Thursday, June 18, 2009
Five Point HITECH Prep Plan
Wednesday, June 17, 2009
FTC Issues Consent Order Against Nutter & Co.
Now as we prepare to enter the enforcement phase of Red Flags Rule compliance it is important to note that enforcement of GLB and other privacy-based laws is ongoing. GLB has very similar recommendations as FACTA regarding compliance.
- The adoption of an identity theft response and prevention plan specific to the business
- The training of all employees on the specific plan
- The oversight of the policies of all contractor businesses and 3rd parties that might have access to NPI.
- A full documentation of the above
- Optionally offering a mitigating identity theft service to all employees for their individual protection.
All of the above combined with other procedures specific to each business comprise a proactive response to the threat of data breaches. That is precisely what the FTC is asking every business to do, establish a proactive program to mitigate the risk of breach and train all employees on their roles to protect the data. If you include in the training a general awareness of identity theft as it affects the individual you create the "culture of security" that is essential in todays' world.
The guidelines set out in GLB and again in FACTA affect almost virtually every business in America either directly as a requirement, or as a service provider for a business that is directly covered. The regulations under a new HIPAA (HITECH), initiative along with new states and federal breach reporting laws will soon make it mandatory for virtually all businesses to adopt such a plan.
While August 1st is set as the enforcement phase date for the Red Flags Rule now is the time for businesses, non-profits, municipalities, school districts, etc, to put such plans in place and get the staff up to speed. In the programs I help my clients initiate, the staff training meeting lasts from 45 minutes to an hour to complete. That along with a short meeting with management and the framework can be in place. It can be much simpler to accomplish than it seems at first.
Monday, June 15, 2009
Medical Problems Could Include Identity Theft
Everyone needs to pay attention to this. When you are shopping for an identity theft service ask yourself if the one you are considering will absolutely protect you or restore you from this nightmare.
Brandon Sharp, a 37-year-old manager at an oil and gas company in Houston, has never had any real health problems and, luckily, he has never stepped foot in an emergency room. So imagine his surprise a few years ago when he learned he owed thousands of dollars worth of emergency-service medical bills.
Mr. Sharp, as it turned out, was a victim of a fast-growing crime known as medical identity theft.
At the time, Mr. Sharp was about to get married and buy his first home. Before applying for a mortgage he requested a copy of his credit report. That is when he found he had several collection notices under his name for emergency room visits throughout the country.
“There was even a $19,000 bill for a Life Flight air ambulance service in some remote location I’d never heard of,” said Mr. Sharp, who made this unhappy discovery in 2003. “I had emergency room bills from places like Bowling Green, Kan., where I’ve never even visited. I’m still cleaning up the mess.”
The last time federal data on the crime was collected, for a 2007 report, more than 250,000 Americans a year were victims of medical identity theft. That number has almost certainly increased since then, because of the increased use of electronic medical records systems built without extensive safeguards, said Pam Dixon, executive director of the nonprofit World Privacy Forum and author of a report on medical identity theft.
And uncountable, Ms. Dixon said, are the people who do not yet know they are victims. They may not know that their medical information has been tampered with for months or even years until, as in Mr. Sharp’s case, it shows up in collections on a credit report.
Medical identity theft takes many guises. In Mr. Sharp’s case, someone got hold of his name and Social Security number and used them to receive emergency medical services, which many hospitals are obliged to provide whether or not a person has insurance. Mr. Sharp still does not know whether he fell victim to one calamitous perp who ended up in several emergency rooms or a ring of accident-prone conspirators.
In another variant of the crime, someone can use stolen insurance information, like the basic member ID and group policy number found on insurance cards, to impersonate you — and receive everything from a routine physical to major surgery under your coverage. This is surprisingly easy to do, because many doctors and hospitals do not ask for identification beyond insurance information.
Even more common, however, are cases where medical information is stolen by insiders at a medical office. Thieves download vital personal insurance data and related information from the operation’s computerized medical records, then sell it on the black market or use it themselves to make fraudulent billing claims.
In a widely reported case in 2006, a clerk at a Cleveland Clinic branch office in Weston, Fla., downloaded the records of more than 1,100 Medicare patients and gave the information to her cousin, who in turn, made $2.8 million in bogus claims.
When people are not aware their medical identities have been stolen, insurance companies may simply continue to pay the fraudulent claims without the victim’s knowledge. The person might learn of the fraud only when trying to make a legitimate claim, and the insurance company informs them they have reached their lifetime cap on benefits.
Or victims may eventually discover erroneous information in their medical files during a doctor or hospital visit. And that may pose a bigger danger than the financial risks. The medical records may now contain vital information like blood type, allergies, prescription drug use or a history of disease that is just plain wrong. In an emergency, doctors could treat you based on this erroneous information.
And there are none of the consumer protections for medical identity theft victims that exist for traditional identity theft. Under the Fair Credit Reporting Act you can get a free copy of your credit report each year, put a fraud alert on your account and get erroneous charges deleted from your record. If your credit card is stolen and the thief goes on a spending spree, you’re not liable for more than $50 worth of the charges. 1
With medical identity theft, though, the fraudulent charges can remain unpaid and unresolved for years, permanently damaging your credit rating. Under the federal law known as Hipaa — the Health Insurance Portability and Accountability Act — you are entitled to a copy of your medical records, but you may have to pay a hefty fee for them.
Worse, Hipaa privacy rules can actually work against you. Once your medical information is intermingled with someone else’s, you may have trouble accessing your files. Privacy laws dictate that the thief’s medical information now contained in your records must be kept confidential, too.
Even when you are able to correct a record, say in your doctor’s office, the erroneous information may have been passed on to dozens of other health care providers and insurers. Victims must track down and resolve these errors largely on a case-by-case basis, Ms. Dixon says.
Medical providers contend that they are taking precautions against identity theft. At Cleveland Clinic, for example, security personnel routinely audit electronic medical record systems and all records are password-protected. Many Blue Cross Blue Shield insurers use software to screen for spikes in claims from providers that look suspicious. They also work with providers on encrypting medical files and carrying out data access restrictions, said Calvin Sneed, senior antifraud consultant at the Blue Cross and Blue Shield Association.
And some medical centers and doctors’ offices now require patients to show photo ID and attach photos to patient charts.
But privacy advocates worry that these steps do not go nearly far enough, especially in light of President Obama’s plans to spend $20 billion to increase the use of electronic medical records nationwide as part of the stimulus package. “Without aggressive safeguards, we could be building an infrastructure for massive medical fraud,” said Ms. Dixon.
If you find yourself a victim of this kind of fraud you are not likely going to be as concerned about new privacy laws as you will about getting help for your situation. Nearly every states Attorney General has gone on record regarding identity theft. With millions of cases each year, and with the amount of investigative work each one requires, the states AG offices cannot give each case the attention it requires. We all need to find ways to safeguard ourselves. A good identity theft service is by far the most efficient way to do that. A restorative service will handle the brunt of the work of sorting out records and establishing a clear record of the crimes that were committed. And finally to go about the process of clearing false records entries.
1 Actually that is not completely true. If you report debit card fraud within 72 hours or within 30 days of a regular bank statement being mailed to you your liability is limited. Banks do not have to recover your losses after those times expire. ed.
Friday, June 12, 2009
Don't Worry, I Can Do It Myself!
A day later dad noticed a strange whirring sound coming from under the car.
Being too proud to take the car in to the garage dad decided to fix it himself. Perhaps a little too much egoism was at work there. Dad tore into the drive train, removing this, and then that until the ground under the car was littered with parts. Dad wasn’t a mechanic. In fact he had a reputation for being essentially inept when it came to the mechanical. He was a good architect. He could design complex systems for big buildings but could not change a light bulb without a struggle.
When he managed to put all the parts back on the car the problem was worse. In fact I think he created a couple of new problems trying to fix the first one. Not to be out foxed by a mere car dad kept at it until nothing worked. When my mother suggested that we call the garage to come and get the car dad got a little irritated. His bruised ego took over. “Don’t worry, I can do it myself.” Fatal words. That little incident caused us a very expensive repair, and because of my dads’ refusal to have a simple auto insurance policy we were left without a car for weeks until my mother decided it was time to get one of her own so we wouldn’t get stranded like that again. Come to think of it that car never did run right after that. Dads’ reasoning, like a lot of car owners at the time was that anything that an insurance company could do he could do himself, and better.
It was common for people to have that attitude in 1957. They suspected the insurance companies of scheming to take the public’ money and doing little for the car owner in return. That kind of thinking triggered a whole new area of lawsuits. With more cars on the road than ever before claims of personal liability flew into every courtroom in America. People were suing each other in a frenzy that threatened to grind the court system to a halt. Enter the age of auto insurance. The system that evolved is one of traffic laws that make liability clear in every claim. Whether or not we agree with all of it, the laws are clear.
Today we have liability insurance as matter of fact for every driver. When claims are filed the system is in place to effect repairs for damaged cars. The relative nightmare our family went through over a simple repair would have never happened had my father and the other driver taken out insurance policies. Auto insurance is a self-evident concept today.
In this era of identity theft I hear the same hubris. “Don’t worry it won’t happen to me, and if it does I can fix it myself.” Tell that to the millions of individuals who have suffered from the fallout of identity theft. You will find a different response from them. They know the advantage of a good identity theft service. My identity theft experience has lasted (so far) 8 years, and I still have issues. If I had an identity theft service before my incident I probably would have cleared it up in weeks or a couple of months at the worst and not had to expend over $26,000 in the process.
Identity theft services did not exist then but they do now. There is no excuse for anyone to not have an identity theft service. But which one to get? That decision was just made a lot easier. Federal courts recently ruled that identity theft services that set fraud alerts with the credit bureaus for a fee are in violation of the FCRA. That is one thing we can do for ourselves. This eliminates most of the companies right there. Find a service that will repair your identity after an incident, using real agents licensed to do that kind of work. Don’t do like my dad and attempt to fix it yourself. With more cases of identity theft every day the system is overwhelmed. You cannot do it without a protracted and painful bureaucratic process and a great expense in both time and money. And it may likely never be done. It is restoration you need to have. Anyone can tell you that you are a victim. You want and need repair after the fact.
