PrivacySignal
Breach

LACMA data breach last year exposed social security and medical data

BleepingComputer · · International · Data Breaches

The Los Angeles County Museum of Art disclosed that a data breach occurring last year exposed sensitive personal information belonging to customers and employees, including Social Security numbers and medical data.

Why this matters: Social Security numbers and medical records are not inconvenient to replace — they are permanent and deeply personal. People who visited a museum or worked there did not sign up to have that information put at risk. When breaches like this sit undisclosed for months, the people affected lose time they could have used to protect themselves. The real accountability question is how LACMA stored this data, how long it took to discover the breach, and whether anyone is responsible for the gap between when it happened and when people were told.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
CyberScoop · · US Federal

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

‘Close Enough’ Data Breach Notifications Create Exposure

A summary judgment ruling against a telecom company in a state regulatory lawsuit illustrates how vague or approximate data breach notifications can create legal liability. The case suggests that companies falling short of precise technical disclosure standards may face enforcement consequences beyond the breach itself.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement#regulation Read original →
Breach
DataBreaches.net · · International

Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

Seoul National University Hospital did not file mandatory cybersecurity disclosures for years, even after a breach that affected 830,000 people. An investigation revealed the hospital had been operating under an exemption from the standard reporting requirements that apply to other large hospitals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →
Breach
HIPAA Journal · · US Federal

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System, a non-profit serving patients in south central Georgia, has agreed to pay $1.2 million to settle a lawsuit stemming from a data breach. The settlement resolves claims against the health system without a court ruling on liability.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
BleepingComputer · · International

Hackers breached over 270 Zimbra servers in ongoing attacks

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →