Cybersecurity & Tech
Virginia Gov. Terry McAuliffe, Chair of the National Governor Association, urges states to:
Fitness Tracker data storage in the cloud leaves individuals subject to the following data privacy issues:
Irish Times | Fitness trackers run into resistance over data security concerns
The Securities Exchange Commission has issued a warning investment advisers that they need to be more proactive in data security by:
Reuters | SEC identifies adviser cyber security flaws
Reuters | Exclusive: New SEC enforcement chiefs see cyber crime as biggest market threat
Has a US city had its credit rating downgraded after a cyber attack? No
Do financial industry analysts think it possible to downfgrade a city’s credit rating after a cyber attack? yes
What factors can play into whether a local governmental entity’s credit rating could get downgraded?
Governing | Can a Cyberattack Cause a Credit Rating Downgrade?
State: California
The legislation: Assemblyman Matt Dababneh sought to apply the standard applied to business of requiring 1 year of ID theft protection services for anyone who is impacted by any government breach in California. AB 241 (2017)
The Opposition is winning as the bill stalls. The loyal opposition includes California State Assn. of Counties, the Urban Counties of California, and the League of California Cities
Opposition arguments:
Government Tech | New Legislation Pressures California Lawmakers to Strengthen Data Security
The federal HEALTH CARE INDUSTRY CYBERSECURITY TASK FORCE released 27 recommendations in its June 2017 report, and set forth these 5 future regulatory issues for health care cybersecurity:
Develop a cohesive plan for implementing this report’s recommendations and develop appropriate metrics to measure data security implementation progress.
Conduct a risk analysis, similar to the National Infrastructure Protection Plan, with an overlay for health care cybersecurity and privacy. Based upon the analysis, develop a comprehensive cybersecurity roadmap for the HPH Sector.
Establish an ongoing public-private forum, similar to this Task Force, to further the discussions of health care industry cybersecurity as the industry evolves. The Task Force members found this engagement with federal partners beneficial to understand our common cybersecurity challenges and concerns.
HHS leadership should partner more closely with existing DHS efforts with the insurance industry in helping identify a roadmap to enable private insurance approaches in the health care industry. The sometimes-conflicting roles of HHS as a regulatory body and facilitator for improved security could be mitigated by encouraging an industry-based insurance market.
Enable an ongoing conversation and develop strategies to identify resources and incentives that would help to overcome the barriers faced by small and rural organizations.
Create a cybersecurity leader role within HHS to align industry- facing efforts for health care cybersecurity.
Establish a consistent, consensus-based health care-specific Cybersecurity Framework
Require federal regulatory agencies to harmonize existing and future laws and regulations that affect health care industry cybersecurity.
Identify scalable best practices for governance of cybersecurity across the health care industry.
Explore potential impacts to the Physician Self-Referral Law, the Anti-Kickback Statute, and other fraud and abuse laws to allow large health care organizations to share cybersecurity resources and information with their partners.
Secure legacy systems.
Improve manufacturing and development transparency among developers and users.
Increase adoption and rigor of the secure development lifecycle (SDL) in the development of medical devices and EHRs.
Require strong authentication to improve identity and access management for health care workers, patients, and medical devices/EHRs.
Employ strategic and architectural approaches to reduce the attack surface for medical devices, EHRs, and the interfaces between these products.
Establish a Medical Computer Emergency Readiness Team (MedCERT) to coordinate medical device-specific responses to cybersecurity incidents and vulnerability disclosures.
Every organization must identify the cybersecurity leadership role for driving for more robust cybersecurity policies, processes, and functions with clear engagement from executives.
Establish a model for adequately resourcing the cybersecurity workforce with qualified individuals.
Create MSSP models to support small and medium-size health care providers
Small and medium-sized health care providers should evaluate options to migrate patient records and legacy systems to secure environments (e.g., hosted, cloud, shared computer environments).
Develop executive education programs targeting Executives and Boards of Directors about the importance of cybersecurity education.
Establish a cybersecurity hygiene posture within the health care industry to ensure existing and new products/systems risks are managed in a secure and sustainable fashion.
Establish a conformity assessment model for evaluating cybersecurity hygiene that regulatory agencies and industry could rely on, instead of a diversity of auditors.
The NIST Baldrige Cybersecurity Excellence Builder, should be further developed: 1) specific to health care, and 2) specific to the types of health care operations that are widely deployed across the industry and have limited access to cybersecurity resources (e.g., small hospitals or practices, rural locations with limited access to security resources).
Increase outreach and engagement for cybersecurity across federal, state, local, tribal, territorial, and the private sector partners through an education campaign including meetings, conferences, workshops, and tabletop exercises across regions and industry.
Provide patients with information on how to manage their health care data, including a cybersecurity and privacy grading system for consumers to make educated decisions when selecting services or products around non-regulated health care services and products.
Develop guidance for industry and academia on creating economic impact analysis and loss for cybersecurity risk for health care research and development.
Pursue research into protecting health care big data sets.
Tailor information sharing for easier consumption by small and medium-size organizations who rely on limited or part-time security staff.
Broaden the scope and depth of information sharing across the health care industry and create more effective mechanisms for disseminating and utilizing data.
Encourage annual readiness exercises by the health care industry.
Provide security clearances for members of the health care community.
HEALTH CARE INDUSTRY CYBERSECURITY TASK FORCE REPORT | June 2017
The Hill | Federal task force: Here’s how to fix healthcare cybersecurity
The State Legislature that created the Office of Cyber Defense Coordination: Nevada
Within which state agency will the Office live? Nevada’s Department of Public Safety
The Legislation creating the office: Nevada’s AB 471 (2017)
What do these cyber offices look like in other states?
New Jersey Cybersecurity and Communications Integration Cell
Georgia has its State Government System Review Board, under the direction of Georgia’s CIO.
California’s Cybersecurity Integration Center is housed within the California Office of Emergency Services
Idaho lawmakers approved the Cybercore Integration Center on the Idaho National Laboratory campus
Oregon has pending legislation for the consolidation of cybersecurity powers under the state CIO, as well as establishing the Oregon Cybersecurity Center of Excellence and the Oregon Cybersecurity Fund.
Government Technology | Nevada Governor Signs Bill to Create Office of Cyber Defense Coordination
State: Massachusetts
The highest level Massachusetts government position created: Secretary of Technology
The MA Secretary of Technology would be tasked with hiring:
Originator of the MA Secretary of Technology post: The Massachusetts Governor
Data and cyber positions are gaining power insisde and outside government.
Greenfield Recorder | New Baker bill creates Cabinet position for technology
The brainchildren behind Intelligent Transportation Cybersecurity Task Force: Intelligent Transportation Society of America & nonprofit Cyber Future Foundation
Which stakeholders are involved? auto manufacturers, government leaders and transportation officials
What will the task forces study? cybersecurity issues- legal and liability issues and policy, regulation and legislation- to esnusre the highest elevel of safety and privacy in a connected transportation environment
Politico | Morning Cyber Security | NEW TRANSPORTATION THINKING
Healthcare Dive | What happens to telemedicine if we lose net neutrality?
Background: The FCC in 2017 overturned internet privacy
What is Congress Doing in Response? Congresswoman Marsha Blackburn, R-Tenn., chairwoman of the Communications and Technology Subcommittee, filed a bill to return the power to regulate the internet back to the FTC.
What do privacy advocacy rights advocates say about this bill? 17 states have bills to protect state resident data privacy. The federal bill by Congrresswoman Blackburn would preempt those state laws.
Improving the Outcomes of Government IT | Internet Privacy Bill Would Override State Laws
Nevada Senate passed an internet security bill that will:
Why are states passing internet security bills?
A court in Vermont ruled that the State Agency of Education must release school bullying information it has collected under the public information act.
Amendments to Congressman Tom Graves’ Active Cyber Defense Certainty Act include:
Politico Morning Cyber Security | Scoop: ‘Hack back’ bill gets version 2.0
State: Florida
The data breach: Department of Agriculture and Consumer Services online payment system was hacked and the following information was obtained:
What steps did Florida take? Ordered a review of the department’s cyber security measures & offering free credit monitoring
What was the reaction of gun owners? “ too little too late”
WWSB ABC 7 | Concealed weapons permit holders targeted in massive data breach
Satte Attorneys General reached an $18.5 Million settlement with Target.
Law 360 | State AGs Set Data Security Bar With Record $18.5M Pact
AG Paxton Announces $18.5 Million Settlement with Target to Resolve 2013 Data Breach
Country: Germany
The protections that Germany seeks to combat election hacking:
SC Media | Lawmakers in Germany push for encryption-busting trojan in lead up to election
Who is proposing a cyber national guard? Congressman Will Hurd, Chair of the House’s information technology subcommittee
Why push for a cyber national guard? to help recruit stronger talent to fill cybersecurity roles in the federal government
How does the private sector factor in? a cyber nataional guard would “allow industry professionals to bring innovative ideas back into the federal government without the government having to keep up with the salaries available in the technology community.”
The Hill | House IT chair eyes ‘cyber national guard’ as next legislative push
The GAO has issued a warning about the economic impact of data breaches & the economic boon of the Internet of Things, inter conencted devices.
The economic impact as a result of a data breach is tempered by the economic benefits of health care adopting connected devices (IoT technology). The numbers:
Health Care Dive | GAO warns about IoT security, privacy and safety issues
4 ways mortgage companies can up their game and push back regulatory fines:
Housing Wire | Mortgage data isn’t secure: Here’s why and how to fix it
State: Delaware
What is HB 180 in Delaware trying to do?
If passed, Delaware would be state #2 to require ID theft services after a breach.
Legislative body is located where? Australia
What triggers licensing issues when failing to meet data security standards?
The goal: Move data security to the forefront with business leadership
Intelligent Insurer | New data breach reporting legislation deemed cyber game changer in Australia
The advocates: Parent Coalition for Student Privacy and the Campaign for a Commercial-Free Childhood
The toolkit for parents to empower them on student data privacy: toolkit
What’s the target: data privacy policies of school districts and ed tech companies
Education Week | New Student Data Privacy Toolkit Encourages Parent Advocacy
The Federal Trade Commission created the website, FTC Small Business.
The goal of FTC Small Business is to:
State agencies to follow…
SC Media | FTC launches cybersecurity site for small businesses
The State: Rhode Island
The New Executive Level Office in Rhode ISland: state cybersecurity officer
The goal of the office: developing and putting into place a comprehensive state cybersecuritystrategy
How did the state cybersecurity officer position emerge? It was a “key recommendation of the governor’s Cybersecurity Commission, established in 2015 with the aim to lay out plans to protect the state’s IT infrastructure as well as grow a thriving cybersecurity industry”
State Tech | Rhode Island Ups Cybersecurity With Creation of CSO Position
the federal legislation: Making Available Information Now to Strengthen Trust and Resilience and Enhance Enterprise Technology (MAIN STREET) Cybersecurity Act
how it helps small businesses: Adds small businesses to the list of things that the National Institute of Standards and Technology must consider when updating its voluntary guidance on how to guard against cyberattacks.
the state commission recommendation: Missouri’s Cybersecurity Task Force recommended increased support for small businesses around cybersecurity threats
The state: Illinois
The election data target: no specific data target, it was a broadly executed hack on the Illinois election system
The hack: Retrieving voter information via voter identification number starting at “000000001 and incrementally adding one” digit
The Hill | Illinois voting records hack didn’t target specific records, says IT staff
The fake statistic: 60 percent of small businesses that suffer a cyberattack will go out of business within six months
The statistic is usually attributed to : National Cyber Security Alliance
What legisaltion has this fake statistic appeared in? HR 2105 & S770
NextGov | HOW A FAKE CYBER STATISTIC RACED THROUGH WASHINGTON
City: Seattle
Seattle’s Broadband Ordinance requires:
Seattle.gov | Seattle issues rule to strengthen broadband privacy for consumers
Cybersecurity Risk Management Audits are a 2 step process:
Bloomberg | “COMMON LANGUAGE” ENVISIONED FOR CYBERSECURITY RISK MANAGEMENT AUDITS
First came New York. Now comes Colorado promulgating cybersecurity rules on their financial sector.
The Colorado proposal will apply to:
The Colorado rules will require securities licensees to:
Bloomberg Law | Colorado Moving to Set Financial Adviser Cybersecurity Rule
The uptick in hacks as connectivity increases:
Smart technology adoption is high, but:
A hypothetical hack of power systems impacting 93 Million in North America would cost:
anywhere from $21 billion to $71 billion in damages.
Harvard Business Review | Smart Cities Are Going to Be a Security Nightmare
South Africa recently enacted a new data breach notification law that requires companies to:
Business Tech | SA companies will soon be forced to tell customers of a data breach by law
City: Newark, NJ
The ransom: 24 bitcoins, or roughly $30,000
the impact to the city: Poilice operations were functioning, but the city’s administrative systems were functioning in safe mode.
The date of the attack: Began on April 21st.
SC Media | City of Newark reportedly hit in ransomware attack
Federal Agency Regulatory Oversight option(s):
4 identified data security areas in fintech:
Balance data security protections with the 3 benefits of fintech:
State: South Carolina
The Cyber Security Executive Level Entity: Critical Infrastructure Cybersecurity Executive Oversight Group
How was the Critical Infrastructure Cybersecurity Executive Oversight Group created? Executive order
The Governor tasked the group with:
State Tech | South Carolina Establishes Cybersecurity Oversight Group
WISTV | McMaster looks to boost state’s cybersecurity through executive order
How the Spring Branch School District school was hacked: with a stolen password
What did the hacker do once in the SBISD computer system: changed grades
Was the hacker caught?
SC Media | Texas 10th grader hacks school network to change grades
When considering legislation to protect state infrastructure and emergency management systems, it has beeen revealed that the hack that led to the triggering of the Dallas emergency alarms was not a computer hack, but a hack of the radio signals.
State Tech | Dallas Reveals Radio Signals, Not Network Hack, Triggered Emergency Sirens
State: Virginia
The breach that triggered legislation: rampant W-2 phishing e-mails that have plagued businesses
Why was a legislative fix necessary? These data breaches and scames cost many states millions of dollars as a result of payments made and investigations conducted on fraudulent tax returns.
The legislative fix:
The survey of utility professionals: Utility Dive’s fourth annual State of the Electric Utility Survey, surveying more than 600 utility professionals
The #1 most pressing issue facing utility companies: cyber and physical security
what you need to know:
Utility Dive | Why utilities say grid security is the most pressing sector issue of 2017
The U.K. Parliament is working to create an election hacking unit that:
SC Magazine UK | Parliamentary committee proposes unit to combat ‘election hacking’
Trendy new exception to data breach notifications: encrypted data
How Tennesee worded the exception in its legislation:
(1) “Breach of system security”:
(A) Means the acquisition of the information set out in subdivision (a)(1)(A)(i) or (a)(1)(A)(ii) by an unauthorized person that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder:
(i) Unencrypted computerized data; or
(ii) Encrypted computerized data and the encryption key;
The National Association of Insurance Commissioners is being urged to adopt New York’s Cyber Finance Security Rules in each of their respective states.
NAIC will release proposed rules soon
Reuters | New York Regulator Wants Other States to Model Cyber Laws After Its Rules
Refresher on the New York Cyber Security Rules from January 2nd, 2017 informed:intel:
The state upping the ante on data security rules for the finance industry: New York
The new New York rules announced December 28th will:
Business Insider | New York delays new cybersecurity rules for financial firms
Background on the emergency system hack:
Procurement Opportunities for Emergency IT:
New York Times | Hacking Attack Woke Up Dallas With Emergency Sirens, Officials Say
An exception to Tennessee’s data notification law is if the data that was hacked was encrypted.
