Thursday, June 25, 2009
Privacy Blunders Foster a New Era of Accountability
The following was in my daily privacy download. It is hard to add any editorial comments as the article spells it out very well. So, without further ado here is today's thought on privacy.
In the early days of mandatory data breach disclosures, which in the U.S. began in 2005, notifications followed a now predictable pattern: Organizations issued a press release expressing contrition, mailed notification letters, strategically released details on the scale of the breach, and emphasized the strides they were taking to mend and prevent. What was perhaps most notable was what didn't happen: At the senior-executive level, no heads rolled. Overall, corporate accountability for lost data seemed slight, at best.
Lately, however, a number of episodes suggest that we may be entering a new culture of senior-level accountability--over privacy, abuses of "secrecy," and for the data-related misdeeds of subordinates. The events seem to suggest a broader cultural shift toward increased transparency and accountability for whoever's in charge, and a growing realization that when it comes to collecting data, "more is better" isn't always best. The privacy buck stops where? The misdeeds of subordinates in several organizations have recently led to the chief's ouster. Last month, discount supermarket chain Lidl sacked its head of German food operations, Frank-Michael Mros, after documents recovered from a dumpster showed that throughout 2008 and 2009, the company illegally collected confidential information on employees (noting such state-of-health information as "operated on for a tumor" and "wants to get pregnant"). In March, the head of Deutsche Bahn, Hartmut Mehdorn, resigned after revelations that the state-owned rail operator had spied on its employees. As part of an internal fraud investigation, managers accessed confidential information on hundreds of thousands of employees and illegally monitored employee e-mail.
That same month, a student journalist at Binghamton University found an unlocked storeroom containing boxes full of documents containing students' and parents' personal information, the third breach in less than a year. While the administration threatened to charge the reporter with trespassing, students circulated a petition to sack Terry Dylewski, the chief information security officer. Those calls were renewed after a fourth privacy breach in April. In December, the Ohio Department of Job and Family Services fired its Deputy Director of Child Support for authorizing database checks on a state resident for no legitimate purpose. Two other department employees associated with the checks also no longer work with the department due to their involvement in a breach of the records of Samuel J. Wurzelbacher, better known as "Joe the Plumber."
Swiss bank secrecy under fire Calls for accountability--and with it, transparency--are becoming the new norm, and the financial services industry is on the frontline, given the furor over bonuses for bailed-out bank executives, and President Obama's pledge to crack down on international tax havens. Not even Swiss banks, legendary for their secrecy, are immune. Last year, federal authorities charged several cross-border private banking executives at UBS, Switzerland's largest bank, with helping American citizens hide an estimated $20 billion in offshore accounts. That, plus the recent threat of indictment for all of the bank's executives, saw UBS, the largest bank in Switzerland, recently admit to defrauding the IRS. The bank agreed to pay a $780 million fine and release the names of American accountholders.
Parliament expenses scandal Perhaps the lesson is this: With notions of transparency and accountability on the rise, companies hide behind secrecy laws at their peril. In the UK, members of Parliament (MPs) learned that the hard way, after details of their expenses revealed that many had abused the system to pay for things not related to their duties as an MP, such as moat cleaning and tennis court repairs. The expenses, which the Labor majority in Parliament battled for five years to keep private, came to light after courts upheld a journalist's right to obtain the information under Britain's relatively new Freedom of Information Act. The irony of MPs who abused and hid their expenses--during a recession, no less--while pushing a national ID card, building a network of millions of CCTV cameras, and regularly losing large amounts of sensitive or classified data has brought British voters to the boiling point. The government and even forms of representational government are facing their biggest shakeup in more than 100 years, with citizens demanding further transparency and accountability, including proportional representation.
Life after "keep everything" Interestingly, resistance is also growing to the UK government's "collect and keep everything" approach to data. One recent study branded the country as a "database state," and estimated that 25 percent of all government databases contained illegal information and should be scrapped. Likewise, courts recently ruled that the UK police practice of photographing everyone who attends a demonstration violated people's liberty, and instructed police to cease such practices and purge all such images from their databases. The UK offers an insightful case study: If a society has gone to the brink of the "more is better" approach to collecting and retaining private data, while demanding little accountability from those in power, what happens next? In fact, the outgoing UK Information Commissioner Richard Thomas recently predicted that collecting less personal information will become the new norm, to better balance security and liberty when government agencies collect and share data to do everything from spotting child abuse to discovering potential terrorists. "If you're looking for a needle in a haystack, it does not make sense to make the haystack bigger," he said. Collect data, but collect it smarter, and retain only what you need? And know that your job is on the line if improper data gets collected, abused, or lost, or if people's rights get trampled? Those are words to live by in what is arguably our new culture of accountability.
