News & Analysis as of

Settlement Agreements Data Breach

Saul Ewing LLP

HHS OCR Continues Active HIPAA Enforcement with Three New Settlements

Saul Ewing LLP on

In the past several weeks, the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR") has announced settlements with three health care organizations — Comstar, LLC ("Comstar"); Guam Memorial...more

Health Care Compliance Association (HCCA)

From $5,000 to $800,000: Days Apart, OCR Security Settlements Show Puzzling Math

A single incident that may have started as a personal vendetta or an extortion threat seven years ago has cost a Florida health care system $800,000, and comes on the heels of an unrelated breach suffered by a different...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

2025 Enforcement Trends: Risk Analysis Failures at the Center of HHS’s Multimillion-Dollar HIPAA Penalties

In the first five months of 2025, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced it had entered into ten Health Insurance Portability and Accountability Act (HIPAA) resolution...more

Robinson+Cole Class Actions Insider

Data Breach Class Action Settlement Approval Affirmed by Ninth Circuit with Attorneys’ Fee Award Reversed and Remanded

Some data breach class actions settle quickly, with one of two settlement structures: (1) a “claims made” structure, in which the total amount paid to class members who submit valid claims is not capped, and attorneys’ fees...more

Alston & Bird

Class Action & MDL Roundup 2024 Q3 – Our Market Research is Sustainable

Alston & Bird on

Welcome to the Class Action & MDL Roundup, our quarterly review of decisions and settlements in the class action arena. In this edition, it’s not a breach if it isn’t stolen, a greenwashing claim is washed away, and a...more

Perkins Coie

FTC and State Coalition Settle Data Breach Cases with Marriott

Perkins Coie on

The Federal Trade Commission (FTC) announced a complaint and proposed consent order against Marriott International Inc. and its subsidiary, Starwood Hotels & Resorts Worldwide LLC, on October 9, 2024, concerning three alleged...more

Jackson Lewis P.C.

Failure to Safeguard, Two Cyber Intrusions, and an $850,000 SEC Settlement

Jackson Lewis P.C. on

Virtually all organizations have an obligation to safeguard their personal data against unauthorized access or use. Failure to comply with such obligations can lead to significant financial and reputational harm. In a...more

Alston & Bird

Class Action & MDL Roundup 2024 Q1 – Reaching Across the Pond

Alston & Bird on

Welcome back to the Class Action & MDL Roundup! This edition covers notable class actions from the first quarter of 2024. In this edition, UK High Court weighs in on information asymmetry, debit is better than credit,...more

Orrick, Herrington & Sutcliffe LLP

District Court approves $1.75 million data breach settlement

On March 3, the U.S. District Court for the Central District of California granted final approval of a $1.75 million class action settlement resolving allegations related to a 2020 data breach that compromised nearly 100,000...more

Skadden, Arps, Slate, Meagher & Flom LLP

Privacy & Cybersecurity Update - January 2023

In this month’s Privacy & Cybersecurity Update, we analyze recent fines against Meta and their impact on the future of behavioral advertising, the timeline for the California Privacy Rights Act’s regulations to become...more

Health Care Compliance Association (HCCA)

One Security Guard, One Container: Find Unravels Derm Practice's Disposal Failure

Report on Patient Privacy 22, no. 9 (September, 2022) - When recommending best practices, federal privacy and security officials stress that organizations need to follow their protected health information (PHI) wherever...more

Health Care Compliance Association (HCCA)

2016 Breach Costs OK State Medical Center $875K; System Initially Missed Vulnerability

Report on Patient Privacy 22, no. 8 (August, 2022) - Oklahoma State University Center for Health Sciences’ (OSUCHS) breach might not have seemed all that serious at the time: No data is believed to have been misused,...more

Robinson+Cole Data Privacy + Security Insider

University of Pittsburgh Medical Center Settles Data Breach Class Action for $450,000

The University of Pittsburgh Medical Center (UPMC) recently settled a data breach class action for $450,000 stemming from a 2020 data breach that led to the compromise of about 36,000 UPMC patients....more

Robinson+Cole Data Privacy + Security Insider

Insurance Technologies Corp. to Pay $11 Million in Data Breach Class Action

Insurance Technologies Corp. faces a class action in the U.S. District Court for the Northern District of Texas for a 2021 data breach. Plaintiffs alleged that Insurance Technologies failed to adequately protect and secure...more

Wyrick Robbins Yates & Ponton LLP

Buyers Beware: the FTC’s Case Against CafePress Highlights Privacy and Data Security Risks in Corporate Transactions

Last week the Federal Trade Commission announced a privacy and data security enforcement action against the online retail platform CafePress. The allegations in the FTC’s complaint read like a list of worst practices,...more

Polsinelli

When the Feds Find Out! Lack of Data Security Leads to Novel and Hefty Settlements

Polsinelli on

The Federal Government continues ramping up enforcement of data security requirements by deploying significant new enforcement theories and tools in support of cyber and data security controls required by federal law....more

Robinson+Cole Data Privacy + Security Insider

IT Staffing Company Settles Data Breach Class Action

Artech Information Systems settled a data breach class action this week for an incident that occurred in January 2020. Artech will pay up to $10,000 to each individual affected by the breach, based on a tiered payment system....more

Robinson+Cole Data Privacy + Security Insider

EyeMed Settles with NY AG for $600,000 Over 2020 Data Breach

EyeMed Vision Care, LLC, was the victim of a hacking incident in 2020 that compromised the personal information of 2.1 million consumers, including their names, addresses, Social Security numbers, member numbers of health and...more

Health Care Compliance Association (HCCA)

Report on Patient Privacy Volume 22, Number 1. Privacy Briefs: January 2022

Report on Patient Privacy 22, no. 1 (January, 2022) - New Jersey issued its third settlement in three months on state-level health care privacy and security laws, announcing that three cancer care providers would adopt new...more

Bilzin Sumberg

Recent Settlements and Penalties Show Perils of Data Breaches

Bilzin Sumberg on

Two major U.S. financial institutions, Morgan Stanley and Capital One, recently agreed to resolve separate class action lawsuits by paying, in the aggregate, hundreds of millions of dollars in compensation for massive data...more

Robinson+Cole Data Privacy + Security Insider

FabFitFun Settles Class Action for $625,000 for Alleged Data Security Failures

FabFitFun, a fashion and beauty subscription service, settled claims that it failed to adequately protect and secure consumer data resulting in a data breach for a sum of $625,000 in the U.S. District Court for the Central...more

Robinson+Cole Data Privacy + Security Insider

$2.35 Million Settlement in Dickey’s Barbecue Data Breach Class Action

This week, a proposed data breach class action against Dickey’s Barbecue Restaurants Inc.  was settled for $2.35 million in the U.S. District Court for the Northern District of Texas with approval of the settlement terms by...more

Robinson+Cole Data Privacy + Security Insider

Filters Fast LLC Fails to Obtain Dismissal of Plaintiffs’ Proposed Class Action

This week, a North Carolina federal judge denied Filters Fast LLC’s motion to dismiss a proposed data breach class action, ruling that the plaintiffs demonstrated adequate harm to satisfy Article III standing....more

Jackson Lewis P.C.

NY Attorney General Announces Settlement After Website Data Breach

Jackson Lewis P.C. on

In late May, New York Attorney General Letitia James announced a $200,000 settlement agreement with Filters Fast, an online water filtration retailer, stemming from a 2019 data breach compromising the personal information of...more

Robinson+Cole Data Privacy + Security Insider

NYDFS Settles with National Securities Corp. for $3M for Violations of DFS Cybersecurity Regulations

The New York Department of Financial Services (NYDFS) has settled alleged violations of the Department’s strict cybersecurity regulations with National Securities Corp. (NSC) for $3 million, over four separate cybersecurity...more

126 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide