Grupo
Financiero Banorte, Mexico’s third largest bank, suffered a data breach earlier
this year and is now reportedly being fined 32 million pesos ($1.98 million) by
the Mexican data protection authority, the National Institute of Transparency,
Access to Information and Protection of Personal Data, for failing to inform
all of its clients immediately after the hack occurred. Mexico’s National
Banking and Securities Commission is also investigating the matter and is
expected to issue corrective measures.
To formulate and implement an effective incident response solution, including but not limited to an attorney and forensic experts on stand buy, contact Gerrie van Gaalen
Showing posts with label protection. Show all posts
Showing posts with label protection. Show all posts
Friday, September 04, 2015
Friday, July 24, 2015
International: China Seeks To Tighten Control Over Internet With Draft Cybersecurity Law
The Chinese parliament has issued
a draft cybersecurity law aimed at “safeguarding China’s sovereignty over
cyberspace and national security and public interests.” The law outlines
a plan for a multi-level system to prevent unauthorized network access, and
calls for Internet-related industry associations, ISPs, and businesses to
strengthen their cybersecurity standards. It also establishes specific
security requirements for operators and suppliers of networks and critical
information infrastructure, including a provision that requires ISPs to store
on Chinese territory any data collected within China and to obtain government
approval before storing data overseas for business purposes. If enacted,
the draft law would allow the Chinese government to expand its online
censorship practices and its control over Internet service providers and
foreign firms operating in the country.
Sounds like certain movements in South Africa...worrying movements.
© Copyright 2015 Steptoe
& Johnson LLP
Friday, May 23, 2014
US: Protection of Personal Information
HHS Announces Record
HIPAA Settlement
New York-Presbyterian
Hospital (NYP) and Columbia University have agreed to pay a combined $4.8
million – the largest HIPAA settlement ever involving a single incident – to
settle charges that they violated the HIPAA Privacy and Security Rules by
accidentally making the electronic protected health information of their
patients accessible to Internet search engines. The Department of Health
and Human Services’ Office for Civil Rights (OCR) launched its investigations
after the entities – which operate a shared data network and firewall –
notified it of the breach. As part of the settlement, NYP will pay $3.3
million, and Columbia will pay $1.5 million. The entities also agreed to
undertake risk analyses, develop risk management plans, revise their existing
policies and procedures, and provide training on privacy and security
awareness.
(c) Steptoe & Johnson LLP
Subscribe to:
Posts (Atom)