Wednesday, June 10, 2009
A Failure to Adequately Protect......
Class actions are beginning to crank up in the area of data breach. Not being able to show penury damages from specific cases of identity theft, the victims of data breaches are increasingly turning to class actions based at least in part on the failure of a data aggregator to protect the information they keep.
A class-action suit has been filed against health insurer Aetna for alleged data protection and privacy failures, reports Hartford Business. The company announced last month that hackers had gained access to its job application site, potentially exposing the Social Security numbers of 65,000 current and former employees. Plaintiffs are seeking credit monitoring, punitive damages, costs and other relief, according to the report. The complaint filed last week in a Pennsylvania District Court states: "Aetna unlawfully failed to maintain reasonable systems and procedures to protect [plaintiffs'] information."Full Story
What are the reasonable actions a company could take that might prevent these kinds of court actions? That varies from case to case and company to company, but will likely include the preventive steps required under FACTA, GLB, and states laws that specifically address identity theft. Whether it is 5 records that have been compromized or the 65,000 mentioned above, the liability is the same. A "Failure to adequately protect records" lawsuit should not be considered the cost of doing business like the petty theft of office supplies. The cost to the business cannot be calculated in terms of simple legal fees.
A business that takes the preventive steps on its' own before any data loss incidents can greatly reduce the liklihood of a class action from being initiated.
Wednesday, June 3, 2009
A Little Break
As much as I love to write this column I'm going to take a few days off for myself and relax. I will see you all in a week. Until then, think security.
John
Tuesday, June 2, 2009
Identity Theft Services, get one!
While there are states and federal laws and guidelines intended for businesses regarding information safety, there is also the relentless wave of information theft resulting in identity theft that goes unabated. Each incident of data loss that is reported to the FTC and law enforcement results in a better understanding of the circumstances that create the opportunity for loss or theft. The laws are increasingly focused on some of the root causes as the data improves. That is partially why we now have a refocus on HIPAA and the challenges medical information protection creates. The new Red Flags Rule has established at least 26 specific activities that indicate possible identity theft and is aimed at virtually every business sector for compliance. Both of these laws are mandatory for the affected businesses and agencies, and if applied effectively should greatly reduce the incidents of data theft and misuse plaguing American business.
At the same time as reported by the Identity Theft Resource Center (ITRC) recently there is no let up in reported cases of identity theft. Reporting is indeed improved which means that we are probably seeing more accurate data but it is undeniable that identity theft is still on the rise.
What does that mean to us as both business people and individuals? I’ve often used the phrase “An armed society is a polite society” jokingly, but there is an element of truth to that. Let’s be clear, I’m not advocating using firearms to fight identity theft! What I am saying however is that for as long as identity theft is an issue, and there is no indication that it will go away soon, we should approach it on both fronts. Both by applying the steps in the laws to our businesses, and by covering our own personal risks as best we can.
That brings us to identity theft protection products. I was talking with a friend recently about auto insurance rates. We both pay more than we would like to pay but agree that when we need to file a claim we are glad its there. So the cost of the insurance is easy to justify to protect the investment we have in our cars. What price are we willing to pay to safeguard our identities? Identity theft is a real problem that affects all of us and is here to stay. What would we be willing to pay to protect ourselves from being falsely arrested as a victim of identity theft? How about having our medical information usurped by thieves, used, and possibly altered innocently by medical records keepers? Bank account takeovers, new lives being established by illegal aliens using our SSN and personal information? Each one of these circumstances when they occur create a permanantly skewed picture of who we are to the world at large. What would we want an identity theft service company to do for us realistically? It needs to be clearly understood that there are no current means to stop identity theft. However, by being smart we can reduce our exposure and risk. The focus needs to be not what the service will do to stop ID theft but what they do to provide an early warning system and safeguard us from the fallout. It often takes months and sometime years to clear up just one incident of identity theft when we act on our own behalf. Victims face a bureaucracy of regulations and red tape when it comes to correcting records and databases. I think that is where the focus needs to be when choosing an identity theft service. It is necessary to have a service with a proven track record of working with federal, state, and private agencies to wade through the complexities, work to correct records and represent the victim by building the appropriate files and history. Once identity theft happens it is statistically more likely to reoccur. Establishing a victims’ identity theft history is just as crucial as the initial restoration itself.
Be smart, protect your business and the employees, but do not count yourself out of the picture. Identity theft has no boundaries and can happen to anyone at any time. Be smart and be prepared. A good service is a very small price to pay to avoid the emotional and financial fallout from identity theft. I don’t know how many auto claims are filed each year but I do know that there are somewhere between 8 and 10 million identity theft victims each year in the U.S.
For more information on the Identity Theft Shield I represent look at the My Business Website link in this column.

