A U.S. Department of Health and Human Services Administrative Law Judge (ALJ) has ruled that The University of Texas MD Anderson Cancer Center (MD Anderson) violated the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules and granted summary judgment to the Office for Civil Rights (OCR) on all issues, requiring…
Category: Commentaries and Analyses
CO: Hacking case against basalt roofer dismissed
Jason Auslander reports: The District Attorney’s Office on Friday dismissed its case against the owner of a basalt roofing company accused of hacking into a competitor’s computer files and using the information to undercut and sabotage the competitor’s bids. Gregg Mackey, owner of Red Eagle Roofing, was first charged with a computer crime felony equal…
Data breach litigation against optometry board revived
Judy Greenwald reports: A federal appeals court has overturned a lower court ruling and reinstated putative class action data breach litigation against the National Board of Examiners in Optometry Inc. The 4th U.S. Circuit Court of Appeals in Richmond, Virginia, said in Tuesday’s ruling in Rhonda L. Hutton et al. v. National Board of Examiners…
Canada Revenue Agency logs 2,338 privacy breaches in just under 2 years
Monique Scotti reports: The personal, confidential information of over 80,000 individual Canadians held by the Canada Revenue Agency may have been accessed without authorization over the last 21 months, according to government documents made public last week. But while the number of potential privacy breaches may be eye-popping, the CRA is downplaying the seriousness of…
Hackers can summon Cortana to break into Windows 10 PCs
Tom Warren reports: Microsoft has issued a Windows 10 security update to prevent hackers from breaking into PCs using Cortana. Microsoft’s digital assistant is built into every version of Windows 10, McAfee security researchers discovered it could be summoned from a lock screen to execute malicious software. Any potential hacker would need physical access to…
French Data Protection Authority Imposes a Record 250,000 € Fine to Optical Center for a Security Breach on its Website
Catherine Muyl and Marion Cavalier of Foley Hoag write: On June 7, 2018, the French Data Protection Authority (the CNIL) published a decision (issued one month earlier) in which it imposed a record 250,000 euros fine on Optical Center (which, although its name does not indicate, is a French company) for having insufficiently secured the…