$17.5 Million Settlement Resolves Infosys McCamish Systems Data Breach Lawsuit
A settlement has been agreed to resolve multiple Infosys McCamish Systems class action lawsuits that were filed in response to a 2023 ransomware attack and data breach that involved unauthorized access to the personal data of more than 6 million individuals. Infosys is India’s second-largest IT services provider, and Infosys McCamish Systems is a U.S. subsidiary that provides life insurance and retirement software and services. In November 2023, Infosys McCamish Systems discovered its systems had been breached in a ransomware attack. The forensic investigation confirmed that an unauthorized cyber actor had access to its systems between October 29 and November 2, 2023, exfiltrated sensitive data, and used ransomware to encrypt files. The LockBit ransomware group claimed responsibility for the attack and demanded a ransom, payment of which was required to obtain the keys to decrypt data and prevent the stolen data from being made public. A LockBit representative claimed that Infosys McCamish offered to pay $50,000 to prevent the release of the stolen data but the lowball offer was...
New HIPAA Exemption Added to Kentucky Consumer Data Protection Act
In April 2024, Kentucky joined the growing number of states that have adopted comprehensive consumer privacy and data protection laws. The Kentucky Consumer Data Protection Act was signed into law on April 4, 2024, and is due to take effect on January 1, 2026. The Kentucky Consumer Data Protection Act applies to individuals and legal entities that control or process the personal data of at least 100,000 Kentucky consumers or control or process the personal data of 25,000 Kentucky consumers and derive over 50% of gross revenue from the sale of personal data. An amendment to the law has been signed by state governor Andy Beshear that narrows the scope of the law, exempting information collected by healthcare providers covered under HIPAA that maintain protected health information in compliance with the HIPAA Rules and other related regulations. The amendment also expands the excluded information to include information collected in a limited data set, as defined in 45 C.F.R. 8 164.514(e) to the extent the information is used, disclosed, and maintained as specified in 45 C.F.R. 8...
Illinois Accountancy Firm Sued Over 217,000-Record Data Breach
Legacy Professionals, an Illinois-based certified public accountancy firm, has notified almost 217,000 individuals about an April 2024 security incident involving data theft from its systems. Suspicious activity was identified within its computer network in late April, and a forensic investigation was launched to confirm the nature and scope of the activity. The investigation confirmed that there had been unauthorized access to its network, but client systems were unaffected. The investigation uncovered no evidence of data theft. In November 2024, Legacy Professionals learned that certain files had been exfiltrated from its network by an unauthorized actor. Legacy Professionals initiated a comprehensive review of the files and engaged data review specialists to assist with the time-intensive review. That process was completed in February 2025 and confirmed that the stolen data included employee benefit plan information such as names, Social Security numbers, driver’s license/state ID numbers, medical treatment information, and health insurance information. Legacy Professionals said...
Department of Labor Announces Senior OSHA Appointments
The U.S. Department of Labor has announced leadership changes at the Occupational Safety and Health Administration (OSHA), including Deputy Assistant Secretary Amanda Wood Laihow serving as the new acting Assistant Secretary of Labor for Occupational Safety and Health. Douglas L. Parker previously led the agency under President Biden and President Trump’s nomination to head OSHA, the former UPS and Amazon safety executive David Keeling, is currently with the Senate HELP Committee. Shortly after Lori Chavez-DeRemer was sworn in as Labor Secretary, OSHA updated its organizational chart confirming Amanda Wood Laihow is the new Acting Assistant Secretary of Labor for Occupational Safety and Health. Since February, Wood Laihow has served as Deputy Assistant Secretary alongside Scott Ketcham. Amanda Wood Laihow is a labor lawyer who previously served as a commissioner to the Occupational Safety and Health Review Commission from 2020 to 2023. She has also served as director of labor and employment policy for the National Association of Manufacturers, deputy general counsel on the...
High Severity Vulnerabilities Identified in Philips Intellispace Cardiovascular (ISCV)
Two high-severity vulnerabilities have been identified in Philips Intellispace Cardiovascular (ISCV), a popular multi-modality image and information management solution for healthcare providers. The vulnerabilities are present in ISCV version 4.1 and prior versions and ISCV version 5.1 and prior versions. The vulnerabilities are due to improper authentication and the use of weak credentials. Both vulnerabilities have been assigned a CVSS v3.1 severity score of 7.7 and a CVSS v4 severity score of 8.5. An attacker can exploit the vulnerabilities to replay the session of a logged-in user and gain access to patient records. Vulnerability CVE-2025-2230 is due to improper authentication. The Windows login flow contains a flaw where an AuthContext token can be exploited for replay attacks and authentication bypass. Vulnerability CVE-2025-2229 is due to weak credentials, where a token is created using the username, current date/time, and a fixed AES-128 encryption key, which is the same across all installations. The vulnerabilities have been resolved in previous releases of ISCV; however,...



