Penalty Amount
$2,000,000
Cottage Health System experienced two data breaches exposing medical information of over 50,000 patients due to inadequate security measures. The settlement requires a $2 million penalty and upgrades to security practices, including designating a Chief Privacy Officer.
Cottage Health must pay $2 million, implement and maintain reasonable security practices for patient information, designate a Chief Privacy Officer, and conduct periodic risk assessments.
In-house legal teams should review all agreements involving protected health information (PHI), including Business Associate Agreements (BAAs) with vendors, patient consent and service agreements, and employee confidentiality/access agreements. Focus on clauses specifying data security standards (encryption, access controls), breach notification timelines and responsibilities, audit rights, and requirements for risk assessments. Given the settlement's mandate for a Chief Privacy Officer and security upgrades, contracts may need amendments to explicitly require these roles/procedures, mandate regular security audits, enforce specific technical safeguards, and clarify liability for inadequate protection of medical data.
Entity
Cottage Health System
Industry
HealthcareOfficial Press Release
Conformed Stipulation with Exhibit FINAL (1)
https://oag.ca.gov/system/files/attachments/press_releases/Conformed%20Stipulation%20with%20Exhibit%20--%20FINAL%20%281%29.pdf
Conformed Cottage Complaint SIGNED
https://oag.ca.gov/system/files/attachments/press_releases/Conformed%20Cottage%20Complaint%20SIGNED.PDF
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.