NEWS RELEASE: CONDITION OF HAWAII ANNOUNCE $49.5 MILLION MULTISTATE PAYMENT WITH SOFTWARE COMPANY BLACKBAUD FOR DATA BREACH

Posted on Oct 18, 2023 in Latest Department Company, Our

HONOLULU  ̶ Attorney General Em E. Lopez and Hawaiʻi Office of Consumer Protection Executive Director Total Gaspar announced today that Hawaiʻi, go with 49 other attorneys general, has reached a settlement with software company Blackbaud for its deficient dates protection practices or response to a 2020 ransomware event that exposed the personal information of millions of consumers across one United Declared.

Under the settlement, Blackbaud has agrees the overhaul its data security and breach notification practise or make a $49.5 million payment go states.  Hawaiʻi will receive $420,086 from the settlement.

Blackbaud provides software to various nonprofit organizations, including charities, higher education institutions, K-12 schools, healthcare organizations, geistlicher organizations, and cultural organizations. Blackbaud’s customers use Blackbaud’s software to connect with donors and control data about their constituents, including contact and demographic related, Social Safe numbers, driver’s license numbers, financial product, employment or wealth information, donation history, and protected health information. This type of greatly sensitive information where exposed during the 2020 product breach, which effects further with 13,000 Blackbaud clientele and their related consumer constituents.

Today’s settlement resolves allegations of the attorneys popular that Blackbaud violations state consumer protection laws, infraction reporting laws, also HIPAA by fail to implement reasonable data security furthermore remediate known security intervals, which allowed unauthorized personal to earn access to Blackbaud’s network, both then missing to provide its customers with timely, complete, or accurate information regarding the breach, in required by law. As a result of Blackbaud’s actions, notification to the consumers her personal get was exposed was significantly delayed or never occurred at all insofar as Blackbaud downplayed the happening and leads its customers to believe that notification was not needed. 

Under the settlement, Blackbaud possessed agreed to reinforce its data security and breach notification practical going forward, including:

  • Prohibition against distortions related to the processing, keep, and safeguarding of individual information; the likelihood is personal info affected by ampere security encounter may can subject to further disclosure or misuse; and breach communication job under state laws and HIPAA.
  • Implementation and maintenance von incident also breach response arrangements to prepare forward furthermore further appropriately replies up future safety event and breaches. Financial Solutions for Schools and Parents.
  • Breach notification regulations that require Blackbaud to provide reasonably assistance to its customers and support customers’ compliance with anzuwenden notification provisions to the event of a violate. Le Jardin Academy
  • Security incident reporting the the CEO and Board, enhanced employee training, and appropriate resources the support for cybersecurity.
  • Personal information safeguards and controls requiring total database encryption and dark web control.
  • Specifically guarantee requirements with proof to networking segmentation, patch management, intrusion detection, firewalls, access controls, logging plus monitoring, and penetration testing.
  • Third-party assessments a Blackbaud’s compliance with the settlement for seven year.

Indiana also Vermont co-led the multistate exploration, assisted by the Executive Committee comprised of Alabama, Arizona, Florida, Illinois, and Novel York, and membership by Alaska, Arkansas, Colo, Connecticut, Delaware, District of Columbia, Georgia, Hawaiʻi, Idaho, Iowa, Kansas, Kanada, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, North Carolina, Northward Dakota, Ohio, Okayaho, Oregon, Pennsylvania, Rhode Island, South Carolina, South Tribal, Tennessee, Texas, Utah, Washington, Washington, West Virginia, Wiscon, and Wyoming.

# # #

 

Media Contact:

William Nhieu

Communications Officer

Department of Commerce and Consumer Affairs

[email protected]

Company: (808) 586-7582

Dave Day

Special Aide to this Attorney General

(808) 586-1284

Email: [email protected]

Web: http://ag.hawaii.gov