<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3645697380824919280</id><updated>2011-07-29T01:45:11.836-04:00</updated><category term='ethics'/><category term='TJX'/><category term='smart grid'/><category term='HealthNet'/><category term='attorney-client privilege'/><category term='IAPP'/><category term='Computer Fraud and Abuse Act'/><category term='Visa'/><category term='data mining'/><category term='cable'/><category term='privacy policies'/><category term='Homeland Security'/><category term='EHR'/><category term='Amazon'/><category term='behavioral advertising'/><category term='privacy'/><category term='eBay'/><category term='termination'/><category term='medical records'/><category term='Maine Supreme Court'/><category term='business associate'/><category term='Citibank'/><category term='state education departments'/><category term='data theft'/><category term='genetic privacy'/><category term='North Korea'/><category term='encryption'/><category term='UK Data Protection Act'/><category term='social networking; cookies'/><category term='information security'/><category term='scams'/><category term='student information'/><category term='wi-fi data collection'/><category term='CNIL'/><category term='privacy notice'/><category term='data security safeguards'/><category term='HITECH Act'/><category term='u.s. government'/><category term='LinkedIn'/><category term='cyberattacks'/><category term='E.U. data privacy'/><category term='GINA'/><category term='Cavoukian'/><category term='opt-in'/><category term='data breach notification'/><category term='Canada'/><category term='reporting of data breaches'/><category term='Social Security numbers'/><category term='safe harbor'/><category term='swine flu'/><category term='safeguards'/><category term='GLBA'/><category term='personal information'/><category term='expectation of privacy'/><category term='self-regulatory principles'/><category term='Washington state data breach law'/><category term='South Korea'/><category term='Italy'/><category term='bank card issuers'/><category term='Clear'/><category term='online data'/><category term='Virginia'/><category term='employee handbooks'/><category term='electronic discovery'/><category term='terms of use'/><category term='consumer protection'/><category term='airline'/><category term='bankruptcy'/><category term='Street View'/><category term='records retention'/><category term='cybercrime'/><category term='consent order'/><category term='end user license agreement'/><category term='Loving Care case'/><category term='New Jersey'/><category term='consumer privacy'/><category term='FTC'/><category term='minors'/><category term='HIPAA'/><category term='software'/><category term='CAN-SPAM'/><category term='WISP'/><category term='costs of data breach'/><category term='breach liability'/><category term='behavioral tracking'/><category term='BJ&apos;s Wholesale'/><category term='marketing'/><category term='blogging'/><category term='Gonzalez'/><category term='cybersecurity'/><category term='Twitter'/><category term='comp'/><category term='Michigan'/><category term='Maine marketing'/><category term='congress'/><category term='American Express'/><category term='Article 29 Working Party'/><category term='Massachusetts H313'/><category term='written information security plan'/><category term='electronic health records'/><category term='registered traveler'/><category term='employee theft'/><category term='European Union'/><category term='France data protection'/><category term='verdict'/><category term='Ninth Circuit'/><category term='Mintz Levin'/><category term='enforcement'/><category term='COPPA'/><category term='Massachusetts data security regulations'/><category term='data breach'/><category term='Heartland'/><category term='social networking; Facebook'/><category term='spammers'/><category term='internet'/><category term='201 CMR 17.00'/><category term='data protection'/><category term='Quon'/><category term='FCC'/><category term='document retention'/><category term='frequent flier'/><category term='credit card'/><category term='Connecticut AG Blumenthal'/><category term='privacy rights'/><category term='Gramm-Leach-Bliley'/><category term='web tracking'/><category term='Wired'/><category term='Nevada'/><category term='HIPAA; HITECH Act'/><category term='employee privacy'/><category term='Facebook'/><category term='copy machines'/><category term='disposal'/><category term='Federal Trade Commission'/><category term='hack'/><category term='TSA'/><category term='prosecution'/><category term='PCI'/><category term='SCOTUS'/><category term='workplace privacy'/><category term='e-mail policy'/><category term='HIPAA Privacy Rule'/><category term='cookies'/><category term='California'/><category term='cell phone'/><category term='Fourth Amendment'/><category term='financial institutions'/><category term='cross-border data transfer'/><category term='pretexting'/><category term='Data Privacy Day'/><category term='Secure Flight'/><category term='Veterans Administration'/><category term='Google'/><category term='tracking software'/><category term='Supreme Court'/><category term='botnet'/><category term='acceptible use policy'/><category term='remote information'/><category term='patient privacy'/><category term='denial of service'/><category term='password management'/><category term='Stored Communications Act'/><category term='class action'/><category term='social networking; Facebook; online advertising; behavioral targeting'/><category term='Securities and Exchange Commission'/><category term='user consent'/><category term='data breach fines'/><category term='Hernandez case'/><category term='HHS'/><category term='payment systems'/><category term='hard drive'/><category term='criminal trial'/><category term='FINRA'/><category term='settlement'/><category term='compliance'/><category term='American Medical Association'/><category term='e-discovery'/><category term='PHI'/><category term='Maine'/><category term='Gap'/><category term='Wyndham Hotel'/><category term='prescription privacy'/><category term='identity theft'/><category term='Red Flag'/><title type='text'>Privacy and Security Information - Privacy MATTERS</title><subtitle type='html'>Privacy and Security Information sponsored by Mintz Levin.  Blogging on privacy laws, privacy breaches, compliance, data security, cybersecurity and all that goes with living in an infocentric society.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://privacyandsecuritymatters.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default?start-index=101&amp;max-results=100'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>157</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-9196053329389440781</id><published>2010-10-22T13:06:00.004-04:00</published><updated>2010-10-22T13:09:29.983-04:00</updated><title type='text'>We've moved! Note our URL change!</title><summary type='text'>After a "summer hiatus,"  we have relaunched the Privacy and Security MATTERS Blog on a new platform.Note our new blog address and make sure to change your favorites to reflect the same.http://www.privacyandsecuritymatters.com/If you are prompted by a browser security warning to accept the URL redirection, please accept by clicking yes.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/9196053329389440781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/9196053329389440781'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/10/weve-moved-note-our-url-change.html' title='We&apos;ve moved! Note our URL change!'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8813946751946216783</id><published>2010-08-06T11:07:00.002-04:00</published><updated>2010-08-06T11:09:40.221-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HHS'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Patient privacy group welcomes HHS withdrawal of HITECH Act breach notification rule</title><summary type='text'>The Patient Privacy Rights Foundation welcomed last week’s announcement by the Department of Health and Human Services (HHS) that it was withdrawing the health data breach notification rule. The Foundation called the withdrawal a "huge step in the right direction" and reiterated its disappointment with the 'harm threshold' provision, which allows health care providers to conduct a risk assessment</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8813946751946216783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8813946751946216783'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/08/patient-privacy-group-welcomes-hhs.html' title='Patient privacy group welcomes HHS withdrawal of HITECH Act breach notification rule'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1135507098988488323</id><published>2010-07-30T11:59:00.004-04:00</published><updated>2010-07-30T12:14:25.143-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cookies'/><category scheme='http://www.blogger.com/atom/ns#' term='Article 29 Working Party'/><category scheme='http://www.blogger.com/atom/ns#' term='behavioral advertising'/><category scheme='http://www.blogger.com/atom/ns#' term='European Union'/><category scheme='http://www.blogger.com/atom/ns#' term='behavioral tracking'/><category scheme='http://www.blogger.com/atom/ns#' term='online data'/><title type='text'>Online Behavioral Advertising:  The European Union Controversy</title><summary type='text'>On June 24, 2010, the European Union's body that addresses data protection issues, the so-called Article 29 Working Party, adopted Opinion 2/2010 (the “Opinion”) providing further clarification on the amended e-Privacy Directive (below) as applied to online behavioral advertising.  The Working Party also issued a press release on this topic. Although the scope of the Opinion is limited to online </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1135507098988488323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1135507098988488323'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/online-behavioral-advertising-european.html' title='Online Behavioral Advertising:  The European Union Controversy'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6757745485989881099</id><published>2010-07-30T11:51:00.003-04:00</published><updated>2010-07-30T11:57:34.273-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HHS'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA; HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='PHI'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>HHS Withdraws Breach Notification Final Rule (but breach notification still effective)</title><summary type='text'>Interesting press release from the Department of Health and Human Services (HHS) relating to the HITECH Breach Notification Final Rule.   The Interim Final Rule is still effective, but one can't help but wonder what HHS may be reconsidering given the numbers of breaches reported since September 2009.Breach Notification Final Rule UpdateThe Interim Final Rule for Breach Notification for Unsecured </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6757745485989881099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6757745485989881099'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/hhs-withdraws-breach-notification-final.html' title='HHS Withdraws Breach Notification Final Rule (but breach notification still effective)'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8552290530227454083</id><published>2010-07-28T09:39:00.002-04:00</published><updated>2010-07-28T09:45:31.030-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='disposal'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA Privacy Rule'/><category scheme='http://www.blogger.com/atom/ns#' term='patient privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='PHI'/><title type='text'>Improper Disposal Costs Rite Aid $1 Million</title><summary type='text'>Written by Dianne BourqueRite Aid has agreed to pay $1 million to settle allegations that it violated HIPAA by disposing of labeled pill bottles in unsecured dumpsters accessible to the public.  The $1 million fine settles a joint Office of Civil Rights (OCR)/Federal Trade Commission (FTC) investigation prompted by televised media reports of pharmacies disposing of pill bottles containing patient</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8552290530227454083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8552290530227454083'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/improper-disposal-costs-rite-aid-1.html' title='Improper Disposal Costs Rite Aid $1 Million'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4250720250638191840</id><published>2010-07-13T17:03:00.003-04:00</published><updated>2010-07-13T17:30:13.962-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HHS'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA; HITECH Act'/><title type='text'>Analysis of Proposed HHS Regulations Implementing HITECH Act</title><summary type='text'>As promised last week in an earlier post, here is our first Mintz Levin client advisory analyzing the 234 pages of regulations issued on Thursday by the Department of Health and Human Services.    