Overheard and Noted: "eRisk Hub is an unparalleled resource for absolutely everything you need to deal effectively with a breach - before and after it happens."                             "eRisk Hub puts everything at your fingertips. It's not a data dump - it's the best of the best."
REGISTER   |   NEWSLETTER SIGNUP   |   CONTACT US   
 
Healthcare Data Breaches
Total Number Reported: 63
Latest Incident
University Health System
State: Nevada
# of Records: 7,526
Type of Breach: Theft
See more at www.HHS.gov

Featured Articles
The Intersection of Business Continuity and Data Breach Preparedness

New Data Breach Legislation

Data Breaches: A Sidewalk Sale of Consumer and Personal Information

The “Should” Rule of Cloud Computing

Social Networking: Setting Boundaries in a Borderless Brave New World


Cyber Risk News
Zurich UK cops $4m data loss fine

Conn. AG investigates Yale med school data breach

Milton Hospital apologizes for breach of confidentiality

Portland psychologist's laptop stolen; 4,000 patients face possible identity breach

Thousands of online banking customers have accounts emptied by 'most dangerous trojan virus ever created'


Security Wire
Microsoft to address DLL load hijacking flaw, issues new tool
 
Researchers, ISPs fail to contain notorious Pushdo botnet
 
CA to acquire Arcot Systems for SaaS identity management
 
Security information sharing is a shared responsibility
 
Intel-McAfee marriage could fuel renewed chip security interest
 
Will 2010 See the Enactment of a Comprehensive Federal Data Security Law?
by David Navetta, Esq., CIPP, Information Law Group

Today the Senate Judiciary Committee approved two federal data security bills, Senator Leahy's S. 1490, the Personal Data Privacy and Security Act, and Senator Feinstein's S. 139, the Data Breach Notification Act.  Of course, there have been dozens of proposed federal breach notification bills over the past several years, from both sides of the aisle.  Senator Leahy's office issued this statement earlier today. While we cannot predict the fate of S. 1490 and S. 139, and we will have future occasion to comment on the bills in more detail, Tanya and I wanted to highlight a few notable provisions now.

S. 139 appears to greatly expand the categories of personal information that would result in a notice obligation in the event of a breach. Under the bill, “sensitive personally identifiable information” includes first name and last name in conjunction with any 2 of the following pieces of information: Home address or telephone number; Mother's maiden name; or Month, day, and year of birth. This definition would significantly alter a company's notice obligations under the current state regulatory scheme (most state follow California's model, requiring notice only for breaches involving name in conjunction with Social Security number, driver's license number, financial account number, and in some cases medical information). Under S. 139, a company that suffers a breach exposing only first and last name, address (or phone number) and date of birth would have notice obligations (subject to the risk of harm threshold incorporated into the bill, discussed below), including a requirement to notify the DOJ, resulting in further scrutiny. Moreover, this bill allows for fines up to $1,000 per day per impacted person (up to $1 million).

To continue reading, you must be a subscriber.
SUBSCRIBE NOW
FOR FULL ACCESS
TO THE eRISK HUB.
SUBSCRIBE NOW
Ask about our
enterprise solution

eRISK HUB PRO