IT Security & Privacy

HHS Office for Civil Rights Issues Letter, Initiates Investigation of Change Healthcare Cyberattack

In response to the recent cyberattack affecting Change Healthcare, a unit of UnitedHealth Group (UHG), the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) has taken decisive action to address the significant disruption caused to the nation's healthcare and billing systems. The cyberattack, which occurred in late February, has raised concerns regarding patient care and the integrity of essential healthcare operations nationwide.

FORIOU Faces Fine from CNIL for Unlawful Use of Data

FORIOU, a company specializing in marketing loyalty programs and cards, has been slapped with a substantial fine of €310,000 by the French data protection authority, CNIL (Commission Nationale de l'Informatique et des Libertés). The penalty comes as a result of FORIOU's use of prospect data obtained from data brokers for commercial prospecting purposes without ensuring valid consent from the individuals involved.

New Zealand Central Bank to Enforce Comprehensive Cyber Reporting Rules

The Reserve Bank of New Zealand has unveiled plans to implement robust cyber reporting rules, following the publication of consultation feedback and decisions on collecting essential data to fortify defenses against cyber threats.

AuditBoard Study Unveils Impact of SEC Cybersecurity Disclosure Rules

AuditBoard, an established risk, compliance, and audit management platform, has released the results of an extensive study examining the ramifications of the SEC Cybersecurity Disclosure Rules on businesses. Drawing insights from a survey involving over 300 executives and security professionals in North America, the report delves into the profound implications of the new U.S. Securities and Exchange Commission (SEC) cybersecurity disclosure ruling, which took effect on December 15, 2023.

FTC Orders Avast to Pay $16.5 Million and Halt Sale of Browsing Data After Deceptive Practices

The Federal Trade Commission (FTC) has mandated that software provider Avast pays $16.5 million and cease the sale or licensing of web browsing data for advertising purposes. The settlement comes as a response to charges asserting that Avast, along with its subsidiaries, violated privacy commitments by selling user data despite assuring customers that its products would safeguard them from online tracking.

California Attorney General Bonta Announces DoorDash Settlement Over Privacy Violations

California Attorney General Rob Bonta revealed a settlement with DoorDash, concluding an investigation that exposed the company's breaches of the California Consumer Privacy Act (CCPA) and the California Online Privacy Protection Act (CalOPPA).

Industrial Sector Ransomware Attacks Surge by 50% in 2023, Dragos Inc. Report Reveals

In a recent report by industrial cybersecurity firm Dragos Inc., alarming statistics indicate a 50% increase in ransomware attacks targeting the industrial sector in 2023. The report, titled "The Importance of Industrial Cybersecurity," underscores the critical role cybersecurity plays in safeguarding industrial operations as companies embrace digital transformation.