Oregon receives $656,000 in Blackbaud data breach settlement

(The Center Square) – Oregon, along with the other 49 states and the District of Columbia, reached a settlement with software company Blackbaud over data security practices and its response to a 2020 ransomware event that exposed the personal information of millions of Americans.

“Blackbaud’s misconduct was nothing short of egregious. They showed real disregard for the impact their data breach had on the lives of millions of consumers and nonprofits and failed to live up to well-established legal and ethical standards,” Oregon Attorney General Ellen Rosenblum said in a press release. “While the money is significant, this is a case that demonstrates the importance of compliance with meaningful data security and breach notification practices going forward.”

Blackbaud downplayed the data beach and either offered a delayed notification or no notification to people impacted by the data breach, the release said.

Blackbaud agreed to make a $49.5 million payment to the states and to overhaul its data security and breach notification practices.

Oregon will receive $655,791 from the lawsuit; 174 Oregon organizations were impacted by the breach.

- Advertisement -

“Those funds will go toward supporting the state’s investigative, consumer protection, and consumer education efforts at the Oregon Department of Justice,” the release said.

Here are actions Blackbaud has agreed to take to strengthen its data security and breach notification practices, according to the release:

Prohibition against misrepresentations related to the processing, storing, and safeguarding of personal information; the likelihood that personal information affected by a security incident may be subject to further disclosure or misuse; and breach notification requirements under state law and HIPAA.Implementation and maintenance of incident and breach response plans to prepare for and more appropriately respond to future security incidents and breaches.Breach notification provisions that require Blackbaud to provide appropriate assistance to its customers and support customers’ compliance with applicable notification requirements in the event of a breach.Security incident reporting to the CEO and Board, enhanced employee training, and appropriate resources and support for cybersecurity.Personal information safeguards and controls requiring total database encryption and dark web monitoring.Specific security requirements with respect to network segmentation, patch management, intrusion detection, firewalls, access controls, logging and monitoring, and penetration testing.Third-party assessments of Blackbaud’s compliance with the settlement for 7 years.

Blackbaud provides software for many organizations, including “charities, higher education institutions, K-12 schools, healthcare organizations, religious organizations, and cultural organizations,” according to the release.

“Blackbaud’s customers use Blackbaud’s software to connect with donors and manage data about their constituents, including contact and demographic information, Social Security numbers, driver’s license numbers, financial information, employment and wealth information, donation history, and protected health information,” the release said.

During the 2020 data breach, over 13,000 clients nationwide and their consumers were impacted.

- Advertisement -

Blackbaud said protecting customers always has been and will be a top priority.

“At Blackbaud, protecting customers’ and their constituents’ privacy has always been, and will continue to be, one of our most important priorities,” Mike Gianoni, president and CEO of Blackbaud, said in a press release. “Cyber-attacks are always evolving, so we are continually strengthening our cybersecurity and compliance programs to ensure our resilience in an ever-changing threat landscape. We are pleased to fully resolve this matter and proud of our role as the essential software provider for purpose-driven organizations.”

The settlement comes seven months after the Securities and Exchange Commission reached a settlement with Blackbaud over inadequate disclosure controls. Blackaud had to pay $3 million, though the SEC never alleged any intentional misconduct by the company.

DON’T MISS OUT

Be the first to know about the latest news, giveaways, events, and updates from The Black Chronicle!

We don’t spam! Read our privacy policy for more info.

Hot this week

African and Caribbean Nations Call for Reparations for Slave Trade, Propose Global Fund

Nations across Africa and the Caribbean, deeply impacted by...

Sports betting expert offers advice on paying taxes for gambling winnings

(The Center Square) – Tax season is underway, and...

Health care company agrees to pay $22.5 million to settle claims of over billing

A health care company agreed to pay nearly $22.5...

Entertainment district benefits don’t outweigh the cost, economists say

(The Center Square) — Weeks later, after more details...

Business association ‘disappointed’ by WA L&I’s proposed workers comp rate hike

(The Center Square) – The Association of Washington Business...

Texas posts nearly $24 billion surplus, higher than originally projected

(The Center Square) – Ahead of the legislative session...

Helene: In late hour move, FEMA shifts deadline to Jan. 25

(The Center Square) – FEMA’s Transitional Sheltering Assistance hotel...

DeSantis won’t rob the House to fill the Senate

(The Center Square) – Gov. Ron DeSantis said this...

Wisconsin governor starts Office of Violence Prevention with $10M in federal funds

(The Center Square) – Wisconsin Gov. Tony Evers signed...

Bill would toughen penalties for unlawful firearm possession

(The Center Square) – A Washington state Republican lawmaker...

Ohio files $17M lawsuit against former mine company over sinkholes

(The Center Square) – Ohio Attorney General Dave Yost...

Hochul pitches $1B tax cut as part of reelection agenda

(The Center Square) — Gov. Kathy Hochul is pledging...

Louisiana parishes seek revenue from carbon storage projects

(The Center Square) − Louisiana lawmakers are grappling with...

More like this
Related

Texas posts nearly $24 billion surplus, higher than originally projected

(The Center Square) – Ahead of the legislative session...

Helene: In late hour move, FEMA shifts deadline to Jan. 25

(The Center Square) – FEMA’s Transitional Sheltering Assistance hotel...

DeSantis won’t rob the House to fill the Senate

(The Center Square) – Gov. Ron DeSantis said this...

Wisconsin governor starts Office of Violence Prevention with $10M in federal funds

(The Center Square) – Wisconsin Gov. Tony Evers signed...