Wednesday, February 25, 2009
Another Payment Card Processor Breached
Computerworld reports that another payment processor has been rocked by a security breach. Details are few and the affected company has not been identified, but according to reports, attackers breached a U.S.-based company, uncovering the account numbers and expiration dates of payment cards used in card-not-present transactions between February 2008 and January 2009. It is the third breach incident involving a payment processor since December, coming on the heels of Heartland Payment Systems' breach announcement just weeks ago. Visa Inc. and MasterCard International Inc. have begun notifying banks and credit unions of the compromise. Some fraudulent transactions have been reported as a result of this latest breach.
Monday, February 23, 2009
An Identity Theft Risk Management Program
In the last four posts I have described the fundamentals of a good identity theft program that takes into account the basic requirements for all parties. There are also additional compliance requirements placed on specific industries such as healthcare, banking and so forth. But it is very important to have all of the fundamentals in place so the program will be more effective. Let me introduce you to the Affirmative Defense Response System offered to businesses from Pre-Paid Legal Services Inc..
First, we covered The Victim and the effects different forms of identity theft might have. We talked about the laws enacted to protect individuals from having their information stolen from databases, company spreadsheets, or HR files and used by thieves.
In The Company I described briefly that entities that keep information for business purposes have a legal responsibility to try and safeguard it. We then outlined the basic procedures that any business can undertake as the foundation of an identity theft prevention program. It is important to remind the reader that without these basics all of the higher order compliance procedures are much less effective.
Documentation Without documentation the company cannot mitigate its exposure to liabilities such as litigation, fines, prosecution, and damaged public relations.
There are companies that provide services to assist with portions of these necessary steps. Some offer training programs, some identity theft products for the employee or client. Some companies provide a complete response package of notification to potential victims, and forensic services to the affected business. In other words there are a number of companies that offer a lot of services to the business. The ones I have looked at are very good at what they do. They are also specifically in the business of providing only these types of compliance services.
Here’s why Pre-Paid Legal Services is unique and very effective. We are the only company in the field that not only offers a highly effective identity theft product to protect from all forms of identity theft, not simply from financial crime, regardless of how and where the crime occurs. It is also the only product that provides complete restoration of the victims’ identity again regardless of the nature. Restoration means no matter what records are affected, Kroll Fraud Solutions has licensed forensic investigators on staff to fully manage all of the restoration processes on behalf of the victim. We also offer the largest and most mature network of major law firms in each state and four provinces of Canada that will represent the client for all forms of identity theft if needed, with 24/hour access to their firm in emergencies, from anywhere in North America. For the 62% of all identity theft victims who have warrants issued in their name that can be very reassuring. (Sorry for the stat). Moreover the entire family has the services of their law firm for all of their life’s legal events such as mortgage contract help, help with estate planning, tax law help, representation in civil court, criminal court, and traffic court, and many other areas of law that otherwise most everyone cannot afford to use an attorney for. You should know that between these two public companies we have amassed over 70 years of experience in our fields. Pre-Paid Legal is celebrating it's 37th year of business this year. We don't do anything else. Those are very briefly our products. No other company in the world offers comprehensive identity theft and comprehensive legal services together as a suite of coverage.
Now on to identity theft help for a business. You recall that the first essential step is to enact a company policy illustrating the company’s position and procedures to protect information. We provide that written policy to the business at no cost. This document is the product of our Advisory Council and is current with the laws including all of the 26 red flags specified in the latest FACTA legislation. The Advisory Council is comprised of three former states Attorneys General, and the General Counsel of one of the nation’s largest energy companies. Each company is encouraged to make whatever changes to customize the policy to the nature of their industry. Next is employee training on the new policy, and a general awareness discussion of identity theft as it affects millions of Americans every day. A key reason for hands on meetings is the interchange if ideas, and the problem solving unique to every business. Very important is documentation of those meetings too. We also provide that hands on training and proof of training documents at no cost. In fact we provide all of the documents the business will need including letters notifying contractors and service providers of the policy. Once those are sent we can then follow up with each contracting company regarding their policy.
We have taken into account the needs of
· The client company by providing an entire package of identity theft prevention services at no cost to the company. Remember Kaiser? As I said before if they had provided the level of awareness training to all staff they might have avoided the recent breach of employee data. That is a very real advantage, and at no cost.
