Cloud Computing Data Breaches: US Regulation

Cloud Computing Data Breaches
Presented by David Kolevski (Questions by Katina Michael)

Cloud computing services have enjoyed explosive growth over the last decade. Users are typically businesses and government agencies who are able to scale their storage and processing requirements and adopt about 175 different kinds of pre-defined services (e.g. specific software-as-a-service applications). But with this outsourcing has also come the potential for data breaches targeted at the end-user, typically consumers (e.g. who purchase goods at an online retail store), and citizens (e.g. who transact information for their social security needs). This paper briefly introduces US-based cloud computing regulation, including the U.S. Health Insurance Portability and Accountability Act (HIPPA), the Gramm Leach Bliley Act (GLBA), and the U.S. Stored Communications Act (SCA). We present how data breach notification (DBN) works in the U.S. in terms of how cloud computing data breaches are reported and examine three mini-case examples: the 2011 Sony PlayStation Network data breach, the 2015 Anthem Healthcare data breach and the 2017 Equifax data breach. The findings of the paper show that there is a systemic failure to learn from past data breaches, that data breaches not only affect business and government clients of cloud computing services but their respective end-user customer base. Finally, the level of sensitivity of data breaches is increasing, from cloud computing hacks on video game platforms, to the targeting of more lucrative network and computer crime abuses aiming at invasive private health and financial data.

Source: David Kolevski, Katina Michael, Roba Abbas, Mark Freeman, 2021, “Cloud computing data breaches: A review of U.S. regulation and data breach notification literature”, UEMGreen, India.

Previous
Previous

Nominee for Outstanding Faculty Mentor

Next
Next

2021 SFIS Education Award