Thanks to colleagues Alden Bianchi, Dianne Bourque and Stephen Bentfield.The regulations are slated to be published in the Federal Register tomorrow, which will trigger the start of the 60-day comment </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4250720250638191840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4250720250638191840'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/analysis-of-proposed-hhs-regulations.html' title='Analysis of Proposed HHS Regulations Implementing HITECH Act'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8366235934639844891</id><published>2010-07-13T12:29:00.001-04:00</published><updated>2010-07-13T12:30:20.353-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><title type='text'>Australian Privacy Commissioner Concludes Google Breached Privacy Act</title><summary type='text'>Written by Jillian Collins Australian Privacy Commissioner Karen Curtis has concluded her investigation into Google's collection of unsecured WiFi payload data in Australia using Street View vehicles and finds that such collection violated Australian law."On the information available I am satisfied that any collection of personal information would have breached the Australian Privacy Act,” she </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8366235934639844891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8366235934639844891'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/australian-privacy-commissioner.html' title='Australian Privacy Commissioner Concludes Google Breached Privacy Act'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8415131492595527263</id><published>2010-07-12T09:19:00.004-04:00</published><updated>2010-07-12T17:24:18.485-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='California'/><category scheme='http://www.blogger.com/atom/ns#' term='Ninth Circuit'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='class action'/><category scheme='http://www.blogger.com/atom/ns#' term='costs of data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Gap'/><category scheme='http://www.blogger.com/atom/ns#' term='data theft'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>No Harm, No Foul; Ninth Circuit Affirms Dismissal of Data Breach Case Against The Gap</title><summary type='text'>Written by Kevin McGintyIt’s a distressingly common scenario. A corporate laptop containing job applicant data, including social security numbers, is stolen from an employee who has taken the laptop off of corporate premises. Access to the social security numbers makes it possible for wrongdoers to engage in identity theft. Is an applicant’s fear that data will be misused enough to support claims</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8415131492595527263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8415131492595527263'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/no-harm-no-foul-ninth-circuit-affirms.html' title='No Harm, No Foul; Ninth Circuit Affirms Dismissal of Data Breach Case Against The Gap'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1874701798355609501</id><published>2010-07-08T16:58:00.003-04:00</published><updated>2010-07-08T17:00:11.292-04:00</updated><title type='text'>REMINDER - HITECH/201 CMR 17.00 Compliance Workshop</title><summary type='text'>Just a reminder of the FREE upcoming data security compliance workshop - Space is limited, so register today at http://tinyurl.com/35pk3yr!On July 13, Mintz Levin will be joined by Sophos, Six Weight Consulting, and MFA Cornerstone Consulting to hold a free compliance workshop focused on both the gaps and overlap of Massachusetts’ data protection regulation 201 CMR 17.oo and the recent updates to</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1874701798355609501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1874701798355609501'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/reminder-hitech201-cmr-1700-compliance.html' title='REMINDER - HITECH/201 CMR 17.00 Compliance Workshop'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8456630333482490441</id><published>2010-07-08T14:50:00.003-04:00</published><updated>2010-07-08T14:54:43.681-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='reporting of data breaches'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA; HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='HealthNet'/><category scheme='http://www.blogger.com/atom/ns#' term='Connecticut AG Blumenthal'/><title type='text'>First Ever State-initiated HIPAA Enforcement Action Settled</title><summary type='text'>Written by Dianne BourqueConnecticut Attorney General Richard Blumenthal has settled the first state-initiated HIPAA enforcement action. The settlement totals $250,000 in statutory damages and Health Net's agreement to implement a variety of measures to improve the security of consumer health and personal information. Health Net also agreed to provide two years of credit monitoring to affected </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8456630333482490441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8456630333482490441'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/first-ever-state-initiated-hipaa.html' title='First Ever State-initiated HIPAA Enforcement Action Settled'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-3011487486419968817</id><published>2010-07-08T14:27:00.003-04:00</published><updated>2010-07-08T14:29:58.415-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HHS'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA; HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><title type='text'>HHS (Finally!) Issues Proposed HIPAA Privacy &amp; Security Rule Changes</title><summary type='text'>The long-awaited proposed changes to the HIPAA Privacy Rules have finally been released by the Department of Health and Human Services (HHS). A  joint statement issued today by the HHS and the Office of Civil Rights (OCR) says that the proposed regulations “would expand individuals’ rights to access their information and restrict certain disclosures of protected health information to health plans</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3011487486419968817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3011487486419968817'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/hhs-finally-issues-proposed-hipaa.html' title='HHS (Finally!) Issues Proposed HIPAA Privacy &amp; Security Rule Changes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6714129581173760487</id><published>2010-07-01T13:27:00.004-04:00</published><updated>2010-07-01T13:45:48.947-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Data Breaches du Jour</title><summary type='text'>Information regarding the latest reports of data breaches -- common thread: it is taking a startingly long time for entities to (a) discover that they have been breached, and (b) to then take action to notify affected customers of potential compromises to personal information.Update on Major Data Breach at California Health Insurer Updating a previous blog post (link) from Monday, WellPoint, the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6714129581173760487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6714129581173760487'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/07/data-breaches-du-jour.html' title='Data Breaches du Jour'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1654460953207308024</id><published>2010-06-29T16:30:00.000-04:00</published><updated>2010-06-29T16:31:11.032-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='American Medical Association'/><category scheme='http://www.blogger.com/atom/ns#' term='Red Flag'/><title type='text'>Latest Postponements and Exemptions of FTC Enforcement of ‘Red Flags’ Rule</title><summary type='text'>Written by Kenneth GantzAt the urging of congressional lawmakers, the Federal Trade Commission has for the fifth time delayed enforcement of the “Red Flags” Rule – this time through December 31, 2010.  In the interim, Congress plans to consider legislation that would alter the scope of entities covered under the Rule.Under the Fair and Accurate Credit Transactions Act, Congress directed the FTC </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1654460953207308024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1654460953207308024'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/latest-postponements-and-exemptions-of.html' title='Latest Postponements and Exemptions of FTC Enforcement of ‘Red Flags’ Rule'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8862012414129532784</id><published>2010-06-28T22:05:00.003-04:00</published><updated>2010-06-28T22:08:28.260-04:00</updated><title type='text'>Major Data Breach at California Health Insurer</title><summary type='text'>Written by Kenneth GantzAnthem Blue Cross is notifying approximately 230,000 members and applicants for individual health insurance of a breach involving a web site used by individuals to apply for insurance and track the status of their applications. Anthem claims that attorneys managed to manipulate the web address within the web site in order to obtain information in support of a class action </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8862012414129532784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8862012414129532784'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/major-data-breach-at-california-health.html' title='Major Data Breach at California Health Insurer'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-3967092890180358056</id><published>2010-06-25T11:21:00.004-04:00</published><updated>2010-06-25T11:26:06.877-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>July 13 Data Security Workshop - FREE</title><summary type='text'>On July 13,  Mintz Levin will be joined by Sophos, Six Weight Consulting, and MFA Cornerstone Consulting to hold a free compliance workshop focused on both the gaps and overlap of Massachusetts’ data protection regulation 201 CMR 17.oo and the recent updates to federal health and medical data privacy found in the HITECH Act.   We'll have an interactive hands-on workshop that will help you to </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3967092890180358056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3967092890180358056'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/july-13-data-security-workshop-free.html' title='July 13 Data Security Workshop - FREE'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4612641140922922134</id><published>2010-06-24T17:25:00.000-04:00</published><updated>2010-06-24T17:26:12.034-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>Twitter Settles With FTC</title><summary type='text'>Twitter has reached a settlement with the Federal Trade Commission (FTC) over charges that it “deceived consumers and put their privacy at risk by failing to safeguard their personal information.”  In the Matter of Twitter, Inc.,  The FTC had alleged that “serious lapses” in Twitter’s security last year  "allowed hackers to obtain administrative control of Twitter, including access to tweets that</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4612641140922922134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4612641140922922134'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/twitter-settles-with-ftc.html' title='Twitter Settles With FTC'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5554363481391484012</id><published>2010-06-22T16:41:00.003-04:00</published><updated>2010-06-22T16:44:55.999-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='consumer privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy policies'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>FTC Highlights Need for Privacy and Security in Internet Commerce</title><summary type='text'>Written by Jillian CollinsThe Federal Trade Commission has weighed in as part of the Department of Commerce's public comment process on privacy and security issues.   According to the FTC's comment, consumers trusting that their personal information will be safeguarded is essential to the success of e-commerce, and innovation is essential to ensuring privacy in the fast-paced, ever-changing world</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5554363481391484012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5554363481391484012'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/ftc-highlights-need-for-privacy-and.html' title='FTC Highlights Need for Privacy and Security in Internet Commerce'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5954780100305033311</id><published>2010-06-22T16:37:00.002-04:00</published><updated>2010-06-22T16:41:01.364-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Street View'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Connecticut AG Blumenthal'/><title type='text'>The Google Payload Data Fallout Continues</title><summary type='text'>Written by Jillian CollinsConnecticut Attorney General Richard Blumenthal says he will lead a multistate investigation into Google Street View cars’ unauthorized collection of personal data from WiFi networks. The Connecticut AG said he expects a significant number of states to participate. More than 30 states participated in a recent conference call regarding the Connecticut investigation.In a </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5954780100305033311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5954780100305033311'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/google-payload-data-fallout-continues.html' title='The Google Payload Data Fallout Continues'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6940080462428883379</id><published>2010-06-22T16:28:00.003-04:00</published><updated>2010-06-22T16:33:43.326-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='expectation of privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Quon'/><title type='text'>More on Supreme Court Ruling in Quon</title><summary type='text'>And as promised in our last post, here is the latest Client Advisory on the Supreme Court's ruling in the Quon case.&lt;!--StartFragment--&gt;    &lt;!