· We have offered all of the employees services that will greatly reduce their family risk while providing much needed help for the family in a number of areas. These voluntary benefits are typically paid for by the individual employee on a month-to-month basis.
· This, by the way also has the effect of limiting the company liability if an internal breach were to occur, since a mitigating service has previously been offered.
· Companies such as financial advisors, accountancies, banks and other financial services can optionally make this available also to clients, which will provide an early warning and restoration of possible identity theft episodes from any source.
Have I left out anyone? I believe not. I can provide all of the above for your company at no direct cost to the business, and provide substantial benefits to the staff that they can use from day one to help with all of the families' identity theft and legal issues they might be facing.
First, we covered The Victim and the effects different forms of identity theft might have. We talked about the laws enacted to protect individuals from having their information stolen from databases, company spreadsheets, or HR files and used by thieves.
In The Company I described briefly that entities that keep information for business purposes have a legal responsibility to try and safeguard it. We then outlined the basic procedures that any business can undertake as the foundation of an identity theft prevention program. It is important to remind the reader that without these basics all of the higher order compliance procedures are much less effective.
Documentation Without documentation the company cannot mitigate its exposure to liabilities such as litigation, fines, prosecution, and damaged public relations.
There are companies that provide services to assist with portions of these necessary steps. Some offer training programs, some identity theft products for the employee or client. Some companies provide a complete response package of notification to potential victims, and forensic services to the affected business. In other words there are a number of companies that offer a lot of services to the business. The ones I have looked at are very good at what they do. They are also specifically in the business of providing only these types of compliance services.
Here’s why Pre-Paid Legal Services is unique and very effective. We are the only company in the field that not only offers a highly effective identity theft product to protect from all forms of identity theft, not simply from financial crime, regardless of how and where the crime occurs. It is also the only product that provides complete restoration of the victims’ identity again regardless of the nature. Restoration means no matter what records are affected, Kroll Fraud Solutions has licensed forensic investigators on staff to fully manage all of the restoration processes on behalf of the victim. We also offer the largest and most mature network of major law firms in each state and four provinces of Canada that will represent the client for all forms of identity theft if needed, with 24/hour access to their firm in emergencies, from anywhere in North America. For the 62% of all identity theft victims who have warrants issued in their name that can be very reassuring. (Sorry for the stat). Moreover the entire family has the services of their law firm for all of their life’s legal events such as mortgage contract help, help with estate planning, tax law help, representation in civil court, criminal court, and traffic court, and many other areas of law that otherwise most everyone cannot afford to use an attorney for. You should know that between these two public companies we have amassed over 70 years of experience in our fields. Pre-Paid Legal is celebrating it's 37th year of business this year. We don't do anything else. Those are very briefly our products. No other company in the world offers comprehensive identity theft and comprehensive legal services together as a suite of coverage.
Now on to identity theft help for a business. You recall that the first essential step is to enact a company policy illustrating the company’s position and procedures to protect information. We provide that written policy to the business at no cost. This document is the product of our Advisory Council and is current with the laws including all of the 26 red flags specified in the latest FACTA legislation. The Advisory Council is comprised of three former states Attorneys General, and the General Counsel of one of the nation’s largest energy companies. Each company is encouraged to make whatever changes to customize the policy to the nature of their industry. Next is employee training on the new policy, and a general awareness discussion of identity theft as it affects millions of Americans every day. A key reason for hands on meetings is the interchange if ideas, and the problem solving unique to every business. Very important is documentation of those meetings too. We also provide that hands on training and proof of training documents at no cost. In fact we provide all of the documents the business will need including letters notifying contractors and service providers of the policy. Once those are sent we can then follow up with each contracting company regarding their policy.
We have taken into account the needs of
· The client company by providing an entire package of identity theft prevention services at no cost to the company. Remember Kaiser? As I said before if they had provided the level of awareness training to all staff they might have avoided the recent breach of employee data. That is a very real advantage, and at no cost.
· We have offered all of the employees services that will greatly reduce their family risk while providing much needed help for the family in a number of areas. These voluntary benefits are typically paid for by the individual employee on a month-to-month basis.
