DocuCrunch.com » Who’s liable for a data breach? Court has some answers

Who’s liable for a data breach? Court has some answers

March 23, 2010 by Steve Hannaford
Posted in: In this week's e-newsletter, Security

In what is likely to be a milestone in the issues of corporate liability for data breaches, a federal district court judge recently dismissed a class action suit against insurance giant Aetna.

The suit concerned a breach of Aetna’s job application database, which contained “the e-mail addresses of 450,000 job applicants, along with the social security numbers of current and former employees.”

Applicants’ social security numbers, telephone numbers for addresses, and employment histories were also in the system.

Aetna sent out warning letters to 65,000 current and former employees after it discovered the breach had occurred, and offered them a year’s worth of free credit monitoring.

A number of applicants subsequently were sent so-called “phishing” e-mails from a source pretending to be Aetna, asking them for even more personal information, supposedly to add to their job application.

The judge in the case threw out the class action, stating in a 14-page opinion that the alleged damage to the plaintiffs was speculative only, with no concrete proof. “At best, plaintiff has alleged a mere possibility of an increased risk of identity theft, which is insufficient for purposes of standing, and he certainly has not asserted a credible threat of identity theft.”

Lesson: This case seems to set a condition that real, provable harm to the plaintiff is a necessary condition for a data breach-related lawsuit. Also, taking prompt action by notifying those affected by the breach can help prevent ID theft, and therefore shield the company from liability.

However, this case is surely just an opening skirmish in what promises to be a long legal war.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , ,


4 Responses to “Who’s liable for a data breach? Court has some answers”

  1. Mike Says:

    This is a bad ruling by a judge without full understanding of the implications. As usual, the courts are well behind the technology.

    The argument is akin to theft of a credit card not being a crime unless the card itself is used in a illegal transaction. The card itself has little to no real value. There would be no *real* loss until the stolen card is used. That would make theft of a credit card or similar item unprosecutable until they were actual used by the thief – an absurd concept.

  2. Jim Says:

    I think Mike may be a bit off the mark. Using his example, I think what the ruling says is that the person who’s card was stolen did not commit a crime by failing to lock it away in a safer place.

    The issue of whether or not any laws were broken and by who is not addressed.

  3. Mike Says:

    My point was that the court ruled that loss of personal information did not constitute harm unless one could proove that information had been misused.

    The credit card anology was related to how such principals are inconsistent within the law.

    The information was stolen from a second party. To your point, does a second party who is entrusted with property (real or otherwise) have a duty to reasonable ensure the security of said property? If not, we are ALL in serious jeopardy considering how much of our personal information we entrust to second parties (who often tranfer to third parties) on a daily basis.

    The court totally sidestepped the question by denying provable harm.

  4. Bob Says:

    This was a civil case. Both of you and you’re comments about ‘unprosecutable’ and ‘not commit a crime’ are off the mark.

    Cheers.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement