In the aftermath of the breach involving MidState Medical Center, Connecticut’s Attorney General George Jepsen and Consumer Protection Commissioner William M. Rubenstein are asking Hartford Healthcare and its Midstate Medical Center affiliate in Meriden for more information about a data breach that may have compromised medical records of 93,500 patients. The hospital notified the Attorney…
Who should be notifying consumers about the Epsilon breach?
Senator Richard Blumenthal, a staunch consumer privacy advocate, has said that Epsilon should be notifying every consumer whose data were involved in the recent humongous breach. You can read his entire letter to Attorney General Eric Holder requesting an investigation on his web site, but here’s part of what he wrote: I believe that immediate…
VT: Barton employee info may have been compromised
Gina Bullard reports: The town of Barton is reporting a security breach that may have exposed personal information. Town officials say they recently discovered spyware on a computer in the town offices affecting the payroll program. They do not know if confidential information, like Social Security numbers, were accessed. Vermont State Police were notified and…
(update) More Student SSNs Were At Risk, TEA Says
Morgan Smith reports that a breach involving the Texas Education Agency was much worse than originally reported. Last month, the TEA reported that an unencrypted disk containing data on almost 25,000 Laredo Independent School District students had gone missing. But when the Texas Tribune obtained records about the breach, they discovered that there were data…
Pointer: Data breach law in Ireland – the current state of play
TJ McIntyre has kindly shared a handout for a presentation he gave on the state of data breach law in Ireland. You can read it on his blog.
Epsilon a Victim of Spear-Phishing Attack, Says Report (update/correction)
Jaikumar Vijayan follows up on the news story by iTnews, mentioned earlier today, which reported that the Epsilon attack was a spear-phishing attack that resulted in the downloading of malware. Jai makes a point of noting, however, that there’s no proof or confirmation yet from Epsilon that this was a spear-phishing attack. As I commented earlier today,…