Tuesday, September 29, 2009

They Keep Sending the Faxes

For all of you who still are under the illusion that data breaches can be prevented I submit the following...

Doctors in three Tennessee cities have been sending sensitive patient information to the fax machine of an Indiana businessman for three years, reports the Tennessean.com. "This is a total breach of privacy," said the recipient of the faxes, Bill Keith. Despite repeated attempts to correct the problem, including calls, faxes and e-mails to state officials and the doctors' offices, Keith says his office continues to receive about five faxes each week that contain patients' data, including medical histories and Social Security numbers. A Department of Human Services spokesperson described the situation as "troubling." Full Story

Monday, September 28, 2009

Only 163,000 Breached Records Contained Social Security Numbers!

The University of North Carolina is notifying 163,000 women that their personally identifiable information was exposed in a security breach, reports Computerworld. A hacker broke into a system containing records on women who participated in a federally-funded research project. The information of more than 236,000 women who have participated in the UNC School of Medicine mammography research study was exposed, but only 163,000 records contained Social Security numbers. The breach was discovered in July. The system was taken offline. A university spokesperson said that UNC is implementing precautions to prevent future breaches. Full Story

Now what do you think about breach notification laws? UNC believes these intrusions might go back several years and the women affected are just being notified now. Does this provide the best opportunity for the potential victims to prepare for what might result in the worst legal nightmare they will ever experience? How many of them are already having difficulties as the result of these breaches?

This also illustrates once again that our personal information is out there in hundreds if not thousands of lists and databases of all types. It really doesn't matter much to information thieves where the info is as long as they can get it. If there is a list somewhere that has value to a data thief then it is a target.

I will always maintain that the best defense against these and other types of data misuse is to have a service that will work for you in the event of a data theft episode. Don't wait until after the fact, have something in place first. Most services will not provide the same level of services after your identity is misused as they will as a preventive tool unless you pay a healthy fee. It is more cost effective to have a service in place first. When you consider that the average identity theft episode costs over $90K an identity theft service provides an amazing ROI.

Thursday, September 24, 2009

Protecting Employee Information in the Hands of Others

In Business Management Daily, Susan Lessack of Pepper Hamilton LLP offers guidance on protecting employee data handled by third-party vendors. Lessack says: "A good contract with your vendor is your best protection against liability," and cites specific terms to include in contracts, such as those that limit the number of people who can access the data. Lessack says that, although the vendor may be reluctant to enter into such a term, the contract "should stipulate that the vendor is legally responsible for any data breach that occurs during its engagement, and that it will indemnify you and your employees for any actions resulting from a breach." Full Story

At Pre-Paid Legal those of us who are qualified to work with companies in establishing a policy framework for information protection and risk management have taken this provision of the Red Flags Rule to heart as it deals with 3rd party contractors. We ask every client company to inform all of their contractors of the efforts they have made to protect PII and to request that they do the same or similar. It is just smart business to complete the loop of data security. Even an office cleaning service should adhere to the basic rules of security. I have visited numerous businesses where the cleaning service has more or less unlimited access to hard copy left on desks, in wastebaskets, and left on file cabinets, to name a few. When we include all contractors in the security formula a much better understanding of personal information security is created which gives rise to the FTC term "Culture of Security" that we are hopefully all striving for.

The recommendations of the FTC are sound. All RFIs and contracts should contain such language. In the not too distant future all federal government contracts will contain this kind of clause I believe. As regards liability FACTA clearly gives liability to all parties who share non-public information. If a company hires an HR service for example and that contractor suffers a breach of that information then the liability is shared by both companies. Even if identity theft does not occur both firms can be sued for a "Failure to adequately protect the information." There is no requirement under such circumstances to prove penury damage.

Monday, September 21, 2009

New ID Theft Bill Introduced in the Senate

A new bill was introduced in the US Senate that would establish a new FTC office. This notice is very timely for me since I have been talking about such legislation.
New York State Senator Charles Schumer has introduced a bill aimed at helping prevent and diagnose identity theft, reports the Evening Observer. The Personal Data Privacy and Security Act would increase penalties for those who commit the crime and would make it illegal for organizations to conceal a security breach involving personal data. The law would also require entities that hold personal data to establish data protection policies. "Identity theft is a scourge on hard-working Americans, and it is a problem that is getting worse," said Schumer. The act would also establish an Office of Federal Identity Protection within the Federal Trade Commission. Full Story

For about 6 years the Federal Trade Commission has offered guidelines for businesses and other enterprises that have files and records containing personal data either of employees past and present, or of customers, or client companies such as HR and payroll businesses.
These guidelines were offered as a way for industry to police its' own operations and to train personnel on protecting the non-public info they handle.

These recommendations have been largely ignored by all but the companies regulated by the banking authorities such as the FDIC. During that time identity theft has become epidemic and is currently costing American business and individuals in excess of $45 billion annually. This figure does not reflect the identity theft losses due to personal theft and fraud, only those incidents that are the result of database losses.

Now in 2009 we are faced with legislation that will require all businesses, schools, and municipalities to take specific measures to thwart these crimes. This will likely be more costly than the voluntary measures previously on the table.