· This, by the way also has the effect of limiting the company liability if an internal breach were to occur, since a mitigating service has previously been offered.
· Companies such as financial advisors, accountancies, banks and other financial services can optionally make this available also to clients, which will provide an early warning and restoration of possible identity theft episodes from any source.
Have I left out anyone? I believe not. I can provide all of the above for your company at no direct cost to the business, and provide substantial benefits to the staff that they can use from day one to help with all of the families' identity theft and legal issues they might be facing.
Friday, February 20, 2009
Documentation
This is the fourth post in a series of five. A program such as a risk-averse compliance program has dual purposes.
First, a business wants to protect its clients and employees from identity theft. It's the responsible thing to do. The program I outlined in my previous column will greatly reduce the incidents of data loss. While nothing is foolproof a holistic approach is far more effective than a patchwork of compliance steps. For example, the Northern California “district” of the Kaiser hospital group had a large breach of personal information very recently. Kaiser takes its’ HIPAA responsibilities seriously. Part of that responsibility is to protect the privacy of the patient files in the Kaiser system. This breach however, was of employee HR file information, and is not covered under the HIPAA compliance requirements. Had the employer included the entire administrative team, payroll, HR, accounting, etc. into a company-wide data security culture they might have prevented that breach.
The other reason to initiate a personal information security program is to lessen exposure to risk and mitigate the company liability.
That is why documentation is so important. When an organization experiences a breach either forensic investigators from the Secret Service, or agents representing the FTC or law enforcement will want to see what the business has done to protect the information prior to the incident. Just as proof of insurance affects the outcome of a traffic accident, proof of an identity theft program will affect the outcome of a breach case. A carefully documented program is key. You need to document that you have enacted the policy, that everyone on staff has been exposed to the policy and has agreed to uphold the policy. Documentation naming the person(s) responsible for administering the program needs to be in the file along with notification to all contractors and service providers that the plan is in place and the business expects a similar policy to be in place with all contractors.
In the next post I will tie all of this together and show how Pre-Paid Legal Services Inc has developed a program that connects the dots and covers each aspect of what I’ve described in the last few posts. I’m proud to say that no other service exists that provides the uniquely comprehensive and "holistic" approach as the Pre-Paid program.
First, a business wants to protect its clients and employees from identity theft. It's the responsible thing to do. The program I outlined in my previous column will greatly reduce the incidents of data loss. While nothing is foolproof a holistic approach is far more effective than a patchwork of compliance steps. For example, the Northern California “district” of the Kaiser hospital group had a large breach of personal information very recently. Kaiser takes its’ HIPAA responsibilities seriously. Part of that responsibility is to protect the privacy of the patient files in the Kaiser system. This breach however, was of employee HR file information, and is not covered under the HIPAA compliance requirements. Had the employer included the entire administrative team, payroll, HR, accounting, etc. into a company-wide data security culture they might have prevented that breach.
The other reason to initiate a personal information security program is to lessen exposure to risk and mitigate the company liability.
That is why documentation is so important. When an organization experiences a breach either forensic investigators from the Secret Service, or agents representing the FTC or law enforcement will want to see what the business has done to protect the information prior to the incident. Just as proof of insurance affects the outcome of a traffic accident, proof of an identity theft program will affect the outcome of a breach case. A carefully documented program is key. You need to document that you have enacted the policy, that everyone on staff has been exposed to the policy and has agreed to uphold the policy. Documentation naming the person(s) responsible for administering the program needs to be in the file along with notification to all contractors and service providers that the plan is in place and the business expects a similar policy to be in place with all contractors.
In the next post I will tie all of this together and show how Pre-Paid Legal Services Inc has developed a program that connects the dots and covers each aspect of what I’ve described in the last few posts. I’m proud to say that no other service exists that provides the uniquely comprehensive and "holistic" approach as the Pre-Paid program.
Thursday, February 19, 2009
The Company
In my previous post I outlined who are the victims of identity theft, and what they might expect to encounter in resolving the fallout from being a victim. In this post let’s take a look at the companies responsible for protecting databases and files. The reason for this is to illustrate that the majority of the information that is stolen and used by identity thieves comes from data files. Either by way of insider theft or by accidental exposure of personal information, the end result is the same. I'm not forgetting that here are also a number of incidents of personal theft, “dumpster diving”, computer data theft, mailbox theft, and so forth. There are steps that everyone can take to reduce that kind of risk. I will address that later. Again, for the victim it is less important where the theft occurred, and more important how to recover.
Every business, college, state and county, hospital, non-profit, utility, frankly everyone keeps records. If not on clients then on personnel, and usually both. Names and addresses along with employee numbers, bank account numbers, SSNs, credit report files, health information, are typical and are considered non-public information. The information in those records by law needs to be protected. Over a number of years dozens of federal and state laws have been enacted that rightfully place the security responsibility on those that keep the records. When they lose that information no matter how it happens scenarios like the ones described in my Victim post can occur.
The fallout affects both the individual victim, their families, and of course the business. Several things can happen when a database is breached. First, the company will need to make a public notice to all potential victims that their information is at risk of identity theft. Statistics show that when that happens 40% of all clients will cease doing business with them, 20% will seriously consider it, and 5 to 10% will sue. I know I said I would refrain from stats but those numbers are staggering. That is just the beginning. The laws all have civil or criminal penalties, and individual and class actions could be likely.
What is a business to do?
There are a number of steps any business can take. Large and high tech companies have vast resources, and can take such steps as hiring permanent privacy and security officers to manage a data security program. Banks, S&Ls and lenders have certain extra responsibilities to insure the accounts they have are genuine and are not the result of stolen or falsified information.
Also encryption programs and procedures are required of insurance and financial organizations such as financial advisors, and accountancies. All businesses however, can take other reasonable steps given their individual resources.
These remaining reasonable steps revolve around awareness. Regardless of the size and nature of a business these are crucial in a "culture of security." Developing a written plan and strategy is the first step in any identity theft program. This policy once approved becomes the engine that drives the program. Next is naming the individuals responsible to implement the plan. Next and perhaps most importantly is to discuss the plan with all employees in general safety meetings, and make them aware of their responsibilities under the plan. This is also a good opportunity for feedback from the staff as to how the company might tighten security around record keeping and office procedures. Another important step needs to be taken in order for the plan to be effective. That is working with any contractor or service provider business to insure that the security practices of that company are of similar caliber. Lastly, make some sort of notification system available to clients and employees if possible identity theft episodes have occurred from any source, not just from the company. Any business that has performed these steps will be considered to have taken the reasonable steps required by the FTC to comply with the spirit and intention of the privacy legislation.
Every business, college, state and county, hospital, non-profit, utility, frankly everyone keeps records. If not on clients then on personnel, and usually both. Names and addresses along with employee numbers, bank account numbers, SSNs, credit report files, health information, are typical and are considered non-public information. The information in those records by law needs to be protected. Over a number of years dozens of federal and state laws have been enacted that rightfully place the security responsibility on those that keep the records. When they lose that information no matter how it happens scenarios like the ones described in my Victim post can occur.
The fallout affects both the individual victim, their families, and of course the business. Several things can happen when a database is breached. First, the company will need to make a public notice to all potential victims that their information is at risk of identity theft. Statistics show that when that happens 40% of all clients will cease doing business with them, 20% will seriously consider it, and 5 to 10% will sue. I know I said I would refrain from stats but those numbers are staggering. That is just the beginning. The laws all have civil or criminal penalties, and individual and class actions could be likely.
What is a business to do?
There are a number of steps any business can take. Large and high tech companies have vast resources, and can take such steps as hiring permanent privacy and security officers to manage a data security program. Banks, S&Ls and lenders have certain extra responsibilities to insure the accounts they have are genuine and are not the result of stolen or falsified information.
Also encryption programs and procedures are required of insurance and financial organizations such as financial advisors, and accountancies. All businesses however, can take other reasonable steps given their individual resources.
