Counsel Ben Wanger discusses the 2024 Global Gaming Expo with Heath Renfroe from Fenix24 and Alexandra Bretschneider from Johnson Kendall Johnson....more
On August 22, 2024, the United States intervened in a whistleblower suit against the Georgia Institute of Technology, initially filed by current and former members of Georgia Tech’s cybersecurity team, alleging that Georgia...more
9/26/2024
/ Compliance ,
Controlled Unclassified Information (CUI) ,
Cybersecurity ,
Data Security ,
Department of Defense (DOD) ,
Department of Education ,
Educational Institutions ,
False Claims Act (FCA) ,
Federal Contractors ,
Information Systems Security Program (ISSP) ,
Misrepresentation ,
NIST ,
Proposed Rules ,
Risk Assessment ,
Risk Mitigation ,
Security and Privacy Controls ,
Whistleblowers
On June 28, 2024, Pennsylvania Governor Josh Shapiro signed an amendment to Pennsylvania’s Breach of Personal Information Notification Act into law. The amended law, which includes significant changes to the Keystone State’s...more
Educational institutions in the United States, as well as those in other countries, are reporting experiencing a fairly new type of fraudulent scheme: the ghost student scam. “Ghost students” are stolen or fake identities...more
The FBI has announced that university aerospace researchers, both foreign and in the U.S., have become a target of a specific phishing scheme that is being conducted by threat actors. Specifically, researchers with access to...more
We’re back with a deeper dive into the 2023 Data Security Incident Response Report, which features insights and metrics from 1,160+ incidents in 2022.
This episode dives deeper into privacy litigation.
Questions & comments:...more
As set forth in BakerHostetler’s 2023 Data Security Incident Report, privacy litigation is on the rise. Indeed, 2023 saw a nearly 100 percent increase from 2022 in the number of lawsuits filed in connection with data security...more
8/16/2023
/ Cause of Action Accrual ,
Class Action ,
Colleges ,
Data Privacy ,
Data Protection ,
Educational Institutions ,
Facebook ,
Invasion of Privacy ,
Personally Identifiable Information ,
PHI ,
Putative Class Actions ,
Social Media ,
Tracking Systems ,
Universities ,
VPPA
On June 1, the FBI, the U.S. Department of State and the National Security Agency, together with the Republic of Korea’s (ROK) National Intelligence Service, National Police Agency and Ministry of Foreign Affairs, issued a...more
6/7/2023
/ Colleges ,
Cybersecurity ,
Data Theft ,
Foreign Policy ,
Geopolitical Risks ,
Hackers ,
Journalists ,
Korea ,
Media ,
Nonprofit Research Organizations ,
North Korea ,
Phishing Scams ,
Public Policy ,
Risk Alert ,
Risk Mitigation ,
Scientific Research ,
State-Owned Enterprises ,
Universities ,
US Department of State
On February 9, 2023, the Department of Education Office of Federal Student Aid (“FSA”) issued an electronic notice regarding the Federal Trade Commission’s Final Rule amending the Standards for Safeguarding Customer...more
Educational institutions have not been excluded from the ransomware epidemic, and stakeholder communications are critical to an effective response. In a typical double-extortion ransomware attack, threat actors demand that...more
2/3/2023
/ Colleges ,
Cyber Attacks ,
Educational Institutions ,
Extortion ,
Harassment ,
Public Communications ,
Public Relations ,
Public Schools ,
Ransomware ,
Students ,
Universities
We recently wrote about North Carolina’s new law prohibiting state agencies - including public schools and universities - from paying a ransom or even communicating with a threat actor following a ransomware incident. On June...more
On April 5th, North Carolina became the first state to prohibit state agencies and local governments from paying ransoms after becoming victims of a ransomware attack. Indeed, in addition to prohibiting said entities from...more
In the event of a ransomware attack, there are a host of legal frameworks that could potentially be implicated. Whether those laws apply often depends on the nature of the data that the threat actor accessed and/or acquired....more
4/19/2022
/ Cyber Attacks ,
Cybersecurity ,
DFARS ,
Educational Institutions ,
FERPA ,
FOIA ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Ransomware ,
Risk Management ,
Safeguards Rule ,
State Data Breach Notification Statutes
The best way to ensure that an educational institution can respond quickly and effectively to a ransomware attack and minimize any chaos and confusion that accompanies such incidents is to have an incident response plan in...more
The ransomware epidemic has affected and continues to affect all industries, including healthcare, manufacturing and finance. Since 2020, however, the education industry has been targeted as much as or more than any other...more
On June 16, 2021, the Connecticut General Assembly adopted an expanded version of Connecticut’s data breach notification statute (2021 CT H.B. 5310 (NS)). Through this expansion, Connecticut’s data breach notification statute...more
The emergence of e-sports is no longer news. According to industry reports, the global e-sports industry created over $950 million in total revenue in 2020, and experts expect that number to grow to $1.6 billion by 2023....more
In certain cases, the General Data Protection Regulation (GDPR) requires entities that experience a personal data breach to provide notice of the incident to relevant national supervisory authorities and the individuals whose...more
2/19/2021
/ Cybersecurity ,
Data Breach ,
Data Controller ,
Data Management ,
Data Protection ,
EU ,
European Data Protection Board (EDPB) ,
General Data Protection Regulation (GDPR) ,
Notification Requirements ,
Personal Data ,
Popular
Although it was widely reported that several ransomware threat actor groups have pledged to not target healthcare providers until the COVID-19 pandemic is over, BakerHostetler’s Digital Assets and Data Management Practice...more