If anyone doubted the FCC was serious about getting more into data breach/security enforcement, they should read this settlement with AT&T released today (pdf). From the order: 1. The Enforcement Bureau (Bureau) of the Federal Communications Commission (Commission) has entered into a Consent Decree to resolve its investigation into whether AT&T Services, Inc. (AT&T or Company)…
Category: U.S.
Advocate Health patients ask Seventh Circuit to revive data breach lawsuit
There’s an update to another case I’ve been following. Although Advocate Health won dismissal of some lawsuits stemming from the theft of four laptops with information on over 4 million patients, plaintiffs have asked the Seventh Circuit for another bite of the apple under the Fair Credit Reporting Act (FCRA). So far, trying to litigate breaches…
PA: Couple gets prison time for tax refund fraud scheme that used Crozer-Chester patients’ information
There’s an update to a case I’ve been covering since March, 2013, when Rafael Henriquez Polanco and his wife, Yanira Lopez, were first charged in a tax refund fraud scheme. According to court records, as part of the scheme, they paid employees at Crozer-Chester Medical Center and Chester Community Hospital to provide them with identity information of 144 patients. The hospitals…
University of California – Riverside notifying 8,000 whose SSNs were on stolen desktop
Mark Muckenfuss reports UC Riverside officials are notifying 8,000 graduate students and graduate applicants that their personal identity information is at risk. A desk-top computer stolen during a break-in at the campus’ graduate division offices March 13, contained the Social Security numbers of the students and potential students. Officials said they had no evidence that…
OK: EyeCare of Bartlesville notifies patients after hard drive locked by malware
EyeCare of Bartlesville in Oklahoma reported a breach to HHS on March 13 that appeared on HHS’s public breach tool on March 19. There was no notice on their web site that I could find at that time. Nor could I locate any public notices via a Google search. The incident was coded on HHS’s breach tool as a…
NJ: Court dismisses breach lawsuit against Horizon Blue Cross Blue Shield
In December, 2013, Horizon Blue Cross Blue Shield of New Jersey notified almost 840,000 members that their protected health information was on laptops stolen from the insurer’s Newark headquarters on November 1, 2013. At the time, Horizon BCBS reported that the laptops were password-protected, but the data were unencrypted, and After a detailed review with…