that addresses how to discard old records, FERPA is clear that [such information] may not be disclosed inappropriately.”
While NAU is a publicly traded, for-profit company, it receives federal money in the form of student loans. In its most recent year-end financial statement, the company recognizes that it is responsible for sensitive student data.
“If an institution fails to comply with FERPA, the Department of Education may require corrective actions by the institution or may terminate an institution’s receipt of further federal funds,” reads a section of the company’s year-end statement.
Writing on the top of the box of documents says “Bus Office” and “Fed Funds, Bank Statements” and “Perkins Statements.” The box contained hundreds of pages of what appears to be student loan document lists.
One typical document is titled “Student Loan Journal” and says “National American University” on the top right. Many of those have dates from the 1990s. They list about 10 names per page and include addresses, phone numbers, Social Security numbers and what appear to be loan account numbers and loan balances.
Another document, titled “Numerical Master List” is dated July 31, 1999. It contains a list of 54 names, each with a loan number, Social Security number, address and loan balance.
Two former NAU students confirmed to the Journal that the personal information listed in the documents is theirs.
The U.S. Attorney for South Dakota, whose office is responsible for enforcing federal laws, told the Journal that due to to budget cuts, he doesn’t have the resources to investigate or prosecute the matter.
“Right now, we have a hard time keeping up with violent crime, meth and human trafficking,” said Brendan Johnson, U.S. Attorney for South Dakota.
Both Johnson and a representative of the state Attorney General’s Office have offered to take the source’s box of data. On the advice of those agencies, the copies of a handful of the documents made by the Journal in order to verify their authenticity were turned over late last week to the U.S. Attorney’s Office in Rapid City.
Jody Swanson, director for the Consumer Protection Division of the state Attorney General’s Office, said it is troubling to think that such sensitive, personal data was thrown away in a dumpster.
“You’ve got Social Security numbers on those,” Swanson said. “The potential for people to open lines of credit, that’s all they need.”
Swanson said South Dakota relies on federal law to cover data security breaches. Forty-six states have laws requiring companies or government entities to notify people who may have fallen victim to a data breach, according to the National Conference of State Legislators.
But South Dakota — along with Alabama, Kentucky and New Mexico — does not have such a law.
Identity theft
Eva Velasquez, president of the non-profit Identity Theft Resource Center, said that since most discussion of personal data now revolves around the Internet, people forget about the danger from improperly disposed paper documents.
“With the amount of data breaches online, people forget that paper breaches exist and are just as harmful,” Velasquez said.
With names and Social Security numbers, someone intent on committing fraud can have multiple avenues to pursue.
“They could use the info to file false tax returns or for government benefits,” she said. Medical or insurance fraud could also be committed with that kind of data, she added.
To prevent identity theft, Velasquez recommends keeping close tabs on bank accounts and other financial statements.
“Read your bank statements, check your credit report,” she said. “The documents you have in your own control, shred them.”
However, “you can do everything right, and still be a victim of identity crime,” Velasquez said.
Swanson, with the state Attorney General’s Office, suggests people get free credit reports that they are entitled to separately from different companies throughout the year. That way, personal financial data can be monitored more often.
Swanson also recommended that people concerned about a personal data breach put a temporary fraud alert on their Social Security numbers.
The name of Debra Bell, the office manager for Sander Sanitation Service, Inc. in Custer, was on one of the lists in the box of documents.
Bell, 57, attended NAU about 20 years ago, and she said graduated with a business degree and was happy with her time at NAU. But she hadn’t been aware that her Social Security number and other information had been left in the bin at NAU’s property.
“Some of that is sensitive information,” said Bell, who says she’s never had her identity stolen.
“And I really don’t want to start,” she added. “Now I’m having my doubts.”
