A hacker group calling themselves @1775Sec on Twitter claims to have hacked DropBox. They’ve since posted some data on a paste site that consists of names and e-mail addresses. Lee of CyberWarNews.info, however, has challenged them to provide real proof, noting that the data they posted matches previously leaked e-mail lists. And for its part,…
Today's HHS update included 16 incidents we already knew about
Working through the latest updates to HHS’s breach tool, the following are incidents where we already knew something about the breach. Once again, some of these entries refer to breaches that occurred in 2012, and I have no idea why HHS didn’t post these publicly before now. Links are to previous coverage on this blog…
Hackers Steal Card Data from Neiman Marcus
Brian Krebs reports: Responding to inquiries about a possible data breach involving customer credit and debit card information, upscale retailer Neiman Marcus acknowledged today that it is working with the U.S. Secret Service to investigate a hacker break-in that has exposed an unknown number of customer cards. Read more on KrebsOnSecurity.com.
OK, now HHS is messing with me…
Friday afternoon and HHS has added dozens of new updates/revisions to the breach tool – after adding dozens more during the week? Yikes. As before, some of them appear to be older incidents that had never been posted publicly while others are more recent. One change that I noted immediately is that they’ve now organized…
House passes bill to require data breach notification for breaches involving Healthcare.gov and state exchanges
Pete Kasperowicz reports: The House passed the Health Exchange Security and Transparency Act, H.R. 3811, in a 291-122 vote. Sixty-seven Democrats voted for the bill, ignoring arguments from party leaders that the bill was a “messaging” vote meant to discourage people from signing up for insurance. The one-sentence bill says that no later than two…
NY Court of Appeals rules employer not liable for actions of employee acting outside scope of employment
There’s a follow-up to a breach lawsuit involving an employee of Guthrie Health System who shared a patients’ sensitive medical information with a third party – and privacy advocates will not be happy. As I first noted in March 2011, “John Doe” sued Guthrie Health System after a nurse sent embarrassing text messages about his…