Maine A.G. Frey: Maine Joins Multistate Settlement Addressing 2014 Anthem Data Breach
Attorney General
In
"It is incumbent on companies like
Under the settlement,
* a prohibition against misrepresentations regarding the extent to which
* implementation of a comprehensive information security program, incorporating principles of zero trust architecture, and including regular security reporting to the Board of Directors and prompt notice of significant security events to the CEO;
* specific security requirements with respect to segmentation, logging and monitoring, anti-virus maintenance, access controls and two factor authentication, encryption, risk assessments, penetration testing, and employee training, among other requirements; and
* third-party security assessments and audits for three (3) years, as well as a requirement that
In the immediate wake of the breach, at the request of the
In addition to this settlement,
Sen. Coons: 'Stripping Health Care Protections in Middle of Pandemic Seems to Be Highest Priority'
Proposed assisted living facility clears first hurdle
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News