Kate Hanniford of Alston & Bird writes: Following the SolarWinds cyber espionage attack (the “Attack”) and the resulting focus on supply chain risk, the New York Department of Financial Services (NYDFS) has issued a report detailing the impact on and responses by its regulated covered entities to the Attack. Although there have been no reported instances of…
Category: U.S.
Implementing the HIPAA Security Rule: Call for Comments on NIST SP 800-66, Revision 1
Implementing the HIPAA Security Rule: Call for Comments on NIST SP 800-66, Revision 1 The National Institute for Standards and Technology (NIST) is planning to update the NIST Special Publication (SP) 800—66, Revision 1, An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (“Resource Guide”). NIST is seeking stakeholder input…
Sekurak blog interviewed Babuk about Metropolitan DC Police attack
A blogger from Sekurak (a Polish blog) conducted a great interview with Babuk yesterday. You can read the write-up here. Here’s a snippet from it: sekurak : How did you get to the police infrastructure in Washington? Babuk : 0-day VPN. We can’t say anything else, it’s 0-day after all. sekurak : When did the Washington Police realize that…
Ransomware gang leaks court and prisoner files from Illinois Attorney General Office
Catalin Cimpanu has an update to a situation first reported on DataBreaches.net last week. The operators of the DopplePaymer ransomware have leaked a large collection of files from the Illinois Office of the Attorney General after negotiations have broken down and officials refused to pay a ransom demand, The Record has learned. Perhaps the most interesting…
Departing lawyers who copied firm’s databases may be liable for unfair business practices, top state court says
On April 15, Debra Cassens Weiss reported: Departing lawyers who downloaded a “treasure trove” of proprietary materials from their Boston law firm may be liable for unfair or deceptive business practices, the Massachusetts Supreme Judicial Court has ruled. The court ruled for the Governo Law Firm in its lawsuit against a group of nonequity partners…
First Horizon discloses data security breach
Paul Davis reports: First Horizon in Memphis, Tenn., disclosed that a number of online customer bank accounts were targeted by a data security breach. The $87.5 billion-asset company said in a regulatory filing Wednesday that it first learned of the breach this month. Read more on Amercan Banker