DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Advocate breach lawsuit says the group didn't adequately secure data

Posted on September 5, 2013 by Dissent

Mitch Smith reports:

Advocate Medical Group, already under federal and state investigation after the theft of computers containing personal information on millions of people, is now facing a class-action lawsuit from patients who say the Downers Grove-based physician group didn’t do enough to protect their private data.

The suit, filed in Cook County Circuit Court, says the health care nonprofit violated privacy regulations by failing to use encryption and other security measures on the four computers that were stolen from its Park Ridge offices in July. The computers contained information on more than 4 million patients.

Read more on Chicago Tribune.

Category: Health Data

Post navigation

← Proposed settlement in lawsuit over AvMed breach
Final re-Analysis of the britam defense leak files →

2 thoughts on “Advocate breach lawsuit says the group didn't adequately secure data”

  1. Anonymous says:
    September 9, 2013 at 5:19 pm

    It would be nice if the media articles would indicate the laws under which a lawsuit, such as this class action (or the Walgreens case), are filed. When I see a first sentence stating “Advocate Medical Group … is now facing a class-action lawsuit from patients who say the Downers Grove-based physician group didn’t do enough to protect their private data”, I think HIPAA. Headlines for other similar articles are also, in my opinion, misleading because I know that civil actions cannot be brought under HIPAA. It took some digging to discover that the lawsuit is based on violations of Illinois’ Personal Information Protection Act (815 ILCS 530) and Illinois’ Medical Patients Right Act (410 ILCS 50/3) – http://cliffordlaw.com/wp-content/uploads/2013/09/PetrichComplaintatLaw.pdf. An article on the class action lawsuit at http://healthitsecurity.com/2013/09/06/patients-file-class-action-suit-v-advocate-medical-group/ states “When the size of the breach and current state and federal investigations already in place are taken into account, the class-action suit decision will be worth monitoring. Private citizens suing organizations in class-action suits has an inconsistent recent history that seems to be based on individual state regulations and interpretations of the law.” At least someone is starting to get accurate information about the lawsuits into the public eye.

    1. Anonymous says:
      September 9, 2013 at 7:49 pm

      Thanks for that first link. I don’t have access to that court’s filings and was as frustrated as you were. Personally, though, I don’t expect any of the class action lawsuits to prevail because plaintiffs usually can’t show actual harm (future harm doesn’t count), but I usually do want to see whether a state’s AG, HHS or FTC do something. Illinois’ Attorney General has not really pursued data breaches unless there were multi-state investigations/actions as in the ChoicePoint and TJMaxx cases. Would they go after an Illinois entity? It would be nice to see, but I’m not optimistic.

      And by all rights, HHS should go after Advocate if they fined BCBS of Tennessee after the theft of unencrypted backup tapes and fined other entities for thefts involved unencrypted devices.

      But we’ll see…

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm
  • Former CIA Analyst Sentenced to Over Three Years in Prison for Unlawfully Transmitting Top Secret National Defense Information
  • FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters
  • Dutch police identify users on Cracked.io
  • Help, please: Seeking copies of the PowerSchool ransom email(s)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • 23andMe Privacy Ombudsman Urges User Consent Pre-Data Sale
  • The Meta AI app is a privacy disaster – TechCrunch
  • Apple fixes new iPhone zero-day bug used in Paragon spyware hacks
  • Norwegian Data Protection Authority’s findings on tracking pixels: 6 cases
  • Multiple States Enact Genetic Privacy Legislation in a Busy Start to 2025
  • Rules Proposed Under New Jersey Data Privacy Act
  • Using facial recognition? Three recent articles of interest.

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.