Feb 9, 2022 | Data Breach
Recent Data Breach Notifications – National Math and Science Initiative / AccelHealth / Injured Workers Pharmacy / Morley Companies, Inc.
Information compromised from the data breach of this company, which processes information for health plans, that may have been subject to unauthorized accessed included name, date of birth, Social Security number, driver’s license number, and health information.
For more information about the data breach, please click Morley Companies, Inc. Data Breach Notification and Morley Companies, Inc. Data Breach Notification Update.
On February 10, 2022, a class action lawsuit was filed in United States District Court, Eastern District of Michigan, Northern Division, against Morley Companies, Inc. “on behalf of individuals whose sensitive personal information was stolen by cybercriminals in a massive ransomware type malware attack on Defendant Morley beginning July 20, 2021, and first observed August 1, 2021.”
Information compromised from the data breach of this education organization that could have been subject to unauthorized access included name, address, and Social Security number.
For more information about the data breach, please click National Math and Science Initiative Data Breach Notification.
Information compromised from the data breach of this healthcare organization which could have been subject to unauthorized access included name, address, date of birth, Social Security number, driver’s license number, financial account information, health insurance information, medical record number, and treatment/diagnosis information.
For more information about the data breach, please click AccelHealth Data Breach Notification.
Information compromised from the data breach of this healthcare company which could have been subject to unauthorized access included name, address, and Social Security number.
For more information about the data breach, please click Injured Workers Pharmacy Data Breach Notification.
Source (except for lawsuit information): Office of The Maine Attorney General, Data Breach Notifications.
Have You Been Harmed As A Result Of A Data Breach Which Has Exposed Your Private Personal, Protected Health Or Personally Identifiable Information?
If you have experienced actual or attempted harm or been the victim of fraud, due to the illegal or unauthorized exposure of your private personal, protected health or personally identifiable information, please contact Kehoe Law Firm, P.C., [email protected], for a free, confidential consultation and no-obligation evaluation of potential legal claims.

Oct 19, 2021 | Data Breach
California Assembly Bill No. 825, Chapter 527, Now Specifies That Personal Information Includes Genetic Data
Kehoe Law Firm, P.C. is making consumers aware that on October 18, 2021, “The National Law Review” reported (“California Broadens Security and Breach Laws, Includes Genetic Data”) that “California recently updated both its data security and breach notice laws to include genetic data. With the passage of AB 825, the data security law now includes in the definition of ‘personal information’ genetic data. The information needs to be ‘reasonably protected.’ While many other states have similar ‘reasonable protection’ requirements in their data security laws, California is one of a handful to specifically list genetic information.”
According to Assembly Bill 825:
. . . ‘genetic data’ means any data, regardless of its format, that results from the analysis of a biological sample of an individual, or from another source enabling equivalent information to be obtained, and concerns genetic material. Genetic material includes, but is not limited to, deoxyribonucleic acids (DNA), ribonucleic acids (RNA), genes, chromosomes, alleles, genomes, alterations or modifications to DNA or RNA, single nucleotide polymorphisms (SNPs), uninterpreted data that results from analysis of the biological sample or other source, and any information extrapolated, derived, or inferred therefrom. [Emphasis added.]
Have You Been Impacted by A Data Breach?
If so, please contact Michael Yarnoff, Esq., (215) 792-6676, Ext. 804, [email protected], complete the form on the right or e-mail [email protected] for a free, no-obligation case evaluation of your facts to determine whether your privacy rights have been violated and discuss potential legal claims.
Examples of the type of relief sought by data privacy class actions, include, but are not limited to, reimbursement of identity theft losses and of out-of-pocket costs paid by data breach victims for protective measures such as credit monitoring services, credit reports, and credit freezes; compensation for time spent responding to the breach; imposition of credit monitoring services and identity theft insurance, paid for by the defendant company; and improvements to the defendant company’s data security systems.
Data privacy class actions are brought on a contingent-fee basis; thus, plaintiffs and the class members do not pay out-of-pocket attorney’s fees or litigation costs. Subject to court approval, attorney’s fees and litigation costs are derived from the recovery obtained for the class.
Jun 1, 2020 | Data Breach
Certain States Have Passed, Expanded or Proposed Legislation To Regulate The Collection, Use, And Dissemination Of Biometric Information – Illinois Provides A Private Right Of Action To Recover Damages For Biometric Privacy Violations
The Illinois Biometric Information Privacy Act (“BIPA”) protects biometric identifiers, otherwise known as biometrics or biometric information. BIPA defines biometric identifier as “a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.”
According to BIPA:
The use of biometrics is growing in the business and security screening sectors and appears to promise streamlined financial transactions and security screenings.
. . .
Biometrics are unlike other unique identifiers that are used to access finances or other sensitive information. For example, social security numbers, when compromised, can be changed. Biometrics, however, are biologically unique to the individual; therefore, once compromised, the individual has no recourse, is at heightened risk for identity theft, and is likely to withdraw from biometric-facilitated transactions.”
An overwhelming majority of members of the public are weary of the use of biometrics when such information is tied to finances and other personal information.
BIPA prohibits a private entity from collecting, capturing, purchasing, receiving through trade, or otherwise obtaining a person’s or a customer’s biometric identifier or biometric information, unless the private entity (1) informs the subject or the subject’s legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) informs the subject or the subject’s legally authorized representative in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and (3) receives a written release executed by the subject of the biometric identifier or biometric information or the subject’s legally authorized representative.
BIPA also prohibits a private entity which possesses a biometric identifier or biometric information from disclosing, redisclosing, or otherwise disseminating a person’s or a customer’s biometric identifier or biometric information unless (1) the subject of the biometric identifier or biometric information or the subject’s legally authorized representative consents to the disclosure or redisclosure; (2) the disclosure or redisclosure completes a financial transaction requested or authorized by the subject of the biometric identifier or the biometric information or the subject’s legally authorized representative; (3) the disclosure or redisclosure is required by State or federal law or municipal ordinance; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
BIPA also mandates that a private entity that possesses a biometric identifier or biometric information shall:
(1) store, transmit, and protect from disclosure all biometric identifiers and biometric information using the reasonable standard of care within the private entity’s industry; and (2) store, transmit, and protect from disclosure all biometric identifiers and biometric information in a manner that is the same as or more protective than the manner in which the private entity stores, transmits, and protects other confidential and sensitive information.
Do You Believe Your Biometric Information May Have Been Illegally Collected, Stored, Used, Disclosed, Transmitted Or Disseminated?
Illinois’ Biometric Information Privacy Act provides a private right of action in an Illinois state circuit court, or as a supplemental claim in federal district court, against an offending party. Among other relief, BIPA provides for liquidated damages of $1,000 or actual damages, whichever is greater, against a private entity that negligently violates a provision of BIPA, as well as liquidated damages of $5,000 or actual damages, whichever is greater, against a private entity that intentionally or recklessly violates a provision of BIPA.
Source of BIPA-related information: ILGA.gov, 740 ILCS 14/1, et seq., accessed 06.01.2020; all emphasis added.
If you believe your biometric data has been illegally collected, stored, used, disclosed, transmitted or disseminated by a private entity, please contact Kehoe Law Firm, P.C., Michael Yarnoff, Esq., (215) 792-6676, Ext. 804, [email protected], [email protected], to discuss potential legal claims.