Penalty Amount
$935,000
Aetna Inc. settled with the California Attorney General for $935,000 over allegations that it revealed the HIV status of 1,991 Californians through a mailing error where medication information was visible through envelope windows. The settlement requires Aetna to implement improved mailing procedures and conduct annual privacy assessments. This action enforces health privacy laws and protects sensitive medical information.
Aetna must implement and maintain specific mailing procedures to ensure medical information is not visible through envelope windows, designate an employee responsible for privacy compliance, and complete annual privacy risk assessments for three years.
In-house legal teams should review all agreements involving the handling of sensitive health information, such as vendor contracts for mailing services, customer membership agreements, employee confidentiality agreements, and data processing addendums. Key clauses to scrutinize include confidentiality provisions, data security measures, mailing and disclosure protocols, and requirements for privacy assessments. Based on the settlement, contracts may need amendments to enforce secure mailing procedures to prevent visible information through envelopes, mandate annual privacy assessments, and ensure compliance with health privacy laws like the Confidentiality of Medical Information Act. Additionally, breach notification clauses should be updated to cover such disclosure errors, and data retention schedules should align with legal requirements for medical data.
Entity
Aetna Inc.
Also known as: Aetna
Industry
HealthcareOfficial Press Release
aetna complaint filed january 30 2019
https://oag.ca.gov/system/files/attachments/press-docs/aetna-complaint-filed-january-30-2019.pdf
aetna proposed final judgment and permanent injunction filed
https://oag.ca.gov/system/files/attachments/press-docs/aetna-proposed-final-judgment-and-permanent-injunction-filed-january-30-2019.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.