Mandy Zuo reports: A three-year investigation by police in southwest China into personal data theft has ended with 32 people behind bars and several more awaiting trial, state media reported. More than 50 people were detained by police in Chongqing as part of a nationwide effort to track down and dismantle a criminal gang known…
Category: Of Note
CPSC Notifies Consumer Product Manufacturers of Possible Data Breach of Safety Information
Merrit Jones and Jena Valdetero of Bryan Cave write: A number of retailers and manufacturers have recently received notices from the U.S. Consumer Product Safety Commission concerning a possible data breach. The CPSC’s letter advises recipients of an unauthorized release of confidential information that did not go through the procedures of 15 U.S.C. § 2055,…
HHS exercises enforcement discretion and reduces maximum civil penalties
Those who want to see HHS/OCR come down like a ton of bricks on more entities and impose heavier civil monetary penalties for HIPAA breaches will likely not be happy to learn that HHS has decided to reduce the maximum civil penalties it will impose for the four tiers of violations of HIPAA. Under the…
University of Alaska discovered a breach in February, 2018 that they are first revealing now?
The following is not quite the typical press release like we’ve been seeing on an almost daily basis. If this notice doesn’t include typos, then it appears that the University of Alaska first became aware that they had a problem in February of 2018. They started an investigation that they expanded in March, 2018 after…
Safeguard your network and customer credentials: Tips from the latest FTC data security case
One of the other enforcement actions the FTC has taken stems from the ClixSense breach in 2016. Lesley Fair of the FTC writes: Suppose a lunch companion says, “I think there’s something wrong with this tuna salad.” To determine if the problem is tuna not to their taste vs. tuna gone bad, would you scarf…
Greek DPA Issues EUR 30,000 Fine For Data Protection Violation by Hellenic Petroleum S.A.
Hunton Andrews Kurth writes: On April 15, 2019, the Greek Data Protection Authority (“DPA”) fined Hellenic Petroleum S.A. EUR 20,000 for unlawful processing of personal data and EUR 10,000 for failing to adopt appropriate data security measures. Hellenic Petroleum S.A. had engaged a vendor to conduct a study on its behalf. The study was exposed…