DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Broomfield Skilled Nursing and Rehabilitation Center settles breach-related charges with Colorado Attorney General

Posted on September 26, 2023 by Dissent

Colorado Attorney General Phil Weiser recently announced a settlement with Broomfield Skilled Nursing and Rehabilitation Center, LLC stemming from a 2021 data breach. The following is the state’s press release:

Sept. 22, 2023 (DENVER) – Attorney General Phil Weiser announced today a settlement with Broomfield Skilled Nursing and Rehabilitation Center, LLC., for failing to protect the personal data of hundreds of patients and employees before and during a 2021 data breach.

“Every cybersecurity threat is potentially devastating, but it’s particularly troubling when older Coloradans and those who care for them are the victims of cybercrime due to a failure on the part of a nursing facility to properly handle the personal data of patients and employees,” Weiser said. “While the damage has already been done in this case, let this settlement be a warning that I will not hesitate to act against any company that fails to comply with Colorado data protection laws.”

In March of 2021, the nursing facility in question discovered that two employee email accounts were compromised. Even though most company emails had been equipped with two-factor authentication, the accounts in question were not protected. The breached inboxes contained tens of thousands of emails, some of which contained personal, financial, and medical data for hundreds of current and former patients and employees, including emails containing personal data going back as far as 2016.

Despite being required under state law, the company had no written data disposal policy. The company also waited months, rather than the legally required 30 days, before notifying those affected.

Under the terms of the settlement agreement, the company will pay a fine of anywhere from $35,000-60,000 and agrees to the following:

  • Develop a written paper and electronic data disposal policy as required by state law.
  • Update its existing written information security program and review and update the existing information security program to ensure it is compliant with the law, meets the needs of the size and scope of the company’s operations, and addresses the vulnerabilities that led to the breach in the first place.
  • Review the safeguards it has put in place on at least an annual basis.
  • Develop an incident response plan.
  • Submit regular compliance reports to the attorney general and cooperate with any proceedings or investigations that arise out of the state’s monitoring of the company’s operations under the agreement.

The settlement funds may be used to pay restitution, and for future consumer fraud or antitrust enforcement, consumer education, or public welfare purposes.


The introduction to the Assurance of Discontinuance begins with a statement that would be appropriate for so many data breach settlements or lawsuits:

A cybercriminal cannot steal data that is not there. Threats of cybercrime and identity theft are exacerbated by the overcollection, overuse, and over-retention of unnecessary personal information, which is then accessed by threat actors in the event of a data breach. It is crucial that companies offset those threats by practicing data minimization coupled with effective data disposal, limiting their collection and maintenance of personal information to that which is necessary for a specific data processing purpose.

This enforcement action was filed under Colorado’s state laws, not HIPAA.

 


Related:

  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach
  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
Category: Commentaries and AnalysesHealth DataOf NotePhishingState/LocalU.S.

Post navigation

← New AtlasCross hackers use American Red Cross as phishing lure
Data breaches put domestic abuse victims’ lives at risk, UK Information Commissioner warns →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.