Madison, IN Sunny intervals 59°
Listen Live

Attorney General Todd Rokita secures $49.5 million multistate settlement with Blackbaud for data breach

Fight to hold tech companies accountable

                               

Attorney General Todd Rokita continued his leadership in the fight to hold tech companies accountable for consumer privacy today, announcing a $49.5 million multistate settlement with the software company, Blackbaud. 

 “Nonprofits doing their great work rely and depend on vendors like Blackbaud to protect sensitive and private information,” Attorney General Rokita said. “This type of leak is unacceptable, and we fought back on behalf of Hoosiers.” 

 Attorney General Rokita, with the Attorney General of Vermont, led a coalition of 50 attorneys general to investigate the incident and negotiate a settlement after its deficient data security practices and response to a 2020 data breach that exposed the personal information of millions of consumers. Under the settlement, Blackbaud has agreed to overhaul its data security and breach notification practices and also make a $49.5 million payment to states.  

 As lead state, Indiana will receive nearly $3.6 million from the settlement, more than any other state.  

“While it doesn’t make up for Blackbaud’s negligence, I am glad we have held them accountable for their actions,” Attorney General Rokita said.   

 Blackbaud provides software to various nonprofit organizations, including charities, schools, churches, and healthcare organizations. Blackbaud’s customers use their software to connect with donors and manage data about their constituents, including demographic information. Social Security numbers, driver’s license numbers, financial information, donation history, and protected health information were also given to the company.  

 This type of highly sensitive information was exposed during the 2020 data breach, which impacted over 13,000 Blackbaud customers and their respective consumer constituents.   

 The settlement resolves allegations that Blackbaud violated state consumer protection laws, breach notification laws, and HIPAA by failing to implement reasonable data security, which allowed hackers to gain access to the network.  

 Blackbaud also failed to provide its customers with timely, complete, or accurate information regarding the breach, which is required by law.   

 As a result of their actions, the proper notification to consumers, whose personal information was exposed, was significantly delayed or never occurred at all. Blackbaud downplayed the incident and led its customers to believe that notification was not required. 

 Under the settlement led by Attorney General Rokita and his office, Blackbaud has agreed to strengthen its data security and breach notification practices going forward.   

 Indiana’s settlement is attached.

 

 

More from Local News

Events

Local News

Gov. Beshear Takes Steps to Lower Gas Prices, Address Affordability for Kentucky Families

Steps come as inflation hits 3-year high and gas soars to over $4 per gallon.

ARMOR-IIMAK To Expand Boone County Operation With Nearly $6 Million Investment, Creating 44 Kentucky Jobs

Increased manufacturing output will help the company meet growing consumer demand

Traffic signal improvements coming to U.S. 421 and Main Street Downtown

Change is being made to improve both vehicular and pedestrian mobility and safety

Local Sports

Personal Branding Activities Approved, High School Basketball Shot Clock Proposal Fails

The Board of Directors voted on both measures this week.

Kring Resigns After Four Years As Shawe Girls Coach

He was 59-32 in four seasons with the Hilltoppers

Pairings Revealed for IHSAA Softball State Tournament

Last season, Franklin County and Milan were the only local teams to advance out of the sectional.