OAIC charges Australian Clinical Labs over delay in reporting hack
The news: Australia's privacy regulator has launched federal court action against Australian Clinical Labs after the pathology service took months to notify authorities of a massive data breach.
The numbers: ACL's Medlab Pathology was hacked in February 2022, resulting in the exposure of 223,000 Australians' private data on the dark web. The Office of the Australian Information Commissioner was not notified until July. The commissioner is alleging ACL failed to notify the the authority in a timely manner and had insufficient customer data protections in place. ALC earned $995.6 million in revenue in FY22, the OAIC said.
What they said: "Organisations are responsible for protecting the information they hold, including effectively managing cyber security risk," Australian Information Commissioner Angelene Falk said in a statement.
"We consider that ACL failed to take reasonable steps to protect personal information it held for an organisation of its size with its resources, and considering the nature and volume of the sensitive personal information it handled."
The source: OAIC Media Release