Monday, May 4, 2009

LexisNexis loses 32,000 from 2004 to 2007!

I normally shy away from posting data breach notices. After all there are so many that we can be inured to the severity of each one. I posted this because while we debate how bad identity theft is thieves are having a field day at our collective expense. And it took two years for the notification to the potential victims to take place! Wake up folks! You cannot prevent these breaches. Be proactive and avail yourselves of a professional identity theft service that provides you with access to attorneys, and restoration from all types of ID theft. Databases are hacked routinely across the world, and by international crime rings. One of my favorite quotes is. "You have to participate in your own rescue." Go to the link to the I've been Mugged column in my links section for a very good article on this particular breach.

LexisNexis has notified tens of thousands that their personal information was exposed in a database security breach, reports the Associated Press. On Friday, the company sent letters to 32,000 people whose information is contained in the LexisNexis database and may have been accessed by fraudsters. Thieves accessed the data between 2004 and 2007 by breaking into the mailboxes of businesses that contained LexisNexis database information, the AP report states. Postal authorities have contacted about 300 of those affected to let them know the perpetrators, former LexisNexis customers, set up fake credit cards using their information. Full Story

Adopting a Written Identity Theft Policy

In light of the recent extension by the FTC of the compliance phase of the new Red Flags Rule (FACTA) I began to wonder what business execs must be thinking. Are they simply in the dark as to whether their business is considered to be covered under this legislation? Are they unclear about being within the jurisdiction of the FTC? Are businesses confused about what compliance entails? Are they concerned about the costs, or a disruption in business? Are they fearful that compliance might expose serious flaws in their current practices? Or is the hubris such that they don't believe this is real and won't affect them? After all, some believe that if they have never had a problem so far why should they think it might happen now? One question that I might ask is. How do you know for certain that it hasn't happened yet? One very reliable national statistic out recently noted the results of interviewing thousands of small business owners. Only 6% of the small business owners surveyed could positively state that their business had not been the source of stolen data or identity fraud. It only takes a disgruntled or recently downsized employee a few minutes to download files onto a CD or flash drive and walk out. That can set into motion a very nasty series of events starting with identity theft episodes and law suits, and because of state notification rules, a possible loss of clients due to a lack of confidence. That is before the federal government steps in. The FTC has the authority to levy fines, prosecute, and require extensive audits. And the business may never discover the source ot the loss. As more people lose their jobs in the economic downturn cases like that are happening more often at businesses, medical facilities, local government agencies, and schools throughout the country.
Another relevant question is simply to ask what is the downside of a compliance program? After all, businesses comply with regulations all the time. They comply because the risk is such that non-compliance can be too costly, and of course because it is the right thing to do for reasons of safety or fairness.

I have studied the identity theft laws and regulations on both the state and federal levels sufficiently to know that they are fairly written and do attempt to stem the tide of data theft and fraud. Lets take the Red Flags Rule for example. Assessing risk and adopting an appropriate program is a very flexible part of the law. Companies are the best estimators of their risk if they are willing to accept that risk does exist and there is always room for improvements. Training of everybody on staff is the single most powerful part of the compliance procedure. After all it is the employees of a business that handle the data that is to be safeguarded and tested for accuracy. If everyone on staff knows what to do and how to respond to problems you put a serious dent in the risk to the company. Now, what company does not want to lower risk?

This should not be a topic for debate. It is the right thing to do for reasons of fairness and safety, and for most entities it can be done at very little or no cost. Every business whether covered or not should implement reasonable programs for their business. Where now is the downside?

If I ran a business that shared sensitive personal information on my employees with the business next door to mine who happens to be my payroll service, and I adopted a program such as described in the Red Flags Rule would I want that company next door to do the same? Yes! Is it because if I went through it so should he? After all it is only fair. No. It is because legally we share the responsibility and risk. Only by both of us adopting a plan we, (both businesses), lower our shared risk even more. That is the idea here. That is the reason for this law, for businesses to adopt a plan and see to it that the companies they share such information with do the same. The net result should be lowering risk to all of our businesses. Who are the winners? All of us as individuals are the winners. Our personal information is safeguarded and properly vetted to be true meaning that identity thieves have less a chance to co-opt our accounts, open new ones, and take over our good name. Shouldn't that be the goal of a good identity theft law? In 2008 there were an estimated 10 million U.S. victims of financial and non-financial identity theft combined. In 2008 businesses directly lost nearly $50 billion to identity theft. Could a well written identity theft law if applied have an affect on those numbers? I think so. Let's try it and see. What is the downside?

