PrivacySignal
Breach

Seoul National University Hospital skips cybersecurity disclosure for years despite breach affecting 830,000

DataBreaches.net · · International · Data Breaches

Seoul National University Hospital did not file mandatory cybersecurity disclosures for years, even after a breach that affected 830,000 people. An investigation revealed the hospital had been operating under an exemption from the standard reporting requirements that apply to other large hospitals.

Why this matters: 830,000 people had their data exposed, and the hospital was not required to tell regulators anything. That exemption is doing a lot of work here. Disclosure rules exist so that breaches get counted, patterns get noticed, and institutions face some pressure to improve. When a hospital this large can sidestep that process, the people whose data was taken have no way to know the system is watching out for them. The real issue is whether an exemption that made sense on paper was ever meant to cover a breach of this scale.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Breach
HIPAA Journal · · US Federal

Valley Oaks Health Data Breach Settlement Gets First Nod from Court

A court has granted preliminary approval to a class action settlement stemming from a June 2023 data breach at Valley Oaks Health, a mental health provider, that affected more than 50,000 individuals. The case now moves toward final approval and distribution of relief to those affected.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →