Analyzing the $7.5 Million UCLA Health Data Breach Settlement episode artwork

EPISODE · Mar 29, 2019

Analyzing the $7.5 Million UCLA Health Data Breach Settlement

from Info Risk Today Podcast · host InfoRiskToday.com

A proposed settlement in a class action lawsuit filed against ULCA Health in the wake of a 2015 cyberattack affecting 4.5 million individuals stands apart from other settlements because it requires the organization to spend a substantial sum on improving its security, says attorney Steven Teppler.

Episode metadata supplied by the publisher feed · Published Mar 29, 2019

Embed this episode

NOW PLAYING

Analyzing the $7.5 Million UCLA Health Data Breach Settlement

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

In 2015, UCLA Health suffered a cyberattack that impacted the records of 4.5 million individuals. Now the healthcare organization has reached a $7.5 million settlement in a class-action lawsuit that was filed against UCLA Health in the wake of the incident. Under the settlement, UCLA Health has agreed to invest $5.5 million in new network security improvements and to pay out $2 million for class-action claims related to ID theft. Impacted individuals will also be entitled to two years of free credit and ID monitoring.

I'm Marian Kolbysak-McGee, Executive Editor at Information Security Media Group, and today I'm speaking with attorney Stephen Tepler of the law firm Mantelbaum Salzburg, PC. Stephen, who is not involved with the lawsuit, will be discussing the significance of the settlement. So Stephen, for starters, what stands out most to you about the settlement? What stands out most to me about this settlement is the amount of funds that are being guaranteed to be spent on improving network security architecture, which I think is a good thing.

I think it's a necessary thing, and it's an enforceable provision in the settlement agreement, and not only enforceable, but it is also capable of supervision, such that not only is there supervision, but the money has to be expended within a certain period of time as well. So there are obligations that are not mere vaporous promises to do something in the future. So Stephen, how does this settlement compare to what we generally see in the outcome of data breach-class action lawsuits? Number one, I think that the settlement amount for identity theft is a little bit low, because I think that there may be more affected individuals than the NAMI API here.

There is two-year identity theft protection, which is pretty much standard, and an amount that's set aside for actual damages, provable demonstrable damages by identity theft victims. What is interesting about this is that the amount that is set aside for the network infrastructure to secure infrastructure improvements, which is, I believe, somewhere in the neighborhood of $5 million, is not a small amount of money to expand on this. And I think that that component is a relatively new component, instead of just having promises apparently accountable and perhaps in cooperation with the defendant, gave some thought to what it would take over a stated period of time to upgrade and fortify the UCLA Health Security Infrastructure. So Stephen, when it comes to data breach settlements, do we often see the requirement for the breached entity to make improvements to their security as part of the settlement?

There will be. Typically, each settlement will be different, but there should, and in increasing numbers, there will be references to undertakings that the victim of the, you know, the institutional victim of these attacks will have to take. But I have not seen that many that get this granular or this exact in saying, you shall spend this amount of money. You shall do it within this period of time.

This shall be a coordinated effort, which in some part will also may also be overseen by counsel for both parties. And of course, because this is part of the settlement order that will come out of the court, this will be enforceable not only by a stipulated contract provision, but by a resource to the court if it's not done. And so do you think this is the way settlements will sort of go from here on? You know, this will set any sort of precedent in terms of these entities that are breached being expected to improve their security as a result of these settlements in these breached cases?

It should. And if I run the plaintiff's side, I would endeavor to make sure that these provisions, that provisions as granular as these are included. I think it's a step in the right direction. We should see more of them.

I can't speak for the parties and their counsel in the future litigation, but certainly it's a good idea. And it shows the money is being well spent and necessarily well spent and deservedly so. Now, Stephen, we often see these sorts of data breach lawsuits get dismissed by courts. Why do you think UCLA Health decided to go ahead and settle?

The short answer is that it decided to do the right thing. The longer answer is that in lieu of spending an inordinate amount of money on counsel fees and an ultimate settlement in some manner, I think that UCLA looked at this and both from a reputational as well as a financial perspective, it just made eminent sense to them. Now, last year, a federal judge in California gave final approval to a $115 million settlement involving health insurer Anthem over its 2015 data breach that impacted almost 79 million individuals. That settlement at the time, or perhaps still, was the largest recorded class action lawsuit filed over a data breach.

But in most cases, as we see, victims either see no money because the cases get dismissed. How do you think that UCLA Health settlement stacks up with what we saw with Anthem? Do you think there's much comparison there? Even though there are fewer people impacted with the UCLA Health incident, the Anthem incident impacted more people.

But are there any similarities there to what we see in the settlement? You know, I think if you scale it, you'll probably find that it apples to apples, that the number of affected individuals in the UCLA case was probably an order of magnitude or two less than those who were affected by Anthem. I think there's a scaling issue. I don't believe that it scales on an arithmetic basis.

In other words, if you have 100 people versus 50 people, you'll have twice the cost. I think that the magnitude, the intensity of the Anthem breach and the infrastructure that was involved in that almost compelled that much larger of the settlement agreement. And you have the cost for identity theft protection, the cost for potential out of actual damages multiplies exponentially. So I don't think they're that far away in terms of amounts based on the size of the breach.

And so, Stephen, when it comes to data security and the key lessons that other healthcare entities should learn from this health data breach cyber attack on UCLA Health and the resulting settlement, what are the key lessons? The key lessons are always the same, and that's you should be working to make your security ecosystem defensible. You know, commercially reasonable security is what you're going to see when you go to court and you have to fight. But defensibility, meaning that you pay attention to what's happening around you.

If you see the dominoes falling all around you, the answer is to get out of the way and see what's causing them to fall. And if you know that there are issues regarding patch management or HR management or a certain type of exploit that's being monetized or a certain type of attack that's just come into play, institutions have to keep their ears to the ground and pay attention. And even if it means devoting resources to it, the resources you devote to it in terms of prevention, detection, prevention, and mitigation in advance, and risk assessment in advance will far outstrip the cost to remediate afterwards. Thanks, Stephen.

I've been speaking to attorney Stephen Tepler. I'm Marianne Kolbesak-McGee of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on March 29, 2019.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!