Over on Bleeping Computer, Lawrence Abrams reports that Cencora confirmed that protected health information was involved in the February cyberattack in its recent SEC filing, As DataBreaches previously reported, a number of Cencora—-Lash Group’s clients disclosed that personal and protected health information (PHI) was involved when they sent out notifications to their patients in May…
Category: Subcontractor
EdTech, Impersonation, and Managing Risk
Bill Fitzgerald (@FunnyMonkey) has written a post that I wish all school districts would read, process, and follow up on. The following is just a snippet from his post: We should assume that the KnowBe4 impersonation and the xz incident are not isolated or unique, and that there are other similar attacks underway that are…
Judge Guts SEC Case Against SolarWinds Over Cyber Practices
Cassandre Coyer reports: A US federal judge dismissed much of the Securities and Exchange Commission’s lawsuit against SolarWinds Corp. that alleged the software provider misled investors about its cybersecurity practices and the significance of a major data breach that spilled into the US government. Thursday’s ruling was seen as a blow to the SEC’s aggressive efforts to regulate…
Au: Healthed data breach exposes personal details
Michelle Wisbey reports: The personal details of a large number of GPs have been published online, in a data breach leaving doctors feeling ‘significantly concerned’. Australian healthcare educator Healthed confirmed that late on Sunday, 14 July, the company became aware of ‘a vulnerability within the Healthed website’ It traced this to work undertaken by a…
Students’ Personal Data Mismanaged; Data Sent to Foreign Businesses, Used to Update Apps
The Yomiuri Shimbun reports: Local governments have authorized Recruit Co. — a provider of educational apps — to directly obtain public school students’ personal data and manage it, The Yomiuri Shimbun has learned. The problem is connected to devices, such as personal computers and tablets, which elementary and junior high schools distribute to their students….
HealthEquity says data breach is an ‘isolated incident’
Lorenzo Franceschi-Bicchierai reports: On Tuesday, health tech services provider HealthEquity disclosed in a filing with federal regulators that it had suffered a data breach, in which hackers stole the “protected health information” of some customers. In an 8-K filing with the SEC, the company said it detected “anomalous behavior by a personal use device belonging…