{"id":3463,"date":"2016-12-02T21:19:45","date_gmt":"2016-12-02T21:19:45","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=3463"},"modified":"2019-03-08T19:52:12","modified_gmt":"2019-03-09T00:52:12","slug":"the-skeleton-of-a-data-breach-the-ethical-and-legal-concerns","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2016\/12\/02\/the-skeleton-of-a-data-breach-the-ethical-and-legal-concerns\/","title":{"rendered":"The Skeleton of a Data Breach: The Ethical and Legal Concerns"},"content":{"rendered":"<p><a href=\"http:\/\/jolt.richmond.edu\/files\/2017\/03\/volume23_article2_Buttrick-1.pdf\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-128\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/blog.richmond.edu\/jolt\/files\/2016\/12\/volume23_article2_Buttrick-2.pdf\">BDM Publication Version PDF<\/a><\/p>\n<p style=\"text-align: center;\">Cite as:\u00a0Hilary G. Buttrick et al.,<em>The Skeleton of A Data Breach: The Ethical and Legal Concerns<\/em>,\u00a023 Rich. J.L. &amp; Tech. 2 (2016),\u00a0http:\/\/jolt.richmond.edu\/wp-content\/uploads\/volume23_article2_Buttrick.pdf.<\/p>\n<p style=\"text-align: center;\">Hilary G. Buttrick,*\u00a0Jason Davidson,**\u00a0Richard J. McGowan***<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>Introduction<\/strong><strong>\u00a0<\/strong><\/p>\n<p>[1] \u00a0\u00a0\u00a0\u00a0\u00a0 After over thirty data breaches spanning the third and fourth quarter of 2012, Forbes magazine labeled the summer of 2012 as \u201cThe Summer of the Data Breach.\u201d<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> Four years later, businesses across multiple industries have suffered brand-image damage and paid millions of dollars in remedial expenses; we are living in the era of the mega breach.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> In 2014, companies such as Target, Home Depot, JP Morgan Chase, Anthem, Sony, UPS, Jimmy John\u2019s, Kmart, Neiman Marcus, Community Health Systems, and the White House suffered data breaches.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> The Home Depot breach alone resulted in the loss of \u201c56 million credit card accounts,\u201d \u201c53 million email addresses,\u201d and an estimated 63 million dollars in damage.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a> In addition to the economic fallout associated with data breaches, the 2015 Ashley Madison data breach highlighted the personal toll faced by consumers when their \u201cprivate\u201d information becomes \u201cpublic.\u201d<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> That data breach exposed the identities of millions of would-be philanderers, shaming not only the subscribers to Ashley Madison\u2019s service, but also innocent bystanders such as their family members.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> The frequency of data breaches has shown no signs of abating in 2016\u2014in the first quarter, multiple hospitals fell victim to \u201cransomware,\u201d a data breach that allows hackers to literally hold patient data hostage.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> Several hospitals had to pay hackers to regain access to their patients\u2019 data.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a><\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cDecentralized technology\u201d creates a different set of problems than the simple misuse of a single individual\u2019s \u201ctechnological profile\u201d and information.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> Today, unauthorized access to electronic information, a result of what Burnham in 1983 referred to as \u201ctransactional information,\u201d<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> includes \u201chackers breaking into systems or networks, third parties accessing personal information on lost laptops or other mobile devices, or organizations failing to dispose of personal information securely.\u201d<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> Data breaches exemplify the first type of unauthorized access and despite their frequent occurrence, they are little examined from an ethical standpoint. Though Google Scholar lists over 82,000 entries under \u201cethics of a data breach,\u201d very few combine both terms in the title.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a> One article that does so notes a \u201cdearth of prior organizational-level privacy research, which has largely overlooked ethical issues or the personal harms often caused by privacy violations.\u201d<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a> Even within the field of technology, \u201cthere has not been a huge literature on ethics within the mainstream of information systems journals.\u201d<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> Part of the problem is the novelty of data breach cases. They are so new and different that they appear to be technologically, morally, and legally unlike other problems. We suggest that analogies and analyses exist which can help resolve some of these moral and legal puzzles.<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 First, this paper discusses the anatomy of a data breach, providing technical background on the way breaches occur. Next, we identify the ethical dimensions of data breaches. While privacy is a key topic in any ethical analysis of a data breach, other issues are more pressing, such as the responsibility of organizations to prevent and to repair consequences of data breaches. Then we analyze the current status of the law with regard to data breaches. We note immediately that the laws of various states are exactly that, various and eclectic. No consistent and stable legal understanding appears to have availed itself. The article concludes with guidance regarding data breach prevention, which can help businesses meet their ethical and legal obligations.<\/p>\n<p style=\"text-align: center;\"><strong>I. Data Breach Basics<\/strong><\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 According to popular folklore, the first computer \u201cbug\u201d was officially documented in 1945.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a> This was years before the first personal computer was released, and instead of malware or social engineering deception, the \u201cbug\u201d was literally a moth that was stuck between two components of IBM\u2019s Harvard Mark II.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> After a cataclysmic data breach in the modern computing age, however, postmortem reports eventually surface that provide the details of each individual breach.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a> These reports explain the hacker\u2019s methodology, the company\u2019s missed warning signs, and the collateral damage from the breach.<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> Each individual breach has its own signature as every data system is as unique as a fingerprint; however, these breaches generally occur in one of several ways.<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The most common and well-documented method of cyber-attack uses malware.<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> Malware, which includes viruses, worms, and trojan horses, is the \u201cgeneric name for evil software.\u201d <a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> A 2016 data breach report by Verizon found that malware continues to be the major contributor to data breaches involving stolen credentials and point of sale attacks. <a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> Malware attacks, specifically worms, were publically credited for both the Target<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a> and Home Depot<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> data breaches. Ironically, the first worm was created in 1975 by Xerox as a network analysis tool.<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> Modern day worms are standalone programs that can replicate and spread throughout a network when activated.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> Some of the more notable worms include Melissa, ILOVEYOU, Slammer, and the Morris worm.<a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a> Malware is not the only factor that can lead to network compromise. Security breaches often are attributable to social engineering.<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a><\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Social engineering employs deception tactics to persuade the user to simply give the cybercriminal direct access to the system under attack, similar to the modus operandi of a traditional con-artist.<a href=\"#_ftn28\" name=\"_ftnref28\">[28]<\/a> Social engineering attacks direct messages and correspondence to users who have access to the systems that are being attacked.<a href=\"#_ftn29\" name=\"_ftnref29\">[29]<\/a> Through different methods of deception, the user is prompted to give away the information needed to access the system.<a href=\"#_ftn30\" name=\"_ftnref30\">[30]<\/a> The most common methods of social engineering are spear phishing, smishing, and vishing.<a href=\"#_ftn31\" name=\"_ftnref31\">[31]<\/a> Spear phishing is direct correspondence, usually via email, that is personally crafted to gain the trust of the end user.<a href=\"#_ftn32\" name=\"_ftnref32\">[32]<\/a> Once trust is obtained, the user is prompted for login credentials and the system is compromised. Smishing and vishing are similar to spear phishing; however, they use text messages (smishing) and voice communication (vishing) as mediums.<a href=\"#_ftn33\" name=\"_ftnref33\">[33]<\/a> It is also worth noting that old-fashioned tactics such as breaking and entering, removing files from the printer, or simply guessing passwords are still commonly used tricks of the trade.<a href=\"#_ftn34\" name=\"_ftnref34\">[34]<\/a><\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 To circumvent the millions of dollars companies invest in information technology security, hackers often use a combination of the tactics discussed above. As detailed in the Dell SecureWorks report on the Target infiltration, a combination of social engineering and malware was used to cause the collapse.<a href=\"#_ftn35\" name=\"_ftnref35\">[35]<\/a> Hackers first targeted Fazio Mechanical Services, a vendor for Target.<a href=\"#_ftn36\" name=\"_ftnref36\">[36]<\/a> They were able to gain login credentials through spear phishing, which in turn granted them direct access to the systems that opened a pathway to Target\u2019s network.<a href=\"#_ftn37\" name=\"_ftnref37\">[37]<\/a> Upon accessing Target\u2019s data network, the hackers injected a worm into the system.<a href=\"#_ftn38\" name=\"_ftnref38\">[38]<\/a> This worm compromised Target\u2019s point of sale systems using a customized version of malware called Black POS.<a href=\"#_ftn39\" name=\"_ftnref39\">[39]<\/a> This malware then compromised Target\u2019s server, which allowed the data to be distributed and copied to servers located throughout the world; accordingly, the hack was very difficult to trace.<a href=\"#_ftn40\" name=\"_ftnref40\">[40]<\/a><\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 For businesses, the question of data breach is not \u201cif\u201d but \u201cwhen.\u201d It is indisputable that the hackers in the examples discussed above bear the moral responsibility for their acts.<a href=\"#_ftn41\" name=\"_ftnref41\">[41]<\/a> But the moral responsibility of the business that sustains the data breach presents a closer question. Businesses require consumers to provide their private information when completing even the most routine transactions; this places the business in a unique position of trust. The scope of a business\u2019s moral responsibility for breach of that trust is discussed below.<\/p>\n<p style=\"text-align: center;\"><strong>II. Moral Responsibility and Data Breach<\/strong><strong>\u00a0<\/strong><\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Of course, the right to privacy is at the fore. However, information technology \u201cexplicitly embodies particular important values\u2026privacy, autonomy, universal usability, trust, and cooperation.\u201d<a href=\"#_ftn42\" name=\"_ftnref42\">[42]<\/a> The existing literature does not explore the scope of a business\u2019 moral responsibility for data breach. Accordingly, reference to other areas, such as moral responsibility for marketing, is instructive. The values associated with information technology suggest moral analysis based on the ethics of marketing and on notions of corporate responsibility, inasmuch as knowledge plays a role in making autonomous choices and trust is associated with responsibility.<a href=\"#_ftn43\" name=\"_ftnref43\">[43]<\/a><\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 Three main positions have been staked out over the years with regard to marketing: the contractual view, the due care theory, and the social costs view, sometimes referred to as the \u201cdeep pockets\u201d view.<a href=\"#_ftn44\" name=\"_ftnref44\">[44]<\/a> Captured in the phrase, <em>caveat emptor,<\/em> the contractual view of the buyer-seller relationship holds that the seller, typically a business, only has the duties to the buyer that the contract states.<a href=\"#_ftn45\" name=\"_ftnref45\">[45]<\/a> Thus, under the contract view, Ford could indeed sell a product which, when struck from behind at 21 miles per hour, could produce a flaming inferno.<a href=\"#_ftn46\" name=\"_ftnref46\">[46]<\/a><\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 The problem is that consumers lack the knowledge that the producer has and therefore cannot act knowledgably in purchasing a product. The due care position recognizes the imbalance and the vulnerable position of the consumer by placing additional duties on the business.<a href=\"#_ftn47\" name=\"_ftnref47\">[47]<\/a> As Culnan and Williams put the matter, \u201c[w]e further argue that because consumers are vulnerable in their dealings with businesses due to information and control deficits, organizations have a moral duty\u2014often overlooked, we observe\u2014that extends beyond legal compliance requiring them to take reasonable precautions with consumer data and to avoid harm in using this data.\u201d<a href=\"#_ftn48\" name=\"_ftnref48\">[48]<\/a> The \u201cdeep pockets\u201d view\u00ad\u2013analogous to the legal notion of strict liability\u2013would have the seller assume all costs\u2013even when exercising \u201cdue care\u201d to protect the consumer from risk and injury\u2013of a product.<a href=\"#_ftn49\" name=\"_ftnref49\">[49]<\/a> In other words, when a problem occurs, no investigation need be undertaken: the seller takes the responsibility, or <em>caveat vendor<\/em>.<a href=\"#_ftn50\" name=\"_ftnref50\">[50]<\/a> Given the poor record of businesses with regard to handling data breaches,<a href=\"#_ftn51\" name=\"_ftnref51\">[51]<\/a> the third option appears most reasonable.<\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 Corporations have been reluctant to take steps to exhibit moral responsibility in the area of data breach.<a href=\"#_ftn52\" name=\"_ftnref52\">[52]<\/a> Normally, when wrongdoing occurs in an organizational setting, the elements of magnitude and certitude of harm as well as connection and contribution to the harm are utilized.<a href=\"#_ftn53\" name=\"_ftnref53\">[53]<\/a> Corporations appear to underestimate magnitude and certitude of harm and appear to ignore the contribution they make to data breaches by being primarily reactive rather than proactive.<a href=\"#_ftn54\" name=\"_ftnref54\">[54]<\/a> While an analysis of a business\u2019s moral responsibility for a data breach suggests the appropriateness of a rule akin to strict liability, the law is far from imposing such an obligation.