Court Rules
All enforcement actions
SettlementCritical RiskMultistate

Multistate Coalition Fines Blackbaud $49.5M for Data Breach Failures

BlackbaudOctober 5, 2023New York Attorney General

Penalty Amount

$49,500,000

Summary

Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.

Remedy

Blackbaud must pay $49.5 million to the states, implement and maintain incident response plans, enhance security measures including encryption and monitoring, undergo third-party assessments for seven years, and discontinue misrepresentations about data safety.

Monetary PenaltyConsent DecreeInjunctionAudit RequirementCompliance ProgramCorrective Notice

Contract Impact

In-house legal teams should review all vendor and data processing agreements with cloud service providers and SaaS vendors, particularly those handling sensitive donor, customer, or constituent data. Focus on clauses governing data security obligations (e.g., specific security frameworks, encryption, access controls), breach notification requirements (including timelines and content), audit and inspection rights, indemnification for data breaches, and limitations of liability. Given the findings of inadequate security and delayed notification, contracts should be amended to include more prescriptive security controls, shorter notification windows (e.g., 72 hours), mandatory reporting of security audits, and clear remedies for non-compliance. Additionally, review customer agreements to ensure robust data protection commitments are flowed down to end-users.

Contract Search Terms

data security standardsbreach notification timelineindemnification clauseaudit rightsencryption requirementsdata processing agreementsubprocessor managementincident response plandata retention and deletionliability caps

Laws Cited

state consumer protection lawsbreach notification lawsHIPAA

Violation Types

Entity Details

Entity

Blackbaud

Industry

Technology

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Blackbaud"
Fine Amount
"$49.5 million"
Laws Cited
"state consumer protection laws, breach notification laws, and HIPAA"
Violation Types
"failed to implement reasonable data security and fix known security gaps"
Violation Types
"neglected to provide its customers with timely, complete, or accurate information regarding the breach"

Related Enforcement Actions

CA

Blackbaud

$6.8M

California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

NJ

Blackbaud

$49.5M

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

NY

Meta Platforms, Inc.

$17.1B

Attorney General James and a bipartisan coalition of 50 other attorneys general secured a landmark settlement with Meta Platforms, Inc. (Meta) worth up to $17.1 billion to address the company's harmful and addictive features targeting minors on Facebook and Instagram. The settlement requires Meta to implement significant changes, including age verification, time limits for minors, restrictions on notifications, and options to opt out of algorithmic feeds, along with monetary payments to states for mental health and education programs.

NY

Cal-Maine Foods, Versova/Centrum, and Hickman's Egg Ranch

$3.3M

New York Attorney General Letitia James announced a multistate settlement with Cal-Maine Foods, Versova/Centrum, and Hickman's Egg Ranch for illegally coordinating to influence a daily price index for eggs, artificially inflating prices for retailers and consumers nationwide. The companies will deliver 53 million eggs to food banks across 17 participating states, pay a combined $3.3 million, and adopt compliance measures to prevent future violations.

NY

Zillow Group, Inc.

$2.0M

New York Attorney General Letitia James, along with four other states and the FTC, settled with Zillow and Redfin after they entered an illegal agreement to stop competing in the multifamily rental advertising market. Zillow paid Redfin $100 million to shut down its advertising business and exclusively display Zillow's listings. The settlement requires the companies to resume competing and pay $2 million.

NY

Thirty Madison, Inc.

$400K

New York Attorney General Letitia James secured $400,000 from Thirty Madison, Inc., an online medication provider, for misleading consumers about auto-renewing subscriptions and making cancellation difficult. The company failed to clearly disclose subscription terms and non-refundable fees, and required multiple steps to cancel. The settlement requires payment, refunds to eligible subscribers, and changes to subscription practices.