Wednesday, June 24, 2009
45,000 Cornell University Records Exposed
As stunning a piece of news as that is I am even more saddened by the following news from Cornell University. After years of hammering the point, laws passed, all of the white papers, and articles written about personal data safety and enterprize liability, why are we still seeing this kind of news? EVERY entity that maintains personal data of ANY kind needs to take care of business. There are no excuses and no arguments to the contrary. Business owners, what more do you need? Cornell just offered to pay at least $1,125,000 for credit monitoring alone at the current going rate. That is a small fraction of what this breach will eventually cost the school.
Cornell University announced that police are investigating the theft of a school laptop containing the personal information--including Social Security numbers--of approximately 45,000 students, alumni, faculty and staff. The Associated Press reports that the laptop was stolen from a Cornell technician and there are, so far, no known misuses of the data. The university sent a letter to those individuals whose records were on the computer, offering a free year of credit services. It has also set up an FAQ page on the Cornell Web site. Full Story
Thursday, June 18, 2009
Five Point HITECH Prep Plan
Wednesday, June 17, 2009
FTC Issues Consent Order Against Nutter & Co.
Now as we prepare to enter the enforcement phase of Red Flags Rule compliance it is important to note that enforcement of GLB and other privacy-based laws is ongoing. GLB has very similar recommendations as FACTA regarding compliance.
- The adoption of an identity theft response and prevention plan specific to the business
- The training of all employees on the specific plan
- The oversight of the policies of all contractor businesses and 3rd parties that might have access to NPI.
- A full documentation of the above
- Optionally offering a mitigating identity theft service to all employees for their individual protection.
All of the above combined with other procedures specific to each business comprise a proactive response to the threat of data breaches. That is precisely what the FTC is asking every business to do, establish a proactive program to mitigate the risk of breach and train all employees on their roles to protect the data. If you include in the training a general awareness of identity theft as it affects the individual you create the "culture of security" that is essential in todays' world.
The guidelines set out in GLB and again in FACTA affect almost virtually every business in America either directly as a requirement, or as a service provider for a business that is directly covered. The regulations under a new HIPAA (HITECH), initiative along with new states and federal breach reporting laws will soon make it mandatory for virtually all businesses to adopt such a plan.
While August 1st is set as the enforcement phase date for the Red Flags Rule now is the time for businesses, non-profits, municipalities, school districts, etc, to put such plans in place and get the staff up to speed. In the programs I help my clients initiate, the staff training meeting lasts from 45 minutes to an hour to complete. That along with a short meeting with management and the framework can be in place. It can be much simpler to accomplish than it seems at first.
Monday, June 15, 2009
Medical Problems Could Include Identity Theft
Everyone needs to pay attention to this. When you are shopping for an identity theft service ask yourself if the one you are considering will absolutely protect you or restore you from this nightmare.
Brandon Sharp, a 37-year-old manager at an oil and gas company in Houston, has never had any real health problems and, luckily, he has never stepped foot in an emergency room. So imagine his surprise a few years ago when he learned he owed thousands of dollars worth of emergency-service medical bills.
Mr. Sharp, as it turned out, was a victim of a fast-growing crime known as medical identity theft.
At the time, Mr. Sharp was about to get married and buy his first home. Before applying for a mortgage he requested a copy of his credit report. That is when he found he had several collection notices under his name for emergency room visits throughout the country.
“There was even a $19,000 bill for a Life Flight air ambulance service in some remote location I’d never heard of,” said Mr. Sharp, who made this unhappy discovery in 2003. “I had emergency room bills from places like Bowling Green, Kan., where I’ve never even visited. I’m still cleaning up the mess.”
The last time federal data on the crime was collected, for a 2007 report, more than 250,000 Americans a year were victims of medical identity theft. That number has almost certainly increased since then, because of the increased use of electronic medical records systems built without extensive safeguards, said Pam Dixon, executive director of the nonprofit World Privacy Forum and author of a report on medical identity theft.
