Friday, September 4, 2009

Medical Identity Theft is on the Rise

According to the Identity Theft Resource Center (ITRC), medical identity theft is on the rise as health insurance fraud becomes more common. NetworkWorld reports that, according to an ITRC study of 2008 identity theft victims, 67 percent had been charged for medical procedures they hadn't received and 11 percent were denied health or life insurance for unexplained reasons--possibly because of incorrect information resulting from fraudulent insurance claims. The NetworkWorld article includes a summary of the worst medical data breach incidents from 2009, including: Virginia Department of Health Professions hack (8 million+); Peninsula Orthopaedic Associates robbery (100K) and Moore's Cancer Center hack (30K).Full Story

Most companies hold personal medical information on their staff for purposes of health insurance, incident reports, cafeteria plans, and so forth. It was only about two years ago that there was a general concensus among professionals that medical identity theft was largely overstated despite warnings that it was largely underreported. Medical identity theft is by far the most difficult type of the crime due to far reaching implications. When medical information is used a lot of databases are automatically updated from insurance claim databases such as MIB, to hospital and doctor records. Blood types and allergy histories can be incorrect in records. When medical procedures are performed this can also effect credit worthiness if bills go unpaid, suits are filed by creditors, criminal files can be opened, in short the misuse of medical information can result in the corruption of dozens of types of records.

What we see in medical database breaches such as the ones above is only part of the puzzle.
Everyone needs to consider the restoration of medical records and legal representation when evaluating identity theft services.

Friday, August 28, 2009

Bernake was a victim of identity theft

This was too good to pass up. Thank you Reuters!

Fri Aug 28, 2009 9:30am EDT
WASHINGTON (Reuters) - Federal Reserve chief Ben Bernanke was among hundreds of victims of an identity fraud ring that stole more than $2.1 million from consumers and financial institutions across the United States, Newsweek magazine reported on its website.
The head of the U.S. central bank and his wife were swept up in a case against the ring after her purse, with personal checks inside, was snatched at a coffee shop in August 2008, Newsweek reported, citing recently filed court documents.
Someone soon began cashing checks on the Bernanke family bank account, a crime that became part of a wide-ranging federal identity theft investigation that was already underway.
The targets were members of a nationwide ring that used a combination of old-fashioned thievery and high-tech fraud to loot the bank accounts of unsuspecting victims, Newsweek reported.
The investigation by the Secret Service and the U.S. Postal Inspection Service culminated in recent months with a series of arrests, criminal complaints and indictments brought by federal prosecutors in Virginia.
In a statement to Newsweek, Bernanke said identity theft is a serious crime that affects millions of Americans each year.
"Our family was but one of 500 separate instances traced to one crime ring," Bernanke said. "I am grateful for the law enforcement officers who patiently and diligently work to solve and prevent these financial crimes."

Wednesday, August 26, 2009

Employees, Especially Temps, Cause Breaches

The majority of data breaches result from inadvertent employee error, say experts. BBC News reports on the results of a study that found unintentional data loss to be the most frequent cause of cyber breaches (14.4 percent per year). IDC and the security firm RSA analyzed 11 categories of risk at 400 organizations in various industry sectors across the U.S., UK, France and Germany. Of the employee-caused breaches, they found 52 percent to be accidental and 19 percent deliberate. Temporary employees, the study found, are more likely to be culpable. "It's likely contractors may be less well-trained in organizational policy..." said RSA's Chris Young.
Read the full story here
Full Story

This survey, one of dozens within the past two years, illustrates my point about employee training as perhaps the most critical aspect of any good breach plan. That 52% of accidental breaches can be greatly diminished by showing employees what is expected of them and seeking their help in improving data security throughout the enterprise. A clear written policy that not only delineates the information that is to be protected, but also provides guidelines for staff and names those who are administering the program is essential in our modern business world. As long as personal identifiable information has value it will be used and sold by illegal profiteers around the world.

Thursday, August 20, 2009

Attention All Keepers of Personal Data!

  1. Do you own a business with employees?
  2. Do you use personal information in sales transactions?
  3. Do you keep personally identifiable information (PII), on your clients including students?
  4. Do you share PII with any other business?
  5. Does any other business have access to your PII database?