Moreover, the reporting aspect of this bill requiring business to reveal breaches to potential victims will have a profound effect on the public confidence of the breached businesses. In economic times such as we are in that is something businesses can hardly afford. Investigations into breaches will also be hampered by this requirement, and I'm certain that we will see push back from business on that point.

It is sad to see that businesses would rather do nothing than to take basic measures to safeguard information. My mantra holds true that; "When you protect the information you hold on others you are protecting them. When someone else does it they are protecting you."

Our data is only as safe as the weakest link. And with literally thousands of databases containing our personal data there are thousands of weak links to contend with.

Thursday, September 17, 2009

Breach Notification Rule Effective Next Week

Breach Notification Rule Effective Next WeekThe new HIPAA breach notification rule takes effect next week, reports HR.blr.com. The rule requires entities covered by the Health Insurance Portability and Accountability Act to notify individuals in the event their personal health information is breached, the report states. Starting on September 23, any healthcare provider, health plan or other HIPAA-covered entity that experiences a breach must notify those affected "as soon as reasonably possible," unless the organization protects the information using encryption or destruction, in which case they need not notify. If the breach involves more than 500 individuals, the organization must also notify the Department of Health and Human Services and the media. Full Story

This constitutes a real milestone in stemming identity theft on a federal level. As this bill passes we will have the first leg of a national reporting policy for all personal data loss. No legislation is perfect. There is still a threshold test for notifying potential victims, and we will most likely always have a conflict between notifying victims and investigating breaches. This is however a good beginning. The remaining conflict of course is the timeliness of the notification. Once notified of a breach individuals should be empowered to provide protection for themselves before any damage is done. The best scenario is to have this in place prior to a breach so that the potential victim will have the early warning and restoration services of professional identity theft specialists.

Wednesday, September 9, 2009

Red Flags Rule Extension

I will be away for a bit on a business trip. Until I return please see the following.
This article is copied from todays newsletter from the law firm of Wiley Rein

Red Flags Rule Deadline Again ExtendedBy Amy E. Worlton, William B. Baker and Hugh Latimer September 2009 Privacy in Focus
The Federal Trade Commission (FTC) will "delay enforcement" until November 1, 2009, of the Red Flags Rule, previously scheduled to begin in August 2009. The delay reflects FTC recognition that some businesses may need more time to develop and implement written identity theft prevention programs.The Red Flags Rule may apply to companies that bill consumers in arrears (i.e., payment is not due at the time of service but at a later point). Even telecom companies, which are generally exempt from FTC jurisdiction, are likely subject to the Red Flags Rule, because they bill in arrears. Such companies are "creditors" subject to the consumer protections of the Fair and Accurate Credit Transactions Act and the Fair Credit Reporting Act. The Red Flags Rule, adopted under these statutes, requires a "creditor" with "covered accounts" to establish a written program for the identification, detection and response to "Red Flags"-patterns or specific activities that could indicate identity theft.The FTC's Red Flags Rule requires no particular practice or procedure. Rather, businesses must tailor their identity-theft-prevention programs to their particular risks. For example, "Red Flags" that probably require a response include alerts from consumer reporting agencies, law enforcement agencies or consumers themselves. Accounts should be monitored for unusual activity to the extent they are susceptible to fraudulent use. Businesses should verify new customer information, authenticate existing account holders and verify the validity of address change requests. (For more on the Red Flags Rule, see May 2009 Privacy In Focus.Companies should ensure that their identity-theft-prevention programs are up and running by November 1, as the FTC is unlikely to extend the enforcement deadline again.

It is vital for all of us to stay focused on a good privacy policy that is aimed at eliminating breaches of personal information. A proactive approach is the most effective way to achieve that goal.

Friday, September 4, 2009

Medical Identity Theft is on the Rise

According to the Identity Theft Resource Center (ITRC), medical identity theft is on the rise as health insurance fraud becomes more common. NetworkWorld reports that, according to an ITRC study of 2008 identity theft victims, 67 percent had been charged for medical procedures they hadn't received and 11 percent were denied health or life insurance for unexplained reasons--possibly because of incorrect information resulting from fraudulent insurance claims. The NetworkWorld article includes a summary of the worst medical data breach incidents from 2009, including: Virginia Department of Health Professions hack (8 million+); Peninsula Orthopaedic Associates robbery (100K) and Moore's Cancer Center hack (30K).Full Story

Most companies hold personal medical information on their staff for purposes of health insurance, incident reports, cafeteria plans, and so forth. It was only about two years ago that there was a general concensus among professionals that medical identity theft was largely overstated despite warnings that it was largely underreported. Medical identity theft is by far the most difficult type of the crime due to far reaching implications. When medical information is used a lot of databases are automatically updated from insurance claim databases such as MIB, to hospital and doctor records. Blood types and allergy histories can be incorrect in records. When medical procedures are performed this can also effect credit worthiness if bills go unpaid, suits are filed by creditors, criminal files can be opened, in short the misuse of medical information can result in the corruption of dozens of types of records.

What we see in medical database breaches such as the ones above is only part of the puzzle.
Everyone needs to consider the restoration of medical records and legal representation when evaluating identity theft services.