As I pointed out in reporting on Starbuck’s response to Bob Sullivan’s disclosure of a breach involving the mobile app accounts, not everyone would find their explanation and response satisfactory. Today, Bob Sullivan fired back: Since I broke news of the Starbucks mobile pay / gift card /credit card attack last Monday, there has been some confusion…
Category: U.S.
University of Texas Southwestern Medical Center sent 1,032 immunization records to state registry by mistake
Sherry Jacobson reports: UT Southwestern Medical Center accidentally transmitted the immunization records of about 1,000 patients to a confidential Texas registry used by physicians, health departments and school districts. Letters were sent last week to the UTSW patients involved, expressing regret that their vaccination information had been shared with ImmTrac, a statewide registry service used…
Columbia Casualty asks court to let it off the hook for $4.1M settlement in Cottage Health System breach
So you apply for cyberinsurance and in your application, you describe all the security controls and policies you have in place. And an insurance company looks it all over and issues you a policy because you meet the minimum security practices they require. But then you don’t actually adhere to all the controls and policies you…
When storing old medical records matters
Over on PHIprivacy.net, I had often questioned the fact that so many healthcare facilities retain patients’ medical records forever. And while those stored records pose a risk in terms of breaches, I had also noted that there might be times when having a patient’s very old records could actually be helpful. Here’s another example. KPLR reports:…
3 Dixon High Students Suspended in Grade Data Breach
As an update to a previously reported incident: at least three students have been suspended so far in the grade-changing hack that has rocked Dixon High School. At least nine teacher accounts were hacked and 200 grades changed since January for 32 students. One teacher noticed something that resulted in the investigation, but I have yet…
Host of NSA’s smtp server hacked?
An interesting paste today by PH1K3 lets us follow along during an attempt to hack the host/dns provider for smtp.nsa.gov.