Latest Publications

Share:

NIST issues Draft Framework for Cyber-Physical System

On September 18, 2015, the National Institute of Standards and Technology (NIST) issued its draft Framework for Cyber-Physical Systems (CPS), which is “intended to provide a methodology for understanding, designing and...more

Excellus Blue Cross Blue Shield sued for data breach announced last week

Within days of Excellus Blue Cross Blue Shields’ (Excellus) announcement that its data had been accessed by a hacker through a “sophisticated” cyber-attack, two law firms teamed up to file a proposed class action suit last...more

79,000 students’ data breached by vendor of Cal State

We End Violence, a third party vendor that provides online sexual assault prevention training to California State (Cal State) students notified Cal State that it experienced a vulnerability in its underlying code that exposed...more

Lyft and First National Bank notified of TCPA violations by FCC

Late last week, Lyft and First National Bank (FNB) were notified by the Federal Communications Commission (FCC) that they had violated the Telephone Consumer Protection Act (TCPA) when they required users to opt in to...more

Weekly Privacy Tip#1 – Password management

I am asked every day how one can protect their information and privacy in this world of daily data breaches, so we are adding a weekly practical tip to assist our readers in managing their information....more

Advocate Health class action lawsuit trimmed

Last week, an Illinois judge dismissed with prejudice five of the six claims levied against Advocate Health Care in a consolidated case of ten cases filed against it following the data breach it experienced in July of 2013...more

Ashley Madison data breach update

Anonymous users of the almost 40 million users of the Ashley Madison website have filed suit against internet service providers (ISPs) GoDaddy and Amazon alleging that they have been damaged because the ISPs hosted the stolen...more

European authorities arrest alleged banking malware developers

Law enforcement authorities have announced the arrest of two individuals-one a Russian national and the other Moldovan, both of whom are alleged to have developed and implemented banking malware known as Citadel and Dridex....more

UCLA cleared in lawsuit alleging breach as to sexually transmitted disease information

UCLA was absolved by a California judge last week in a suit filed by a patient of a UCLA affiliated doctor’s group, who alleged that a temporary worker in the doctor’s office used the doctor’s username and password to get...more

UCLA suffers another data breach

Last week, UCLA notified 1242 patients that their health information may have been compromised in July when a faculty member’s laptop was stolen. UCLA has notified the patients, the Office for Civil Rights and the California...more

National Futures Association proposes cybersecurity rules for its members

The National Futures Association (NFA) recently approved new mandatory cybersecurity rules for members of the futures industry. Members of the NFA include exchange-traded futures, forex and over-the-counter swaps industries....more

10 million Excellus Blue Cross Blue Shield members’ information compromised

Yesterday, Excellus Blue Cross Blue Shield, located in Rochester, NY, announced that it will notify up to 10 million members that it was the victim of a cyber-attack dating back to December of 2013 that exposed their members’...more

32 alleged IRS hackers arrested

The federal government has arrested 32 members of the Insane Crip gang and charged them with 283 counts of criminal conspiracy, 299 counts of identity theft, 226 counts of grand theft and 58 counts of attempted theft through...more

U.S. Department of Education issues FERPA guidance related to medical information

In conjunction with the new school year, the U.S. Department of Education issued guidance, in the form of a “Dear Colleague” letter, to higher education institutions to remind them of FERPA’s requirements as they relate to...more

OPM data breach update–$133 million contract awarded to vendor

The Office of Personnel Management (OPM) and the Defense Department announced this week that a Portland, OR based vendor has been selected to assist with breach notification and credit assistance for the almost 22 million...more

MAC zip code privacy suit settled

MAC Cosmetics, Inc. (MAC) has settled a proposed class action suit filed in Massachusetts federal court, which alleged that it illegally obtained customers’ zip codes at the point of sale. MAC has agreed to set up a fund...more

Maryland AG settles with Visionworks over security practices

Using the Maryland Consumer Protection Act, Maryland Attorney General Brian Frosh has announced that eye care retailer Visionworks, Inc. has agreed to pay the state of Maryland $100,000 and enhance its security measures...more

New survey shows continued lack of executive confidence in cybersecurity and increases in data loss

A new survey released by Raytheon and websense, called “Study-Why Executives Lack Security Posture Confidence While Knowing that the Metrics They Use to Gauge it are Ineffective” “reveals that confidence in [executives’]...more

Online entertainment network Machinima settles with FTC

California based Machinima, an online entertainment network that promoted Xbox One, has settled an investigation with the FTC surrounding its advertising practices. The FTC alleged that Machinima paid “influencers” to post...more

NIST issues Cybersecurity Practice Guide for Electric Utilities

Yesterday, the National Cybersecurity Center of Excellence issued its NIST Cybersecurity Practice Guide, Draft Special Publication 1800-2 “Identity and Access Management for Electric Utilities.” The Guide is a result of...more

Ashley Madison Fallout: Class Actions, Pentagon investigation and easily searchable data

We previously reported that hackers The Impact Team had posted legitimate detailed information about 36 million adultery website Ashley Madison users. In the wake of the shocking posting of the data last week, two class...more

First “Right to be Forgotten” enforcement action levied against Google

The U.K. Information Commissioner issued an order to Google this week requiring it to remove nine search results of an individual’s minor criminal offense that was committed close to ten years ago. This is reported to be the...more

Third Circuit affirms FTC’s jurisdiction over security practices in Wyndham case

In a strongly worded opinion, the Third Circuit Court of Appeals on Monday slammed Wyndham Worldwide Corporation’s arguments that the FTC did not have jurisdiction to enforce the security practices of businesses following a...more

OPM Breach Update

In response to the massive OPM data breach, the government has been searching for a vendor to provide identity protection services for the almost 22 million individuals affected. Bids were due last week, and the chosen vendor...more

IRS sued in putative class action for lax security

Following the IRS’ admission that its data breach was actually larger than it originally reported and caused fraudulent tax returns to be filed affecting over 330,000 taxpayers, the IRS was sued this week in a proposed class...more

2,214 Results
 / 
View per page
Page: of 89

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide