While there are other cyber provisions in the NDAA, a long-touted incident notification rule, requiring some victims of breaches to alert the federal government within a few days of noticing, was not included.
It is common for security teams to forget that chats and email accounts that live on breached networks will no longer be secure, a variety of breach responders, negotiators, and preparation consultants told SC Media.
This week’s roundup is led by a ransomware-related data exfiltration incident at Planned Parenthood LA, joining a number of other reported data theft and hacking incidents.
A patient recently filed a lawsuit against ReproSource Fertility Diagnostics over alleged security failings that led a healthcare data breach impacting 350,000 patients.
An unauthorized third party dwelled inside GoDaddy’s Managed WordPress network for two months via a compromised password. SSL private keys were also exposed.
This week’s roundup is led by a months-long hack and data theft of Sea Mar Community Health and includes a number of HIPAA-compliance concerns with delayed notifications.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.