Friday, September 4, 2009
Medical Identity Theft is on the Rise
Most companies hold personal medical information on their staff for purposes of health insurance, incident reports, cafeteria plans, and so forth. It was only about two years ago that there was a general concensus among professionals that medical identity theft was largely overstated despite warnings that it was largely underreported. Medical identity theft is by far the most difficult type of the crime due to far reaching implications. When medical information is used a lot of databases are automatically updated from insurance claim databases such as MIB, to hospital and doctor records. Blood types and allergy histories can be incorrect in records. When medical procedures are performed this can also effect credit worthiness if bills go unpaid, suits are filed by creditors, criminal files can be opened, in short the misuse of medical information can result in the corruption of dozens of types of records.
What we see in medical database breaches such as the ones above is only part of the puzzle.
Everyone needs to consider the restoration of medical records and legal representation when evaluating identity theft services.
Friday, August 28, 2009
Bernake was a victim of identity theft
Fri Aug 28, 2009 9:30am EDT
WASHINGTON (Reuters) - Federal Reserve chief Ben Bernanke was among hundreds of victims of an identity fraud ring that stole more than $2.1 million from consumers and financial institutions across the United States, Newsweek magazine reported on its website.
The head of the U.S. central bank and his wife were swept up in a case against the ring after her purse, with personal checks inside, was snatched at a coffee shop in August 2008, Newsweek reported, citing recently filed court documents.
Someone soon began cashing checks on the Bernanke family bank account, a crime that became part of a wide-ranging federal identity theft investigation that was already underway.
The targets were members of a nationwide ring that used a combination of old-fashioned thievery and high-tech fraud to loot the bank accounts of unsuspecting victims, Newsweek reported.
The investigation by the Secret Service and the U.S. Postal Inspection Service culminated in recent months with a series of arrests, criminal complaints and indictments brought by federal prosecutors in Virginia.
In a statement to Newsweek, Bernanke said identity theft is a serious crime that affects millions of Americans each year.
"Our family was but one of 500 separate instances traced to one crime ring," Bernanke said. "I am grateful for the law enforcement officers who patiently and diligently work to solve and prevent these financial crimes."
Wednesday, August 26, 2009
Employees, Especially Temps, Cause Breaches
Read the full story here Full Story
This survey, one of dozens within the past two years, illustrates my point about employee training as perhaps the most critical aspect of any good breach plan. That 52% of accidental breaches can be greatly diminished by showing employees what is expected of them and seeking their help in improving data security throughout the enterprise. A clear written policy that not only delineates the information that is to be protected, but also provides guidelines for staff and names those who are administering the program is essential in our modern business world. As long as personal identifiable information has value it will be used and sold by illegal profiteers around the world.
Friday, August 21, 2009
HHS Issues a Breach Notification Rule
The Department of Health and Human Services (HHS) published its rule on mandatory breach notification requirements, reports Government Health IT. The rule applies to all entities covered by the Health Insurance Portability and Accountability Act (HIPAA). The notification requirement stems from a Congressional mandate in the American Recovery and Reinvestment Act, (ARRA). "These protections will be a cornerstone of maintaining consumer trust as we move forward with meaningful use of electronic health records and electronic exchange of health information," said Robinsue Frohboese of the HHS Office for Civil Rights. Earlier this week, the FTC issued its rule on mandatory breach notification requirements for personal health records vendors.
For more on that rule here.
Thursday, August 20, 2009
Attention All Keepers of Personal Data!
- Do you own a business with employees?
- Do you use personal information in sales transactions?
- Do you keep personally identifiable information (PII), on your clients including students?
- Do you share PII with any other business?
- Does any other business have access to your PII database?
If you can answer yes to any of these questions ask yourself this. What are you doing to actively safeguard that information from loss or theft? Remember, it is your responsibility to protect that information from misuse or theft. No business (above) is exempt.
The federal government has issued guidelines for you to follow in order to be compliant with the standards set forth in several privacy laws.The Federal Trade Commission FTC , has oversight of all businesses apart from the banking and savings industries which have separate oversight. They have the authority to investigate breaches and to even prosecute those businesses whose security practices are lacking.
The answer to anyone who questions the need for securing this kind of information is very simple. There are roughly 9 to 10 million identity theft victims in the U.S. each year. The majority of those victims had their information compromised from a database and not from direct theft. When you and your business safeguards the information you keep on others you are protecting them. When someone else does the same they are protecting you. All of us leave a trail of data behind in the course of our lives. Every school we have ever attended, every home we have purchased, loan made, insurance claim, military service, in short everything we have ever done has left a record that needs to be protected from theft or misuse. Each one of us is a link in the chain of protection. When you and your business safeguards the information you keep on others you are protecting them. When someone else does the same they are protecting you.
Tuesday, August 18, 2009
Data Security Measures Deadline Extended
The government has long been under pressure to create a federal standard for data security. Existing laws such as the FCRA and GLB Safety Act have set out guidelines for businesses that include risk analysis, written policy definitions, and employee training. However, apart from the Red Flags Rules [sec.114 FACTA] to date nothing definitive has been issued that delineates specifically what each business must do and what criteria they must follow to safeguard PII. This new Mass. law promises to provide much of that language to guide businesses in that State. It is my belief that when enacted this new legislation will become a model for similar federal legislation.
Thursday, August 6, 2009
Companies Take Heed
While it is true that businesses are not required to disclose security procedures and methods, the public still has the last say in this. When you go to work for a company, enter into an agreement or contract with another business, invest in or simply do business with them you have the right to expect that they are handling your personal information in a responsible manner. And you have the right to NOT get involved with a business that does not take this seriously. If covered by the Red Flags Rule you can ask to see their identity theft prevention and response policy. I have been to bank branches for speaking engagements since Nov 1st of '08 where the branch manager had no idea of the banks policy nor what the policy document looked like. Banks were to be in compliance prior to November 1st of '08. The bottom line is this. If you are one of the people who are waiting for the government to fix the problem you are not going to get any satisfaction. We are empowered to make businesses take the responsible route when it comes to data security. We live in a society where lawyers throw cases of client files in dumpsters, and personnel departments email sensitive personal info to one another without any sort of encryption or protection, and employees that lose laptops and thumb drives containing unencrypted NPI on a regular basis. These are just a few of the "mistakes" companies make daily, and do not include the intentional acts of theft of paper files, flash drives, and CD ROMS by underpaid, laid-off or disgruntled employees needing extra cash.
If a business does not address this issue head on by training and honestly assessing internal risk they are playing with fire. There is no limit in company size either. EVERY business regardless of size must take heed. This is a real issue with real consequences and businesses are the prime source of data.