Bloomberg Law | New Tenn. Law: No Breach Notice Needed if Data Encrypted
The Bill: Illinois Right to Know Bill
What does the Right to Know Bill in Illinois do? It allows a person to know what information is collected about the person and to which businesses that information could be sold.
Why is it considered bad for business?
Dispatch Argus | Bill will crush small business, tech investment
Teaching Hospitals.
Johns Hopkins Carey Business School looked at data for data breeches at hospitals:
Health Care Dive | Teaching hospitals at higher risk for data breaches, study finds
75% of adults polled want digital privacy & “would not let investigators tap into their Internet activity to help the U.S. combat domestic terrorism”
Reuters | Most Americans unwilling to give up privacy to thwart attacks: Reuters/Ipsos poll
New York Times | Push for Internet Privacy Rules Moves to Statehouses
A March 2017 GAO highlights flaws with credit monitoring services.
Credit monitoring services do not address these cyberthreats:
State: Ohio
IT Procurement Issue: How to get innovative tech firms to bid on IT contracts, especially for data analytics.
The procurement change: Remove the old school, clunky procurement process
The procurement fix:
Governing | Letting the Little Guy In: How Ohio Expanded Its IT Expertise
What guidance is the FBI giving medical and dental providers on cybersecurity? That file transfer protocols, FTP, transfers csn be accessed by anonymous users without passwords. Cyber secuity measures should be taken to correct server settings.
What speficially did the FBI say about protected health information (PHI) pr personally identifiable information (PII) ? PHI & PII should not be kept on FTP servers allowing for anonymous operation
National Law Review | New FBI Warning for Healthcare Providers: Cybersecurity
No, thank you. Or, thank you, but no.
Microsoft has taken the stand that the only way it will turn over data to the government is if Microsoft is legally compelled to do so.
What is Microsoft saying? Sue me or more politically correct, “”We will not help any government, including our own, hack or attack any customer anywhere,””
SC Media | Microsoft president takes stand against turning over data
The U.S. Chamber of Commerce is making cyber security recommendations for regulators and policy makers, including:
The Hill | Chamber of Commerce urges Trump to get business input for cyber strategy
The data breach: Denton Health Group had thieves steal 7 years of patient data
The cyber theft: The thieves stole physical hard drives which were not encrypted
Encryption & health care:
The Legislation: Strengthening State and Local Cyber Crime Fighting Act of 2017
What does the bill do? Allows the National Computer Forensics Institute to train law enforcement to combat cyberthreats
Will training be available for state and local law enforcment? yes
Rep. Ratcliffe introduces bill to provide cybersecurity training to local law enforcement
Global Manufacturing | The importance of data security in manufacturing
The Agencies: FTC and NHTSA
The goal of rulemaking: fight cybersecurity and privacy threats from vehicles with systems that connect to the internet
State: California
The legislation:
Sacramento Bee | Are your household items spying on you? One California lawmaker has an answer
State: Indiana
Indiana legislation: HB 1444
What Indiana’s legislation does to penalize ransomeware users:
Do other states treat ransomeare differently from other cyber crimes? Yes, California and Wyoming
Wyoming legislature had a package of student data privacy bills which will:
State: California
The student data security bill: Removes schools from the California Electronic Communications Privacy Act
Where would student daat security responsibility lie? each school district
The profferred reasons why: Cyber bullying, schools need access to student electronic use
Record Bee | Bill would strip privacy protections from students and teachers
State: Kansas
Details of the new Kansas agency on cybersecurity:
Kansas House Bills 2331 and 2359 (2017)
Hutchinson News | In effort to shore up cybersecurity, Kansas panel supports formation of agency
The legislation: Active Cyber Defense Certainty Act
The decriminlaization of hacking: If you’re a vicitm of hacking, this bill would allow you to hack the hackers. It’s like a Castle Doctrine for your Cyber Home.
