In a first, Chinese hackers are arrested at the behest of the U.S. government – The Washington Post

This is shocking. Let’s see where it goes. The Chinese government has quietly arrested a handful of hackers at the urging of the U.S. government — an unprecedented step to defuse tensions with Washington at a time when the Obama administration has threatened economic sanctions. Source: In a first, Chinese hackers are arrested at the …

Cyber Insurance, You Need to Know if You Have It, and Your Lawyer Darn Sure Does!

Cyber law, cybersecurity, cyber attacks, and cyber insurance — unless you live under a rock, you’ve heard of it. And, you had better hope your lawyer has also. I would argue that the minimum standard of care for lawyers practicing in 2015 requires a basic understanding of cyber insurance. In fact, I did make that …

Texas Broadens Unauthorized Access of Computer Law to Specifically Address Insider Misuse

Not that it was really needed, but Texas just amended its unauthorized access of computers law to specifically address misuse by insiders. I have always read the prior version (one of the broadest) as already prohibiting misuse by insiders. But, that is ok. As someone who regularly explains how these laws work to judges and juries, …

Fifth Circuit: Accessing Computer Per Later-Overturned Order Does Not Violate CFAA

In Land and Bay Gauging L.L.C. v. Shor, –Fed.Appx — (5th Cir. Aug. 21, 2015), the Fifth Circuit recently held that accessing a computer under the authority of a court order that authorizes the access is sufficient to render the access as being authorized, even if the order is later overturned. An essential element under …

Those 3rd party IT audit provisions you

Those 3rd party IT audit provisions you’re seeing in Privacy & Data Security Addenda to contracts – this is why: Hillary Clinton’s email firm was run from a loft apartment with its servers in the bathroom

Employee Retaining Stored Patient List on Personal Laptop Triggers Data Breach Obligation

An employee of East Bay Perinatal Medical Associates in Oakland, CA, retained on his personal laptop, a patient list that he had prepared as part of his job. The list did not contain PHI information but it did contain PII information. The Berkley Police discovered the list during an unrelated investigation and notified EBPMA that it …

Employee Viewing Information Without Authorization Triggers Data Breach Notification Obligation for Credit Union

An employee of Golden State Credit Union viewed member account information, containing Personally Identifiable Information (PII), without having the requisite authority to view such accounts. This action — alone — was sufficient to trigger the notification requirement of the California data breach notification law, at great expense and frustration for the Credit Union, which offered …

Rocky Dhir Interviews Shawn Tuma About Cybersecurity for Lawyers at State Bar of Texas 2015 Annual Meeting

I had the wonderful opportunity to visit with and get to know Rocky Dhir (@rockydhir) at the State Bar of Texas 2015 Annual Meeting in San Antonio. Rocky is the Founder and CEO of Atlas Legal Research, LP (@atlaslegal), “the world’s leading legal outsourcing company.” Rocky and I did a brief interview where we talked …

The CFAA Requires Access of a Computer — Not Just Access to Information

To have a valid CFAA claim, there must be an access to a computer. The Computer Fraud and Abuse Act is often referred to as an “access crime” because the act that is prohibited is accessing a computer. Misusing information that someone else obtained from a computer is not accessing a computer. Doing so may …

Using Single Individual Password to Access News Site to Share Info With Others is Not CFAA Interruption of Service

A person’s use of his single individual use password to access a news site to access content that he then shared with over 100 other people did not cause any impairment to the integrity or availability of data or loss due to interruption of service as required to bring a civil claim under the Computer Fraud …