News: 1662004178

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LabMD gets another shot at defamation claim against 'extortionate' infosec biz

(2022/09/01)


LabMD, the embattled and now defunct cancer-testing company, will get another chance at suing security firm Tiversa for defamation following an appeals court ruling.

The testing laboratory has long alleged that: Tiversa illegally obtained a 1,178-page computer file containing confidential data on more than 9,000 LabMD patients back in 2008; lied about the file being publicly available on a peer-to-peer file-sharing network and that it was downloaded by miscreants; and tried to use this alleged privacy fiasco to bully the medical company into paying for Tiversa's incident response services to the tune of $475 an hour.

Tiversa has since been acquired by risk consulting biz Kroll.

[1]

According to LabMD, it declined to hire Tiversa after it could find no evidence of a leak. And in response, the cybersecurity shop retaliated against LabMD, the medical company claimed.

[2]

[3]

First, Tiversa handed over the 1,718-page computer file to a former director of the Center for Digital Strategies at Dartmouth College who subsequently published critical research titled "Data Hemorrhages in the Health-Care Sector," LabMD claimed. This paper did not name LabMD but included a redacted version of the file.

Additionally, Tiversa provided this patient data to America's consumer watchdog, the FTC, claiming it found the massive file on a public peer-to-peer network, and that crooks were still downloading the sensitive data from that network.

[4]

This spawned a [5]legal complaint against LabMD by the FTC, which the testing firm said cost it "virtually all of its patients, referral sources, and workforce" and forced it out of business in 2014.

Triversa whistleblower steps up

Later, a [6]Tiversa whistleblower claimed he actually downloaded the file from one of LabMD's servers, and fabricated evidence that the data had been shared on a public peer-to-peer network. This set off a [7]congressional-level investigation into Tiversa, which found the security company "often acted unethically and sometimes unlawfully in its use of documents unintentionally exposed on peer-to-peer networks."

With that out in the open, LabMD successfully contested and overturned the punishment handed down against it earlier by the FTC. But according to appeal court documents, "although it was awarded attorneys' fees from the government in the amount of almost $850,000, that was too little too late. LabMD's business was destroyed."

N ext, LabMD filed a lawsuit in Georgia against Tiversa, alleging it violated America's Computer Fraud and Abuse Act and Georgia's computer crimes statute, along with other allegations related to the stolen data. A judge dismissed those claims.

[8]Feds raid 'extortionist' IT security biz Tiversa, CEO put on leave

[9]Rogue cybersecurity firm killed cancer testing lab, claims ex-employee

[10]Crooks target top execs on Office 365 with MFA-bypass scheme

[11]Now Oktapus gets access to some DoorDash customer info via phishing attack

A second LabMD lawsuit against Tiversa, filed in Pennsylvania, alleged defamation, negligent misrepresentation, fraud, and other charges, and claimed the security shop violated federal Racketeer Influenced and Corrupt Organizations Act (RICO) laws.

These claims were also tossed out. The district court judge had, notably, blocked expert testimony supporting LabMD's claims that Tiversa illegally accessed its file containing patient data, on the basis it would't be needed. It would appear the district judge decided the expert testimony would only be needed if LabMD's claims survived Tiversa's motion to throw out the case, and then approved the motion, thus throwing out the case.

The judge also sanctioned LabMD due to the "irrelevant" questions its attorney James Hawkins asked chairman of Tiversa's board, Joel Adams, during a deposition. This, according to the appeals court, included asking:

If there was something secretive about [Adams's] children, strengths and weaknesses of a certain employee, the workplace culture at Tiversa, leadership styles, guns in the workplace, an AIDS clinic in Chicago, Edward Snowden…

And so on. Hawkins is said to have continued this kind of "irrelevant" questioning in further depositions of witnesses, which Tiversa complained about leading to the aforementioned sanctions. The district judge then held LabMD in contempt when it said it was unable to pay up.

This week, 3rd US Circuit Court of Appeals judges unanimously

[12]PDF

sent the defamation claims back to the district court, saying the lower court was wrong to issue a summary judgment against LabMD primarily because the "prohibition on expert testimony was unwarranted."

[13]

The appeals court judges did note the whistleblower's claims to the FTC that Tiversa "had essentially made an extortionate business model out of accessing a company’s files, fabricating evidence of the files spreading across a network, using the false impression of a leak to sell data security remediation services to the company."

Attorneys for LabMD and Kroll could not be reached for comment.

The lower court's dismissal of the RICO claims, as well as tortious interference with business relations, fraud, and negligent misrepresentation will stand, though. The appeals court also ruled the sanctions and contempt finding weren't necessary despite LabMD's lawyer's odd line of questioning. The appeal judges did, however, issue a warning:

Nothing we say here, however, should be understood as license for any counsel to disregard the warnings and orders given by district courts. That we believe the district court in this case overstepped its bounds with its sanctions orders in no way condones the hyper-aggressive behavior that burned through the patience of a thoughtful judge and got Hawkins and LabMD into trouble. The court is free to keep them on an appropriately designed and well-explained short leash, as the case continues.

So unfortunately, we will probably never learn what Edward Snowden had to do with all of this. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YxAuWRDWbHgW5Czd9wBi@AAAAAU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxAuWRDWbHgW5Czd9wBi@AAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxAuWRDWbHgW5Czd9wBi@AAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YxAuWRDWbHgW5Czd9wBi@AAAAAU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.ftc.gov/news-events/news/press-releases/2013/08/ftc-files-complaint-against-labmd-failing-protect-consumers-privacy

[6] https://www.theregister.com/2015/05/08/rogue_cybersecurity_firm_killed_cancer_testing_lab_claims_exemployee/

[7] https://www.theregister.com/2016/03/18/fbi_raids_cybersecurity_firm_tiversa/

[8] https://www.theregister.com/2016/03/18/fbi_raids_cybersecurity_firm_tiversa/

[9] https://www.theregister.com/2015/05/08/rogue_cybersecurity_firm_killed_cancer_testing_lab_claims_exemployee/

[10] https://www.theregister.com/2022/08/25/microsoft_365_bec/

[11] https://www.theregister.com/2022/08/26/doordash_oktapus_phishing/

[12] https://regmedia.co.uk/2022/08/31/3rd_circuit_labmd_decision.pdf

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YxAuWRDWbHgW5Czd9wBi@AAAAAU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Actually, what I'd like is a little toy spaceship!!