Sophos | Bill proposes letting victims of cybercrime hack the hackers
The lawmakers: Rep. Joaquin Castro (D-Texas) and Sen. John Cornyn (R-Texas)
The legislative concept: Allow agencies, like Department of Homeland Security, to work with consortia
What could the private entities do for the agencies?
The Hill | Bipartisan bill would let DHS team with consortiums on cybersecurity
Goals of Georgia’s Cyber Innovation Center:
Georgia’s Investment in the Cyber Innovation Center:
State Tech Magazine | Q&A: Georgia CIO Calvin Rhodes on Launching a Cyber Innovation Center
Secure Technology Alliance | Smart Card Alliance Becomes Secure Technology Alliance as the Organization Expands Its Mission to Include a Broader View of Security Technologies
Pennsylvania courts have determined that an employer owes no duty to an employee against a data breach. Next Stop: Codification via the Legislature.
The State: Kansas
The issues that are clouding a bill to protect data stored in the cloud:
Long live the bitcoin in the Texas Constitution thanks to HJR 89 that protects all mediums of currency.
The race: Ft. Lauderdale A1A Half Marathon
The runner’s claim to fame: 2nd fastest time for the race
Any guesses, man or woman who claimed the fast time? a woman
How did she get caught? She posted her GPS race data
SC Media | Char-IOTs of Fire: Marathon cheater exposed by own fitness tracking device, app
Health Care Dive | Charts: Must-know healthcare cybersecurity statistics
What screams fix cybersecurity laws? A breach of a voice recording teddy bear
What’s the issue that would be addresed in legislation? The Teddy Bear company stored customer data and information on a public database that required no authentication.
What does no authentication mean? No security protocols, no passwords, no limited IP addresses etc… It’d be like leaving your credit card statement on a public park bench.
TechHive | Smart teddy bears for kids suffer a contentious data breach
FoxNews | CloudPets data breach: Toy security in the spotlight
Alexa, the Amazon product, home guru records voices.
Alexa also records suspected murderers, at least it did in Arkansas.
What kind of protection is Amazon seeking for the Alexa recordings?
Next step: Legislative fixes
The Verge | Amazon says Alexa’s speech is protected by the First Amendment
The Public Private Partnership: Virginia and Amazon
The role of Amazon: to support scalable cloud infrastructure and collaborate on cybersecurity educational efforts
How far down the state employee food chain will education go? The partnership will also help educate teachers with cybersecurity courseware
A former top national security adviser says the cybersecurity legislation that is necessary is: uniform definitions for cybersecurity across all government levels.
Why do we need uniform definitions? Uniform defintions improve strategy for enforcement and legislation.
Defense of Democracies | Framework and Terminology for Understanding Cyber-Enabled Economic Warfare
5 ways oil and gas comapnies can minimize legal exposure from a data breach:
Oil and Gas Financial Journal | Legal Liability From Cyber Attacks
What group is launching a new campaign fundraising tool? the Internet Association (Google, Facebook, et.al.)
How does the new fundraising tool work?
The Hill | Internet group rolls out new political fundraising tool
What survey reveals that 1 in 4 U.S. Consumers had a health care data breach? An Accenture survey released at HIMSS2017 in Orlando
What is the impact to health care providers? 25% changed health care providers
The Chair of the National Governor’s Association lays out 3 ways states can tackle data and cyber security:
3 States with model public-private partnerships, task forces, and cybersecurity commissions:
The state landscape: Virginia
The cyber security proposals: make it a felony for cyber criminals to use ransomware
The reasons that the change in law may do more harm than good:
What do good cyber security laws do?