--EndFragment--&gt;   </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6940080462428883379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6940080462428883379'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/more-on-supreme-court-ruling-in-quon.html' title='More on Supreme Court Ruling in Quon'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7057701211077564284</id><published>2010-06-17T16:48:00.001-04:00</published><updated>2010-06-17T16:50:25.308-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Quon'/><title type='text'>Breaking News: Supreme Court Issues Decision in Employee Privacy Case</title><summary type='text'>Written by Martha ZackinAs we’ve blogged in this space,, back in December, the Supreme Court agreed to hear City of Onatario v. Quon, a case on the privacy of text messages sent by a government employee on employer-provided devices.  Specifically, the Court agreed to consider whether a police sergeant assigned to a Ontario, California SWAT team had a reasonable expectation of privacy under the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7057701211077564284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7057701211077564284'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/06/breaking-news-supreme-court-issues.html' title='Breaking News: Supreme Court Issues Decision in Employee Privacy Case'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1982801434162772076</id><published>2010-05-26T13:06:00.002-04:00</published><updated>2010-05-26T13:09:03.542-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wi-fi data collection'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>Congressmen Question Google on Wi-Fi</title><summary type='text'>Today,  Congressmen Joe Barton (R-TX), Edward Markey (D-MA), and Henry Waxman (D-CA)wrote to Google Chairman and CEO Eric Schmidt seeking answers to the company’s collection of private information over Wi-Fi networks.“We are concerned that Google did not disclose until long after the fact that consumers’ Internet use was being recorded, analyzed and perhaps profiled.  In addition, we are </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1982801434162772076'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1982801434162772076'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/congressmen-question-google-on-wi-fi.html' title='Congressmen Question Google on Wi-Fi'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6649318366102745597</id><published>2010-05-24T13:44:00.001-04:00</published><updated>2010-05-24T13:45:44.860-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='Red Flag'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>Red Flags Rule Compliance Date Approaching - American Medical Association Sues</title><summary type='text'>It’s been a while since we have visited the Federal Trade Commission’s Red Flags Rule here in this blog.   The oft-postponed deadline is now fast approaching on June 1.  Except, that is, for lawyers and now, doctors. On Friday, the American Medical Association filed a lawsuit against the FTC for defining physicians as “creditors” and claiming that requiring physicians to comply with the Red Flags</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6649318366102745597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6649318366102745597'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/red-flags-rule-compliance-date.html' title='Red Flags Rule Compliance Date Approaching - American Medical Association Sues'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6685268544413931946</id><published>2010-05-13T16:20:00.003-04:00</published><updated>2010-05-13T16:27:22.212-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='social networking; Facebook'/><title type='text'>Facebook Holding Privacy Summit</title><summary type='text'>As a follow-on to yesterday's posts regarding the public face of the Facebook privacy brouhaha, at this hour Facebook is holding an “all-hands” meeting to discuss the company’s overall privacy strategy.  PC World suggests that perhaps today’s company meeting is the beginning of Facebook's effort to improve user guidance on issues of sharing and privacy, or maybe the company is considering a roll </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6685268544413931946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6685268544413931946'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/facebook-holding-privacy-summit.html' title='Facebook Holding Privacy Summit'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6698936130865653108</id><published>2010-05-12T16:49:00.000-04:00</published><updated>2010-05-12T16:50:15.165-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='social networking; Facebook; online advertising; behavioral targeting'/><title type='text'>The back-and-forth on Facebook's privacy travails</title><summary type='text'>Whether the terse discussions in the public arena over Facebook’s privacy “changes” demonstrate that the world’s largest social network is playing fast and loose with the truth about its internal controls on user privacy, or whether it is just an example of poor corporate communication of policies to end users is still a matter of debate.  See Glitch Brings New Worries About Facebook’s Privacy - </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6698936130865653108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6698936130865653108'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/back-and-forth-on-facebooks-privacy.html' title='The back-and-forth on Facebook&apos;s privacy travails'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6698448692374435393</id><published>2010-05-12T16:23:00.002-04:00</published><updated>2010-05-12T16:24:05.994-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cavoukian'/><category scheme='http://www.blogger.com/atom/ns#' term='Canada'/><category scheme='http://www.blogger.com/atom/ns#' term='airline'/><category scheme='http://www.blogger.com/atom/ns#' term='Homeland Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure Flight'/><title type='text'>Two privacy issues from North of the Border</title><summary type='text'>Ann Cavoukian, Ontario’s information and privacy commissioner, has issued her 2009 Annual Report, entitled “Access &amp; Privacy, A Time for Innovation.”  One of Cavoukian’s main subjects this year is the smart grid and the associated privacy issues, including the collection of knowledge about personal habits via “smart” appliances communicating with the grid.  Cavoukian is a thought leader in </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6698448692374435393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6698448692374435393'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/two-privacy-issues-from-north-of-border.html' title='Two privacy issues from North of the Border'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6740555104736160438</id><published>2010-05-06T09:42:00.001-04:00</published><updated>2010-05-06T10:31:05.138-04:00</updated><title type='text'>Privacy Events Calendar</title><summary type='text'>Symposium on Privacy and InnovationTomorrow, the Commerce Department is hosting a day-long symposium called “A Dialogue on Privacy and Innovation.”   It will include several panel discussions to discuss stakeholder views and to facilitate further public discussion on privacy policy in the United States. The event will seek participation and comment from all Internet stakeholders, including the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6740555104736160438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6740555104736160438'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/privacy-events-calendar.html' title='Privacy Events Calendar'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2142285698720986598</id><published>2010-05-03T15:15:00.002-04:00</published><updated>2010-05-03T15:19:27.577-04:00</updated><title type='text'>Welcome to the Privacy Revolution</title><summary type='text'>This is "Choose Privacy Week" – an initiative by the American Library Association to raise awareness about sharing information online. The Association has launched a new website, Privacy Revolution, offering tips for educators and parents on ways to address privacy concerns with children. One sure way not to raise the issue was demonstrated by a principal in Ridgewood, New Jersey last week.  </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2142285698720986598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2142285698720986598'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/welcome-to-privacy-revolution.html' title='Welcome to the Privacy Revolution'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-392863998549289073</id><published>2010-05-02T22:06:00.000-04:00</published><updated>2010-05-02T22:06:46.833-04:00</updated><title type='text'>OT -- Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico</title><summary type='text'>Off the privacy topic, but certainly an issue of national security.   Mintz Levin client, InnoCentive, is crowdsourcing a solution to respond to the oil spill in the Gulf of Mexico.  Over 250 people are currently working on the challenge posted to the site (link below) -- pass this on and get the collective wisdoms of the crowd moving!!Emergency Response 2.0 : Solutions to Respond to Oil Spill in</summary><link rel='related' href='http://gw.innocentive.com/ar/challenge/index/9383447' title='OT -- Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/392863998549289073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/392863998549289073'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/05/ot-emergency-response-20-solutions-to.html' title='OT -- Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6260918915571050012</id><published>2010-04-30T13:18:00.002-04:00</published><updated>2010-04-30T13:21:57.812-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reporting of data breaches'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='PHI'/><category scheme='http://www.blogger.com/atom/ns#' term='copy machines'/><title type='text'>Privacy and Security Bits and Bytes</title><summary type='text'>On this last day of April, there are a couple of breaches and another clarion warning about copy machines --We have blogged on this issue here and here  -- and again, there is another warning about the treasure trove of information residing on the hard drive of your copy machine.  A  CBS Evening News investigation revealed just how much information is stored on copy machines that gets passed on </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6260918915571050012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6260918915571050012'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/privacy-and-security-bits-and-bytes_30.html' title='Privacy and Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2419699890505348332</id><published>2010-04-29T15:21:00.002-04:00</published><updated>2010-04-29T15:23:10.812-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='medical records'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='genetic privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='GINA'/><title type='text'>Connecticut Woman Files First Suit Under Federal Law Prohibiting Genetic Discrimination</title><summary type='text'>Written by Jennifer RubinA Connecticut woman has filed a charge of discrimination under the Federal Genetic Information Nondiscrimination Act ("GINA"), which prohibits discrimination against employees based upon their status as carriers of genetic information. The woman claims her status as a carrier of the BRCA2 gene, a gene sometimes associated with the elevated risk of breast cancer, led to </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2419699890505348332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2419699890505348332'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/connecticut-woman-files-first-suit.html' title='Connecticut Woman Files First Suit Under Federal Law Prohibiting Genetic Discrimination'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-140001873528171686</id><published>2010-04-26T16:36:00.002-04:00</published><updated>2010-04-26T16:40:00.952-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HHS'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><category scheme='http://www.blogger.com/atom/ns#' term='business associate'/><title type='text'>Proposed HITECH Regulations Out in May?</title><summary type='text'>Buried in a part of today's Federal Register was the publication of the Department of Health and Human Services' regulatory agenda.  The agenda presents a forecast of expected HHS rulemaking activities and suggests that in May of this year HHS will issue the long-awaited proposed rules to modify the HIPAA Privacy, Security, and Enforcement Rules as necessary to implement the privacy, security, </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/140001873528171686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/140001873528171686'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/proposed-hitech-regulations-out-in-may.html' title='Proposed HITECH Regulations Out in May?'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5574561756626997240</id><published>2010-04-15T13:07:00.003-04:00</published><updated>2010-04-15T13:09:45.195-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data protection'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='FINRA'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><title type='text'>Brokerage firm victim of elaborate extortion scheme - but also gets hit with a fine</title><summary type='text'>Brokerage firm DA Davidson has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers who breached the company in 2007 in an online extortion scheme and the three have pleaded guilty in Montana.The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.The Financial Industry Regulatory Authority, which </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5574561756626997240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5574561756626997240'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/brokerage-firm-victim-of-elaborate.html' title='Brokerage firm victim of elaborate extortion scheme - but also gets hit with a fine'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8521312511589086235</id><published>2010-04-15T12:54:00.003-04:00</published><updated>2010-04-15T12:59:46.674-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='financial institutions'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy notice'/><category scheme='http://www.blogger.com/atom/ns#' term='Gramm-Leach-Bliley'/><category scheme='http://www.blogger.com/atom/ns#' term='GLBA'/><title type='text'>Federal Regulators Release Model Consumer Privacy Notice Online Form Builder</title><summary type='text'>Last year, the eight federal regulators that regulate the financial services industry issued a "simplified" model privacy notice that was published in the Federal Register on December 1, 2009.   