<a href=\"#_ftn55\" name=\"_ftnref55\">[55]<\/a><\/p>\n<p style=\"text-align: center;\"><strong>III. Legal Liability and Data Breach<\/strong><\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 Not surprisingly, the development of data breach law has lagged behind the speed of technological innovation.<a href=\"#_ftn56\" name=\"_ftnref56\">[56]<\/a> There are two significant legal questions surrounding data breaches. First, what legal obligations does a business owe its customers regarding data security and notifications of a breach? Second, what legal remedies do consumers have if their private information is compromised as the result of a data breach? As discussed below, there is currently no comprehensive federal regulatory scheme addressing data breach.<a href=\"#_ftn57\" name=\"_ftnref57\">[57]<\/a> Instead, businesses must attempt to comply with a patchwork of state laws addressing data breach notifications.<a href=\"#_ftn58\" name=\"_ftnref58\">[58]<\/a> Additionally, consumers are left with few effective civil remedies when their private information is breached.<a href=\"#_ftn59\" name=\"_ftnref59\">[59]<\/a><\/p>\n<p style=\"padding-left: 30px;\"><strong>A. Data Breach Notification Laws<\/strong><\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 At present, there is no comprehensive federal statute addressing a business\u2019s obligation to safeguard personal information.<a href=\"#_ftn60\" name=\"_ftnref60\">[60]<\/a> While there are a few federal statutes aimed at protecting personal information in narrow contexts (such as the protection of medical and health-related information under the Health Insurance Portability and Accountability Act of 1996),<a href=\"#_ftn61\" name=\"_ftnref61\">[61]<\/a> the legal rules governing data breach are handled largely at the state level.<a href=\"#_ftn62\" name=\"_ftnref62\">[62]<\/a> Currently, \u201c[f]orty-seven states, [and] the District of Columbia\u201d have laws addressing business obligations with regard to data breaches.<a href=\"#_ftn63\" name=\"_ftnref63\">[63]<\/a> Three states\u2014Alabama, New Mexico, and South Dakota\u2014have no statutes on the books addressing consumer notification of data breaches.<a href=\"#_ftn64\" name=\"_ftnref64\">[64]<\/a> Most states impose obligations on businesses to maintain \u201creasonable security\u201d measures \u201cto protect personal information.\u201d<a href=\"#_ftn65\" name=\"_ftnref65\">[65]<\/a> While definitions vary from state to state, \u201cpersonal information\u201d commonly includes an individual\u2019s social security number,<a href=\"#_ftn66\" name=\"_ftnref66\">[66]<\/a> or<\/p>\n<p style=\"padding-left: 30px;\">[A]n individual&#8217;s first and last names, or first initial and last name, and one (1) or more of the following data elements that are not encrypted or redacted: (A) A driver&#8217;s license number. (B) A state identification card number. (C) A credit card number. (D) A financial account number or debit card number in combination with a security code, password, or access code that would permit access to the person&#8217;s account.<a href=\"#_ftn67\" name=\"_ftnref67\">[67]<\/a><\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 A \u201cbreach\u201d occurs when there is an \u201cunauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. . . .\u201d<a href=\"#_ftn68\" name=\"_ftnref68\">[68]<\/a><\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 In the event of a data breach, existing statutes require businesses to provide some type of notification to the consumer.<a href=\"#_ftn69\" name=\"_ftnref69\">[69]<\/a> The type and timing of that notice, however, varies from state to state.<a href=\"#_ftn70\" name=\"_ftnref70\">[70]<\/a> Some states require consumer notification whenever unauthorized access of personal information occurs.<a href=\"#_ftn71\" name=\"_ftnref71\">[71]<\/a> Other states require businesses to notify consumers only if there appears to be a reasonable risk that some harm will result from the breach.<a href=\"#_ftn72\" name=\"_ftnref72\">[72]<\/a> Many states require businesses to notify the attorney general of data breaches.<a href=\"#_ftn73\" name=\"_ftnref73\">[73]<\/a> Some statutes require notification within a specified time frame, while others simply require that notification be done expediently.<a href=\"#_ftn74\" name=\"_ftnref74\">[74]<\/a> Businesses that serve consumers in multiple states must comply with the notification requirements of each of the states where affected consumers reside.<a href=\"#_ftn75\" name=\"_ftnref75\">[75]<\/a> Thus, when a large data breach occurs, businesses face a considerable challenge in ensuring compliance with the various notification laws throughout the country.<a href=\"#_ftn76\" name=\"_ftnref76\">[76]<\/a><\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0 This patchwork of state regulation leads commentators and policy advocates to suggest that a comprehensive federal data breach statute should be enacted.<a href=\"#_ftn77\" name=\"_ftnref77\">[77]<\/a> A federal data breach statute would preempt state regulation, thus simplifying the breaching business\u2019s compliance requirements and costs.<a href=\"#_ftn78\" name=\"_ftnref78\">[78]<\/a> Instead of struggling to comply with the various notification laws of multiple states, a business would look to only one source\u2014federal law\u2014to discern its obligations in the event of a data breach.<a href=\"#_ftn79\" name=\"_ftnref79\">[79]<\/a> While federal bills have been proposed,<a href=\"#_ftn80\" name=\"_ftnref80\">[80]<\/a> Congress has failed to pass any comprehensive proposal.<a href=\"#_ftn81\" name=\"_ftnref81\">[81]<\/a><\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 Moreover, critics claim that draft bills are weak and do not offer enough protection for consumers.<a href=\"#_ftn82\" name=\"_ftnref82\">[82]<\/a> In particular, critics note that the proposals do not do enough to incentivize data breach prevention because they focus on consumer notification after a breach has already occurred.<a href=\"#_ftn83\" name=\"_ftnref83\">[83]<\/a> To incentivize data breach prevention, businesses must view added security measures as solid investments that minimize risks of loss.<a href=\"#_ftn84\" name=\"_ftnref84\">[84]<\/a> The primary business risks associated with data breaches are loss of customer goodwill and, of course, lawsuits from affected consumers.<a href=\"#_ftn85\" name=\"_ftnref85\">[85]<\/a> As discussed below, data breach lawsuits are difficult to pursue. Accordingly, the threat of consumer litigation has not played an extensive role in influencing businesses to adopt more stringent security measures.<a href=\"#_ftn86\" name=\"_ftnref86\">[86]<\/a><\/p>\n<p style=\"padding-left: 30px;\"><strong>B. Consumer Remedies for Data Breach<\/strong><\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 Some commentators have argued that in order to meaningfully encourage businesses to adopt better data protection measures, businesses must view customer litigation as a serious threat.<a href=\"#_ftn87\" name=\"_ftnref87\">[87]<\/a> The threat of litigation in this context has been largely hollow because consumers have few legal remedies when their personal information is breached.<a href=\"#_ftn88\" name=\"_ftnref88\">[88]<\/a> While data breach statutes require businesses to notify consumers in the event of a breach, only a handful of those statutes create a private cause of action that allows the consumer to bring a lawsuit against the business.<a href=\"#_ftn89\" name=\"_ftnref89\">[89]<\/a> Thus, in the majority of states with data breach statutes, the consumer is statutorily entitled to notice of the breach but little else.<a href=\"#_ftn90\" name=\"_ftnref90\">[90]<\/a> Given the lack of meaningful statutory remedies for data breaches, consumers have looked to the common law for a cognizable theory of recovery.<a href=\"#_ftn91\" name=\"_ftnref91\">[91]<\/a> Consumers have sought damages for data breaches under theories of negligence, breach of contract, breach of fiduciary duty, and infliction of emotional distress.<a href=\"#_ftn92\" name=\"_ftnref92\">[92]<\/a> These common law theories are not well-suited to data breach cases and often end in dismissal for several reasons.<a href=\"#_ftn93\" name=\"_ftnref93\">[93]<\/a><\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 First, the harm that results from data breaches is most commonly economic harm\u2014there is no personal injury or physical property damage sustained by the consumer as a result of the data breach.<a href=\"#_ftn94\" name=\"_ftnref94\">[94]<\/a> Many jurisdictions follow a rule called the \u201ceconomic loss doctrine,\u201d which prevents consumers from recovering purely economic damages under a tort theory (such as negligence or infliction of emotional distress).<a href=\"#_ftn95\" name=\"_ftnref95\">[95]<\/a> Thus, in jurisdictions that follow the economic loss doctrine, data breach claims sounding in tort rarely reach the jury because they are dismissed as the result of pretrial dispositive motions filed by the defendant.<a href=\"#_ftn96\" name=\"_ftnref96\">[96]<\/a><\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 Second, many data breach cases are dismissed because the consumer lacks standing to bring such a claim.<a href=\"#_ftn97\" name=\"_ftnref97\">[97]<\/a> Standing is a constitutional prerequisite to litigation that requires the plaintiff to have suffered an injury in fact.<a href=\"#_ftn98\" name=\"_ftnref98\">[98]<\/a> In other words, the harm sustained by the plaintiff must be real, not hypothetical or speculative.<a href=\"#_ftn99\" name=\"_ftnref99\">[99]<\/a> In data breach cases, the injury can be hard to define. Plaintiff consumers often argue that the data breach itself and the risk of future identity theft are sufficient harms; defendant businesses contend that no injury has occurred unless the plaintiff can show a link between the data breach and an actual instance of identity theft.<a href=\"#_ftn100\" name=\"_ftnref100\">[100]<\/a> Not surprisingly, the courts are divided on what type of injury suffices to confer standing in a data breach case.<a href=\"#_ftn101\" name=\"_ftnref101\">[101]<\/a><\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 Even if the plaintiff consumer in a data breach case survives the standing hurdle, he or she must still prove all of the elements of his or her case in order to win. In most instances, the consumer will have to prove that his or her injury was caused by the defendant\u2019s data breach.<a href=\"#_ftn102\" name=\"_ftnref102\">[102]<\/a> Proving causation in data breach cases can be difficult because the plaintiff\u2019s personal information may have been compromised in other data breaches, making it nearly impossible to establish that the suffered identity theft was solely the result of the defendant\u2019s breach.<a href=\"#_ftn103\" name=\"_ftnref103\">[103]<\/a><\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 The procedural and substantive difficulties associated with data breach litigation mean that very few of these cases are likely to survive dispositive motions and reach a jury, which in turn makes them less attractive to class action attorneys.<a href=\"#_ftn104\" name=\"_ftnref104\">[104]<\/a> The procedural hurdles, the cost of litigation, and the prospect of a small recovery are enough to deter most individual consumers from bringing a data breach lawsuit.<a href=\"#_ftn105\" name=\"_ftnref105\">[105]<\/a> Without effective legal remedies, most consumers must simply put up with the headaches associated with data breaches.<a href=\"#_ftn106\" name=\"_ftnref106\">[106]<\/a> While external litigation pressures and the current data breach regulatory state may not incentivize businesses to take additional steps to safeguard consumer privacy, ethics would certainly suggest that businesses should voluntarily adopt higher standards for data protection.<a href=\"#_ftn107\" name=\"_ftnref107\">[107]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>IV. Business Strategies to Minimize the Risk of Data Breach<\/strong><\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 Several tactics can help reduce the threat of cybercrime. The first tactic is infrastructure.<a href=\"#_ftn108\" name=\"_ftnref108\">[108]<\/a> A modern company must continually perform routine maintenance including, but not limited to, security patches, operating system upgrades, and hardware upgrades. Often cyber criminals exploit older software to maliciously gain access to data networks.<a href=\"#_ftn109\" name=\"_ftnref109\">[109]<\/a> The initial discovery of these exploits before the software manufacturer has developed a security patch is called a &#8220;zero-day attack.\u201d<a href=\"#_ftn110\" name=\"_ftnref110\">[110]<\/a> Once a hardware or software exploit is identified, software and hardware vendors act to create patches to repair the problem as quickly as possible.<a href=\"#_ftn111\" name=\"_ftnref111\">[111]<\/a> It is up to the corporation to obtain and apply these patches.<\/p>\n<p>[25]<strong>\u00a0\u00a0\u00a0\u00a0 <\/strong>The second prevention method is active monitoring.<a href=\"#_ftn112\" name=\"_ftnref112\">[112]<\/a> Similar to the way that the FBI manages the national threat level, a company\u2019s IT department must manage the cybercrime threat level.<a href=\"#_ftn113\" name=\"_ftnref113\">[113]<\/a> Myriad firewall and IT monitoring software is available to monitor network traffic.<a href=\"#_ftn114\" name=\"_ftnref114\">[114]<\/a> Many anti-virus software programs automatically scan and remove commonly found malware.<a href=\"#_ftn115\" name=\"_ftnref115\">[115]<\/a> In addition, IT security companies provide external monitoring services to augment a company\u2019s internal monitoring procedures.<a href=\"#_ftn116\" name=\"_ftnref116\">[116]<\/a> These offsite IT services offer network traffic monitoring and even provide built-in client insurance\/reimbursement if a data breach occurs due to negligence within their services.<\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 The third prevention method is education.<a href=\"#_ftn117\" name=\"_ftnref117\">[117]<\/a> While most people envision a hacker in a dark basement surrounded by computers, social engineering is a remarkably effective method of data intrusion.<a href=\"#_ftn118\" name=\"_ftnref118\">[118]<\/a> For example, a study of data breaches occurring in 2015 found that \u201c30% of phishing messages were opened by the target across all campaigns.\u201d<a href=\"#_ftn119\" name=\"_ftnref119\">[119]<\/a> The risk of data breach can be mitigated if employees know they should never share passwords; they should frequently change passwords, and they should lock their office doors.<a href=\"#_ftn120\" name=\"_ftnref120\">[120]<\/a> Additional security measures such as key fobs, biometric readers, and similar devices that must remain with employees, should also be kept private. While no one strategy can guarantee that a business will not sustain a data breach, the preceding measures will lessen the risk.<\/p>\n<p style=\"text-align: center;\"><strong>V. Conclusion<\/strong><\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 Though data breaches are a relatively new phenomena, guidance about the technology, morality, and legality of data breaches is available. If we are correct, corporations must do a better job of determining where data breaches are likely to occur, whether from human error or informational system flaw. Corporations must take steps to minimize risk before data breaches occur. Protocols must be put in place that assume responsibility for the consumers\u2019 negative consequences, such as notifying them immediately and providing help in diminishing the harm from the data breach. The legal liability will be mitigated; trust and cooperation will more likely flourish.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\"><\/a>*J.D., Assistant Professor of Business Law, Butler University.<\/p>\n<p>**M.B.A., Instructor of Management Information Systems, Butler University.<\/p>\n<p>***Ph.D., Instructor of Business Ethics, Butler University.<\/p>\n<p>[1] <em>See<\/em> Dave Lewis, <em>Notes from RSA: Accountability in Security<\/em>, Forbes, (Apr. 29, 2015, 6:30 PM), http:\/\/www.forbes.com\/sites\/davelewis\/2015\/04\/29\/notes-from-rsa-accountability-in-security\/#47e46e292163,<em> archived at<\/em> https:\/\/perma.cc\/HV4B-D7T8.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See<\/em> Bill Hardekopf, <em>The Big Data Breaches of 2014<\/em>, Forbes, (Jan. 13, 2015, 7:06 PM), http:\/\/www.forbes.com\/sites\/moneybuilder\/2015\/01\/13\/the-big-data-breaches-of-2014\/#4ad6aa5f3a48,<em> archived at<\/em> https:\/\/perma.cc\/WYT4-8JX8.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <em>See id.<\/em>; <em>see <\/em>Ellen Nakashima, <em>Hackers Breach Some White House Computers<\/em>, Wash. Post (Oct. 28, 2014), https:\/\/www.washingtonpost.com\/world\/national-security\/hackers-breach-some-white-house-computers\/2014\/10\/28\/2ddf2fa0-5ef7-11e4-91f7-5d89b5e8c251_story.html,<em> archived at<\/em> https:\/\/perma.cc\/HD4S-MUX2.<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> The Home Depot, Inc., Annual Report (Form 10-K) (Mar. 25, 2015), at 18\u201319.<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See<\/em> Eric Basu, <em>Cybersecurity Lessons Learned from the Ashley Madison Hack<\/em>, Forbes, (Oct. 26, 2015, 11:55 AM), http:\/\/www.forbes.com\/sites\/ericbasu\/2015\/10\/26\/cybersecurity-lessons-learned-from-the-ashley-madison-hack\/#14c58a7eed99,<em> archived at<\/em> https:\/\/perma.cc\/U4L3-R6VE.<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>See id. <\/em><\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a><em> See<\/em> Seung Lee, <em>Ransomware Wreaking Havoc in American and Canadian Hospitals<\/em>, Newsweek, (Mar. 23, 2016, 10:23 AM), http:\/\/www.newsweek.com\/ransomware-wreaking-havoc-american-and-canadian-hospitals-439714,<em> archived at<\/em> https:\/\/perma.cc\/MJ2N-UW4T.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>See<\/em> Mary J. Culnan &amp; Cynthia Clark Williams, <em>How Ethics Can Enhance Organizational Privacy: Lessons From the ChoicePoint and TJX Data Breaches<\/em>, 33 MIS Q. 673, 673 (2009).<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> David Burnham, The Rise of the Computer State 50 (1983).<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> Culnan &amp; Williams, <em>supra<\/em> note 9, at 675.<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>See<\/em> Search Results for \u201cEthics of a Data Breach,\u201d Google Scholar, https:\/\/scholar.google.com\/scholar?hl=en&amp;q=ethics+of+a+data+breach&amp;btnG=&amp;as_sdt=1%2C47&amp;as_sdtp=,<em> archived at<\/em> https:\/\/perma.cc\/7HZG-UK9D (last visited Sept. 20, 2016).<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> Culnan &amp; Williams, <em>supra<\/em> note 9, at 673.<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> John Mingers &amp; Geoff Walsham, <em>Toward Ethical Information Systems: The Contribution of Discourse Ethics<\/em>, 34 MIS Q. 833, 837 (2010).<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See <\/em>Computerworld Staff, <em>The Moth in the Machine: Debugging the Origins of the Bug<\/em>, Computerworld (Sept. 3, 2011, 7:00 AM), http:\/\/www.computerworld.com\/article\/2515435\/app-development\/moth-in-the-machine&#8211;debugging-the-origins-of&#8211;bug-.html,<em> archived at <\/em>https:\/\/perma.cc\/KC3P-8QRF; <em>see also<\/em> Fred R. Shapiro, <em>Etymology of the Computer Bug: History and Folklore<\/em>, 62 American Speech 376, 376\u201377 (1987).<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>See <\/em>Shapiro, <em>supra <\/em>note 15, at 376\u201377 (noting that a moth was found in the Mark II in 1945, but contending that the word \u201cbug\u201d was used to describe defects in machines long before 1945; thus, the term did not originate with the insect found in the Mark II).<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>See <\/em>Pragati Verma, <em>You\u2019ve Been Breached &#8212; What Now? A Post-Mortem Checklist<\/em>, Forbes: AllClear ID (Aug. 17, 2015, 11:27 AM), http:\/\/www.forbes.com\/sites\/allclearid\/2015\/08\/17\/youve-been-breached-what-now-a-post-mortem-checklist\/#13a42ec34384,<em> archived at<\/em> https:\/\/perma.cc\/Z365-VFCT.<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>See id. <\/em><\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>See<\/em> Raymond R. Panko &amp; Julia L. Panko, Business Data Networks and Security 91 (Pearson, 10th ed. 2015).<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>See<\/em> Verizon, Inc., 2016 Data Breach Investigations Report, at 20 (2016), http:\/\/www.verizonenterprise.com\/verizon-insights-lab\/dbir\/2016,<em> archived at<\/em> https:\/\/perma.cc\/E8S4-RHVU (follow \u201cDownload the 2016 DBIR\u201d) [hereinafter Verizon Report].<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>See<\/em> Keith Jarvis &amp; Jason Milletary, <em>Inside a Targeted Point-of-Sale Data Breach<\/em>, Dell SecureWorks, at 1 (Jan. 24, 2014), http:\/\/krebsonsecurity.com\/wp-content\/uploads\/2014\/01\/Inside-a-Targeted-Point-of-Sale-Data-Breach.pdf,<em> archived at<\/em> https:\/\/perma.cc\/5V6Y-CAED.<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a><em> See<\/em> Hardekopf, <em>supra<\/em> note 2.<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> <em>See <\/em>Michael A. Hiltzik, <em>Computer Viruses Can Be Healthy for Innovation<\/em>, L.A. Times (Apr. 5, 1999), at 1, http:\/\/articles.latimes.com\/1999\/apr\/05\/business\/fi-24293,<em> archived at<\/em> https:\/\/perma.cc\/A5ZD-P4R4.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> <em>See<\/em> Panko &amp; Panko, <em>supra<\/em> note 19, at 93.<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>See, e.g.<\/em>, Ned Potter, <em>Top 10 Computer Viruses and Worms<\/em>, ABC News (Sept. 3, 2009), http:\/\/abcnews.go.com\/Technology\/top-computer-viruses-worms-internet-history\/story?id=8480794,<em> archived at<\/em> https:\/\/perma.cc\/C6DW-YT2P (listing the top 10 most well-known computer viruses and worms).<\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[27]<\/a> <em>See<\/em> Verizon Report, <em>supra<\/em> note 21, at 17 (noting that most phishing cases \u201cfeature phishing as a means to install persistent malware,\u201d leading to security breach).<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[28]<\/a> <em>See<\/em> Panko &amp; Panko, <em>supra<\/em> note 19, at 96\u201397.<\/p>\n<p><a href=\"#_ftnref29\" name=\"_ftn29\">[29]<\/a> <em>See id.<\/em> at 96.<\/p>\n<p><a href=\"#_ftnref30\" name=\"_ftn30\">[30]<\/a> <em>See id.<\/em> at 97.<\/p>\n<p><a href=\"#_ftnref31\" name=\"_ftn31\">[31]<\/a> <em>See id.<\/em> at 96\u201397; <em>see <\/em>FBI, <em>Smishing and Vishing and Other Cyber Scams to Watch Out for This Holiday<\/em>, Federal Bureau of Investigation (Nov. 24, 2010), https:\/\/archives.fbi.gov\/archives\/news\/stories\/2010\/november\/cyber_112410\/cyber_112410 [hereinafter <em>Smishing and Vishing<\/em>].<\/p>\n<p><a href=\"#_ftnref32\" name=\"_ftn32\">[32]<\/a> <em>See<\/em> Panko &amp; Panko, <em>supra<\/em> note 19, at 97.<\/p>\n<p><a href=\"#_ftnref33\" name=\"_ftn33\">[33]<\/a> <em>See<\/em> <em>Smishing and Vishing, supra <\/em>note 31.<\/p>\n<p><a href=\"#_ftnref34\" name=\"_ftn34\">[34]<\/a> <em>See<\/em>, <em>e.g.<\/em>, Eric Geier, <em>Your Printer Could Be a Security Sore Spot<\/em>, PC World (Apr. 25, 2012, 6:01 PM), http:\/\/www.pcworld.com\/article\/254518\/your_printer_could_be_a_security_sore_spot.html,<em> archived at <\/em>https:\/\/perma.cc\/7PZY-87MX (discussing five security threats network printers may impose); <em>see also <\/em>Matt Smith,<em> The 5 Most Common Tactics Used to Hack Passwords<\/em>, Make Use Of (Dec. 20, 2011), http:\/\/www.makeuseof.com\/tag\/5-common-tactics-hack-passwords\/,<em> archived at<\/em> https:\/\/perma.cc\/YJ4K-NDLR.<\/p>\n<p><a href=\"#_ftnref35\" name=\"_ftn35\">[35]<\/a> <em>See<\/em> Jarvis &amp; Milletary, <em>supra<\/em> note 22, at 1,10.<\/p>\n<p><a href=\"#_ftnref36\" name=\"_ftn36\">[36]<\/a> <em>See<\/em> Staff of S. Comm. on Com., Sci., and Transp., 113th Cong., A \u201cKill Chain\u201d Analysis of the 2013 Target Data Breach 4 (2014), http:\/\/www.public.navy.mil\/spawar\/Press\/Documents\/Publications\/03.26.15_USSenate.pdf,<em> archived at<\/em> https:\/\/perma.cc\/SLX8-24UD.<\/p>\n<p><a href=\"#_ftnref37\" name=\"_ftn37\">[37]<\/a> <em>See id.<\/em> at 8.<\/p>\n<p><a href=\"#_ftnref38\" name=\"_ftn38\">[38]<\/a> <em>See id.<\/em> at 9.<\/p>\n<p><a href=\"#_ftnref39\" name=\"_ftn39\">[39]<\/a> <em>See id.<\/em> at 2, 9.<\/p>\n<p><a href=\"#_ftnref40\" name=\"_ftn40\">[40]<\/a> <em>See id.<\/em> at 4.<\/p>\n<p><a href=\"#_ftnref41\" name=\"_ftn41\">[41]<\/a> <em>See generally<\/em> Richard J. McGowan &amp; Hilary G. Buttrick, <em>Moral Responsibility and Legal Liability, or Ethics Drives the Law<\/em>, 11 J. Learning in Higher Educ. 9, 10 (2015) (discussing the three basic elements of moral responsibility).<\/p>\n<p><a href=\"#_ftnref42\" name=\"_ftn42\">[42]<\/a> Mingers &amp; Walshman, <em>supra<\/em> note 14 at 839.<\/p>\n<p><a href=\"#_ftnref43\" name=\"_ftn43\">[43]<\/a> <em>See generally<\/em> John Rawls, A Theory of Justice 347-50 (1971) (discussing the moral psychology and the acquisition of the sentiment of justice).<\/p>\n<p><a href=\"#_ftnref44\" name=\"_ftn44\">[44]<\/a> <em>See<\/em> Manuel Velasquez, Business Ethics: Concepts and Cases 308 (7th ed. 2012).<\/p>\n<p><a href=\"#_ftnref45\" name=\"_ftn45\">[45]<\/a> <em>See<\/em> <em>id.<\/em> at 314; <em>see generally<\/em> Thomas Garrett &amp; Richard Klonoski, Business Ethics 88 (2nd ed. 1986) (discussing the fairness of a sales contract and the importance of protecting the dignity of the buyers).<\/p>\n<p><a href=\"#_ftnref46\" name=\"_ftn46\">[46]<\/a> <em>See generally<\/em> Clark Butler, Human Rights Ethics: A Rational Approach 80 (2008) (discussing the moral psychology and the acquisition of the sentiment of justice).<\/p>\n<p><a href=\"#_ftnref47\" name=\"_ftn47\">[47]<\/a> S<em>ee <\/em>Edgar H. Schein, <em>The Problem of Moral Education for the Business Manager<\/em>, 8 Indust. Rev. 3, 4 (1966).<\/p>\n<p><a href=\"#_ftnref48\" name=\"_ftn48\">[48]<\/a> Culnan &amp; Williams, <em>supra<\/em> note 9, at 674.<\/p>\n<p><a href=\"#_ftnref49\" name=\"_ftn49\">[49]<\/a> <em>See<\/em> Reed Dickerson, <em>The Basis of Strict Products Liability<\/em>, 16 Food, Drug, Cosmetic L.J. 585, 591 (1961).<\/p>\n<p><a href=\"#_ftnref50\" name=\"_ftn50\">[50]<\/a> <em>See<\/em> David A. Hall, <em>Strict Liability and Computer Software: Caveat Vendor<\/em>, 4 Computer\/L. J. 373, 373 (1983).<\/p>\n<p><a href=\"#_ftnref51\" name=\"_ftn51\">[51]<\/a> <em>See generally<\/em> Culnan &amp; Williams, <em>supra<\/em> note 9, at 681-82 (discussing the ways in which consumers are vulnerable when businesses lack appropriate data security measures); <em>see also<\/em> Simon Petravick &amp; Stephan G. Kerr, <em>Protect Your Portable Data\u2014Always and Everywhere<\/em>, 6 J. of Acct. 30, 31 (2009) (discussing the ways in which businesspeople often fail to appropriately safeguard confidential client information).<\/p>\n<p><a href=\"#_ftnref52\" name=\"_ftn52\">[52]<\/a> <em>See <\/em>Culnan &amp; Williams, <em>supra<\/em> note 9, at 681-82.<\/p>\n<p><a href=\"#_ftnref53\" name=\"_ftn53\">[53]<\/a> <em>See<\/em> McGowan &amp; Buttrick, <em>supra <\/em>note 41, at 11.<\/p>\n<p><a href=\"#_ftnref54\" name=\"_ftn54\">[54]<\/a> <em>See<\/em> Culnan &amp; Williams, <em>supra<\/em> note 9, at 674.<\/p>\n<p><a href=\"#_ftnref55\" name=\"_ftn55\">[55]<\/a> <em>See<\/em> Norman C. Simon, Brendan M. Schulman &amp; Samantha V. Ettari, <em>Beware the Breach: Data Breaches, Notification Duties, and Legal Liability<\/em>, Lexology.com (Aug. 29, 2012), http:\/\/www.lexology.com\/library\/detail.aspx?g=221e63eb-ccea-4f5f-80e7-b72905037a6f,<em> archived at<\/em> https:\/\/perma.cc\/9FBG-KKQY.<\/p>\n<p><a href=\"#_ftnref56\" name=\"_ftn56\">[56]<\/a> <em>See <\/em>Adi Snir, <em>Dealing with the Law Lag<\/em>, LegalVision (May 6, 2016),\u00a0https:\/\/legalvision.com.au\/dealing-with-the-law-lag\/,<em> archived at<\/em> https:\/\/perma.cc\/7SW7-4KFE.<\/p>\n<p><a href=\"#_ftnref57\" name=\"_ftn57\">[57]<\/a> <em>See<\/em> Peter J. Arant, <em>Understanding Data Breach Liability: The Basics Every Attorney Should Know<\/em>, 40 Mont. L. 8, 8\u20139 (2015) (\u201cAt the federal level, there is no comprehensive data privacy or security law. Instead the U.S. follows a \u2018sectoral\u2019 approach, meaning there are federal laws that apply to specific sectors.\u201d).<\/p>\n<p><a href=\"#_ftnref58\" name=\"_ftn58\">[58]<\/a> <em>See id.<\/em>;<em> see also Comparison of U.S. State and Federal Security Breach Notification <\/em>Laws, Steptoe &amp; Johnson LLP (Jan. 21, 2016), http<em>:\/\/<\/em>www.steptoe.com\/assets\/htmldocuments\/SteptoeDataBreachNotificationChart.pdf,<em> archived at<\/em> https:\/\/perma.cc\/4R39-6XJQ.<\/p>\n<p><a href=\"#_ftnref59\" name=\"_ftn59\">[59]<\/a> <em>See<\/em> Rachel M. Peters, <em>So You\u2019ve Been Notified, Now What? The Problem with Current Data-Breach Notification Laws<\/em>, 56 Ariz. L. Rev. 1171, 1175 (2014) (\u201c[O]nce an individual has been notified of a breach, she has limited legal recourse against the company or organization that exposed her personal information.\u201d).<\/p>\n<p><a href=\"#_ftnref60\" name=\"_ftn60\">[60]<\/a> <em>See<\/em> Arant, <em>supra<\/em> note 57, at 8\u20139.<\/p>\n<p><a href=\"#_ftnref61\" name=\"_ftn61\">[61]<\/a> <em>See <\/em>Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936; <em>see <\/em>Arant, <em>supra<\/em> note 57, at 9 (noting that the Federal Trade Commission may bring lawsuits against companies with \u201clax security and privacy practices\u201d because they are considered \u201cunfair or deceptive practices\u201d); <em>see also <\/em>Charlotte A. Tschider, <em>Experimenting with Privacy: Driving Efficiency Through a State-Informed Federal Data Breach Notification and Data Protection Law<\/em>, 18 Tul. J. Tech. &amp; Intell. Prop. 45, 47, 53\u201354 (2015) (\u201cBecause no federal law in the United States provides a broad, comprehensive set of data breach notification or data protection requirements for all businesses and consumers, other federal administrative bodies have provided catch-all protection in some circumstances.\u201d).<\/p>\n<p><a href=\"#_ftnref62\" name=\"_ftn62\">[62]<\/a> <em>See<\/em> Jeff Kosseff, <em>Cyberwars: Navigating Responsibilities for the Public and Private Sector: Positive Cybersecurity Law: Creating a Consistent and Incentive-Based System<\/em>, 19 Chap. L. Rev. 401, 402 (2016) (We have \u201ca patchwork of related laws, including breach notification and privacy statutes, that focus on penalizing companies for inadequate data security. But our legal system lacks a coordinated network of laws that are designed to promote cybersecurity and prevent data breaches from occurring in the first place.\u201d); <em>see also<\/em> Peters, <em>supra<\/em> note 59, at 1181 (discussing various state law data-breach notification statutes).<\/p>\n<p><a href=\"#_ftnref63\" name=\"_ftn63\">[63]<\/a> <em>Security Breach Notification Laws<\/em>, Nat\u2019l Conf. of St. Legislatures (Jan. 4, 2016), http:\/\/www.ncsl.org\/research\/telecommunications-and-information-technology\/security-breach-notification-laws.aspx,<em> archived at<\/em> https:\/\/perma.cc\/8JUS-CXX5 [hereinafter NCSL Security Breach Research]<\/p>\n<p><a href=\"#_ftnref64\" name=\"_ftn64\">[64]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref65\" name=\"_ftn65\">[65]<\/a> Timothy J. Toohey, <em>Beyond Technophobia: Lawyers\u2019 Ethical and Legal Obligations to Monitor Evolving Technology and Security Risks<\/em>, 21 J.L. &amp; Tech. 1, 14 (2015) (explaining general state law requirements for data breach security in context of attorneys\u2019 obligations to secure data).