Virginia Business | Cybersecurity legislation may do more harm than good
New Mexico’s House Bill 15 wants to put the state on par with other states by remedying a gap in our existing consumer protections by:
Los Alamos Daily Post | House Passes Data Breach Notification Act
A lawyer for Google says new laws are needed to cover data stored on the cloud for these reasons:
The Recorder | Google Lawyer Says New Laws Needed to Govern Cloud Data
Who was targeted by hackers? Backers of Mexico’s soda tax
The hack: text messages that family members had died, with funeral information. Dark, dark stuff.
It’s dark hacktivism in repsonse to activism. Indeed there are companies that sell services in these dark arts.
NY Times | Spyware’s Odd Targets: Backers of Mexico’s Soda Tax
The Legislature: Congress
The data protection bill: Email Privacy Act to update a 1986 law on email
Where is the bill? It passed the House and is moving to the Senate
What’s the fundamental change in the Email Privacy Act? To universally require warrants for emails stored on 3rd party servers
Is this in line with industry standards? Yes, Google, Facebook, Apple, Microsoft and Verizon require warrants before they release emails stored on their servers
The Hill | House passes bill requiring warrants for email searches
State: California
Who pays for ID Protection when a private corportation has a data breach? The corporation
Who currently pays for ID protection when a locla government has a data breach? The person whose data was hacked
Is there a bill to make local governments pay for ID protection when a hack occurs? Yes, California Assembly Bill 241
Government Technology | When a Data Breach Happens, Will California Pay for Protection?
Long gone are the days when data breach notifications only applied to retailers, or so says New Mexico.
The Bill: House Bill 15 (2017) The Data Breach Notification Act
What it does:
KOB 4 | Lawmaker sponsors data breach notification bill
The Company: Vizio
The privacy breach: installed software in televisions that recorded consumers tv habits
The regulatory enforcement: Federal Trade Commission and the New Jersey Attorney General
The fine: $2.2 million + must delete customer data by March
Engadget | Vizio tracked and sold your TV viewing habits without consent (updated)
the hospital: Children’s Medical Center of Dallas
the data security charge: years of noncompliance with HIPAA rules and after failing to request a hearing on the penalty. Since 2010 the hospital used unencrypted devices to store HIPAA protected info
the regulator: U.S. Department of Health and Human Services’ Office for Civil Rights
the fine: $3.2 million civil money penalty
Add Nevada to the list of states moving to create an Office of Cyber Defense. Governor Sandoval proposes funding it with $3.5 million.
The Office of Syber Defense will be within the Nevada Department of Public Safety and will offer assistance to local government agencies and private industry.
Las Vegas Review Journal | Marijuana, cybersecurity among debates to happen in Nevada Legislature
Where: California
How is cybersecurity impacting education statutes? Requiring instruction on determining truth.
Is this a way to repsond to fake news and election hacking? Yes.
How did they wrap this up in pretty policy words? By requiring instruction in “civic online reasoning” means the ability to judge the credibility and quality of information found on Internet Web sites, including social media.”
Holland- the country, not the city in Michigan, will count all its ballots by hand as a reaction to the possibility of election tampering by hackers.
USA Today | Amid hacking fears, Dutch to use pen, paper for vote
The Government cannot compete with tech companies for the employees. Money, money, money.
Where: Maryland
The Governor’s cybersecurity proposal: tax credit accessibility to investors in cybersecurity startups
The state goal: Make Maryland a leader in cybersecurity
WCBM | Governor Larry Hogan’s Robust 2017 Legislative Agenda
Which police department? Cockrell Hill Police Department
What digital data was lost by way of a ransomware attack? video evidence & digital documents
How was the ransomware attack triggered? “someone clicked on a cloned email made to look like it was sent from a department email address”
What did the police department do in response to the ransomeware? wiped their servers in lieu of paying the ransom
WFAA | Cockrell Hill police lose years worth of evidence in ransom hacking
A ransomware attack hit Washington D.C.’s closed circuit tv 8 days before inauguration. Here’s what you need to know to get up to speed:
Washington Post | Hackers hit D.C. police closed-circuit camera network, city officials disclose
Thank you for subscribing to our newsletter.
Great things are just around the corner!