Paxton Sues PowerSchool
Posted in Data Breaches
Nearly a year after PowerSchool’s December 2024 data breach, the cloud-based software provider is facing a lawsuit initiated by Texas Attorney General Ken Paxton. PowerSchool is a leading global provider of technology solutions that manage student data for K-12 schools. Paxton alleges that, despite claiming to have “state-of-the-art protections” in place to safeguard personal information, PowerSchool failed to take reasonable steps to protect the student and teacher personal information that it maintains. Paxton further alleges that PowerSchool’s failures are violations of the Texas Deceptive Trade Practices Act and the Identity Theft Enforcement and Protection Act. Specifically, Paxton accuses PowerSchool of misleading schools about its software, and he criticizes PowerSchool for its failure to implement multifactor authentication, adequate access controls and proper data encryption. Consequently, a hacker (a 19-year-old student in Massachusetts – not a foreign threat actor) obtained administrative access to PowerSchool’s systems and exfiltrated the unencrypted personal information of more than 880,000 teachers and school-age children in Texas alone.
As regulators take greater interest in data breaches and enforcing data privacy and consumer protection laws, organizations are learning that simply providing timely notification and identity monitoring services is not enough to protect them from regulatory scrutiny. While an organized, timely and thorough response process is necessary for those experiencing a data breach, organizations should also proactively approach data security and privacy issues in an effort to minimize risk to data before an incident occurs.
To organizations that have not implemented basic safeguards like multifactor authentication, access controls and encryption: Now is the time. Further, organizations should conduct regular risk assessments that identify gaps in security coverage and should draft policies and procedures to help plan and memorialize security practices. These measures will not only help defend against potential regulatory investigations; they will also help organizations increase their defenses against cybersecurity threats. Finally, when representing the nature and extent of their security controls, organizations need to be careful not to overstate the security measures they have in place, as that could be considered a deceptive trade practice.
