Court Rules
All enforcement actions
SettlementCritical RiskMultistate

Multistate Coalition Fines Blackbaud $49.5M for Data Breach Failures

BlackbaudOctober 5, 2023New York Attorney General

Penalty Amount

$49,500,000

Summary

Blackbaud, a cloud company providing donor management software, experienced a 2020 data breach exposing personal information of millions of donors through its nonprofit customers. A multistate investigation found Blackbaud failed to implement adequate data security and delayed breach notifications. As a result, Blackbaud agreed to pay $49.5 million and overhaul its security practices.

Remedy

Blackbaud must pay $49.5 million to the states, implement and maintain incident response plans, enhance security measures including encryption and monitoring, undergo third-party assessments for seven years, and discontinue misrepresentations about data safety.

Monetary PenaltyConsent DecreeInjunctionAudit RequirementCompliance ProgramCorrective Notice

Contract Impact

In-house legal teams should review all vendor and data processing agreements with cloud service providers and SaaS vendors, particularly those handling sensitive donor, customer, or constituent data. Focus on clauses governing data security obligations (e.g., specific security frameworks, encryption, access controls), breach notification requirements (including timelines and content), audit and inspection rights, indemnification for data breaches, and limitations of liability. Given the findings of inadequate security and delayed notification, contracts should be amended to include more prescriptive security controls, shorter notification windows (e.g., 72 hours), mandatory reporting of security audits, and clear remedies for non-compliance. Additionally, review customer agreements to ensure robust data protection commitments are flowed down to end-users.

Contract Search Terms

data security standardsbreach notification timelineindemnification clauseaudit rightsencryption requirementsdata processing agreementsubprocessor managementincident response plandata retention and deletionliability caps

Laws Cited

state consumer protection lawsbreach notification lawsHIPAA

Violation Types

Entity Details

Entity

Blackbaud

Industry

Technology

Multistate Coalition

Alabama AGAlaska AGArizona AGArkansas AGColorado AGConnecticut AGDelaware AGDistrict of Columbia AGFlorida AGGeorgia AGHawaii AGIdaho AGIllinois AGIndiana AGIowa AGKansas AGKentucky AGLouisiana AGMaine AGMaryland AGMassachusetts AGMichigan AGMinnesota AGMississippi AGMissouri AGMontana AGNebraska AGNevada AGNew Hampshire AGNew Jersey AGNew Mexico AGNorth Carolina AGNorth Dakota AGOhio AGOklahoma AGOregon AGPennsylvania AGRhode Island AGSouth Carolina AGSouth Dakota AGTennessee AGTexas AGUtah AGVermont AGVirginia AGWashington AGWest Virginia AGWisconsin AGWyoming AG

Official Sources

Source Evidence

Entity Name
"Blackbaud"
Fine Amount
"$49.5 million"
Laws Cited
"state consumer protection laws, breach notification laws, and HIPAA"
Violation Types
"failed to implement reasonable data security and fix known security gaps"
Violation Types
"neglected to provide its customers with timely, complete, or accurate information regarding the breach"

Related Enforcement Actions

CA

Blackbaud

$6.8M

California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

NJ

Blackbaud

$49.5M

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.

NY

Evolutions Festival LLC and 845 Vibrations LLC

$5.9M

New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.