And uncountable, Ms. Dixon said, are the people who do not yet know they are victims. They may not know that their medical information has been tampered with for months or even years until, as in Mr. Sharp’s case, it shows up in collections on a credit report.
Medical identity theft takes many guises. In Mr. Sharp’s case, someone got hold of his name and Social Security number and used them to receive emergency medical services, which many hospitals are obliged to provide whether or not a person has insurance. Mr. Sharp still does not know whether he fell victim to one calamitous perp who ended up in several emergency rooms or a ring of accident-prone conspirators.
In another variant of the crime, someone can use stolen insurance information, like the basic member ID and group policy number found on insurance cards, to impersonate you — and receive everything from a routine physical to major surgery under your coverage. This is surprisingly easy to do, because many doctors and hospitals do not ask for identification beyond insurance information.
Even more common, however, are cases where medical information is stolen by insiders at a medical office. Thieves download vital personal insurance data and related information from the operation’s computerized medical records, then sell it on the black market or use it themselves to make fraudulent billing claims.
In a widely reported case in 2006, a clerk at a Cleveland Clinic branch office in Weston, Fla., downloaded the records of more than 1,100 Medicare patients and gave the information to her cousin, who in turn, made $2.8 million in bogus claims.
When people are not aware their medical identities have been stolen, insurance companies may simply continue to pay the fraudulent claims without the victim’s knowledge. The person might learn of the fraud only when trying to make a legitimate claim, and the insurance company informs them they have reached their lifetime cap on benefits.
Or victims may eventually discover erroneous information in their medical files during a doctor or hospital visit. And that may pose a bigger danger than the financial risks. The medical records may now contain vital information like blood type, allergies, prescription drug use or a history of disease that is just plain wrong. In an emergency, doctors could treat you based on this erroneous information.
And there are none of the consumer protections for medical identity theft victims that exist for traditional identity theft. Under the Fair Credit Reporting Act you can get a free copy of your credit report each year, put a fraud alert on your account and get erroneous charges deleted from your record. If your credit card is stolen and the thief goes on a spending spree, you’re not liable for more than $50 worth of the charges. 1
With medical identity theft, though, the fraudulent charges can remain unpaid and unresolved for years, permanently damaging your credit rating. Under the federal law known as Hipaa — the Health Insurance Portability and Accountability Act — you are entitled to a copy of your medical records, but you may have to pay a hefty fee for them.
Worse, Hipaa privacy rules can actually work against you. Once your medical information is intermingled with someone else’s, you may have trouble accessing your files. Privacy laws dictate that the thief’s medical information now contained in your records must be kept confidential, too.
Even when you are able to correct a record, say in your doctor’s office, the erroneous information may have been passed on to dozens of other health care providers and insurers. Victims must track down and resolve these errors largely on a case-by-case basis, Ms. Dixon says.
Medical providers contend that they are taking precautions against identity theft. At Cleveland Clinic, for example, security personnel routinely audit electronic medical record systems and all records are password-protected. Many Blue Cross Blue Shield insurers use software to screen for spikes in claims from providers that look suspicious. They also work with providers on encrypting medical files and carrying out data access restrictions, said Calvin Sneed, senior antifraud consultant at the Blue Cross and Blue Shield Association.
And some medical centers and doctors’ offices now require patients to show photo ID and attach photos to patient charts.
But privacy advocates worry that these steps do not go nearly far enough, especially in light of President Obama’s plans to spend $20 billion to increase the use of electronic medical records nationwide as part of the stimulus package. “Without aggressive safeguards, we could be building an infrastructure for massive medical fraud,” said Ms. Dixon.
If you find yourself a victim of this kind of fraud you are not likely going to be as concerned about new privacy laws as you will about getting help for your situation. Nearly every states Attorney General has gone on record regarding identity theft. With millions of cases each year, and with the amount of investigative work each one requires, the states AG offices cannot give each case the attention it requires. We all need to find ways to safeguard ourselves. A good identity theft service is by far the most efficient way to do that. A restorative service will handle the brunt of the work of sorting out records and establishing a clear record of the crimes that were committed. And finally to go about the process of clearing false records entries.
1 Actually that is not completely true. If you report debit card fraud within 72 hours or within 30 days of a regular bank statement being mailed to you your liability is limited. Banks do not have to recover your losses after those times expire. ed.
Friday, June 12, 2009
Don't Worry, I Can Do It Myself!
