86 Medicare data breaches by Department of Human Services in past financial year

November 15, 2016

A regular theme running through privacy and data protection law is how poorly government agencies and private organisations manage health records.  That seems to be counter intuitive given the extraordinary problems that arise from revealing personal information held in medical records.  Under Australian law there are potentially serious consequences for Read the rest of this entry »

A UK Historical Society fined for data breach by the Information Commissioner’s Office

November 14, 2016

Data breaches through lost or stolen lap tops or other BYODs (bring your own devices) is quite common.  Unlike lost paper documents it is possible to lose a significant amount of data held in digital form.  Which is what happened to a Historical Society recently.  The Information Commissioner has issued a Monetary Penalty Notice, fining the Historical Society £500.

The media release Read the rest of this entry »

Big W has self inflicted data leak but nothing compared to the massive data breach at the Friend Finder Network.

Data breaches involving the personal information of thousands of people barely rates a mention in data security journals.  Even those involving hundreds of thousands are seemingly ubiquitous, though Read the rest of this entry »

The vulnerability of health information…

The Health sector is a perfect storm of a poor privacy culture, high staff turnover, inadequate training for professionals resistant to perceived outside interference, ineffective regulation and highly sensitive personal information of patients.  It is little wonder that data breaches and privacy invasive practices in the health sectory are chronic problems. On 12 November two Dutch Hospitals reportedly stopped using a Belgium laboratory for pre natal testing when they found it was using the personal information for commercial marketing.   A California health plan had a data breach in October while in Florida Read the rest of this entry »

Federal Trade Commissioner provides guidance on how to defend against Ransomware…

November 13, 2016

Ransomware is a chronic problem, particularly in the health sector which is reliant on very sensitive records, including those of patients, and in a work environment which has a high turnover of staff and generally a poor privacy culture. Ransomware is almost invariably Read the rest of this entry »

Australia’s biggest data breach, involving 1.3 million records collected by the Red Cross..not quite the world beating Yahoo data breach earlier this year but very significant

October 28, 2016

Another day, another massive data breach. This time an Australian record with more than a million personal and medical records of people donating blood to the Australian Red Cross having their information exposed on line.

The Red Cross issued a fairly comprehensive statement which Read the rest of this entry »

US Federal Communications Commission institutes new rules to enhance internet users privacy

The Federal Communications Commission (the “FCC”) has just passed new rules which will limit internet service providers in the United States selling on customer information and increases customers control over their personal information.  The announcement is Read the rest of this entry »

Privacy Amendment (Notifiable Data Breaches) Bill 2016 introduced into House of Representatives today….first step to mandatory data breach notification in Australia

October 19, 2016

Today the Privacy Amendment (Notifiable Data Breaches) Bill 2016 was introduced and read for the first time.  Mandatory data breach notification laws have Read the rest of this entry »

Victoria police has yet another problem with data security… new breaches familiar pattern of behaviour

October 16, 2016

Misuse of confidential information and regular data breaches has been a longstanding and systemic problem for the Victorian Police Force.  In the past two years I have posted on problems with the misuse of the LEAP database, which contains personal information of Victorians, here and here.  Police documents containing sensitive personal information were found in the possession of outlaw bikie gang members in 2013.

In his 2016 annual report Victorian Commissioner for Privacy and Data Security set out problems in the Victorian Police with data management.  There was a 36% increase in data security breaches over the previous year.  The Commissioner identified Read the rest of this entry »

Hera Project Pty Ltd v Bisognin & Anor [2016] VSC 591 (3 October 2016); prohibitive and mandatory injunctive relief, defence of hardship, undertaking as to damages

Applications for injunctive relief are not uncommon in the commercial division of the superior courts.  In Hera Project Pty Ltd v Bisognin & Anor [2016] VSC 591 Justice McCaulay considered an application arising relating to a contract of sale of land.

FACTS

His Honour described the events leading up to this application was Read the rest of this entry »