2 weeks after JPS Health Network outage, patients still dealing with fallout

Giles Bruce reports: Patients at Fort Worth, Texas-based JPS Health Network are facing lasting consequences from a network outage that stretched nearly two weeks, the Fort Worth Star-Telegram reported. JPS Health Network operated under a “controlled ne… Continue reading 2 weeks after JPS Health Network outage, patients still dealing with fallout

New Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing data

Sharman Gill reports: …  BYU research finds that EdTech vendors don’t always meet their student privacy obligations; that research has led to new Utah legislation that tightens up the privacy issues. In an August 2025 investigation report prepare… Continue reading New Utah law protects student privacy after BYU research found K-12 apps were collecting and sharing data

Inside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police Unit

Hudson Rock’s InfoStealers has an interesting story. From their Executive Summary: In May 2023, an infostealer infected a computer belonging to the Military Police Investigation Section in Suluk, northern Syria – a unit of the Turkish-backed Syri… Continue reading Inside a Syrian Interrogation Room: The Detainee Files an Infostealer Stole From a Military Police Unit

Health systems warn of coordinated phishing targeting Epic’s patient portal

Chad Van Alstin reports: Numerous health systems across the country have issued alerts, warning patients to ignore scam messages that are attempting to phish passwords from patients, allowing hackers to gain access to Epic Systems’ MyChart patient port… Continue reading Health systems warn of coordinated phishing targeting Epic’s patient portal

Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

This is one of those headlines where our first thought was “Uh oh!” but then we read more and thought “Hmmm…” Ko Jae-woo reports: Seoul National University Hospital has not filed a mandatory cybersecurity disclosure for ye… Continue reading Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

Ascent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was Deleted

A DataBreaches.net Commentary On July 31, Asheville Beaverdam NC Opco LLC d/b/a Bear Mountain Health and Rehabilitation, Asheville Victoria NC Opco LLC d/b/a Elevate Health & Rehabilitation, and Asheville US Seventy NC Opco LLC d/b/a Swannanoa Vall… Continue reading Ascent Skilled Nursing Facilities Assure Breach Victims of “Credible Evidence” Stolen Data Was Deleted

“Cognizable damage” required for data breach claims, MA appeals court says in a first

Christopher R. Deubert of Constangy, Brooks, Smith & Prophete, LLP writes: Helpful guidance for businesses, and for Massachusetts state courts. In 2021, the U.S. Supreme Court held in TransUnion, LLC v. Ramirez that in a suit for damages, “the mere… Continue reading “Cognizable damage” required for data breach claims, MA appeals court says in a first

ShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuest

Yesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings. ReliaQuest did no… Continue reading ShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuest