The recent fine of $5.55 million dollars levied on Advocate Health Care Networks (AHCN) starts to sketch out liability levels for failing to protect sensitive personal information. This will be of great interest to insurance companies looking to calculate risk premiums and to IT providers looking to limit liability.
AHCN is the largest health care provider in the Chicago area and between July and November 2013 they suffered 3 data breaches. 4 million records went missing but there has been no indication that these records have been used or published. So no loss to date for the victims.
2 of the 3 breaches were straighforward theft of hardware (4 desktops / 1 laptop) rather than the more exotic type of cyber attack.
The areas of failure were identified as follows;
failure to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to all of its ePHI;
failure to implement policies and procedures and facility access controls to limit physical access to the electronic information systems housed within a large data support center;
failure to obtain satisfactory assurances in the form of a written business associate contract that its business associate would appropriately safeguard all ePHI in its possession; and
failure to reasonably safeguard an unencrypted laptop when left in an unlocked vehicle overnight.
No doubt AHCN will have attempted to present itself as the victim of crime, which it was, but was fined nevertheless even though the data does not appear to have been misused.
How many handlers of personal data would currently pass the tests above ?
Showing posts with label cyber liability. Show all posts
Showing posts with label cyber liability. Show all posts
Thursday, 18 August 2016
Tuesday, 16 August 2016
Sage hacked : insider threat and third party liability
Recent news that Sage (the accounting software provider) has been hacked and that staff details of around 300 UK businesses have been accessed (names, addresses, bank details etc) should alarm many SME's who rely on third party technology providers without question.
According to reports internal login details were used so this was less of a high tech hack and more of a walking in through an unlocked door - a disgruntled insider probably.
The Information Commissioners Office are having a look at this and this breach is potentially more serious than TalkTalk as the type of data access looks to be more valuable and personal. But when the fire has been put out who will pick up the tab and compensate the individuals whose data has been taken ?
Sage will no doubt be going through the terms and conditions of standard contracts to determine if they can wriggle out of any liability to their impacted customers. In any event what direct loss does a customer suffer if name, address, bank details etc are published on the open internet ? If a customer is later the victim of internet fraud will it be possible to create a causal link between the breach and the loss ?
Might Sage be insured for cyber breach ? If so does this cover insider threat which might well be viewed as negligent ? Will the insurance extend to pay customers of Sage compensation ?
Given the above complexity it is understandable that Sage should seek to keep as low a profile as possible on this matter but if you are using a Sage solution right now how secure do you feel ?
Anybody can be hacked but the question of who picks up the tab when it happens is far from settled.
According to reports internal login details were used so this was less of a high tech hack and more of a walking in through an unlocked door - a disgruntled insider probably.
The Information Commissioners Office are having a look at this and this breach is potentially more serious than TalkTalk as the type of data access looks to be more valuable and personal. But when the fire has been put out who will pick up the tab and compensate the individuals whose data has been taken ?
Sage will no doubt be going through the terms and conditions of standard contracts to determine if they can wriggle out of any liability to their impacted customers. In any event what direct loss does a customer suffer if name, address, bank details etc are published on the open internet ? If a customer is later the victim of internet fraud will it be possible to create a causal link between the breach and the loss ?
Might Sage be insured for cyber breach ? If so does this cover insider threat which might well be viewed as negligent ? Will the insurance extend to pay customers of Sage compensation ?
Given the above complexity it is understandable that Sage should seek to keep as low a profile as possible on this matter but if you are using a Sage solution right now how secure do you feel ?
Anybody can be hacked but the question of who picks up the tab when it happens is far from settled.
Friday, 19 February 2016
Cyber attacks; Who carries the liability ?
It is clear that the volume of cyber / hacking attacks is rapidly increasing whether very low tech (but effective) phishing scams or much more advanced activity.
What is less clear is who is picking up the tab when things go wrong. Given that most companies tend to outsource hosting and webdesign and frequently work with freelance IT contractors liability may be limited at the contractual level. There is also a strong incentive for existing technical providers to insist all is well to avoid clients digging too deep and realizing that they are carrying all the liability.
Insurance has a part to play here but the insurance industry seems to be struggling to determine risk premiums and the policies available are awash with exclusions.
It was widely reported that TalkTalk suffered substantial loss from being hacked but not made clear whether this was an insured risk.
If private data is held on a third party shared server and that data is stolen partly through the failure of the hosting company to implement reasonable levels of security who pays ?
Arguably none of this has really mattered in hard financial terms because losses have been difficult to quantify. This is set to change if the legislation which can fine companies up to 4% of turnover comes into force in 2017.
One way or another the issue will be clarified and whether the liability rests with the client or IT / hosting contractors. With the average cost to an SME of a cyber attack being @£190,000 the cost is material.
What is less clear is who is picking up the tab when things go wrong. Given that most companies tend to outsource hosting and webdesign and frequently work with freelance IT contractors liability may be limited at the contractual level. There is also a strong incentive for existing technical providers to insist all is well to avoid clients digging too deep and realizing that they are carrying all the liability.
Insurance has a part to play here but the insurance industry seems to be struggling to determine risk premiums and the policies available are awash with exclusions.
It was widely reported that TalkTalk suffered substantial loss from being hacked but not made clear whether this was an insured risk.
If private data is held on a third party shared server and that data is stolen partly through the failure of the hosting company to implement reasonable levels of security who pays ?
Arguably none of this has really mattered in hard financial terms because losses have been difficult to quantify. This is set to change if the legislation which can fine companies up to 4% of turnover comes into force in 2017.
One way or another the issue will be clarified and whether the liability rests with the client or IT / hosting contractors. With the average cost to an SME of a cyber attack being @£190,000 the cost is material.
Subscribe to:
Posts (Atom)

