Grand jury indicts man allegedly responsible for Las Vegas University Medical Center breach

In a follow-up to a HIPAA breach as Las Vegas’ University Medical Center reported last November, the FBI investigation into the matter has resulted in an indictment of the UMC employee allegedly responsible for selling data…

Virginia enacts limited-scope medical information breach notification law

Last month, the Virginia General Assembly passed a new law, to take effect on January 1, 2011, that will implement new disclosure notification rules for breaches of medical information about Virginia residents. The new law appears…

Data loss lessons from TSA disclosure

As reported on Wednesday in the Washington Post and elsewhere, the Transportation Security Administration (TSA) inadvertently disclosed sensitive information about its airline passenger screening practices by posting a document containing this information online. The mistakes involved…

Sometimes a breach is data theft, sometimes it’s business as usual

Among the latest unauthorized disclosures of personal information making headlines is the admission last week by T-Mobile that thousands of its British customers had essentially become pawns in a “black market” for mobile service subscriber information…

Health Net breach highlights weaknesses in state-level breach laws

While affected Connecticut residents and authorities are understandably upset about the recently reported loss by regional health plan provider Health Net of personal information on all 446,000 Connecticut customers served by the plan, the six-month delay…

Are skeptics on federal data breach law missing the point?

As noted in this space last week, based on recent activity in the Senate and similar if less immediate legislative proposals in the House of Representatives, it seems possible that Congress will move ahead with enactment…

More Congressional progress on data breach laws

Thanks to the action of the Senate Judiciary Committee this week, it looks like we have not one but two bills addressing data breach notification requirements that would apply broadly to commercial entities. The measure introduced…