Blackbaud to Pay $6.75 Million Penalty to California Over 2020 Data Breach

Blackbaud, a South Carolina company that provides fundraising software for nonprofits has settled alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) and state laws with the California Attorney General. Blackbaud will pay a $6.75 million financial penalty, improve security, and change its business practices to ensure future compliance with federal and state laws.

Blackbaud was investigated by state attorneys general over a ransomware attack that it disclosed in June 2020. Hackers stole data and used ransomware to encrypt files and Blackbaud paid a 24 bitcoin ($250,000) ransom to have the stolen data deleted. The stolen data included names, contact information, and highly sensitive information such as Social Security numbers, bank account information, and medical information. Approximately 13,000 of the company’s clients had data stolen in the attack.

State attorneys general in 49 U.S. states and Washington D.C. combined their efforts and agreed to a $49.5 million settlement with Blackbaud in October 2023; however, California chose not to be part of that multi-state action and conducted its own investigation. According to California Attorney General Rob Bonta, Blackbaud failed to implement reasonable and appropriate security measures to ensure the confidentiality, integrity, and availability of the data it stored on its network and made misleading statements to its customers about the sufficiency of its data security measures. When the breach was detected, Blackbaud made misleading statements about the extent of the data breach.

The investigation revealed Blackbaud had failed to implement basic security measures to address the technical vulnerabilities exploited by the ransomware group. For instance, despite storing vast amounts of sensitive data, Blackbaud had not implemented multifactor authentication, requiring just a username and password to be provided for access. Despite the high risk of cyberattacks, Blackbaud was not properly monitoring systems that contained sensitive data for suspicious activity, was not staying up to date on evolving security standards, and was storing data for longer than was necessary. In addition to violating HIPAA, Blackbaud was found to have violated California’s Reasonable Data Security Law, Unfair Competition Law, and False Advertising Law.

“Not only did Blackbaud fail to protect consumers’ personal information, but they misled the public of the full impact of the data breach. This is simply unacceptable. Today’s settlement will ensure that Blackbaud prioritizes safeguarding consumers’ personal information and enhances security measures to prevent future incidents,” said Attorney General Bonta.

In addition to paying the financial penalty, Blackbaud is required to comply with the injunctive requirements of the settlement. Those measures include limiting the information stored in backup files to the minimum necessary information and securely disposing of backup files when there is no business reason for storing those files. Access controls must be improved by implementing password confidentiality and password rotation or multi-factor authentication policies. Security infrastructure must be improved through network segmentation, and the company must ensure it properly monitors its systems for unauthorized activity and takes prompt action in response to security alerts.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

In January 2024, the FTC ordered Blackbaud to implement a comprehensive information security program, erase data when it is no longer needed, strengthen password security, and implement multifactor authentication. The Securities and Exchange Commission (SEC) also investigated Blackbaud and fined the company $3 million for making misleading statements about the data breach.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/