<\/p>\n<p><a href=\"#_ftnref66\" name=\"_ftn66\">[66]<\/a> <em>See <\/em>Ind. Code \u00a7 24-4.9-2-10(1) (2014).<\/p>\n<p><a href=\"#_ftnref67\" name=\"_ftn67\">[67]<\/a> Ind. Code \u00a7 24-4.9-2-10(2)(A)-(D) (2014).<\/p>\n<p><a href=\"#_ftnref68\" name=\"_ftn68\">[68]<\/a> Ind. Code \u00a7 24-4.9-2-2(a) (2014).<\/p>\n<p><a href=\"#_ftnref69\" name=\"_ftn69\">[69]<\/a> <em>See <\/em>NCSL Security Breach Research, <em>supra <\/em>note 63.<\/p>\n<p><a href=\"#_ftnref70\" name=\"_ftn70\">[70]<\/a> <em>See<\/em> <em>Data Breach Charts, <\/em>Baker Hostetler 1, 17-18, http:\/\/www.bakerlaw.com\/files\/Uploads\/Documents\/Data%20Breach%20documents\/Data_Breach_Charts.pdf, <em>archived at<\/em> https:\/\/perma.cc\/MM5K-ZRT3 (last visited Oct. 4, 2016) (providing state-by-state-survey of data breach notification requirements).<\/p>\n<p><a href=\"#_ftnref71\" name=\"_ftn71\">[71]<\/a> <em>See id. <\/em>at 9.<\/p>\n<p><a href=\"#_ftnref72\" name=\"_ftn72\">[72]<\/a> <em>See id.<\/em> at 9-12.<\/p>\n<p><a href=\"#_ftnref73\" name=\"_ftn73\">[73]<\/a> <em>See id. <\/em>at 13-16.<\/p>\n<p><a href=\"#_ftnref74\" name=\"_ftn74\">[74]<\/a> <em>See id.<\/em> at 15-16, 18-19.<\/p>\n<p><a href=\"#_ftnref75\" name=\"_ftn75\">[75]<\/a> <em>See <\/em>Sasha Romanosky et al., <em>Empirical Analysis of Data Breach Litigation<\/em>, 11 J. Empirical Legal Stud. 74, 80 (2014) (\u201c[I]t is the residence of the individual that drives disclosure, not the location of the breach. That is, disclosure to an individual is required only if the state in which the individual is a citizen has adopted a disclosure law.\u201d).<\/p>\n<p><a href=\"#_ftnref76\" name=\"_ftn76\">[76]<\/a> <em>See<\/em> Arant, <em>supra<\/em> note 56, at 10 (\u201cGiven the heterogeneous nature of state data breach notification laws, simultaneous compliance with multiple laws can be a logistical nightmare\u2014and an expensive one at that.\u201d).<\/p>\n<p><a href=\"#_ftnref77\" name=\"_ftn77\">[77]<\/a> <em>See<\/em> Jill Joerling, Note, <em>Data Breach Notification Laws: An Argument for a Comprehensive Federal Law to Protect Consumer Data<\/em>, 32 Wash. U. J.L. &amp; Pol\u2019y 467, 486 (2010) (\u201cCongress should take action immediately to enact a federal data breach notification law.\u201d); <em>see also<\/em> Jay P. Kesan, <em>et al<\/em>., <em>A Comprehensive Empirical Study of Data Privacy, Trust, and Consumer Autonomy<\/em>, 91 Ind. L.J. 267, 346-48 (2016) (suggesting \u201ca complete overhaul of data privacy law[s] and the creation of [centralized] profile repository\u201d for consumers\u2019 data that would operate in a fashion similar to credit bureaus); Tschider, <em>supra<\/em> note 61, at 72 (\u201ca federal statute should regulate all businesses involving consumer personal information to effectively preserve customer choice and control with respect to their information, to drive contract efficiency, and to facilitate international trade.\u201d).<\/p>\n<p><a href=\"#_ftnref78\" name=\"_ftn78\">[78]<\/a> <em>See<\/em> Joerling, <em>supra<\/em> note 77, at 486.<\/p>\n<p><a href=\"#_ftnref79\" name=\"_ftn79\">[79]<\/a> <em>See id.<\/em> (\u201cReplacing the current patchwork of . . . state laws with a single comprehensive federal law would give businesses a clear road map to follow after a breach.\u201d).<\/p>\n<p><a href=\"#_ftnref80\" name=\"_ftn80\">[80]<\/a> <em>See<\/em>,<em> e.g.<\/em>, Data Security and Breach Notification Act of 2015, H.R. 1770, 114th Cong. (2d Sess. 2016) (demonstrating a proposed federal data breach law that did not pass in Congress).<\/p>\n<p><a href=\"#_ftnref81\" name=\"_ftn81\">[81]<\/a> <em>See<\/em> Brett V. Newman, <em>Hacking the Current System: Congress\u2019 Attempt to Pass Data Security and Breach Notification Legislation<\/em>, 2015 U. Ill. J.L. Tech. &amp; Pol\u2019y 437, 445 (2015) (\u201cThe patchwork state legislation and numerous bill introduced in Congress show how difficult it is to agree on breach notification and data security measures. There is likely an agreement that the United States needs a data breach law, but that does not mean that one will be passed. The problem may also come from a surplus of Congressional committees claiming jurisdiction and trying to tackle the issue\u2014resulting in too many different bills.\u201d).<\/p>\n<p><a href=\"#_ftnref82\" name=\"_ftn82\">[82]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1196. (Although Peters analyzes an earlier draft bill, the Data Security &amp; Breach Notification Act of 2013, her criticism holds true for the Data Security Breach Notification Act of 2015.)<\/p>\n<p><a href=\"#_ftnref83\" name=\"_ftn83\">[83]<\/a> <em>See id.<\/em>; <em>see also<\/em> Tschider, <em>supra<\/em> note 61, at 74-75 (emphasizing the need for a federal law that focuses on data protection in addition to data breach notification: \u201cHaving clear data protection standards will dramatically reduce uncertainty for consumers and business, as standard data protection requirements will be articulated and required for implementation . . .\u201d); s<em>ee also<\/em> Andrea Peterson, <em>Why this National Data Breach Notification Bill has Privacy Advocates Worried<\/em>, Wash. Post (Apr. 15, 2015), https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2015\/04\/15\/why-this-national-data-breach-notification-bill-has-privacy-advocates-worried,<em> archived at<\/em> https:\/\/perma.cc\/C9U3-S3W3 (noting that consumers could have fewer protections under Data Security Breach Notification Act of 2015 than they have under existing state laws).<\/p>\n<p><a href=\"#_ftnref84\" name=\"_ftn84\">[84]<\/a> <em>See<\/em> Kosseff, <em>supra<\/em> note 62, at 403 (arguing that laws should create incentives through tax credits and litigation safe harbors to encourage businesses to invest in cybersecurity infrastructure; rather than focus solely on penalties for data breaches).<\/p>\n<p><a href=\"#_ftnref85\" name=\"_ftn85\">[85]<\/a> <em>See <\/em>Ponemon Inst., 2016 Cost of Data Breach Study: United States, IBM, 1, 3, 13 (2016).<\/p>\n<p><a href=\"#_ftnref86\" name=\"_ftn86\">[86]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1193.<\/p>\n<p><a href=\"#_ftnref87\" name=\"_ftn87\">[87]<\/a> <em>See id. <\/em>at 1197 (noting that a national data breach law that gives consumers a private right of action or requires mandatory credit monitoring \u201cwill be an incentive for companies to minimize data breaches.\u201d).<\/p>\n<p><a href=\"#_ftnref88\" name=\"_ftn88\">[88]<\/a> <em>See, e.g.<\/em>, Nicole Hong, <em>For Consumers, Injury Is Hard to Prove in Data-Breach Case<\/em>, Wall St. J. (June 26, 2016, 8:06 PM), http:\/\/www.wsj.com\/articles\/for-consumers-injury-is-hard-to-prove-in-data-breach-cases-1466985988,<em> archived at<\/em> https:\/\/perma.cc\/F3VF-8LKD.<\/p>\n<p><a href=\"#_ftnref89\" name=\"_ftn89\">[89]<\/a> <em>See<\/em> Baker Hostetler, <em>supra<\/em> note 70, at 16\u201318.<\/p>\n<p><a href=\"#_ftnref90\" name=\"_ftn90\">[90]<\/a> <em>See<\/em> Kesan <em>et al<\/em>., <em>supra<\/em> note 77, at 277 (noting that \u201cmany other states merely require companies to notify customers of data breaches and the relevant statutes do not create any additional duties or entitlements.\u201d).<\/p>\n<p><a href=\"#_ftnref91\" name=\"_ftn91\">[91]<\/a> <em>See also<\/em> Thomas Martecchini, <em>A Day in Court for Data Breach Plaintiffs: Preserving Standing Based on Increased Risk of Identity Theft After Clapper v. Amnesty International USA<\/em>, 114 Mich. L. Rev. 1471, 1474 (noting that courts are divided on \u201cwhether increased risk of identity theft is an injury-in-fact sufficient to create standing\u2026\u201d).<\/p>\n<p><a href=\"#_ftnref92\" name=\"_ftn92\">[92]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1185 (discussing various common law theories available to consumers for data breach).