If you can answer yes to any of these questions ask yourself this. What are you doing to actively safeguard that information from loss or theft? Remember, it is your responsibility to protect that information from misuse or theft. No business (above) is exempt.

The federal government has issued guidelines for you to follow in order to be compliant with the standards set forth in several privacy laws.The Federal Trade Commission FTC , has oversight of all businesses apart from the banking and savings industries which have separate oversight. They have the authority to investigate breaches and to even prosecute those businesses whose security practices are lacking.

The answer to anyone who questions the need for securing this kind of information is very simple. There are roughly 9 to 10 million identity theft victims in the U.S. each year. The majority of those victims had their information compromised from a database and not from direct theft. When you and your business safeguards the information you keep on others you are protecting them. When someone else does the same they are protecting you. All of us leave a trail of data behind in the course of our lives. Every school we have ever attended, every home we have purchased, loan made, insurance claim, military service, in short everything we have ever done has left a record that needs to be protected from theft or misuse. Each one of us is a link in the chain of protection. When you and your business safeguards the information you keep on others you are protecting them. When someone else does the same they are protecting you.

Tuesday, August 18, 2009

Data Security Measures Deadline Extended

The Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) has amended its data security regulations. In a media release yesterday, the OCABR announced that the rules will facilitate a risk-based approach to data security, which is expected to help the small-business community, in particular. In creating written security programs, businesses will be able to take into account their size, industry type and identity-theft risk, among other characteristics. The OCABR also modified the regulations to make them technology neutral. The new effective date is March 1, 2010. A public hearing on the changes will take place Tuesday, September 22.

The government has long been under pressure to create a federal standard for data security. Existing laws such as the FCRA and GLB Safety Act have set out guidelines for businesses that include risk analysis, written policy definitions, and employee training. However, apart from the Red Flags Rules [sec.114 FACTA] to date nothing definitive has been issued that delineates specifically what each business must do and what criteria they must follow to safeguard PII. This new Mass. law promises to provide much of that language to guide businesses in that State. It is my belief that when enacted this new legislation will become a model for similar federal legislation.

Thursday, August 6, 2009

Companies Take Heed

Corporate Ethics Must Change, Says Matwyshyn. A Wharton School professor says that corporations will have to adapt to increasing consumer savvy when it comes to the role of information security in business dealings, reports Forbes. At Defcon last week, privacy expert and Wharton professor of legal studies and business ethics Andrea Matwyshyn said: "Companies need to be aware that their customers are going to start asking questions about their security and what they're doing." Matwyshyn studies corporate law and information technology. She says even though they are not required to disclose their security procedures to consumers, big businesses should inform customers about their security practices and threats, adding that if corporate ethics don't change, legislators might step in.

While it is true that businesses are not required to disclose security procedures and methods, the public still has the last say in this. When you go to work for a company, enter into an agreement or contract with another business, invest in or simply do business with them you have the right to expect that they are handling your personal information in a responsible manner. And you have the right to NOT get involved with a business that does not take this seriously. If covered by the Red Flags Rule you can ask to see their identity theft prevention and response policy. I have been to bank branches for speaking engagements since Nov 1st of '08 where the branch manager had no idea of the banks policy nor what the policy document looked like. Banks were to be in compliance prior to November 1st of '08. The bottom line is this. If you are one of the people who are waiting for the government to fix the problem you are not going to get any satisfaction. We are empowered to make businesses take the responsible route when it comes to data security. We live in a society where lawyers throw cases of client files in dumpsters, and personnel departments email sensitive personal info to one another without any sort of encryption or protection, and employees that lose laptops and thumb drives containing unencrypted NPI on a regular basis. These are just a few of the "mistakes" companies make daily, and do not include the intentional acts of theft of paper files, flash drives, and CD ROMS by underpaid, laid-off or disgruntled employees needing extra cash.

If a business does not address this issue head on by training and honestly assessing internal risk they are playing with fire. There is no limit in company size either. EVERY business regardless of size must take heed. This is a real issue with real consequences and businesses are the prime source of data.