Taylor and Associates is prepared to assist any business with their program. Concerned about the sheer cost of using counsel to write a relevant plan for the board to adopt? We have taken care of that. We offer a framework for such a policy that any business can use and adopt to their individual needs. This policy framework was written by specialists in Privacy law to be consistent with the law, and by former Attorneys General as our panel of consultants. So now we have nearly or completely eliminated that cost. Next we train the staff. Do you need to hire expensive training consultants to perform that function? No. We are specially qualfied as Identity Theft specialists to handle that as well. The cost? How about an hour of their time. That is your cost for the training. We gather the staff together in as many meetings as it will take to eventually see everyone and give them a solid hour of orientation on the company policy as adopted by the board, and include awareness of the realities of identity theft for themselves and their families. After all identity theft can occur anywhere to anyone, no exceptions. Next we have to identify the person(s) responsible to administer the program for the business. Lastly in this case is to make notifications and communicate with the other businesses about your program and inquire about theirs. In any compliance program documentation is necessary to prove that compliance steps were taken and when. We provide all of the necessary documentation for everything mentioned above. After the program is begun we follow up as needed to update the program for all of our client businesses.

Now, lets add up the costs for these compliance services,
1. Written policy $0
2. Employee training $0 (one hour of time in mandatory company meetings)
3. letters and documentation $0
4. Notification letters and follow up with 3rd party and contractor businesses $0

No one can estimate the savings of a reduction in risk and potential liability. It cannot be done. Significantly lowering the risk of law suits and a loss of public confidence that results in losing customers could make the difference whether a business survives or fails in the most extreme cases, and at the least prevent identity theft. There is no downside to establishing an identity theft prevention program.
When can we start?

Friday, May 1, 2009

FTC Grants 90 Day Delay of Enforcement of ‘Red Flags’ Rule Requiring Creditors and Financial Institutions to Adopt Identity Theft Prevention Policy

How about this?

The Federal Trade Commission will delay enforcement of the new “Red Flags Rule” until August 1, 2009, to give creditors and financial institutions more time to develop and implement written identity theft prevention programs.

Here is the FTC website announcement,

http://www.ftc.gov/opa/2009/04/redflagsrule.shtm?goback=%2Ehom

Thursday, April 30, 2009

This Just In!

Red Flags Rule on Enforcement Eve

The FTC's Red Flags Rule goes into effect tomorrow. The rule intends to help prevent identity theft, reports InternetNews.com. "The Red Flags Rule covers what to do when, despite our best efforts, thieves steal data," said Tiffany George, an attorney for the FTC's division of privacy and identity protection. Prepping for compliance involves businesses' identifying their "red flags"--early indicators of suspicious or fraudulent activity. Compliance has come easily for some organizations affected by the rule, but for others the task has been more daunting. Some businesses have been surprised to find they fall under the rule's definition of "creditor." Full Story

FACTA Red Flags Rule enforcement begins

Tomorrow, May 1st the Federal Trade Commission will begin the enforcement phase as regards the Red Flags Rule (FACTA). The FTC estimates that an additional 11 million U.S. businesses are to be compliant on this date. These 11 million businesses are in addition to the savings and banking institutions that were to be compliant prior to November 1st of 2008. FDIC and NCUA have jurisdiction over the banking industry’s practices and will enforce compliance and perform compliance audits within that group.

