Im confused why dont they use the same value per incident as what judges use when penalizing mp3 file copying ?
US contractor pays $300K to settle accusation it didn't properly look after Medicare users' data
A US government contractor will settle claims it violated cyber security rules prior to a breach that compromised Medicare beneficiaries' personal data. Virginia-based ASRC Federal Data Solutions (AFDS) signed a deal with the Justice Department this week agreeing to pay $306,722 in restitution, but without admitting liability …
COMMENTS
-
-
Thursday 17th October 2024 09:58 GMT Guy de Loimbard
December 23 Strategy..... ?
Maybe I'm not reading this correctly, but a December 2023 Cyber Strategy is being referenced for an event that happened before it was published.
Not that I'm defending the 3rd Party Contractor as you'd need to take your role extremely seriously when dealing with PII or other sensitive information!
Slowly getting through to these entities handling data in a shite way, fines is one way to do it, but better education and collaboration on regulations would help too I think.
-
Monday 21st October 2024 10:26 GMT CA Dave
What's the point?
I will never understand why the government allows a company/contractor to settle out of court for something like this. It only ever results in "we'll pay the small fine but we didn't do it". I would very much like to see these kinds of cases fully shaken out to actually and definitively determine if there was any violation. That way these companies can be held truly liable if they did, and massive egg on the government if they didn't. Fines do nothing to deter companies unless it sends them halfway to chapter 11.