en.osm.town is one of the many independent Mastodon servers you can use to participate in the fediverse.
An independent, community of OpenStreetMap people on the Fediverse/Mastodon. Funding graciously provided by the OpenStreetMap Foundation.

Server stats:

261
active users

#powerschool

2 posts2 participants0 posts today

PowerSchool, the cloud platform provider providing services to school boards across Canada & the US has confirmed that even though a ransom has been paid to the cybercriminals holding the data ransom & received assurances that the data was destroyed, the criminals have returned demanding for more money as they have not actually destroyed the data.

This unfortunately highlights the biggest risk when it comes to paying ransom for data destruction, threat actors can always come back demanding for more once they realize exactly how valuable the data is.

www.thestar.com/news/gta/student-data-obtained-in-a-cyberattack-on-gta-school-boards-was-supposed-to-be-destroyed/article_cf2901bb-3fcc-4f84-ad7b-32399076b7e5.html

#infosec #PowerSchool #PowerSchoolHack #ransom #TDSB #YRDSB #PDSB #Toronto #YorkRegion #PeelRegion #Ontario #Canada

Toronto StarStudent data obtained in a cyberattack on GTA school boards was supposed to be destroyed. It wasn’tTDSB tells parents that PowerSchool “confirmed that they have paid a ransom in an attempt to secure deletion” but now there’s a new ransom demand.

Lexington School District Four in SC reported that 15,894 residents were affected by the PowerSchool breach. The state reached out to districts on Jan. 8 to tell them what was known at that time.

The district filed this with the state today: consumer.sc.gov/sites/consumer

It appears to be a copy of what they have sent out to residents as a preliminary notification.

If memory serves, PowerSchool had told districts they would be giving them something for communications by the evening of the 8th. Did they ever do that? Or are the four bullets in the district's notification what #PowerSchool gave districts to use?

@douglevin @brett @funnymonkey

Some folks may get confused by PowerSchool saying that if they have medical records on students, they may have to notify under HIPAA.

Most student medical/health records are not covered under HIPAA. They are covered under FERPA.

If the district is billing the student's health insurance for services like speech therapy, physical therapy, or occupational therapy, then there's a HIPAA issue. Or if the school has arrangements with an actual clinic that is providing medical/health services to students. But most things like doctor's absence notes or even allergy action plans or school medication orders are not under HIPAA.

If the district has a health plan for employees that it administers, there's also a HIPAA issue there.

#PowerSchool #databreach #incidentresponse #HIPAA #FERPA

@douglevin @funnymonkey