These remaining reasonable steps revolve around awareness. Regardless of the size and nature of a business these are crucial in a "culture of security." Developing a written plan and strategy is the first step in any identity theft program. This policy once approved becomes the engine that drives the program. Next is naming the individuals responsible to implement the plan. Next and perhaps most importantly is to discuss the plan with all employees in general safety meetings, and make them aware of their responsibilities under the plan. This is also a good opportunity for feedback from the staff as to how the company might tighten security around record keeping and office procedures. Another important step needs to be taken in order for the plan to be effective. That is working with any contractor or service provider business to insure that the security practices of that company are of similar caliber. Lastly, make some sort of notification system available to clients and employees if possible identity theft episodes have occurred from any source, not just from the company. Any business that has performed these steps will be considered to have taken the reasonable steps required by the FTC to comply with the spirit and intention of the privacy legislation.
Wednesday, February 18, 2009
The Victim
In my last post I said that at Pre-Paid Legal Services we take into account the employee of a business, the customers of the business, the business itself, and other companies that have a business relationship with them. In this post I want to focus on the individual victim. Victims can be employees, customers or simply someone unfortunate enough to have their information stolen as the result of a breach of records, like from a county or former university for example.
I want to write this series without relying on statistics to make my point. I wade through mountains of identity theft statistics almost every day. Some are so contradictory as to negate their conclusions, and a lot of data and surveys you see from companies are simply skewed to validate preconceived ideas of the company and their product. One fact is irrefutable however. No victim of identity theft cares about statistics, only what resources they need to try and solve their problem. The effectiveness of a service to aid the client is the only statistic that matters.
First, lets’ recognize identity theft as the crime that it is. It is most assuredly not victimless as I can personally attest to. You become one of about 10 million North American victims each year. Your local police and County attorney can’t help you. The Attorney General of your state can’t help you. With very rare exeptions these agencies simply do not have the resources to help individual identity theft victims. Every victim is on their own to plow through the maze of issues they need to resolve in order to try and put the episode behind them. That bears repeating. Every victim of identity theft needs to be actively engaged in dealing with their own identity theft rescue. So, when you become the victim of identity theft you want help plain and simple. As it is with anything every victim wants to be able to pick up the phone and know that the person on the other end will help them.
This is a lot more than working with your bank to get your account straight, although that can be difficult enough. I've often said that victims of financial (bank account), identity theft are fortunate! It is the easiest type of the crime to resolve. However, identity theft might involve representation with the IRS in the event your SSN has been used to obtain employment, or to make false tax filings to get refunds, or not paying taxes at all. Your situation might involve the use of your medical insurance to file false claims, or receive medical services leaving you stuck with the bill and incorrect medical records. It might be one of using your identity in the commission of a crime, or a number of circumstances where an attorney will be your best advocate. Remember, identity theft is a crime, and crime is a legal issue
You will also need your records scrubbed of false entries after the fact. It will likely involve the credit bureaus, but also many other local, federal and private databases that can contain untrue entries and documents depending on the nature of the crime. You will need to have those records restored to their pre-theft status. That can take years.
In my next post we will look at those databases and the businesses that keep them.
I want to write this series without relying on statistics to make my point. I wade through mountains of identity theft statistics almost every day. Some are so contradictory as to negate their conclusions, and a lot of data and surveys you see from companies are simply skewed to validate preconceived ideas of the company and their product. One fact is irrefutable however. No victim of identity theft cares about statistics, only what resources they need to try and solve their problem. The effectiveness of a service to aid the client is the only statistic that matters.
First, lets’ recognize identity theft as the crime that it is. It is most assuredly not victimless as I can personally attest to. You become one of about 10 million North American victims each year. Your local police and County attorney can’t help you. The Attorney General of your state can’t help you. With very rare exeptions these agencies simply do not have the resources to help individual identity theft victims. Every victim is on their own to plow through the maze of issues they need to resolve in order to try and put the episode behind them. That bears repeating. Every victim of identity theft needs to be actively engaged in dealing with their own identity theft rescue. So, when you become the victim of identity theft you want help plain and simple. As it is with anything every victim wants to be able to pick up the phone and know that the person on the other end will help them.
