IT Security & Privacy

Corewell Health Faces Second Data Breach, Exposing 1 Million Michigan Residents' Information

Corewell Health has found itself at the center of another data breach, further highlighting the persistent threat that malicious actors pose to health systems. The latest incident involves HealthEC, a vendor of Corewell Health, with a mission to "identify high-risk patients, close gaps in care, and recognize barriers to optimal care."

Regulators Unveil Cyber Resilience Best Practices for Financial Firms

In a concerted effort to bolster cyber resilience in the financial sector, the UK's Financial Conduct Authority (FCA), Bank of England, and Prudential Regulation Authority (PRA) have released a comprehensive set of guidelines highlighting good practices for firms to adopt. The initiative underscores the regulators' commitment to enhancing operational resilience and fortifying the financial system against cyber threats.

SEC's New Cybersecurity Incident Disclosure Rules Take Effect: Compliance and IT Security Implications

Today marks a pivotal moment in the realm of financial regulatory compliance as the U.S. Securities and Exchange Commission's (SEC) new cybersecurity incident disclosure rules, specifically Form 8-K, come into effect. This initiative, aimed at bolstering transparency and fortifying the response to cybersecurity incidents, applies to all filers except smaller reporting companies. The rules mandate reporting to the SEC within four business days from the determination of materiality.

FBI Offers Guidance on SEC Reporting Requirements for Cyber Incidents

In anticipation of the Securities and Exchange Commission's (SEC) upcoming requirements for companies to disclose material cybersecurity incidents, the Federal Bureau of Investigation (FBI), in collaboration with the Department of Justice, is providing crucial guidance for victims of cyber incidents. With the SEC's new rules set to take effect on December 18, 2023, the FBI aims to assist companies in navigating these reporting requirements, particularly in scenarios involving national security or public safety concerns.

Norton Healthcare Ransomware Attack Exposes 2.5 Million Individuals, Highlighting Growing Vulnerabilities in Healthcare Sector

In a recent data breach notification filed with Maine's attorney general, Norton Healthcare revealed that a ransomware attack in May exposed sensitive data on 2.5 million individuals. The Kentucky-based clinic and hospital group discovered the cyberattack on May 9, determining later that ransomware was involved. The threat actors gained access to some network storage devices between May 7 - 9, although the medical record system remained uncompromised.

Credit Unions Face Outages Amid Ransomware Attack on Third-Party Vendor

Approximately 60 credit unions are grappling with service disruptions following a ransomware attack on Trellance, a third-party IT vendor catering to the industry, as reported by the National Credit Union Administration (NCUA) on Friday. Trellance subsidiaries, including Ongoing Operations and FedComp, have confirmed the cyber incident, with Ongoing Operations specifying a ransomware attack on November 26.

Deutsche Wohnen Ruling by ECJ Anticipated to Escalate GDPR Fines

A recent ruling by the European Court of Justice (ECJ) in the case of German property company Deutsche Wohnen is expected to have far-reaching financial implications for organizations found in breach of the General Data Protection Regulation (GDPR). Legal experts have deemed the decision a "landmark" ruling, altering the landscape of GDPR enforcement.