Following what appears to be a pretty well-established pattern by now, Maine’s Supreme Court has dealt victims of the Hannaford Bros. breach what will likely be the final blow, telling them that they cannot sue unless they have suffered unreimbursed financial losses, physical harm or identity theft. In their opinion, they state: We, therefore, are…
Category: Of Note
Creator of CallService.biz extradited to New York
Dmitry Naskovets, the creator and operator of CallService.biz — an online business that assisted over 2,000 identity thieves in over 5,000 instances of fraud — was extradited from the Czech Republic on charges of conspiracy to commit wire fraud, conspiracy to commit credit card fraud, and aggravated identity theft. According to a press released issued…
Julie’s Place hack: an all-too-familiar story by now
This breach was first reported earlier this month, but I seem to have missed it: About 100 people found out over the last couple weeks that someone else had accessed their bank account, taking their money and leaving them stunned. […] After being flooded with reports of fraud, the Leon County Sheriff’s Office began to…
Former UPMC Shadyside Hospital employee charged with HIPAA violation
In the first HIPAA prosecution in the Western District of Pennsylvania, United States Attorney David J. Hickton announced this week that a resident of Monroeville, Pa., had been indicted by a federal grand jury in Pittsburgh on charges of multiple illegal disclosures and use of patient individually identifiable health information for personal gain. The Health…
CA: 33,000 patient records sold for the value of the paper
I saw this press release on the breach I mentioned yesterday on PHIprivacy.net where a janitor allegedly sold 14 boxes of patient records to a recycler for the value of the paper although I cannot find a copy of this press release on either the DHS web site or the LASD web site: The Los…
The Securosis 2010 Data Security Survey
Over the summer we initiated what turned out to be a pretty darn big data security survey. The primary goal of the survey was to assess what data security controls people find most effective, as well as get a better understanding of how they are using the controls, what’s driving adoption, and a bit on…