This is a lot more than working with your bank to get your account straight, although that can be difficult enough. I've often said that victims of financial (bank account), identity theft are fortunate! It is the easiest type of the crime to resolve. However, identity theft might involve representation with the IRS in the event your SSN has been used to obtain employment, or to make false tax filings to get refunds, or not paying taxes at all. Your situation might involve the use of your medical insurance to file false claims, or receive medical services leaving you stuck with the bill and incorrect medical records. It might be one of using your identity in the commission of a crime, or a number of circumstances where an attorney will be your best advocate. Remember, identity theft is a crime, and crime is a legal issue
You will also need your records scrubbed of false entries after the fact. It will likely involve the credit bureaus, but also many other local, federal and private databases that can contain untrue entries and documents depending on the nature of the crime. You will need to have those records restored to their pre-theft status. That can take years.
In my next post we will look at those databases and the businesses that keep them.
Tuesday, February 17, 2009
What do I do?
After writing this column for over a year it seemed a good idea to share exactly what it is that I do in the field of identity theft. Over the next few posts I hope to lay out what it is that makes our suite of products and services uniquely better suited to deal with identity theft. And then how I fit into it.
The company that I represent is Pre-Paid Legal Services Inc.. A Couple of years after being victimized by identity theft in 2000 I found this company. When I saw what they offer to customers I realized right away that they had the best answer to identity theft.
There are a lot of products flooding the market that say they can, “stop identity theft in it’s tracks”, or “track down the perpetrator”, “prevent the crime from happening”, “insure your losses”, and all sorts of claims. The truth is all of them are simply selling you a product. The good news is that most all of them have at least some merit, and a few are very good. I am not going to comment on the claims you see in their ads, nor will I go into any kind of comparison here, I’ll leave that up to you.
What I want to accomplish in the next few posts is to explain how the products and services of Pre-Paid can be the most elegant, solution-oriented products that take in to account the company that might have data to protect, the employees of that company, the clients or customers of that company and the other businesses that do business with that company. And also the future of identity theft no matter what direction it takes.
The company that I represent is Pre-Paid Legal Services Inc.. A Couple of years after being victimized by identity theft in 2000 I found this company. When I saw what they offer to customers I realized right away that they had the best answer to identity theft.
There are a lot of products flooding the market that say they can, “stop identity theft in it’s tracks”, or “track down the perpetrator”, “prevent the crime from happening”, “insure your losses”, and all sorts of claims. The truth is all of them are simply selling you a product. The good news is that most all of them have at least some merit, and a few are very good. I am not going to comment on the claims you see in their ads, nor will I go into any kind of comparison here, I’ll leave that up to you.
What I want to accomplish in the next few posts is to explain how the products and services of Pre-Paid can be the most elegant, solution-oriented products that take in to account the company that might have data to protect, the employees of that company, the clients or customers of that company and the other businesses that do business with that company. And also the future of identity theft no matter what direction it takes.
FAA Employee Database Hacked
And the beat goes on....
The Associated Press reported last week that hackers broke into a Federal Aviation Administration employee database accessing the personally identifiable information of 45,000 employees and retirees. The break-in was disclosed by the FAA in an announcement to union representatives. An FAA representative confirmed that the event took place last week.
Tom Waters , president of American Federation of State, County and Municipal Employees Local 3290 said union leaders were told hackers gained access to two files. One file had the names and Social Security numbers of 45,000 employees and retirees on the FAA's rolls as of February 2006. Social security numbers can be used to steal identities for illicit purposes.
Waters said the other file contained medical information that was encrypted.
An FAA contracts attorney complained that federal computer systems "should be the best in the world" and not vulnerable to hackers; the FAA said this was the first incident of its kind to affect the agency.
The Associated Press reported last week that hackers broke into a Federal Aviation Administration employee database accessing the personally identifiable information of 45,000 employees and retirees. The break-in was disclosed by the FAA in an announcement to union representatives. An FAA representative confirmed that the event took place last week.
Tom Waters , president of American Federation of State, County and Municipal Employees Local 3290 said union leaders were told hackers gained access to two files. One file had the names and Social Security numbers of 45,000 employees and retirees on the FAA's rolls as of February 2006. Social security numbers can be used to steal identities for illicit purposes.
Waters said the other file contained medical information that was encrypted.
An FAA contracts attorney complained that federal computer systems "should be the best in the world" and not vulnerable to hackers; the FAA said this was the first incident of its kind to affect the agency.
Subscribe to:
Posts (Atom)

