Members of the House Committee on Energy and Commerce are concerned that the data breach notification provision included in the HITECH Act may have been undermined by a Health and Human Services rule, known as the "harm threshold," which gives breached companies leeway in deciding whether notice may be required. In a letter to HHS Secretary Kathleen Sebelius, committee chair Rep. Henry Waxman (D-CA) and other members of the committee urged the secretary to revise or repeal the provision, published in late September. Privacy watchdogs claim the HHS rule was drafted under pressure from the healthcare industry to eliminate possible financial repercussions stemming from a health information data breach.Full Story
I was heartened to see this news item. As I have said before harm thresholds give too much discretionary power to the breached entity in determining who and if to notify of a breach of NPI. The point of notification laws is twofold. To put teeth in the data protection legislation so that private and public enterprises will take heed, and also to give potential victims the advantage of an early warning when a breach does occur giving them the opportunity to respond and protect themselves.
While there needs to be a modicum of discretion on the part of investigators of data breaches to not reveal information that might compromise the discovery of evidence, it is the responsibility of the company or agency to make certain the victims are aware of the breach(es).
No business can really afford the fallout from a data breach, both in public confidence and the direct financial losses and fines. A proactive approach to information protection is essential including the identity theft awareness training of all staff regardless of job title.
Wednesday, October 7, 2009
Friday, October 2, 2009
76 million Veteran records in Question
The inspector general of the National Archives and Records Administration (NARA) is investigating a potential data breach involving the sensitive data of 76 million military veterans, reports Wired. The records were contained on a failed hard drive that was returned to a contractor for repair without first being sanitized, the report states. The contractor passed along the drive, which was beyond repair, to a recycling firm. The NARA IT manager who reported the incident to the inspector general told Wired: "This is the single largest release of personally identifiable information by the government ever." NARA says it does not believe there was a breach of PII. Full Story
Ladies and gentlemen, let me make this as clear as a bell for you. There is only ONE way to insure that a hard drive is safe to recycle. Do not listen to any other advice!
There is only ONE certain way to render a drive of any kind useless to data thieves. DRIVE A BIG NAIL THROUGH THE DISK. If it is a flash drive smash it with a hammer, smash it good. Never recycle a laptop, photo copy machine, server, desk top computer, fax machine, unless you, the user, render the drives useless. Never leave it to anyone else to do.
Ladies and gentlemen, let me make this as clear as a bell for you. There is only ONE way to insure that a hard drive is safe to recycle. Do not listen to any other advice!
There is only ONE certain way to render a drive of any kind useless to data thieves. DRIVE A BIG NAIL THROUGH THE DISK. If it is a flash drive smash it with a hammer, smash it good. Never recycle a laptop, photo copy machine, server, desk top computer, fax machine, unless you, the user, render the drives useless. Never leave it to anyone else to do.
Tuesday, September 29, 2009
They Keep Sending the Faxes
For all of you who still are under the illusion that data breaches can be prevented I submit the following...
Doctors in three Tennessee cities have been sending sensitive patient information to the fax machine of an Indiana businessman for three years, reports the Tennessean.com. "This is a total breach of privacy," said the recipient of the faxes, Bill Keith. Despite repeated attempts to correct the problem, including calls, faxes and e-mails to state officials and the doctors' offices, Keith says his office continues to receive about five faxes each week that contain patients' data, including medical histories and Social Security numbers. A Department of Human Services spokesperson described the situation as "troubling." Full Story
Doctors in three Tennessee cities have been sending sensitive patient information to the fax machine of an Indiana businessman for three years, reports the Tennessean.com. "This is a total breach of privacy," said the recipient of the faxes, Bill Keith. Despite repeated attempts to correct the problem, including calls, faxes and e-mails to state officials and the doctors' offices, Keith says his office continues to receive about five faxes each week that contain patients' data, including medical histories and Social Security numbers. A Department of Human Services spokesperson described the situation as "troubling." Full Story
Monday, September 28, 2009
Only 163,000 Breached Records Contained Social Security Numbers!
The University of North Carolina is notifying 163,000 women that their personally identifiable information was exposed in a security breach, reports Computerworld. A hacker broke into a system containing records on women who participated in a federally-funded research project. The information of more than 236,000 women who have participated in the UNC School of Medicine mammography research study was exposed, but only 163,000 records contained Social Security numbers. The breach was discovered in July. The system was taken offline. A university spokesperson said that UNC is implementing precautions to prevent future breaches. Full Story
Now what do you think about breach notification laws? UNC believes these intrusions might go back several years and the women affected are just being notified now. Does this provide the best opportunity for the potential victims to prepare for what might result in the worst legal nightmare they will ever experience? How many of them are already having difficulties as the result of these breaches?
This also illustrates once again that our personal information is out there in hundreds if not thousands of lists and databases of all types. It really doesn't matter much to information thieves where the info is as long as they can get it. If there is a list somewhere that has value to a data thief then it is a target.
I will always maintain that the best defense against these and other types of data misuse is to have a service that will work for you in the event of a data theft episode. Don't wait until after the fact, have something in place first. Most services will not provide the same level of services after your identity is misused as they will as a preventive tool unless you pay a healthy fee. It is more cost effective to have a service in place first. When you consider that the average identity theft episode costs over $90K an identity theft service provides an amazing ROI.
Now what do you think about breach notification laws? UNC believes these intrusions might go back several years and the women affected are just being notified now. Does this provide the best opportunity for the potential victims to prepare for what might result in the worst legal nightmare they will ever experience? How many of them are already having difficulties as the result of these breaches?
This also illustrates once again that our personal information is out there in hundreds if not thousands of lists and databases of all types. It really doesn't matter much to information thieves where the info is as long as they can get it. If there is a list somewhere that has value to a data thief then it is a target.
I will always maintain that the best defense against these and other types of data misuse is to have a service that will work for you in the event of a data theft episode. Don't wait until after the fact, have something in place first. Most services will not provide the same level of services after your identity is misused as they will as a preventive tool unless you pay a healthy fee. It is more cost effective to have a service in place first. When you consider that the average identity theft episode costs over $90K an identity theft service provides an amazing ROI.
Thursday, September 24, 2009
Protecting Employee Information in the Hands of Others
In Business Management Daily, Susan Lessack of Pepper Hamilton LLP offers guidance on protecting employee data handled by third-party vendors. Lessack says: "A good contract with your vendor is your best protection against liability," and cites specific terms to include in contracts, such as those that limit the number of people who can access the data. Lessack says that, although the vendor may be reluctant to enter into such a term, the contract "should stipulate that the vendor is legally responsible for any data breach that occurs during its engagement, and that it will indemnify you and your employees for any actions resulting from a breach." Full Story
At Pre-Paid Legal those of us who are qualified to work with companies in establishing a policy framework for information protection and risk management have taken this provision of the Red Flags Rule to heart as it deals with 3rd party contractors. We ask every client company to inform all of their contractors of the efforts they have made to protect PII and to request that they do the same or similar. It is just smart business to complete the loop of data security. Even an office cleaning service should adhere to the basic rules of security. I have visited numerous businesses where the cleaning service has more or less unlimited access to hard copy left on desks, in wastebaskets, and left on file cabinets, to name a few. When we include all contractors in the security formula a much better understanding of personal information security is created which gives rise to the FTC term "Culture of Security" that we are hopefully all striving for.
The recommendations of the FTC are sound. All RFIs and contracts should contain such language. In the not too distant future all federal government contracts will contain this kind of clause I believe. As regards liability FACTA clearly gives liability to all parties who share non-public information. If a company hires an HR service for example and that contractor suffers a breach of that information then the liability is shared by both companies. Even if identity theft does not occur both firms can be sued for a "Failure to adequately protect the information." There is no requirement under such circumstances to prove penury damage.
At Pre-Paid Legal those of us who are qualified to work with companies in establishing a policy framework for information protection and risk management have taken this provision of the Red Flags Rule to heart as it deals with 3rd party contractors. We ask every client company to inform all of their contractors of the efforts they have made to protect PII and to request that they do the same or similar. It is just smart business to complete the loop of data security. Even an office cleaning service should adhere to the basic rules of security. I have visited numerous businesses where the cleaning service has more or less unlimited access to hard copy left on desks, in wastebaskets, and left on file cabinets, to name a few. When we include all contractors in the security formula a much better understanding of personal information security is created which gives rise to the FTC term "Culture of Security" that we are hopefully all striving for.
The recommendations of the FTC are sound. All RFIs and contracts should contain such language. In the not too distant future all federal government contracts will contain this kind of clause I believe. As regards liability FACTA clearly gives liability to all parties who share non-public information. If a company hires an HR service for example and that contractor suffers a breach of that information then the liability is shared by both companies. Even if identity theft does not occur both firms can be sued for a "Failure to adequately protect the information." There is no requirement under such circumstances to prove penury damage.
Monday, September 21, 2009
New ID Theft Bill Introduced in the Senate
A new bill was introduced in the US Senate that would establish a new FTC office. This notice is very timely for me since I have been talking about such legislation.
New York State Senator Charles Schumer has introduced a bill aimed at helping prevent and diagnose identity theft, reports the Evening Observer. The Personal Data Privacy and Security Act would increase penalties for those who commit the crime and would make it illegal for organizations to conceal a security breach involving personal data. The law would also require entities that hold personal data to establish data protection policies. "Identity theft is a scourge on hard-working Americans, and it is a problem that is getting worse," said Schumer. The act would also establish an Office of Federal Identity Protection within the Federal Trade Commission. Full Story
For about 6 years the Federal Trade Commission has offered guidelines for businesses and other enterprises that have files and records containing personal data either of employees past and present, or of customers, or client companies such as HR and payroll businesses.