Today, the regulators released an "Online Form Builder" to guide a covered institution to select the version of the model form that fits its practices, such as whether the institution provides an opt-out </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8521312511589086235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8521312511589086235'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/federal-regulators-release-model.html' title='Federal Regulators Release Model Consumer Privacy Notice Online Form Builder'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7375709186668917310</id><published>2010-04-09T14:04:00.003-04:00</published><updated>2010-04-09T14:11:21.225-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UK Data Protection Act'/><category scheme='http://www.blogger.com/atom/ns#' term='Virginia'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach fines'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='behavioral tracking'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>Privacy and Security Bits and Bytes</title><summary type='text'>Our Friday afternoon feature -- Virginia Adds Medical Information Breach Law - The Commonwealth of Virginia has amended its data breach notification law to include breaches of medical information.  For the text of the amendment, link here.   Even if the data is encrypted, the law requires notice if the breach involved a person with access to the encryption key.  The law requires notice to </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7375709186668917310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7375709186668917310'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/privacy-and-security-bits-and-bytes.html' title='Privacy and Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8930955386863590180</id><published>2010-04-08T17:37:00.002-04:00</published><updated>2010-04-08T17:39:14.199-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Mississippi Becomes 46th State to Enact Data Breach Notification Law</title><summary type='text'>It appears that Governor Haley Barbour has signed legislation sent to his desk by the Legislature on April 1, making Mississippi the 46th state to enact a data breach notification law.Similar to most of the other laws, the Mississippi law applies to any person who owns, licenses or maintains computerized personal information of any resident of that state.  Breaches must be disclosed “without </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8930955386863590180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8930955386863590180'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/mississippi-becomes-46th-state-to-enact.html' title='Mississippi Becomes 46th State to Enact Data Breach Notification Law'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8030941091622101984</id><published>2010-04-06T16:24:00.005-04:00</published><updated>2010-04-06T16:32:28.200-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='e-mail policy'/><category scheme='http://www.blogger.com/atom/ns#' term='New Jersey'/><category scheme='http://www.blogger.com/atom/ns#' term='acceptible use policy'/><category scheme='http://www.blogger.com/atom/ns#' term='employee handbooks'/><title type='text'>More on last week's NJ Supreme Court decision  -</title><summary type='text'>The decision we blogged about in this space last week is creating quite a bit of buzz in both privacy and employment law circles. My employment law colleagues in our New York office have authored an analysis of the decision here: Employment Alert: New Jersey Supreme Court Finds Privacy Rights in Employee E-MailsAnd, the International Association of Privacy Professionals' Daily Dashboard quoted my</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8030941091622101984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8030941091622101984'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/04/more-on-last-weeks-nj-supreme-court.html' title='More on last week&apos;s NJ Supreme Court decision  -'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2269560816702332731</id><published>2010-03-31T13:15:00.001-04:00</published><updated>2010-03-31T13:18:55.491-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='New Jersey'/><category scheme='http://www.blogger.com/atom/ns#' term='employee handbooks'/><category scheme='http://www.blogger.com/atom/ns#' term='Loving Care case'/><title type='text'>BREAKING NEWS:  NJ Court Upholds Employee E-mail Privacy</title><summary type='text'>In a precedent-setting decision, the New Jersey Supreme Court today ruled that a company should not have read e-mails a former employee sent to her lawyer from a private Web account through her employer's computer (See November 5, 2009 Privacy and Security Information blog post).  According to the Star-Ledger, the court, which determined the company's policy regarding e-mail use was vague, upheld</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2269560816702332731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2269560816702332731'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/breaking-news-nj-court-upholds-employee.html' title='BREAKING NEWS:  NJ Court Upholds Employee E-mail Privacy'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8658164709361855514</id><published>2010-03-30T13:43:00.004-04:00</published><updated>2010-03-30T16:34:47.866-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gonzalez'/><category scheme='http://www.blogger.com/atom/ns#' term='TJX'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='BJ&apos;s Wholesale'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Government "Outs" Mystery Retailers in Gonzalez Hack Case</title><summary type='text'>Interesting post in today’s Wired: Threat Level blog about a motion in the Alberto Gonzalez hacking case that was unsealed on Monday. We now have the identities of the other two “mystery” retailers – J.C. Penney was “Company A” and Wet Seal was “Company B.”J.C. Penney argued unsuccessfully last week to keep the company’s identity under seal, and that it (a corporation) was entitled to anonymity </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8658164709361855514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8658164709361855514'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/data-breach-du-jour-33-million-student.html' title='Government &quot;Outs&quot; Mystery Retailers in Gonzalez Hack Case'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1591393198742670825</id><published>2010-03-29T14:19:00.002-04:00</published><updated>2010-03-29T14:26:09.426-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gonzalez'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>More detail on Dave &amp; Buster's FTC Settlement</title><summary type='text'>As we blogged here last week, we were going to post our Client Alert with further details about the settlement and consent order reached by the restaurant chain Dave &amp; Buster's and the Federal Trade Commission relating to the breach suffered by the chain.  Here is the alert -- Privacy and Security Alert: Popular Restaurant Chain Settles Federal Trade Commission Data Breach Charges.Tip:  This </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1591393198742670825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1591393198742670825'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/more-detail-on-dave-busters-ftc.html' title='More detail on Dave &amp; Buster&apos;s FTC Settlement'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2606601383615982313</id><published>2010-03-29T14:10:00.003-04:00</published><updated>2010-03-30T16:47:35.381-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='E.U. data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='CNIL'/><category scheme='http://www.blogger.com/atom/ns#' term='France data protection'/><title type='text'>French Senate Passes Breach Notice Bill</title><summary type='text'>The French Senate has overwhelmingly approved a major draft bill updating the country's 1978 data protection act to, among other things, create the European Union's strongest breach notification requirement and expand powers of the French data protection authority, known as "CNIL."This bill also doubles monetary penalties for violations of the data protection law. It now moves on to the National </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2606601383615982313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2606601383615982313'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/french-senate-passes-breach-notice-bill.html' title='French Senate Passes Breach Notice Bill'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2129657419112605027</id><published>2010-03-26T15:24:00.003-04:00</published><updated>2010-03-26T15:25:25.604-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='password management'/><category scheme='http://www.blogger.com/atom/ns#' term='Washington state data breach law'/><category scheme='http://www.blogger.com/atom/ns#' term='copy machines'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><title type='text'>Privacy and Security Bits and Bytes</title><summary type='text'>Some news items for the last Friday in March -Another state has joined the Payment Card Industry Data Security Standard ("PCI") bandwagon.  On March 22, 2010, Washington state became the third state to incorporate the into law. The Washington House and Senate passed HB 1149 and it has been signed into law by the governor. HB 1149 amends Washington’s breach notice law (and borrows some of its </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2129657419112605027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2129657419112605027'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/privacy-and-security-bits-and-bytes_26.html' title='Privacy and Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8352816629620334192</id><published>2010-03-26T14:54:00.003-04:00</published><updated>2010-03-26T14:58:40.162-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><category scheme='http://www.blogger.com/atom/ns#' term='business associate'/><title type='text'>HHS Announces Delay in Enforcement of HITECH Rules as Applied to Business Associates</title><summary type='text'>As we have discussed before, HHS’s Office of Civil Rights has let it be known that a proposed rule implementing the HITECH Act’s privacy and security provisions as they apply to business associate liability is in the works. The proposed rule will also deal with new limitations on the sale of protected health information, marketing, and fundraising communications, and stronger individual rights to</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8352816629620334192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8352816629620334192'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/hhs-announces-delay-in-enforcement-of.html' title='HHS Announces Delay in Enforcement of HITECH Rules as Applied to Business Associates'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2592919436452461775</id><published>2010-03-26T10:19:00.003-04:00</published><updated>2010-03-26T10:21:47.048-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Restaurant Chain Settles FTC Data Breach Charges</title><summary type='text'>Yesterday, the Federal Trade Commission (“FTC”) weighed in with another proposed settlement agreement requiring that the Dave &amp; Buster's restaurant chain that experienced a massive data breach in 2007 establish and maintain a comprehensive information security program as a condition of settling a consumer protection action arising out of that data breach. This is the FTC’s 27th case challenging </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2592919436452461775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2592919436452461775'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/restaurant-chain-settles-ftc-data.html' title='Restaurant Chain Settles FTC Data Breach Charges'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7522684124215157692</id><published>2010-03-25T17:04:00.001-04:00</published><updated>2010-03-25T17:06:12.778-04:00</updated><title type='text'>TJX hacker sentenced to 20 years</title><summary type='text'>A computer hacker has been sentenced to 20 years in prison for helping engineer one of the largest thefts of credit and debit card numbers in US history.http://www.boston.com/business/ticker/2010/03/tjx_hacker_sent.html</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7522684124215157692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7522684124215157692'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/tjx-hacker-sentenced-to-20-years.html' title='TJX hacker sentenced to 20 years'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4763808961705069879</id><published>2010-03-24T15:56:00.002-04:00</published><updated>2010-03-24T15:58:08.659-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyberattacks'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><title type='text'>Senate Commerce Committee Approves Rockefeller-Snowe Cybersecurity Act</title><summary type='text'>We will post a link to the amended legislation as soon as it is released by the Committee.The Senate Commerce Committee press release --WASHINGTON, D.C.