A day later dad noticed a strange whirring sound coming from under the car.
Being too proud to take the car in to the garage dad decided to fix it himself. Perhaps a little too much egoism was at work there. Dad tore into the drive train, removing this, and then that until the ground under the car was littered with parts. Dad wasn’t a mechanic. In fact he had a reputation for being essentially inept when it came to the mechanical. He was a good architect. He could design complex systems for big buildings but could not change a light bulb without a struggle.
When he managed to put all the parts back on the car the problem was worse. In fact I think he created a couple of new problems trying to fix the first one. Not to be out foxed by a mere car dad kept at it until nothing worked. When my mother suggested that we call the garage to come and get the car dad got a little irritated. His bruised ego took over. “Don’t worry, I can do it myself.” Fatal words. That little incident caused us a very expensive repair, and because of my dads’ refusal to have a simple auto insurance policy we were left without a car for weeks until my mother decided it was time to get one of her own so we wouldn’t get stranded like that again. Come to think of it that car never did run right after that. Dads’ reasoning, like a lot of car owners at the time was that anything that an insurance company could do he could do himself, and better.
It was common for people to have that attitude in 1957. They suspected the insurance companies of scheming to take the public’ money and doing little for the car owner in return. That kind of thinking triggered a whole new area of lawsuits. With more cars on the road than ever before claims of personal liability flew into every courtroom in America. People were suing each other in a frenzy that threatened to grind the court system to a halt. Enter the age of auto insurance. The system that evolved is one of traffic laws that make liability clear in every claim. Whether or not we agree with all of it, the laws are clear.
Today we have liability insurance as matter of fact for every driver. When claims are filed the system is in place to effect repairs for damaged cars. The relative nightmare our family went through over a simple repair would have never happened had my father and the other driver taken out insurance policies. Auto insurance is a self-evident concept today.
In this era of identity theft I hear the same hubris. “Don’t worry it won’t happen to me, and if it does I can fix it myself.” Tell that to the millions of individuals who have suffered from the fallout of identity theft. You will find a different response from them. They know the advantage of a good identity theft service. My identity theft experience has lasted (so far) 8 years, and I still have issues. If I had an identity theft service before my incident I probably would have cleared it up in weeks or a couple of months at the worst and not had to expend over $26,000 in the process.
Identity theft services did not exist then but they do now. There is no excuse for anyone to not have an identity theft service. But which one to get? That decision was just made a lot easier. Federal courts recently ruled that identity theft services that set fraud alerts with the credit bureaus for a fee are in violation of the FCRA. That is one thing we can do for ourselves. This eliminates most of the companies right there. Find a service that will repair your identity after an incident, using real agents licensed to do that kind of work. Don’t do like my dad and attempt to fix it yourself. With more cases of identity theft every day the system is overwhelmed. You cannot do it without a protracted and painful bureaucratic process and a great expense in both time and money. And it may likely never be done. It is restoration you need to have. Anyone can tell you that you are a victim. You want and need repair after the fact.
Wednesday, June 10, 2009
A Failure to Adequately Protect......
Class actions are beginning to crank up in the area of data breach. Not being able to show penury damages from specific cases of identity theft, the victims of data breaches are increasingly turning to class actions based at least in part on the failure of a data aggregator to protect the information they keep.
A class-action suit has been filed against health insurer Aetna for alleged data protection and privacy failures, reports Hartford Business. The company announced last month that hackers had gained access to its job application site, potentially exposing the Social Security numbers of 65,000 current and former employees. Plaintiffs are seeking credit monitoring, punitive damages, costs and other relief, according to the report. The complaint filed last week in a Pennsylvania District Court states: "Aetna unlawfully failed to maintain reasonable systems and procedures to protect [plaintiffs'] information."Full Story
What are the reasonable actions a company could take that might prevent these kinds of court actions? That varies from case to case and company to company, but will likely include the preventive steps required under FACTA, GLB, and states laws that specifically address identity theft. Whether it is 5 records that have been compromized or the 65,000 mentioned above, the liability is the same. A "Failure to adequately protect records" lawsuit should not be considered the cost of doing business like the petty theft of office supplies. The cost to the business cannot be calculated in terms of simple legal fees.
A business that takes the preventive steps on its' own before any data loss incidents can greatly reduce the liklihood of a class action from being initiated.