These guidelines were offered as a way for industry to police its' own operations and to train personnel on protecting the non-public info they handle.
These recommendations have been largely ignored by all but the companies regulated by the banking authorities such as the FDIC. During that time identity theft has become epidemic and is currently costing American business and individuals in excess of $45 billion annually. This figure does not reflect the identity theft losses due to personal theft and fraud, only those incidents that are the result of database losses.
Now in 2009 we are faced with legislation that will require all businesses, schools, and municipalities to take specific measures to thwart these crimes. This will likely be more costly than the voluntary measures previously on the table.
Moreover, the reporting aspect of this bill requiring business to reveal breaches to potential victims will have a profound effect on the public confidence of the breached businesses. In economic times such as we are in that is something businesses can hardly afford. Investigations into breaches will also be hampered by this requirement, and I'm certain that we will see push back from business on that point.
It is sad to see that businesses would rather do nothing than to take basic measures to safeguard information. My mantra holds true that; "When you protect the information you hold on others you are protecting them. When someone else does it they are protecting you."
Our data is only as safe as the weakest link. And with literally thousands of databases containing our personal data there are thousands of weak links to contend with.
New York State Senator Charles Schumer has introduced a bill aimed at helping prevent and diagnose identity theft, reports the Evening Observer. The Personal Data Privacy and Security Act would increase penalties for those who commit the crime and would make it illegal for organizations to conceal a security breach involving personal data. The law would also require entities that hold personal data to establish data protection policies. "Identity theft is a scourge on hard-working Americans, and it is a problem that is getting worse," said Schumer. The act would also establish an Office of Federal Identity Protection within the Federal Trade Commission. Full Story
For about 6 years the Federal Trade Commission has offered guidelines for businesses and other enterprises that have files and records containing personal data either of employees past and present, or of customers, or client companies such as HR and payroll businesses.
These guidelines were offered as a way for industry to police its' own operations and to train personnel on protecting the non-public info they handle.
These recommendations have been largely ignored by all but the companies regulated by the banking authorities such as the FDIC. During that time identity theft has become epidemic and is currently costing American business and individuals in excess of $45 billion annually. This figure does not reflect the identity theft losses due to personal theft and fraud, only those incidents that are the result of database losses.
Now in 2009 we are faced with legislation that will require all businesses, schools, and municipalities to take specific measures to thwart these crimes. This will likely be more costly than the voluntary measures previously on the table.
Moreover, the reporting aspect of this bill requiring business to reveal breaches to potential victims will have a profound effect on the public confidence of the breached businesses. In economic times such as we are in that is something businesses can hardly afford. Investigations into breaches will also be hampered by this requirement, and I'm certain that we will see push back from business on that point.
It is sad to see that businesses would rather do nothing than to take basic measures to safeguard information. My mantra holds true that; "When you protect the information you hold on others you are protecting them. When someone else does it they are protecting you."
Our data is only as safe as the weakest link. And with literally thousands of databases containing our personal data there are thousands of weak links to contend with.
Thursday, September 17, 2009
Breach Notification Rule Effective Next Week
Breach Notification Rule Effective Next WeekThe new HIPAA breach notification rule takes effect next week, reports HR.blr.com. The rule requires entities covered by the Health Insurance Portability and Accountability Act to notify individuals in the event their personal health information is breached, the report states. Starting on September 23, any healthcare provider, health plan or other HIPAA-covered entity that experiences a breach must notify those affected "as soon as reasonably possible," unless the organization protects the information using encryption or destruction, in which case they need not notify. If the breach involves more than 500 individuals, the organization must also notify the Department of Health and Human Services and the media. Full Story
This constitutes a real milestone in stemming identity theft on a federal level. As this bill passes we will have the first leg of a national reporting policy for all personal data loss. No legislation is perfect. There is still a threshold test for notifying potential victims, and we will most likely always have a conflict between notifying victims and investigating breaches. This is however a good beginning. The remaining conflict of course is the timeliness of the notification. Once notified of a breach individuals should be empowered to provide protection for themselves before any damage is done. The best scenario is to have this in place prior to a breach so that the potential victim will have the early warning and restoration services of professional identity theft specialists.
This constitutes a real milestone in stemming identity theft on a federal level. As this bill passes we will have the first leg of a national reporting policy for all personal data loss. No legislation is perfect. There is still a threshold test for notifying potential victims, and we will most likely always have a conflict between notifying victims and investigating breaches. This is however a good beginning. The remaining conflict of course is the timeliness of the notification. Once notified of a breach individuals should be empowered to provide protection for themselves before any damage is done. The best scenario is to have this in place prior to a breach so that the potential victim will have the early warning and restoration services of professional identity theft specialists.
Subscribe to:
Posts (Atom)

