Cub Pharmacies is the fourth chain I’ve seen that is reporting some theft of protected health information related to looters during protests in May. But when you read the descriptions of these events — these not just protesters protesting. These people intentionally stole patient data and records. For what political protest purpose? None that I…
Month: July 2020
Tampa teen arrested in hack of Twitter accounts of Obama, Bill Gates and others (Updated with DOJ Press Release)
Josh Fiallo and Peter Talbot report: A 17-year-old Tampa man was arrested Friday morning after the Federal Bureau of Investigation and the U.S. Department of Justice discovered he was behind an extensive Twitter hack, which temporarily gave him access to the accounts of Bill Gates, Barack Obama and many others. Graham Ivan Clark, 17, was arrested…
Some potential victims of PaperlessPay breach are first finding out about the breach now
At the end of April, this site reported a breach at PaperlessPay that put its clients’ employees at risk of tax refund fraud and identity theft. As reported at the time, PaperlessPay had been contacted by Homeland Security on February 19 to alert them that someone was offering access to their clients’ data for sale…
After ransomware attack, legal services company Epiq faces California privacy lawsuit
Sara Merken reports: Lawyers for Epiq Systems Inc have removed a lawsuit to federal court that alleges the legal services provider failed to adequately protect personal information under California’s consumer privacy law. Read more on Reuters.
NZ: Kiwibank breach ‘significant’ – Privacy Commissioner
Kiwibank is investigating how it sent 4200 customers an email or online bank statement with their own account number, name and address, but another person’s transaction history. The commissioner, John Edwards, said some people will be identifiable by the statements and information sent. Read more on RNZ.
WV: Elkins Rehabilitation & Care Center notifies residents and employees of breach first discovered in February 2019
I know some people may think I’m being too harsh, but really — almost 1.5 years from detection to notifications to people of a breach? Their response in terms of preventing more incidents seems reasonable, but the gap to figure out that notification was needed and then whom to notify seems too long. What will…