Casey Tonkin reports: Woolworths gave data about customers who use its Everyday Rewards scheme to NSW Health in order to assist contact tracers. At the outbreak of the recent Berala cluster linked to a BWS in Sydney’s west, Woolworths analysed information from its Everyday Rewards loyalty scheme to find customers who visited the store at times when…
Category: Of Note
EDPB Publishes Guidelines on Examples regarding Data Breach Notification
Hunton Andrews Kurth writes: On January 18, 2021, the European Data Protection Board (“EDPB”) released draft Guidelines 01/2021 on Examples regarding Data Breach Notification (the “Guidelines”). The Guidelines complement the initial Guidelines on personal data breach notification under the EU General Data Protection Regulation (“GDPR”) adopted by the Article 29 Working Party in February 2018. The new draft…
CHwapi hospital hit by ransomware; operations canceled, and another city hit
Another hospital has been hit with ransomware. The following is a Google translation of a report The CHwapi, hospital center of Picardy Wallonia in Tournai, was the victim of a computer attack on Sunday evening. All non-urgent operations were canceled on Monday. No ransom demand has been demanded, according to management. The CHwapi was the…
Cybercriminals are Bypassing Multi-factor Authentication to Access Organisation’s Cloud Services
Graham Cluley writes: The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to companies to better protect their cloud-based accounts after several recent successful attacks. According to an advisory published by CISA, an increasing number of attacks have succeeded as more employees have begun to work remotely with a variety…
Cz: They attacked Hospital of Aftercare in Horažďovice; police are investigating
Jan Horák reports (translation): According to the findings of Aktuálně.cz, criminal investigators are revealing the background to the hacker attack on the aftercare hospital. Hackers attacked a medical facility in Horažďovice last week, knocking out part of its information systems. The hospital now operates without restrictions. The National Office for Cyber and Information Security consulted with the facility…
Excellus to pay $5 million to settle charges stemming from breach that impacted 9.3 million
Excellus Health Plan, Inc. has agreed to pay $5.1 million to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to implement a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules related to a breach…