Madeline Salinas and Libbie Canter of Covington and Burling write: As we look ahead at 2022, we here provide a quick wrap-up of key developments for U.S. state privacy laws in the past year: California Privacy Protection Agency is appointed and commences rulemaking. In June, the new California Privacy Protection Agency (CPPA) held its inaugural public meeting,…
Morgan Stanley to pay $60 million to resolve data security lawsuit
Jonathan Stempel reports: Morgan Stanley agreed to pay $60 million to settle a lawsuit by customers who said the Wall Street bank exposed their personal data when it twice failed to properly retire some of its older information technology. A preliminary settlement of the proposed class action on behalf of about 15 million customers was…
Tokyo police lose 2 floppy disks containing personal info on 38 public housing applicants
Here’s one I missed, but luckily Zack Whittaker noted it in his weekly newsletter (and if you don’t get his newsletter, you should subscribe!) The Mainichi reported: The Metropolitan Police Department (MPD) has lost two floppy disks containing personal information on 38 people, the department announced on Dec. 27 The MPD said the floppy disks…
Out with the old, in with the new? Saltzer Health, Broward Health report data breaches impacting protected health information
Saltzer Health, Idaho As 2021 wound down, Saltzer Health in Idaho reported a breach it had discovered on June 1. According to their notification, an employee’s email account had been compromised. Investigation showed the access began on May 25. On December 29, Saltzer issued a notice that disclosed the incident and reported that the types…
Portuguese newspaper is hacked by group that attacked Ministry of Health
Abhishek Pratap reports: The Portuguese newspaper Expresso was attacked by hackers at dawn this Sunday, 2. Those responsible for the invasion are the Lapsus Group, the same team that shut down the Ministry of Health’s systems last December. The newspaper’s website displays a page similar to the one shown in the attack on the Brazilian government agency….
UVA Health notified patients after Ciox Health data breach (updated)
Someone on Twitter asked me what the first breach of 2022 would be. The following public notice is not the first breach of 2022. It is a 2021 breach that just showed up after midnight in my news search this morning. And because it involves a third-party breach, we may see other covered entities affected,…