I have found that a lot of businesses don't understand that they are under the jurisdiction of the FTC. For example mortgage brokers, investment advisors, law groups, and others cite various different regulatory agencies that cover their businesses. What they fail to understand is that the FTC has sweeping jurisdiction of the business “practices”, not necessarily the business “functions” of these types of businesses. When it comes to billing, maintaining accounts, ethical transactional practices, and commerce in general the FTC is the federal authority. That can explain some of the confusion on the part of companies who are used to regulations surrounding the professional services they perform. Agencies and bodies such as the SEC, Departments of Justice, Commerce, BLM, etc and state and national BAR Assns. have authority to regulate certain industry practices, but the FTC is concerned mainly in this case with the “sale of goods or services” to the public and the personal information businesses collect. The Commission is concerned with the protection of the publics’ rights to fair treatment and protection from (sic)predatory or irresponsible actions on the part of business. That also extends to the safekeeping of the personal information companies maintain on their clients or customers, and adopting practices to identify, isolate, and report possible identity fraud.

The FACT Act (1999) and subsequently the Red Flags Rule (2007) was designed in part to protect the personally identifiable information businesses collect in the process of doing business. It outlines the methods recommended in collection of this type of information, identifying possible fraudulent information, the safekeeping once it is collected, and the disposal of the data once it is no longer of practical use by the business. Other aspects of the rule are concerned with the adoption of a company identity theft policy, the education of employees, and the identity theft policies of contractors and service providers.

There are other laws enacted that also cover these kinds of practices. The Gramm Leach Bliley Safety Rule (GLB), and the Health Insurance Portability and Accountability Act (HIPAA) are examples of these rules and regulate these practices for specific types of organizations. With the enactment of the Red Flags Rule there is an overlapping of some of these compliance regulations which is taking us in my opinion, to a more universal set of compliance guidelines for all businesses, non-profits, state and local government agencies to follow. As more data is collected from forensic studies subsequent to breaches and identity theft episodes, there emerges predictable practices that all entities should follow regardless of the industry type. We are also closer to a more universal reporting and notification regulation that hopefully will provide simple bright line criteria for any affected organization to inform the public when their information is at risk of identity misuse due to a breach or loss.

It is incumbent on all businesses or any entity that acts as a “creditor” or “financial institution” as defined by the FTC to assess that entities’ risk of data loss or accepting information that may indicate identity fraud. As I wrote in a previous column businesses are finding that this kind of assessment is helpful to the company as it brings this issue into focus. Having a plan for a business is essential whether it is about data loss, identity fraud, or about increasing revenue. And no business can afford the fallout from such an episode without a plan.

As to enforcement, Betsy Broder, Assistant Director for Privacy and Identity Protection for the FTC made it clear last week that enforcement will begin immediately and will begin with the most risky businesses that have done nothing to date regarding an identity theft program.

Taylor and Associates can assist any organization with their program, and provide the essential training and documentation required.

Thursday, April 23, 2009

Study: Lost Laptops = Big Bucks

From todays' IAPP bulletin,

The Mercury News reports on the results of an Intel-commissioned study on business costs associated with lost or stolen laptops. Over five months, researchers from the Ponemon Institute examined 138 lost-laptop incidents across 29 business and government organizations. The typical cost per laptop to employers was $49,246. Much of the expense derives from the valuable sensitive data contained on the missing machines. "With each lost laptop there is the risk that sensitive data about customers, employees and business operations will end up in the wrong hands," according to the Ponemon report. Full Story

Monday, April 20, 2009

HEALTHCARE PRIVACY IN THE U.S.

As the American Recovery and Reinvestment Act of 2009 (ARRA), unfolds businesses are going to have to pay attention. This legislation will affect everyone in some way and knowledge of the law and how it pertains to business will be the responsibility of each individual business Board of Directors or owner.

The Department of Health and Human Services (DHSS), on Friday published guidance aimed at helping entities secure and protect health information. "Protecting patient privacy is a top priority and this guidance specifies proactive steps organizations can take to limit the potential harm a breach can cause," said HHS spokesperson Nick Papas. The guidance stems from requirements in the Health Information Technology for Economic and Clinical Health (HITECH) Act. It covers the standards for what makes PHI "secured," and a request for information related to the security breach notification requirements. Full Story

Just as the Red Flags Rule (FACTA) affects most businesses including those businesses who are not accustomed to FTC oversight, the HITECH Act will also impact the way businesses collect and use personal medical information.