<\/p>\n<p><a href=\"#_ftnref93\" name=\"_ftn93\">[93]<\/a> <em>See id.<\/em> at 1185-87 (\u201c[A] principle reason that civil causes of action in data-breach cases are rarely successful is the difficulty consumer data-breach victims have in meeting the standing and injury requirements.\u201d).<\/p>\n<p><a href=\"#_ftnref94\" name=\"_ftn94\">[94]<\/a> <em>But see<\/em> Kesan <em>et al<\/em>., <em>supra<\/em> note 77, at 344 (discussing the various types of harm that result from loss of control over personal data, \u201cincluding dignitary harms; a chilling effect from law enforcement having too much control over individual expression; and circumstances that interfere with an individual\u2019s ability to exercise freedoms or develop a sense of self-determination.\u201d).<\/p>\n<p><a href=\"#_ftnref95\" name=\"_ftn95\">[95]<\/a> <em>See,<\/em> <em>e.g.<\/em>, Gunkel v. Renovations, Inc., 822 N.E.2d 150, 154 (Ind. 2005) (holding that economic losses are not recoverable in a tort action premised on the failure of a product or service to perform as expected unless the failure results in personal injury or physical harm to property other than the product; proper remedy sounds in contract).<\/p>\n<p><a href=\"#_ftnref96\" name=\"_ftn96\">[96]<\/a> <em>See <\/em>Peters, <em>supra<\/em> note 59, at 1186 (discussing data breach cases dismissed on economic loss grounds).<\/p>\n<p><a href=\"#_ftnref97\" name=\"_ftn97\">[97]<\/a> <em>See<\/em> <em>id.<\/em> at 1187 (discussing split of authority with regard to whether consumers have standing to bring suit in data breach cases).<\/p>\n<p><a href=\"#_ftnref98\" name=\"_ftn98\">[98]<\/a> <em>See,<\/em> <em>e.g.<\/em>, Remijas v. Nieman Marcus Group, LLC, 794 F.3d 688, 691\u201392 (7th Cir. 2015) (holding that standing requires a litigant to show a concrete injury that is causally linked to the defendants conduct and can be redressed by the court).<\/p>\n<p><a href=\"#_ftnref99\" name=\"_ftn99\">[99]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref100\" name=\"_ftn100\">[100]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1189\u201392 (collecting cases addressing standing and injury-in-fact in context of data breach litigation).<\/p>\n<p><a href=\"#_ftnref101\" name=\"_ftn101\">[101]<\/a> <em>See id.<\/em>; <em>see also<\/em> Martecchini, <em>supra<\/em> note 91, at 1474 (noting that courts are divided on \u201cwhether increased risk of identity theft is an injury-in-fact sufficient to create standing\u2026\u201d).<\/p>\n<p><a href=\"#_ftnref102\" name=\"_ftn102\">[102]<\/a> <em>See<\/em> Michael D. Simpson, <em>All Your Data Are Belong to Us Consumer Data Breach Rights and Remedies in an Electronic Exchange Economy<\/em>, 87 U. Colo. L. Rev. 669, 685\u201386 (2016) (discussing difficulties of applying common law tort theories to data breach cases).<\/p>\n<p><a href=\"#_ftnref103\" name=\"_ftn103\">[103]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1188 (\u201c[I]f a person is the victim of two or more data breaches in which similar personal information is stolen and that information is not used until years later to harm her, it may be difficult for the victim to demonstrate which breach was the source of the information used.\u201d); <em>see also<\/em> Newman, <em>supra<\/em> note 81, at 440 (\u201cproving that a customer lost money due to a specific breach can be difficult.\u201d).<\/p>\n<p><a href=\"#_ftnref104\" name=\"_ftn104\">[104]<\/a> <em>See<\/em> Peters, <em>supra<\/em> note 59, at 1192\u201393.<\/p>\n<p><a href=\"#_ftnref105\" name=\"_ftn105\">[105]<\/a> <em>See generally <\/em>Jeff John Roberts, <em>This Court Ruling Just Made It Easier to Sue Companies That Get Hacked<\/em>, Fortune (July 29, 2015, 7:00 PM), http:\/\/fortune.com\/2015\/07\/29\/data-breach-7th-circuit\/,<em> archived at<\/em> https:\/\/perma.cc\/C4ZT-SQD7 (discussing the hurdles victims of data breaches face when trying to sue).<\/p>\n<p><a href=\"#_ftnref106\" name=\"_ftn106\">[106]<\/a> <em>See<\/em> Simpson, <em>supra<\/em> note 102, at 698 (observing that \u201cthe average consumer is essentially at the mercy of a breached entity\u2019s largesse to gain any recompense for stolen data.\u201d).<\/p>\n<p><a href=\"#_ftnref107\" name=\"_ftn107\">[107]<\/a> <em>See<\/em> <em>supra <\/em>Part II; <em>see also<\/em> Martecchini, <em>supra<\/em> note 91, at 1473 (noting that while many businesses are implementing data protection plans, \u201cmany other businesses still remain in denial about the threat of data breaches, either failing to implement any data-security changes or making only nominal modifications.\u201d).<\/p>\n<p><a href=\"#_ftnref108\" name=\"_ftn108\">[108]<\/a> <em>See <\/em>Pierluigi Paganini,<em> Preventing and Recovering From Cybercrime<\/em>, Tripwire (Nov. 4, 2014), http:\/\/www.tripwire.com\/state-of-security\/incident-detection\/preventing-and-recovering-from-cybercrime\/,<em> archived at<\/em> https:\/\/perma.cc\/PYB7-VKN5.<\/p>\n<p><a href=\"#_ftnref109\" name=\"_ftn109\">[109]<\/a> <em>See<\/em> Panko &amp; Panko, <em>supra<\/em> note 19, at 92.<\/p>\n<p><a href=\"#_ftnref110\" name=\"_ftn110\">[110]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref111\" name=\"_ftn111\">[111]<\/a> <em>See<\/em> <em>id.<\/em><\/p>\n<p><a href=\"#_ftnref112\" name=\"_ftn112\">[112]<\/a> <em>See <\/em>Paganini, <em>supra<\/em> note 108.<\/p>\n<p><a href=\"#_ftnref113\" name=\"_ftn113\">[113]<\/a> <em>See DC Metro Cyber Security Summit<\/em>, The CyberWire (June 3, 2015), https:\/\/www.thecyberwire.com\/events\/dc-metro-cyber-security-summit-2015.html,<em> archived at<\/em> https:\/\/perma.cc\/Z4XN-M6NK.<\/p>\n<p><a href=\"#_ftnref114\" name=\"_ftn114\">[114]<\/a> <em>See, e.g.<\/em>, Panko &amp; Panko, <em>supra<\/em> note 19, at 116\u201323 (discussing various forms of firewalls, their strengths, and their weaknesses).<\/p>\n<p><a href=\"#_ftnref115\" name=\"_ftn115\">[115]<\/a> <em>See id.<\/em> at 124.<\/p>\n<p><a href=\"#_ftnref116\" name=\"_ftn116\">[116]<\/a> <em>See, e.g.<\/em>, <em>Third Party Monitoring &#8211; Vendor Monitoring<\/em>, ObserveIT, http:\/\/www.observeit.com\/solutions\/third-party-monitoring,<em> archived at<\/em> https:\/\/perma.cc\/P3SX-SW4W (last visited Sept. 23, 2016) (illustrating the monitoring services that a third party security company provides).<\/p>\n<p><a href=\"#_ftnref117\" name=\"_ftn117\">[117]<\/a> <em>See<\/em> Paganini, <em>supra <\/em>note 108.<\/p>\n<p><a href=\"#_ftnref118\" name=\"_ftn118\">[118]<\/a> <em>See<\/em> Verizon Report, <em>supra<\/em> note 21, at 17.<\/p>\n<p><a href=\"#_ftnref119\" name=\"_ftn119\">[119]<\/a> <em>Id.<\/em> at 18.<\/p>\n<p><a href=\"#_ftnref120\" name=\"_ftn120\">[120]<\/a> <em>See generally<\/em> Jerry Fitzgerald, Alan Dennis &amp; Alexandra Durcikova, Business Data Communications and Networking 362 (11th ed. 2012) (noting that security policies should explain to employees how to control the risk of intrusion).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0BDM Publication Version PDF Cite as:\u00a0Hilary G. Buttrick et al.,The Skeleton of A Data Breach: The Ethical and Legal Concerns,\u00a023 Rich. J.L. &amp; Tech. 2 (2016),\u00a0http:\/\/jolt.richmond.edu\/wp-content\/uploads\/volume23_article2_Buttrick.pdf. Hilary G. Buttrick,*\u00a0Jason Davidson,**\u00a0Richard J. McGowan*** \u00a0 Introduction\u00a0 [1] \u00a0\u00a0\u00a0\u00a0\u00a0 After over thirty data breaches spanning the third and fourth quarter of 2012, Forbes magazine labeled the summer of [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-3463","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-TR","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=3463"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3463\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=3463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=3463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=3463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}