Robinson Cole LLP
High Contrast Mode
May 22, 2025 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

College Student Behind Cyber Extortions

The U.S. Attorney’s Office for the District of Massachusetts has charged a student at Assumption University with hacking into two U.S.-based companies’ systems and demanding a ransom.

Matthew D. Lane, 19, has agreed to plead guilty to one count of cyber extortion conspiracy, one count of cyber extortion, one count of unauthorized access to protected computers, and one count of aggravated identity theft. Read more


ENFORCEMENT + LITIGATION

Clock Ticking: DOJ’s New Data Security Rule Requires Compliance by July 8

U.S. companies are running out of time to comply with a sweeping new Department of Justice rule that limits sharing sensitive personal data with certain foreign countries—including China, Russia, and Iran. With a hard compliance deadline of July 8, 2025, businesses must act quickly to avoid steep civil or criminal penalties. Read more

FTC Order with GoDaddy Finalized Over Lax Data Security

On May 21, 2025, the Federal Trade Commission (FTC) finalized its order with GoDaddy over allegations that GoDaddy “failed to implement standard data security tools and practices to protect customers’ websites and data.” In a Complaint filed against GoDaddy in January 2025, the FTC alleged that the company had “failed to implement reasonable and appropriate security measures to protect and monitor its website-hosting environments for security threats, and misled customers about the extent of its data security protections on its website hosting services.” Read more

Getting Too Personal? Illinois Court Says Family Medical History is Genetic Information

On May 15, 2025, a district court in Illinois denied a motion by defendant Hospital Sisters Health System and Saint Francis (HSHS) to dismiss a class action claim brought against the hospital system under the Illinois Genetic Information Privacy Act (GIPA). Read more


DATA PRIVACY

Data Breach Lawsuits Surge Against Chord Specialty Dental Partners

Pennsylvania-based Chord Specialty Dental Partners is under fire after a September 2024 data breach compromised the personal information of over 173,000 individuals. At least seven proposed class action lawsuits have been filed in federal courts in Tennessee and Pennsylvania, alleging the company failed to secure and protect patient data properly. Read more

Florida Data Broker Fined $46,000 by California Privacy Watchdog

In yet another reminder that California takes data privacy seriously, this month, the California Privacy Protection Agency (CPPA) fined Florida-based data broker Jerico Pictures, Inc. (d/b/a National Public Data) $46,000 for failing to register under the state’s Delete Act. Read more


ARTIFICAL INTELLIGENCE

Bipartisan Take It Down Act Becomes Law

On Monday, May 19, 2025, President Donald Trump signed the “Take It Down Act” into law. The Act, which unanimously passed the Senate and cleared the House in a 409-2 vote, criminalizes the distribution of intimate images of someone without their consent. Lawmakers from both parties have commented that the law is long overdue to protect individuals from online abuse. It is disheartening that a law must be passed (almost unanimously) to require people and social media companies to do the right thing. Read more

AI Service Provider Faces Class Actions Over Catholic Health Data Breach

AI service provider Serviceaide Inc. faces two proposed class action lawsuits from a data breach tied to Catholic Health System Inc., a nonprofit hospital network in Buffalo, New York. The breach reportedly exposed the personal information of over 480,000 individuals, including patients and employees. Read more


Privacy Tip #444

Best Phishing Campaigns are from HR or IT

Everyone thinks they can spot a phish. Whether it is an email, SMS text, or QRish phishing, people have an overinflated view of their capabilities to detect them.

A new summary by KnowB4, “What Makes People Click?” provides an insightful review and proves that people still click when curiosity gets the best of them. Read more


RECENT EVENTS AND NEWS

Kathryn Rattigan Recognized as 2025 Professional Services Woman to Watch by Providence Business News

 Data Privacy + Cybersecurity team partner Kathryn Rattigan was honored as a “Professional Services Woman to Watch” by Providence Business News (PBN) as part of the publication’s 2025 Business Women Awards, which was held on May 22, 2025. The annual event recognizes leading women in various business, government, and nonprofit sectors for their respective organizations. The distinction recognizes younger, professional women who are making a significant impact in their fields. Kathryn will also be featured in a special profile published as part of PBN’s May 23 – June 5 print and digital editions.