As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…
What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
I know this is USA, but FYI in the EU, all personal data is protected.