—Senator John D. (Jay) Rockefeller IV, Chairman of the U.S. Senate Committee on Commerce, Science, and Transportation, and Senator Olympia J. Snowe (R-ME), a senior member of the committee, issued the following statements today after the Commerce </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4763808961705069879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4763808961705069879'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/senate-commerce-committee-approves.html' title='Senate Commerce Committee Approves Rockefeller-Snowe Cybersecurity Act'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-970219215975546648</id><published>2010-03-24T15:01:00.003-04:00</published><updated>2010-03-24T15:06:44.388-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><title type='text'>Boston ranks 2nd in U.S. cyber-crime study</title><summary type='text'>A new study has Boston ranked No. 2 among U.S. cities as a "hotspot" of cybercrime.In a study published yesterday by California data security firm Symantec Corp. (Nasdaq: SYMC), Boston registered as the second-riskiest city in the U.S., after Seattle, due to its high concentration of cyber crimes and WiFi availability. Out of 50 cities spotlighted in the report, Boston narrowly missed the top </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/970219215975546648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/970219215975546648'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/boston-ranks-2nd-in-us-cyber-crime.html' title='Boston ranks 2nd in U.S. cyber-crime study'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8534440063168573722</id><published>2010-03-24T11:19:00.001-04:00</published><updated>2010-03-24T11:21:36.907-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><title type='text'>Quick Compliance Survey</title><summary type='text'>No, we're not "taking names" here.   This is just a 10-question survey to gauge some basic compliance metrics.   Please participate!Click here to take survey</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8534440063168573722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8534440063168573722'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/quick-compliance-survey.html' title='Quick Compliance Survey'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-3135084782391444035</id><published>2010-03-23T15:04:00.003-04:00</published><updated>2010-03-23T15:11:56.695-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyberattacks'/><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><title type='text'>International Cybercrime Reporting and Cooperation Act introduced this afternoon</title><summary type='text'>Senators Gillibrand and Hatch  this afternoon introduced their cybersecurity bill, the International Cybercrime Reporting and Cooperation Act. The complete text of the bill is not yet available online, but the press release does include the details of the bill, which include: (1) an annual Presidential report on the state of other countries' use of communication infrastructure and the extent of </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3135084782391444035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3135084782391444035'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/international-cybercrime-reporting-and.html' title='International Cybercrime Reporting and Cooperation Act introduced this afternoon'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-920487805628249987</id><published>2010-03-23T14:22:00.004-04:00</published><updated>2010-03-23T14:27:06.076-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='WISP'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><category scheme='http://www.blogger.com/atom/ns#' term='written information security plan'/><title type='text'>Massachusetts Data Security Compliance Workshop</title><summary type='text'>In case your data security compliance plan is stuck in neutral, you have questions, or you haven't started yet...there will be a free (!) breakfast hands-on workshop on Thursday in Tewksbury, MA."Massachusetts Data Protection Law: Demystifying the Details" is being sponsored by the Merrimack Valley Venture Forum. The Merrimack Valley Venture Forum has assembled a panel of legal, technology, and </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/920487805628249987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/920487805628249987'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/massachusetts-data-security-compliance.html' title='Massachusetts Data Security Compliance Workshop'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-376806215578318386</id><published>2010-03-15T15:49:00.002-04:00</published><updated>2010-03-15T15:50:20.532-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data mining'/><category scheme='http://www.blogger.com/atom/ns#' term='Maine'/><category scheme='http://www.blogger.com/atom/ns#' term='Maine marketing'/><title type='text'>Maine Legislative Committee Votes to Repeal Marketing Law Aimed at Minors</title><summary type='text'>We have blogged about the on-again, off-again, then on-again (but revised) Maine "Act to Prevent Predatory Marketing Practices Against Minors".   Well, it’s now off.   For good.  Last week, a Maine legislative committee voted to repeal the controversial online marketing law, which was widely seen as unconstitutional, that restricts the data that can be collected from minors in the state.The </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/376806215578318386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/376806215578318386'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/maine-legislative-committee-votes-to.html' title='Maine Legislative Committee Votes to Repeal Marketing Law Aimed at Minors'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2162170376004754060</id><published>2010-03-11T16:55:00.001-05:00</published><updated>2010-03-11T17:18:58.305-05:00</updated><title type='text'>Privacy and Security Bits and Bytes</title><summary type='text'>Our Friday afternoon feature is back  (albeit on Thursday due to schedule tomorrow) – a quick round-up of bits and bytes related to data privacy and security.Don't Ignore New Massachusetts Data Privacy Regs – a piece by Lora Bentley from ITBusinessEdge (for which the editor of this blog was interviewed)Your smart phone may soon be smarter than you’d like it to be: researchers in Japan have </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2162170376004754060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2162170376004754060'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/privacy-and-security-bits-and-bytes.html' title='Privacy and Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1632950148348427978</id><published>2010-03-11T15:41:00.001-05:00</published><updated>2010-03-11T15:46:28.238-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UK Data Protection Act'/><category scheme='http://www.blogger.com/atom/ns#' term='reporting of data breaches'/><category scheme='http://www.blogger.com/atom/ns#' term='costs of data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Big Fines Coming in UK for Data Breaches</title><summary type='text'>By Susan Foster, Mintz Levin LondonAs of April 6, 2010, the UK’s Information Commissioner’s Office (ICO) can levy fines of up to £500,000 for breaches of the Data Protection Act 1998 that are:• serious in nature• deliberate or reckless, and• likely to cause substantial damage or distress to an individual.The standard for “reckless” non-compliance may take some by surprise: Did the data controller</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1632950148348427978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1632950148348427978'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/big-fines-coming-in-uk-for-data.html' title='Big Fines Coming in UK for Data Breaches'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6315068764171684653</id><published>2010-03-10T11:17:00.000-05:00</published><updated>2010-03-10T11:18:02.587-05:00</updated><title type='text'>Another Potential Privacy Pitfall on Facebook</title><summary type='text'>Rumors are flying that Facebook will unveil a new geolocation sharing device next month. According to a post in  Bits Blog in the New York Times, you will be able to share your location with friends without updating your status.  Jared Newman in an article in PCWorld has a good point … “My gut reaction is nervousness….”Related LinksFacebook Updates May Share Your Location Soon - PCWorld</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6315068764171684653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6315068764171684653'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/another-potential-privacy-pitfall-on.html' title='Another Potential Privacy Pitfall on Facebook'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4944986011392799611</id><published>2010-03-09T14:17:00.002-05:00</published><updated>2010-03-09T14:19:23.099-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='settlement'/><title type='text'>Breaking News - ID Theft Company to Pay $12 Million for Deceptive Advertising</title><summary type='text'>“[E]nough holes that you could drive a truck through it…..”That’s how Federal Trade Commission Chairman Jon Leibowitz described the identity theft protection offered to consumers by the widely-advertised LifeLock product and the claims made by the company that its service provided comprehensive identity theft protection. Those claims have cost the company $12 million dollars in a settlement </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4944986011392799611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4944986011392799611'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/breaking-news-id-theft-company-to-pay.html' title='Breaking News - ID Theft Company to Pay $12 Million for Deceptive Advertising'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1228481113151152180</id><published>2010-03-04T13:32:00.003-05:00</published><updated>2010-03-04T13:35:24.230-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='Citibank'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Major "goof" at Citibank</title><summary type='text'>For all of you who have been struggling with data security compliance obligations from various fronts, and trying to handle complex technical issues such as encryption of portable devices and data "at rest" and "in transit" --- here is a very big story regarding plain old everyday mail.   If you are a Citibank customer, Citi may have printed your Social Security number on the outside of an </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1228481113151152180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1228481113151152180'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/major-goof-at-citibank.html' title='Major &quot;goof&quot; at Citibank'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2901801585728224918</id><published>2010-03-02T13:33:00.003-05:00</published><updated>2010-03-02T13:50:13.932-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wyndham Hotel'/><category scheme='http://www.blogger.com/atom/ns#' term='data theft'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Hotel Chain Hacked Again....</title><summary type='text'>Wyndham Hotels and Resorts has apparently notified the U.S. Secret Service and several state attorneys that hackers stole customer names and payment card information from its computer system. Wyndham has since notified credit card companies so that affected cardholders' accounts may be monitored. It also has hired a firm to investigate the breach and assist in data security improvements. This is </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2901801585728224918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2901801585728224918'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/hotel-chain-hacked-again.html' title='Hotel Chain Hacked Again....'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8465061817213293182</id><published>2010-03-01T12:30:00.002-05:00</published><updated>2010-03-01T12:37:58.357-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><title type='text'>Today is the day......</title><summary type='text'>After implementation delays and rule changes, new data protection regulations that are widely considered the most stringent in the nation take effect today. The Massachusetts data security regulations require institutions that hold personal data on Massachusetts citizens to encrypt that information and implement written data protection policies, reports the Boston Globe.Discussion continues and </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8465061817213293182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8465061817213293182'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/03/today-is-day.html' title='Today is the day......'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8438491093775849899</id><published>2010-02-26T14:39:00.004-05:00</published><updated>2010-02-26T15:11:33.606-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='data protection'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>Top 3 questions relating to compliance with 201 CMR 17.00</title><summary type='text'>At the beginning of the "countdown" to the March 1st effective date of 201 CMR 17.00, we offered some posts with "misapprehensions" and compliance suggestions (see  16 Days to March 1..... and Countdown to compliance with 201 CMR 17.00.....11 days).    