February 22, 2009

University of Florida Computer System Breached

A hacker gained access to the computer network at the University of Florida which contains the personal information of approximately 97,000 people, according to an article on News4Jax.com. The University of Florida initiated an investigation after the data breach was discovered, but it was not clear if the personal information was successfully accessed.

Due to the proliferation of computers, the Internet and computer networks, companies have increasingly stored the personal and financial information of clients and employees on their computer networks. As a result, hackers and thieves have increased their efforts to obtain this information that is often easily accessed and unencrypted on company networks. Florida law requires companies that have had their networks compromised to follow certain procedures or face severe financial penalties and bad publicity that could severely damage the company. At a minimum, if a company experiences a data breach of its network and personal information is materially compromised, the company should conduct a thorough investigation to determine if harm has, or likely will, come to those whose information may have been accessed. Records of this investigation and the results must be kept for five years.

Depending on the results of the investigation and the extent of the data breach, Florida law may require the company to do more, including notifying all of the individuals whose information was compromised. If you suspect your company's network has been breached and personal information has been compromised, visit our website or contact us for more information about what Florida law requires your company to do.

February 2, 2009

New Jersey Company Suffers Massive Breach of Credit Card Data

Heartland Payment Systems is a credit card processing company that handles 100 million credit card transactions per month. They recently went public with the fact that their network was breached and unauthorized access was gained to those credit card transactions. The company did not know, or did not disclose, which and how many credit card records were compromised, but they did say that the records accessed were sufficient to allow hackers to make duplicate credit cards.

In Florida, if a company that maintains certain identification or financial information about others suffers a material breach of its network or files, an important legal duty is triggered. Failure to comply with that legal duty could subject the company to costly penalties and severe damage to its reputation. When a company has reason to believe its network has been materially compromised, Florida law requires the company to conduct a reasonable investigation to determine the extent of the breach and whether harm has, or likely will, come to any of the individuals whose data are maintained. This investigation must be thoroughly documented. Depending on the results of that investigation, the company may be required to notify individuals of the data breach.

If you work for a company in Florida and have had your network breached, or have reason to believe your network has been breached, you can learn more about your legal rights here or contact us to learn more about what Florida law requires when a data breach occurs.