Class Action Breach Lawsuits: The Impact of Data for Sale episode artwork

EPISODE · Jan 13, 2020

Class Action Breach Lawsuits: The Impact of Data for Sale

from Info Risk Today Podcast · host InfoRiskToday.com

After a data breach, if individuals' stolen information is offered for sale on the dark web, that potentially bolsters class action lawsuits filed by plaintiffs against the breached organization, says technology attorney Steven Teppler of the law firm Mandelbaum Salsburg P.C.

Episode metadata supplied by the publisher feed · Published Jan 13, 2020

Embed this episode

NOW PLAYING

Class Action Breach Lawsuits: The Impact of Data for Sale

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

The Georgia Supreme Court recently reversed a Georgia Court of Appeals ruling to dismiss a class action that was filed against Georgia-based Athens-Orthopedic clinic. The clinic suffered a cyber attack in 2016, allegedly committed by hacking group The Dark Overlord, which reportedly offered at least some of the stolen data for sale on the dark web. I'm Mary Ann Colbusak McGee, Executive Editor at Information Security Media Group, and today I'm speaking about the significance of the recent Georgia Supreme Court ruling with technology attorney Steven Teppler of the law firm, Mendelbaum, Salzburg, PC. So Steven, among other things, in its ruling, the Georgia Supreme Court says the appeals court should have not dismissed plaintiff's negligence claims against Athens at this stage of litigation.

What does that mean and what's the significance about the Georgia Supreme Court ruling in the context of data breach litigation? First, it's important to understand that on a motion to dismiss the credible claims of a plaintiff are usually construed most in a plaintiff's figure. You know, there's been no discovery, per se, there's no testimony, etc. etc.

But the idea is that at least at the motion to dismiss the stage, the plaintiffs pled a credible cause of action for negligence, which is a duty breach in damage and injury. Here, what's interesting is the Georgia Supreme Court really looked at the imminence of damage, the likelihood of damage, rather than actual damage that occurred. But this was as a result of an actual data theft, rather than a speculative event. Well, what could it be construed as a speculative event involving the loss or exfiltration or exposure of data?

So Steven, with that said, how does or doesn't this ruling fit in with other recent trends involving data breach claims action lawsuits? This decision falls in line with a more expansive view of what a damage and standing for victims of data breach, okay? And here, this is medical information as well. So there was a heightened risk because of the richness of the information, the amount of information per victim that was disclosed.

The defendants here, the defense alleged negligence exposed the plaintiff's to risk of harm that was more likely to occur because the fact that the threat actor, the criminal who stole the information, was actually offering it for sale on the dark web. And so you could more likely connect with us between a sale of this information and an immediate identity compromise than the exposure of information arguably. So Steven, as you mentioned in the Athens case, because some of the data was allegedly found on the dark web for sale, in general, if a plaintiff in a data breach case does discover their data on sale on the dark web, does this help his or her case in data breach litigation and why? Well, it does.

It does because it actually shows that the victim's information, someone's attempting to monetize that information. And the likelihood that the purchaser used is very, very much more heightened because you have to prove that aid is information is for sale or is available. And the connecting the docs to say that it's much, much more likely that what happened is made much more clear. And being that there are so many data breaches, are there any definitive ways that plaintiffs could prove that there are data landed on the dark web because of this breach versus another breach, how much burden is there to sort of show where this data might have came from, if it's on the dark web.

Typically, the source of the credit card opinion card information or PHI or PII is not necessarily disclosed together with the offering on the dark web. Could be, but it may not be. One of the better ways to determine that this might have happened is to monitor your own information, find out whether or not all of a sudden your information now appears on the dark web following a disclosed data breach or to try to find out as quickly as possible, whether or not, once you know that there's been a data breach, whether or not the information does, it doesn't appear on the dark web. You can go to a site called HAVAID and TWAID, HAVAID PUNTIN.

You will be notified based on email address in how many data breaches you've been involved as a victim. So Stephen, it's still fairly early in this case, but one of the top security lessons that you think other breached entities could learn from this Athens data breach court case as it proceeds. As a healthcare provider, the clinic was obligated to follow HIPAA guidance and HIPAA rules that relate to confidentiality and accessibility and integrity. Apparently, according to the complaint, it did not.

The idea that compliance is something that can be kind of addressed but not addressed in a really concerted fashion by an enterprise is a myth at this point. And it's a fallacy because at this point, it's trying to switch data breaches, but the onset and the prevalence of ransomware that has been increasing both in size and in volume over the past couple of years makes it even more imperative for a healthcare organization or any organization for that matter that wants to keep on operating to take appropriate measures to either comply with your associated rules, laws, or regulations, whether it's HIPAA or GLB or part 500 in New York, or with doing the steep best practices to keep ahead of the, try to keep ahead of the curve. I mean, no security implementation will be perfect, but taking efforts and being cognizant aware and trying to keep up and making sure everything's patched and taking the appropriate measures and educating and training employees, all play a big hand and being able to make your enterprise defensible and maybe not impervious to but maybe resistant to an attack like this and attack like having the evidence. And finally, Stephen, aside from this case, any predictions for data breach litigation trends in 2020, any other cases that the healthcare sector should be keeping its eye on?

I think, Mary Ann, that there will be an increase, maybe not huge increase in the amount of data breach cases brought because I think there will be an increased number of data breaches that will take place. I think really though that we should be looking at the effects, the cumulative effects of ransomware at this point, because it is being used and targeted more and more at enterprises whose operations would be severely impacted if they were hit by ransomware, but not only their operations, but their clients and customers. So in the healthcare field, also for any managed service provider, managed service providers now are really low hanging fruit for ransomware attacks. There's also at burgeoning data breach plus ransomware attack, double whammy that is starting to be seen.

I have not seen any of my practice yet, but where the information is first exfiltrated, you have a data breach that takes place and then the data is locked up for ransom. These are, they're troubling. I don't see any decrease in the amount of attacks, particularly in light of, you know, the political situation and even the international situation right now, as with what's happening in the Middle East, I think you might see an increase in the amount of attacks and breaches. So I think it'll be a rocky 2020.

Thanks, Stephen. I've been speaking to attorney Stephen Teppler. I'm Mary Ann Cobazak McGee of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 13, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!