Here are some questions that have been reoccurring over the last few weeks:1)  What should I be doing about the requirement relating to third </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8438491093775849899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8438491093775849899'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/top-3-questions-relating-to-compliance.html' title='Top 3 questions relating to compliance with 201 CMR 17.00'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4257147346229154336</id><published>2010-02-26T14:29:00.005-05:00</published><updated>2010-02-26T14:36:54.285-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>And, it's Friday, February 26th......</title><summary type='text'>And that means today is the last business day before the new Massachusetts data security regulations go live-- as Jim Cramer would say, "That's 201 CMR 17.00 for all you home gamers."</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4257147346229154336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4257147346229154336'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/and-its-friday-february-26th.html' title='And, it&apos;s Friday, February 26th......'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1891373194252265094</id><published>2010-02-25T13:00:00.000-05:00</published><updated>2010-02-25T13:01:20.077-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Italy'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='criminal trial'/><title type='text'>“Stunning”/ “Shear Madness”  – Reaction to Google Convictions</title><summary type='text'>The reactions are coming in fast and furious to yesterday’s conviction of three Google executives in an Italian court.  Linked here are just a few of the more than 1,000 media stories on the decision so far.Google privacy convictions in Italy spark outrageLarger Threat Is Seen in Google Case - NYTimes.comConviction of Google Execs in Italy Shear MadnessKerry: Sending Google execs to prison '</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1891373194252265094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1891373194252265094'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/stunning-shear-madness-reaction-to.html' title='“Stunning”/ “Shear Madness”  – Reaction to Google Convictions'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8818529800735130180</id><published>2010-02-24T10:01:00.002-05:00</published><updated>2010-02-24T10:03:50.597-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Italy'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='criminal trial'/><title type='text'>BREAKING NEWS:  Google Executives Convicted on Privacy Charges in Italy</title><summary type='text'>In the first case of its kind, an Italian judge today convicted three Google executives on privacy violations in Milan court. Global Privacy Counsel Peter Fleischer, Chief Legal Officer David Drummond, and another executive were found guilty of failing to comply with Italian privacy code in allowing a disparaging video to be posted online. A fourth defendant was acquitted. All three will appeal </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8818529800735130180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8818529800735130180'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/breaking-news-google-executives.html' title='BREAKING NEWS:  Google Executives Convicted on Privacy Charges in Italy'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4370726663217485693</id><published>2010-02-22T22:01:00.002-05:00</published><updated>2010-02-22T22:04:33.107-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='breach liability'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='reporting of data breaches'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Today's compliance deadline - Enforcement of the HITECH/HIPAA data breach notification rule</title><summary type='text'>February and March are just full of significant deadlines for privacy/security reporting and compliance.Today is the day that the Health &amp; Human Services Office of Civil Rights begins to enforce the HITECH/HIPAA data breach notification rule.  To "celebrate" the occasion, the agency publicly posted the first list of reported breaches affecting 500 or more individuals. The list is available on the</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4370726663217485693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4370726663217485693'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/todays-compliance-deadline-enforcement.html' title='Today&apos;s compliance deadline - Enforcement of the HITECH/HIPAA data breach notification rule'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4120422433350669944</id><published>2010-02-22T16:22:00.001-05:00</published><updated>2010-02-22T16:25:24.215-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><title type='text'>HITECH Act Compliance Date Arrived -- Without the Promised Regulatory Guidance</title><summary type='text'>We have been so focused on the upcoming Massachusetts data security deadline, that we let one last week go without fanfare.   As we have gently reminded you on several occasions, the new HIPAA privacy and security rules contained in the Health Information Technology for Clinical and Economic Health Act (HITECH) became effective on February 17th.The HITECH Act was passed as part of the “Stimulus </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4120422433350669944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4120422433350669944'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/hitech-act-compliance-date-arrived.html' title='HITECH Act Compliance Date Arrived -- Without the Promised Regulatory Guidance'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-297931813928543344</id><published>2010-02-22T14:34:00.003-05:00</published><updated>2010-02-22T14:41:52.065-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>T Minus 10,080 Minutes and Counting.....</title><summary type='text'>We have just one week to go before all entities that own, store, license -- or basically do anything with -- personal information of Massachusetts residents must comply with the Commonwealth's new data security regulations. Things to consider:Have you done your risk assessment? Looked at what you collect and how you collect and how it is transmitted through and outside your organization?Have you </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/297931813928543344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/297931813928543344'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/t-minus-10080-minutes-and-counting.html' title='T Minus 10,080 Minutes and Counting.....'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2879618944087825850</id><published>2010-02-17T11:23:00.004-05:00</published><updated>2010-02-17T11:36:44.630-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><title type='text'>Countdown to compliance with 201 CMR 17.00.....11 days</title><summary type='text'>As we approach the 10 day mark to the March 1 effective date of the Massachusetts data security regulations,  201 CMR 17.00, we thought that we would share another misapprehension in the ever-growing list."I ordered one of those $99 "Compliance Kits" from the Internet, and they say that they will "certify" that I am compliant.  I should be all set."You might be -- but then again, we are not sure </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2879618944087825850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2879618944087825850'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/countdown-to-compliance-with-201-cmr.html' title='Countdown to compliance with 201 CMR 17.00.....11 days'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5650669347975290799</id><published>2010-02-11T12:50:00.002-05:00</published><updated>2010-02-11T13:01:37.781-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>16 Days to March 1.....</title><summary type='text'>Just in case you missed it, March 1 is the deadline for compliance with 201 CMR 17.00, the new Massachusetts data security regulations, and we published a client alert last week as a "reminder"... Privacy and Security Alert.In addition to the top five "misapprehensions" about the applicability of the new regulations that we included in the Privacy and Security Alert, here are a couple of others:"</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5650669347975290799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5650669347975290799'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/16-days-to-march-1.html' title='16 Days to March 1.....'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6749090410574755200</id><published>2010-02-11T09:09:00.001-05:00</published><updated>2010-02-11T09:11:11.210-05:00</updated><title type='text'>New Facebook privacy lawsuits</title><summary type='text'>Facebook has been hit with two new potential class-action lawsuits stemming from recent revisions to its privacy settings.The cases, filed recently in federal district court in San Jose, Calif. on behalf of nine Facebook users, allege that the new settings are "confusing and materially deceptive" and lessened their privacy.   "Facebook has violated the privacy rights of the members of the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6749090410574755200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6749090410574755200'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/new-facebook-privacy-lawsuits.html' title='New Facebook privacy lawsuits'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5843139549744045573</id><published>2010-02-01T23:36:00.003-05:00</published><updated>2010-02-01T23:41:06.639-05:00</updated><title type='text'>Roundtable data privacy and security discussions on YouTube</title><summary type='text'>See a series of Data &amp; IT Security Roundtable discussions with thought leaders: www.youtube.com/user/JaxsonGroup</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5843139549744045573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5843139549744045573'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/roundtable-data-privacy-and-security.html' title='Roundtable data privacy and security discussions on YouTube'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6483406384404371135</id><published>2010-02-01T16:08:00.002-05:00</published><updated>2010-02-01T16:14:42.265-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cookies'/><category scheme='http://www.blogger.com/atom/ns#' term='user consent'/><title type='text'>Tracking the cookie crumbs</title><summary type='text'>Disabling cookies may not be the answer to controlling your online identity.  Regardless of whether you have cookies enabled or not, Web sites collect certain amounts of operational information about your browser.   The Electronic Frontier Foundation has detailed how companies can use browser-configuration information to identify users, and also launched a new project, Panopticlick, aimed at </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6483406384404371135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6483406384404371135'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/tracking-cookie-crumbs.html' title='Tracking the cookie crumbs'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-648761666652876669</id><published>2010-02-01T14:02:00.002-05:00</published><updated>2010-02-01T14:13:39.394-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><category scheme='http://www.blogger.com/atom/ns#' term='comp'/><title type='text'>27 days and counting...</title><summary type='text'>March 1st is the deadline for compliance with the Massachusetts data security regulations, 201 CMR 17.00.   We have blogged incessantly for months about the need to get compliance programs into gear and develop information security plans as required by the regulations.   The time is here.If you are one of the procrastinators (and, you are not alone), the basic information and the regulations can </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/648761666652876669'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/648761666652876669'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/02/27-days-and-counting.html' title='27 days and counting...'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4905720254095610830</id><published>2010-01-28T22:06:00.002-05:00</published><updated>2010-01-28T22:06:59.149-05:00</updated><title type='text'>Interesting perspective on Data Privacy Day and data privacy in general</title><summary type='text'>Declan McCullagh is always a good read -It's been 10 years: Why won't people pay for privacy?  Politics and Law - CNET News</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4905720254095610830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4905720254095610830'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/interesting-perspective-on-data-privacy.html' title='Interesting perspective on Data Privacy Day and data privacy in general'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4569163669835277256</id><published>2010-01-28T16:20:00.005-05:00</published><updated>2010-01-28T16:28:26.047-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='E.U. data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic discovery'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>Data Privacy Day -- Tip #4 -- Transactional Best Practices for Lawyers</title><summary type='text'>Written by Michael Arnold and Jennifer RubinEven though lawyers working on both sides of an M&amp;A transaction during the due diligence phase might immerse themselves in a “confidentiality bubble”, they still must be careful not to disclose or access confidential employee information in the course of that transaction. Attorneys evaluating potential transactions might be tempted to access information</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4569163669835277256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4569163669835277256'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/data-privacy-day-tip-4-transactional.html' title='Data Privacy Day -- Tip #4 -- Transactional Best Practices for Lawyers'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7004909989406689068</id><published>2010-01-28T15:49:00.003-05:00</published><updated>2010-01-28T15:56:16.671-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='employee theft'/><title type='text'>Data Privacy Day - Tip #3 - The weakest link??</title><summary type='text'>My lunchtime speaking engagement was at the International Association of Privacy Professional's Boston KnowledgeNet.   I had the pleasure to share the panel with Mike Spinney from SixWeight (www.sixweight.com) and identity theft guru  Robert Siciliano.  We had a spirited discussion about privacy training and awareness.    You can access their blogs in the panel to the right.Our conclusion -- </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7004909989406689068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7004909989406689068'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/data-privacy-day-tip-3-weakest-link.html' title='Data Privacy Day - Tip #3 - The weakest link??'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2382408278236786653</id><published>2010-01-28T14:20:00.002-05:00</published><updated>2010-01-28T14:26:20.035-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='behavioral advertising'/><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='cable'/><title type='text'>Happy Data Privacy Day!   Post #3 - Cable/Online Behavioral Advertising Issues</title><summary type='text'>Earlier this week, Mintz Levin’s Chris Harvie, a Member in the Communications section, spoke at the PLI Broadband and Cable Industry Law Seminar in New York City.  Chris provided an overview of the cable privacy provisions found in Title VI of the Communications Act and discussed the restrictions and obligations that apply to the collection and use of personally identifiable information (PII) by </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2382408278236786653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2382408278236786653'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/happy-data-privacy-day-post-3.html' title='Happy Data Privacy Day!   Post #3 - Cable/Online Behavioral Advertising Issues'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6097746486308627822</id><published>2010-01-28T14:11:00.002-05:00</published><updated>2010-01-28T14:18:11.949-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><title type='text'>Data Privacy Day Tip #2 - HITECH Act</title><summary type='text'>Written by Dianne BourqueEffective February 17, 2010, significant new compliance obligations will be imposed on business associates through the HITECH provisions of the American Recovery and Reinvestment Act of 2009 ("ARRA").  Business associates (or organizations that use or disclose protected health information on behalf of covered entities subject to HIPAA) will be directly liable for </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6097746486308627822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6097746486308627822'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/data-privacy-day-tip-2-hitech-act.html' title='Data Privacy Day Tip #2 - HITECH Act'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-2318623465647556922</id><published>2010-01-28T10:03:00.003-05:00</published><updated>2010-01-28T14:18:57.539-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data Privacy Day'/><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='E.U. data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>Happy Data Privacy Day! Tip #1</title><summary type='text'>Today is worldwide Data Privacy Day. What is your company doing to promote data privacy and security in your enterprise? I'll be participating in a KnowledgeNet in Boston, sponsored by the International Association of Privacy Professionals. The discussion topic is Privacy Awareness and Training.And don’t forget, the March 1 deadline for compliance with the sweeping Massachusetts data security </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2318623465647556922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/2318623465647556922'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/happy-data-privacy-day.html' title='Happy Data Privacy Day! Tip #1'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7451328334752811432</id><published>2010-01-15T11:31:00.002-05:00</published><updated>2010-01-28T14:19:57.860-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='HITECH Act'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><title type='text'>Connecticut Attorney General Brings Charges Against Health Net for HIPAA Violations</title><summary type='text'>Written by Dianne Bourque&lt;?xml:namespace prefix = o /&gt;On January 13, Connecticut Attorney General Richard Blumenthal filed charges against Health Net of Connecticut, Inc., for violating federal privacy law. Blumenthal is the first state attorney general to file such a suit using HIPAA enforcement authority granted to states under the HITECH provisions of the American Recovery and Reinvestment Act</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7451328334752811432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7451328334752811432'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/written-by-dianne-bourque.html' title='Connecticut Attorney General Brings Charges Against Health Net for HIPAA Violations'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1297575595176461988</id><published>2010-01-11T11:02:00.002-05:00</published><updated>2010-01-11T11:04:10.525-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='costs of data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Visa'/><category scheme='http://www.blogger.com/atom/ns#' term='bank card issuers'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Securities and Exchange Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='Heartland'/><title type='text'>New Settlement Agreement in Heartland Breach</title><summary type='text'>And the cash register continues to ring with respect to the Heartland Payment Systems Inc. breach. Heartland disclosed last week in a filing with the Securities and Exchange Commission that it has agreed to pay a maximum of $60 million to Visa Inc. and Visa card-issuing banks to settle claims arising out of the massive payment card data breach last January.The proposed settlement is conditioned </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1297575595176461988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1297575595176461988'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/new-settlement-agreement-in-heartland.html' title='New Settlement Agreement in Heartland Breach'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8485651482154308408</id><published>2010-01-08T14:11:00.003-05:00</published><updated>2010-01-08T14:29:39.831-05:00</updated><title type='text'>Security Bits and Bytes</title><summary type='text'>A few items to wrap up/review privacy and security issues in 2009 and open up 2010:Gonzalez Pleads Guilty in December 2009 - but this piece from Retail Research Systems explains why retailers should not be sanguine about data security: Privacy Risks for 2010RFID in 2010: The New Hampshire House of Representatives voted this week to prohibit the implantation of tracking devices in humans without </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8485651482154308408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8485651482154308408'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/security-bits-and-bytes.html' title='Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-3747090511907997365</id><published>2010-01-07T14:10:00.001-05:00</published><updated>2010-01-07T14:12:17.953-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data mining'/><category scheme='http://www.blogger.com/atom/ns#' term='minors'/><category scheme='http://www.blogger.com/atom/ns#' term='Maine marketing'/><title type='text'>Maine - New Year, New Legislative Session, New Version of the Marketing to 'Tweens Law</title><summary type='text'>As promised last year, the Maine legislative session opened this week with the introduction of a new predatory marketing bill--LD 1677. This bill would repeal the beleaguered LD 1883, which was signed to law last year, but faced major opposition from industry groups, leading Maine's attorney general to promise not to enforce the law. The new bill applies to online information only and is limited </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3747090511907997365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3747090511907997365'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/maine-new-year-new-legislative-session.html' title='Maine - New Year, New Legislative Session, New Version of the Marketing to &apos;Tweens Law'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6134789250846543229</id><published>2010-01-06T10:17:00.004-05:00</published><updated>2010-01-06T10:21:55.846-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Social Security numbers'/><category scheme='http://www.blogger.com/atom/ns#' term='records retention'/><category scheme='http://www.blogger.com/atom/ns#' term='document retention'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach notification'/><title type='text'>Happy 2010 - Data Breach du Jour</title><summary type='text'>We are just barely into the new year, and there is already a rather large data breach to report. Officials at Eastern Washington University (EWU) are notifying up to 130,000 current and former students that their personal information may have been exposed in a security breach, reports the Seattle Times. The data involved includes names, Social Security numbers and dates of birth for students </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6134789250846543229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6134789250846543229'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/happy-2010-data-breach-du-jour.html' title='Happy 2010 - Data Breach du Jour'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4463443980704424794</id><published>2010-01-04T15:05:00.001-05:00</published><updated>2010-01-06T11:38:19.657-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='electronic health records'/><category scheme='http://www.blogger.com/atom/ns#' term='EHR'/><title type='text'>New Regulations Propose a Definition of 'Meaningful Use'</title><summary type='text'>Written by DianneOn December 30, 2009, the Centers for Medicare &amp; Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued interim final rules necessary to implement electronic health record (EHR) incentive programs enacted under the American Recovery and Reinvestment Act of 2009. The ONC rule sets initial standards, implementation </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4463443980704424794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4463443980704424794'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/new-regulations-propose-definition-of.html' title='New Regulations Propose a Definition of &apos;Meaningful Use&apos;'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1267408151212647057</id><published>2010-01-04T15:01:00.002-05:00</published><updated>2010-01-04T15:04:57.506-05:00</updated><title type='text'>Happy New Year - New Health Care Reform Issues</title><summary type='text'>Now that it is 2010, we will be getting back up to speed with our blog postings, bringing you the latest in the world of privacy and security information. The world of health care reform also has significant impact on all of us, and my colleagues here at Mintz published an important advisory right at the stroke of midnight -- Health Care Reform Advisory: Assessing the Impact of Federal Health </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1267408151212647057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1267408151212647057'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2010/01/happy-new-year-new-health-care-reform.html' title='Happy New Year - New Health Care Reform Issues'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4577038770900573315</id><published>2009-12-22T12:45:00.004-05:00</published><updated>2009-12-22T12:47:37.680-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='data security safeguards'/><category scheme='http://www.blogger.com/atom/ns#' term='costs of data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>Data Security Roundtable</title><summary type='text'>Here is a link to a couple of segments of a data security roundtable I participated in not long ago:http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&amp;newsId=20091222005345&amp;newsLang=enSome very interesting discussions with folks who are on the cutting edge of data security.  I'll post the other segments as they are released.