Excellus Health Plan, Inc. has agreed to pay $5.1 million to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to implement a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules related to a breach…
Category: Of Note
Polish DPA fines Virgin Mobile Polska €460,000: Incidental safeguards review is not regular testing of technical measures
The President of the Personal Data Protection Office (UODO) imposed a fine of PLN 1.9 million (EUR 460,000) on Virgin Mobile Polska for the lack of implemented appropriate technical and organisational measures to ensure the security of the processed data. UODO stated that the company infringed the principles of data confidentiality and accountability specified in…
M.D. Anderson’s $4.3 Million Fine for Patient Data Loss Vacated
This is huge. Mary Anne Pazanowski reports: The University of Texas’s M.D. Anderson Cancer Center dodged a $4.3 million fine for losing over 35,000 people’s protected health information after the Fifth Circuit ruled Thursday that HHS acted arbitrarily and capriciously in finding that the provider violated two information security regulations. You can read more on…
Guangdong authority orders Tencent, Xpeng, other tech firms to amend apps over cybersecurity concerns
Iris Deng reports: The communications authority in southern Guangdong province has cracked down on the operation of 209 apps, including seven run by internet giant Tencent Holdings and one from electric car maker Xpeng, over privacy and security concerns amid China’s renewed drive against misuse of consumer data. The Guangdong Communications Administration in November and…
Email security firm Mimecast says hackers hijacked its products to spy on customers
Reuters reports: Email security provider Mimecast said on Tuesday that hackers had hijacked its products in order to spy on its customers. The company said it had been alerted to the attack by investigators at Microsoft and that “a sophisticated threat actor” had compromised the certificate used to guard connections between its products and Microsoft’s…
Convicted Hacker Charged with Fraud and Identity Theft Committed While Incarcerated in Federal Prison
There’s an update to the case involving Ardit Ferizi, whose criminal history and conviction for hacking and providing material support to a terrorist organization have been covered previously. Just last month, Ferizi had been sentenced to 20 years in prison, but was granted a reduction to time served plus 10 years supervised release, to be…