Michael Sessa reports: The names and Social Security numbers of about 9,800 Syracuse University students, alumni and applicants have been exposed after someone gained unauthorized access to an employee’s email account. The university has sent letters to affected students, alerting them that the university had investigated a data security breach involving some of their personal information….
Category: U.S.
NY: Man Pleads Guilty to Stealing Nude Photos of Dozens of Victims
A New York man pleaded guilty Monday to computer fraud and aggravated identity theft related to his hacking of online social media accounts and theft of nude images of dozens of female victims. Acting Assistant Attorney General Nicholas L. McQuaid, Acting U.S. Attorney Antoinette T. Bacon of the Northern District of New York, Special Agent…
When to Report a Breach: Consideration of Encryption States
Matt Fisher of Carium writes: Data breaches grab headlines on a daily basis and arise from a number of different scenarios. However, one question that is not necessarily examined closely (at least in news articles), is whether encryption was in place and why the encryption did not prevent the breach. That rhetorical question does not…
What Does the Fifth Circuit’s Vacating of HHS HIPAA Fines Mean for Companies This Year?
Here is some more commentary on the Fifth Circuit opinion in MD Anderson v. HHS. Elfin Noce, Liisa Thomas & Susan Ingargiola of SheppardMullin write, in part: On the ruling regarding the disclosure of ePHI, the Fifth Circuit held that HHS had failed to establish that MD Anderson disclosed ePHI to someone outside of the covered entity. The…
Lessons from Wengui v. Clark Hill: Structuring a Two Track Cyber Investigation
Stephanie A. Diehl of Proskauer writes: As the D.C. District Court in Wengui v. Clark Hill recently commented, “[m]alicious cyberattacks have unfortunately become a routine part of our modern digital world. So have the lawsuits that follow them….” The court’s decision in that case has added another data point to developing jurisprudence of the cyberattack landscape, specifically…
The M.D. Anderson Case and the Future of HIPAA Enforcement
Privacy law scholar Daniel Solove writes: The U.S. Court of Appeals for the 5th Circuit just issued a blistering attack on HIPAA enforcement by the U.S. Department of Health and Human Services (HHS). In University of Texas M.D. Anderson Cancer v. Department of Health and Human Services (No. 19-60226, Jan. 14, 2001), the 5th Circuit struck down a fine…