As I’m sure many have seen, Governor Walz finally appointed Shireen Gandhi commissioner of the Department of Human Services (DHS). Until now, Gandhi had been serving as temporary commissioner for a full year. I’m sure many Minnesotans are now wondering what this all means. I want to let folks know the implications of this move.
Back in February 2025, Gandhi was appointed as temporary commissioner after our last commissioner retired, despite the enormous fraud we were already seeing. To be fair, we all recognized Gandhi was dealt a tough hand. DHS had been inundated with fraud for years prior to her appointment, and she came into the position at a turbulent time. But in her year of being the temporary commissioner, it feels as though we have made zero headway on fraud whatsoever. That’s a big problem, folks.
ADVERTISEMENT
With more fraud being uncovered every month, often…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
