DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Advocate breach lawsuit says the group didn't adequately secure data

Posted on September 5, 2013 by Dissent

Mitch Smith reports:

Advocate Medical Group, already under federal and state investigation after the theft of computers containing personal information on millions of people, is now facing a class-action lawsuit from patients who say the Downers Grove-based physician group didn’t do enough to protect their private data.

The suit, filed in Cook County Circuit Court, says the health care nonprofit violated privacy regulations by failing to use encryption and other security measures on the four computers that were stolen from its Park Ridge offices in July. The computers contained information on more than 4 million patients.

Read more on Chicago Tribune.

Category: Health Data

Post navigation

← Proposed settlement in lawsuit over AvMed breach
Final re-Analysis of the britam defense leak files →

2 thoughts on “Advocate breach lawsuit says the group didn't adequately secure data”

  1. Anonymous says:
    September 9, 2013 at 5:19 pm

    It would be nice if the media articles would indicate the laws under which a lawsuit, such as this class action (or the Walgreens case), are filed. When I see a first sentence stating “Advocate Medical Group … is now facing a class-action lawsuit from patients who say the Downers Grove-based physician group didn’t do enough to protect their private data”, I think HIPAA. Headlines for other similar articles are also, in my opinion, misleading because I know that civil actions cannot be brought under HIPAA. It took some digging to discover that the lawsuit is based on violations of Illinois’ Personal Information Protection Act (815 ILCS 530) and Illinois’ Medical Patients Right Act (410 ILCS 50/3) – http://cliffordlaw.com/wp-content/uploads/2013/09/PetrichComplaintatLaw.pdf. An article on the class action lawsuit at http://healthitsecurity.com/2013/09/06/patients-file-class-action-suit-v-advocate-medical-group/ states “When the size of the breach and current state and federal investigations already in place are taken into account, the class-action suit decision will be worth monitoring. Private citizens suing organizations in class-action suits has an inconsistent recent history that seems to be based on individual state regulations and interpretations of the law.” At least someone is starting to get accurate information about the lawsuits into the public eye.

    1. Anonymous says:
      September 9, 2013 at 7:49 pm

      Thanks for that first link. I don’t have access to that court’s filings and was as frustrated as you were. Personally, though, I don’t expect any of the class action lawsuits to prevail because plaintiffs usually can’t show actual harm (future harm doesn’t count), but I usually do want to see whether a state’s AG, HHS or FTC do something. Illinois’ Attorney General has not really pursued data breaches unless there were multi-state investigations/actions as in the ChoicePoint and TJMaxx cases. Would they go after an Illinois entity? It would be nice to see, but I’m not optimistic.

      And by all rights, HHS should go after Advocate if they fined BCBS of Tennessee after the theft of unencrypted backup tapes and fined other entities for thefts involved unencrypted devices.

      But we’ll see…

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • FTC Finalizes Order with GoDaddy over Data Security Failures
  • Hacker steals $223 million in Cetus Protocol cryptocurrency heist
  • Operation ENDGAME strikes again: the ransomware kill chain broken at its source
  • Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials
  • Mysterious hacking group Careto was run by the Spanish government, sources say
  • 16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
  • Russian national and leader of Qakbot malware conspiracy indicted in long-running global ransomware scheme
  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Meta may continue to train AI with user data, German court says
  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.