Tuesday, August 4, 2009

Government Employees' Names, SSNs Exposed

HELLO!?

U.S. Commerce Department employees have been notified that their sensitive personal information was exposed last month, reports the Washington Post. The names and Social Security numbers of 27,000 were on an Excel spreadsheet that a National Finance Center employee sent to a co-worker via unencrypted e-mail, the report states. The department is making arrangements to track for identity theft resulting from the breach and is urging employees to monitor their credit reports.

I repeat, your information is out there and used, or misused each and every day of the week.
No one can prevent accidents or mistakes from happening, just as you cannot prevent intentional acts of data theft. If you have a comprehensive ID theft early warning and restoration service working for you, you can be assured that no matter how your personal information gets in the hands of the wrong people that they cannot ruin your life. The damage is very limited and correctable.

Thursday, July 30, 2009

Network Solutions Begins a Damage Control Effort

If anyone still has reservations as to whether or not to have some sort of identity theft mitigation service one only needs to consider the following.

Following disclosure of a data breach that may have compromised the credit card data of more than 573,000 patrons of small commercial Web sites, Internet domain administer and host Network Solutions has initiated a crisis response effort. Reaching out to its clients affected by the breach, Network Solutions has offered assistance in helping sites notify those customers whose credit card data may have been compromised, including offering credit monitoring services. Network Solutions spokesperson Susan Wade told DMNews, "Unfortunately, something like this could happen to any online business, so we're just letting our customers know that we're there for them, we will help them as much as we can, and we take this issue very seriously."

It is important to recognize that identity theft can and often does raise its ugly head in many different ways. Our information is out in the world and used by thousands of businesses and government agencies constantly. It doesn't take a statistician to see that the odds are that your information will be compromised, and likely many times. Why then would anyone want to gamble that they won't become the victim of the most difficult crime in history. Difficult you say? When identity theft strikes records are corrupted with false information. There is no one source to use to correct them and once corrupted the onus is on the victim to prove that they have been victimized. When the data says one thing how are you going to prove otherwise? Most victims spend years trying to correct their health or SSN files or DMV or insurance records, or any number of files that are used to shape who we are perceived to be in the official and public eye.

Having a service which will not only shortcut the crime but most importantly go to work for you to correct those records no matter how or when they have been corrupted by misuse of your personal data. It is also in the best interest of each and every employer to make such a service available to all of their employees. An employee distracted by this kind of problem cannot concentrate on work or maintain a healthy attitude for as long as they are dealing with an identity theft episode.

Wednesday, July 29, 2009

Red Flags Rule Enforcement Deadline Extended

The Federal Trade Commission has again extended the enforcement deadline for the Red Flags Rule, according to an agency press release. Creditors and financial institutions now have until November 1, 2009 to come into compliance with the rule, which was mandated by the Fair and Accurate Credit Transactions Act of 2003. Meanwhile, the commission will redouble efforts to educate businesses affected by the rule on what they must do to comply. The Red Flags Rule requires entities to implement programs for identifying, detecting and responding to harbingers of identity theft, or "red flags."
Go to www.ftc.gov/redflagsrule for more information regarding your business.

Friday, July 24, 2009

Will the Third Try be a Charm for Federal Breach Notification Law?

The following article was in today's privacy bulletin. Since the first state breach notification law went into effect in 2003 in California, 43 other states have enacted their own versions creating a worthwhile but patched together set of regulations that are at best vague, and contain huge lapses so that a company experiencing a breach can likely get away without any sort of notification to potential victims. Hopefully this legislation will contain enough bite to be effective. Only when we see transcripts of the bill will we know if we are headed in the right direction or for another legislative compromise. Thresholds for notification need to include not only electronic breaches and large scale hacks of computer servers, but also theft and misuse of paper records, and need to provide for smaller incidents. Only by creating effective notification laws can businesses be held accountable to the public who expect their information to be reasonably safe.

Vermont Senator Patrick Leahy (D) has reintroduced the Personal Data Privacy and Security Act, the third attempt by Congress to pass a federal data breach law that would pre-empt the 44 individual state data breach laws and create a single response and notification standard in the U.S. InternetNews reports that in a statement, Leahy said the bill addresses serious consumer privacy and data security issues and vowed that, "Passing this comprehensive data privacy legislation is one of my highest legislative priorities as chairman of the Judiciary Committee."Full Story

Monday, July 13, 2009

Who Needs High Tech Information Security Measures?

Whenever I see articles about the latest high tech "solution" for data loss I can't help but to think about the vast number of data breaches that result from situations such as the one below.
Just as there is no one form of data theft there is no one type of solution.


Medical records, including names, credit card numbers, Social Security numbers and cancelled checks were found in a dumpster behind a Salt Lake City shoe distribution center last week, reports KUTV News. At least some of about 20 boxes that Salt Lake City police confiscated appear to have come from a now-closed chiropractic office. KUTV reports that surveillance footage showing two people unloading materials into the dumpster exists. Disposing of medical records in this way is a violation of state law, according to the Utah Attorney General's office, and could lead to a $2,500 fine per patient record.
Full Story

Train your staff, train your staff, train your staff. This kind of an incident happens too often due to a lack of understanding of the law and simple common sense in protecting records from falling into the wrong hands.

Most ID theft that results from breaches of information at companies occurs when an employee walks out with the data with the intention of selling it, not to open credit card accounts. While the thief may be caught the data is long gone with other parties. Once the information is sold it can proliferate in a matter of days across the world.

A lack of understanding of the value of employee personal information as well as customer information has led to more identity theft incidents than any other cause.

Friday, July 10, 2009

What is a privacy policy, and what is an identity theft policy? What's the difference?

Good morning all. I have been noticeably absent from my column duties while I took care of some other projects, and fitting in a short vacation.

Very often when I speak with business owners especially in the small to mid-sized organizations I find that a lot of them either confuse a company privacy policy with identity theft, or believe that an identity theft policy is an outgrowth of a privacy policy or statement.
In very general terms the two are not the same and in fact address two different issues. A privacy policy deals with either company intellectual property or customer information. Any business that collects customer information in the course of doing business must have a privacy policy that informs the customer as to how their information is used and protected, and encryption procedures for transactions. That falls largely under the direction of the Payment Card Initiative, PCI DSS rules to protect the public from fraud resulting from purchase transactions. Also, customers are protected by other state and federal laws suchas the FTC Act and FCRA that prohibit companies from distributing personal information without regard to personal privacy without first notifying the client of their intent. That issue is being hotly debated again due to the proliferation of social networking websites. Another area of privacy policy is the protection of company secrets, proprietary information regarding how a business operates and its plans and strategies. While the distribution and misuse of personally identifiable information (PII) is highly regulated by consumer law, protecting company secrets are internal policies. Businesses engaged in technological and scientific research and development often have non-disclosure agreements with employees to protect that kind of information. Employees who violate those agreements are subject to termination, and possible prosecution as a breach of contract.

Identity Theft policy addresses the area of PII data loss, a definition of what is considered by the company to be PII, the various forms the company uses to store and use PII, and finally the procedure a company has put into place to respond to breaches and to protect the individuals who might be affected and are at increased risk of identity theft resulting from a company breach. This policy must address not only the data it keeps on its clients but also of the employees personnel records, and also must address the identity theft policies of any contractor or service provider who might have access to that information. Vendors can include not only outsourced HR, payroll, insurance and Benefits brokers, but also cleaning services, construction contractors, and even parking services, any business that has the potential of obtaining PII.

It isn’t my intention to delineate what the law is or provide legal advice in these areas but instead to provoke thought on the part of businesses. With new legislation such as GLB, FACTA, and now the Red Flags Rule under FACTA, the banking regulators and the FTC have made it clear that in order to stem the tide of identity theft and the company data breaches that result in the majority of identity theft, business needs to take certain steps proactively to prevent breaches and to respond quickly and effectively when they do occur.
Every company is different and therefore needs to take the steps that are most effective for that organization. It all begins with an honest risk assessment on the part of each company to find the weak links in information security, and to train the staff on their responsibilities. Establishing a clear identity theft policy is the roadmap every responsible business uses to lay out everyone’s duties, and how the business will handle data breaches. The FTC auditors investigating companies who have experienced these breaches are most interested in seeing what a business did to protect the information before the breach. A proactive identity theft policy is good policy, and good business.

Friday, June 26, 2009

35 days until the enforcement phase of the Red Flags Rule, Are you ready?

The deadline for non-banking entities to comply with the Fair Credit Reporting Act Red Flags Rule is August 1. Joel Winston and his colleagues at the Federal Trade Commission have spent the last several months helping businesses understand the requirements. Winston is associate director of the Division of Privacy and Identity Protection at the commission's Bureau of Consumer Protection. In this interview with GovInfoSecurity.com, he discusses the Red Flags Rule, the greatest information security risks for consumers, privacy implications of new technologies and his team's work to help prevent identity theft, among other topics.
Full Story