Official Notes bug made all notes visible to all users?
I am hearing from other schools that there was a bug yesterday that allowed all users access to all official notes. Does anyone know more about this? How do we know if we were or are affected?
Comments
-
@Brian Hoyt thats not good! Are you impersonating parents to see if it is true? I jsut impersonated one parent and didnt see anything i just added to their account.
0 -
@Coco Parham It is possible it has been fixed already. My concern is that it may have affected my school and I don't know. There are some serious privacy issues that may need to be addressed.
0 -
@Brian Hoyt our school experienced this. The students brought it our attention. They saw a number beside Official Notes on the LMS. When they opened it they saw the list of students who received notes from teachers about grades in Sept/Oct. Our IT team made some changes and when students logged off and back on it was no longer there. Blackbaud was working on it as well. Not sure how it ended up.
0 -
@Lisa Baylor The issue was resolved around 10 am, apparently. We also had students (and a parent) bring it to our attention with some screenshots. I removed the ability for students and parents to see (any) Official Notes and that fixed it for most, but anyone who was currently logged in still had the Official Notes button in the upper right, and could still access them, despite having those tasks turned off in their roles. It was very obvious to students - suddenly 2477 official notes appeared! Fortunately there were no emotional crises but we are waiting for the statement of explanation from Blackbaud - hopefully with an apology - so we can explain to parents how the confidentiality of those records was breached so badly. It was a major FERPA violation for those schools and some people are ticked.
1 -
@Brian Hoyt There was a follow-up this evening from Blackbaud to affected schools. In part they wrote that “This issue only affected customers who set their privacy settings to allow all faculty for all school levels to view data in the Official Notes field.” So if you didn't have that, you should have been all clear.
They also sent a Word doc supposedly listing the comments viewed and by whom, but it cannot be trusted. Our file contained a single comment viewed by one student, but I personally observed several other students showing me the problem by bringing up another student's comment (and then quickly closing it). If you received this notice you may need to follow up with customer support to get an accurate accounting if you want that information.
1 -
@David Gillespie
David,Where are the settings for this?
0 -
@Barbara Glass you edit each comment type and scroll down to the bottom you'll see the groups that can view it. There's an additional checkbox to limit to the students school level. We didn't have that turned on for a couple of our comment types.
1 -
@David Gillespie
Thanks for the details. We don't use the All Teachers setting on any of our official notes so that seems like it excluded us from the issue. This is the kind of security / privacy oops that really shouldn't happen.0 -
Final follow-up from me! Our report was limited because I changed the access rights to the comments before it was generated. Once the Blackbaud folks knew that, they were able to go back and retrieve all of the comments that students had viewed. So if you see this and your school was affected but the report you received doesn't seem complete, you can follow up with them and they can provide you a report with the new parameters that they're sure is complete.
0 -
If you haven't had an opportunity, please consider voting for these three ideas that could help during similar situations.
Develop the ability for platform managers to immediately disable accounts for a specific role
https://blackbaudk12.ideas.aha.io/ideas/K12CO-I-3754
- Although we immediately disabled the Official Notes feature yesterday, it didn’t take effect on many students until they logged off (some multiple times). Those who didn’t log off were able to surf through private information for an extended period until we blocked Blackbaud at our firewall.
Contact schools Immediately/directly when an active broken feature comprises data security
https://blackbaudk12.ideas.aha.io/ideas/K12CO-I-3756
- The only way many schools learned of the Official Notes permissions issue on 2/13/23 was from a BB listserve and then a long wait for BB support. Schools should be alerted immediately when they need to adjust settings to protect school data due to a broken feature.
Create a useful K-12 status page with a list of currently broken features
https://blackbaudk12.ideas.aha.io/ideas/K12CO-I-3755
- Schools need a way to quickly identify known issues (broken features from weekly updates) without waiting an hour on the phone for support just to tell us that BB agrees there is a problem that has been sent to development. A simple page with known problems would save us all a great deal of time and frustration.
0
Categories
- All Categories
- 6 Blackbaud Community Help
- 211 bbcon®
- 1.4K Blackbaud Altru®
- 402 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 1.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- 15 donorCentrics®
- 360 Blackbaud eTapestry®
- 2.6K Blackbaud Financial Edge NXT®
- 655 Blackbaud Grantmaking™
- 576 Blackbaud Education Management Solutions for Higher Education
- 3.2K Blackbaud Education Management Solutions for K-12 Schools
- 940 Blackbaud Luminate Online® and Blackbaud TeamRaiser®
- 84 JustGiving® from Blackbaud®
- 6.7K Blackbaud Raiser's Edge NXT®
- 3.7K SKY Developer
- 248 ResearchPoint™
- 120 Blackbaud Tuition Management™
- 165 Organizational Best Practices
- 240 Member Lounge (Just for Fun)
- 34 Blackbaud Community Challenges
- 37 PowerUp Challenges
- 3 (Open) PowerUp Challenge: Grid View Batch
- 3 (Closed) PowerUp Challenge: Chat for Blackbaud AI
- 3 (Closed) PowerUp Challenge: Data Health
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Product Update Briefing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports+
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Email Marketing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Gift Management
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Event Management
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Home Page
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Query
- 796 Community News
- 3K Jobs Board
- 54 Blackbaud SKY® Reporting Announcements
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)