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4577038770900573315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4577038770900573315'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/data-security-roundtable.html' title='Data Security Roundtable'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4979811730944018538</id><published>2009-12-21T11:26:00.003-05:00</published><updated>2009-12-21T11:29:44.477-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='payment systems'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Securities and Exchange Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='Heartland'/><title type='text'>The real cost of data breaches - Heartland to pay Amex $3.5 million</title><summary type='text'>According to its 8-K filing with the Securities and Exchange Commission (SEC), Heartland Payment Systems Inc. has agreed to pay American Express Travel Related Services Co. Inc. just over $3.5 million to settle any claims arising out of a massive payment card data breach.This settlement is likely to be only the first over the compromise of tens of millions of debitand credit card accounts by </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4979811730944018538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4979811730944018538'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/real-cost-of-data-breaches-heartland-to.html' title='The real cost of data breaches - Heartland to pay Amex $3.5 million'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6290334325591085900</id><published>2009-12-16T15:42:00.002-05:00</published><updated>2009-12-16T15:46:24.080-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SCOTUS'/><category scheme='http://www.blogger.com/atom/ns#' term='Supreme Court'/><category scheme='http://www.blogger.com/atom/ns#' term='workplace privacy'/><title type='text'>More Detail on Quan Case</title><summary type='text'>My colleague, Martha Zackin, has published a more extensive discussion of the issues before the U.S. Supreme Court in the Quan case --ELB Law Information: Supreme Court to Hear Case re Employer's Access to Employee's Text Messages</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6290334325591085900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6290334325591085900'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/more-detail-on-quan-case.html' title='More Detail on Quan Case'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-89967788712594021</id><published>2009-12-15T09:33:00.005-05:00</published><updated>2009-12-15T09:40:01.693-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Stored Communications Act'/><category scheme='http://www.blogger.com/atom/ns#' term='SCOTUS'/><category scheme='http://www.blogger.com/atom/ns#' term='Fourth Amendment'/><category scheme='http://www.blogger.com/atom/ns#' term='Supreme Court'/><category scheme='http://www.blogger.com/atom/ns#' term='workplace privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Quon'/><title type='text'>Supreme Court will review some issues in Quon Case, denied review to other issues</title><summary type='text'>Some additional information on yesterday's post regarding the Supreme Court's decision to hear the Quon case. The high Court agreed to hear some, but not all of the issues presented by the Ninth Circuit decision in the case.The Court will consider whether a police sergeant assigned to a SWAT team had a reasonable expectation of privacy under the Fourth Amendment in text messages transmitted on a </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/89967788712594021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/89967788712594021'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/supreme-court-will-review-some-issues.html' title='Supreme Court will review some issues in Quon Case, denied review to other issues'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5319368530467766274</id><published>2009-12-14T15:53:00.001-05:00</published><updated>2009-12-14T15:59:12.209-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UK Data Protection Act'/><title type='text'>Good data protection sense from the Brits</title><summary type='text'>The UK's Information Commissioner's Office (ICO) has done what the Federal Trade Commission should do -- produced a no-nonsense Guide to Data Protection.   This Guide is intended to provide small and medium sized enterprises with practical advice about the UK's Data Protection Act and takes a straightforward look at the data protection principles, using practical, business-based examples.   It </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5319368530467766274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5319368530467766274'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/good-data-protection-sense-from-brits.html' title='Good data protection sense from the Brits'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6859250842935970645</id><published>2009-12-14T12:41:00.003-05:00</published><updated>2009-12-14T15:52:59.406-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='workplace privacy'/><title type='text'>Supreme Court To Decide Privacy of Employee Texts</title><summary type='text'>U.S. Supreme Court this morning decided to hear a case on the privacy of employee text messages sent on employer-provided devices, reports the Washington Post (see below).The case--City of Ontario v. Quon--could have profound implications on employee privacy rights, according to a Baltimore Sun report. It involves an Ontario, California police officer who sent sexually explicit messages to </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6859250842935970645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6859250842935970645'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/supreme-court-to-decide-privacy-of.html' title='Supreme Court To Decide Privacy of Employee Texts'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7547866328469131662</id><published>2009-12-08T10:55:00.003-05:00</published><updated>2009-12-08T10:57:54.785-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='online data'/><category scheme='http://www.blogger.com/atom/ns#' term='cell phone'/><title type='text'>National Public Radio 3-part special series on privacy</title><summary type='text'>These are from October, but if you missed them, they are worth a look (or downloading the podcasts) --Part 1: Online Data Present a Privacy MinefieldPart 2: Is Your Facebook Profile as Private as You Think?Part 3: Digital Bread Crumbs: Following Your Cell Phone Trail</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7547866328469131662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7547866328469131662'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/national-public-radio-3-part-special.html' title='National Public Radio 3-part special series on privacy'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1980966213692939577</id><published>2009-12-08T10:09:00.003-05:00</published><updated>2009-12-08T10:13:38.367-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='consumer privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><category scheme='http://www.blogger.com/atom/ns#' term='cell phone'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><title type='text'>Holiday Privacy Watch: Take care before you donate that cell phone</title><summary type='text'>During the holiday season, many organizations are soliciting donations of old cell phones to be repurposed.   This is an excellent way to "reuse, reduce, and recycle" and puts those useless (to you) items to use in a positive way, but please remember -- important and private data reside in your cell phone's internal memory, even if your phone has a removable SIM card.    PINs, passwords and other</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1980966213692939577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1980966213692939577'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/holiday-privacy-watch-take-care-before.html' title='Holiday Privacy Watch: Take care before you donate that cell phone'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-8817869327913992990</id><published>2009-12-07T10:26:00.000-05:00</published><updated>2009-12-07T10:27:40.732-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data protection'/><category scheme='http://www.blogger.com/atom/ns#' term='consumer privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='congress'/><title type='text'>House scheduled to act today on several privacy bills</title><summary type='text'>The House is scheduled to vote on HR 1319, The Informed P2P User Act, and HR 2221, The Data Accountability and Trust Act, tomorrow under suspension of the rules.  We will monitor the debate and keep you updated on its passage.</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8817869327913992990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/8817869327913992990'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/house-scheduled-to-act-today-on-several.html' title='House scheduled to act today on several privacy bills'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-1958463133532333586</id><published>2009-12-07T09:56:00.002-05:00</published><updated>2009-12-07T10:00:32.821-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='behavioral advertising'/><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='consumer privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='expectation of privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='social networking; Facebook; online advertising; behavioral targeting'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><title type='text'>Federal Trade Commission hosts privacy roundtable today</title><summary type='text'>The FTC kicks off the first in a series of "roundtable" discussions to explore privacy challenges posed by 21st technology and business practices that collect and use consumer data.  Today's roundtable is being held in Washington, DC, and will focus on data collection, use and retention, consumer expectations of privacy, online behavioral advertising, information brokers and a discussion </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1958463133532333586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/1958463133532333586'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/federal-trade-commission-hosts-privacy.html' title='Federal Trade Commission hosts privacy roundtable today'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-7426009274727138270</id><published>2009-12-04T11:08:00.004-05:00</published><updated>2009-12-04T11:15:06.325-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='social networking; Facebook; online advertising; behavioral targeting'/><title type='text'>Privacy and Security Bits and Bytes</title><summary type='text'>The Most Wonderful Time of the Year -- It's time for the annual "top ten" lists.  Information Security Resources has posted an article that is eye-opening reading with respect to data breaches in 2009.   Ten Most Damaging Data Breaches of 2009 U.S. to Join Fingerprint Sharing -- CBC News - Canada reports that the U.S. will join Canada, Australia and Britain in sharing fingerprints and other data </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7426009274727138270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/7426009274727138270'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/privacy-and-security-bits-and-bytes.html' title='Privacy and Security Bits and Bytes'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6188424658545420963</id><published>2009-12-03T09:48:00.005-05:00</published><updated>2009-12-03T09:56:43.814-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='Red Flag'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><category scheme='http://www.blogger.com/atom/ns#' term='attorney-client privilege'/><title type='text'>Court issues written opinion explaning decision regarding applicability of Red Flags Rule to attorneys</title><summary type='text'>As we first blogged here, hours before the last Red Flags enforcement deadline, a federal court judge in the D.C. Circuit ruled from the bench that attorneys would not be subject to the Red Flags Rule. The court released Judge Walton's written opinion was released on December 1, 2009, which provides clarification of his comments from the bench. Click here for the opinion. Walton found the Federal</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6188424658545420963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6188424658545420963'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/12/court-issues-written-opinion-explaning.html' title='Court issues written opinion explaning decision regarding applicability of Red Flags Rule to attorneys'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-3424880231763604183</id><published>2009-11-13T16:09:00.002-05:00</published><updated>2009-11-13T16:11:14.826-05:00</updated><title type='text'>Breakfast and social media policies</title><summary type='text'>Related to the last post -- is your company working on its social media employee policy?  If not, you should be.   If you happen to be in Boston, Mintz Levin is hosting a breakfast briefing on social media in the workplace next week.Register here</summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3424880231763604183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/3424880231763604183'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/11/breakfast-and-social-media-policies.html' title='Breakfast and social media policies'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6076774275274663463</id><published>2009-11-13T15:14:00.006-05:00</published><updated>2009-11-13T16:17:04.844-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='expectation of privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='blogging'/><category scheme='http://www.blogger.com/atom/ns#' term='Twitter'/><category scheme='http://www.blogger.com/atom/ns#' term='social networking; Facebook'/><title type='text'>Some startling statistics regarding social networking issues in the workplace......</title><summary type='text'>You might be surprised to know that social networking policies, governing employee use of blogging, Facebook, Twitter and the like, are still a rarity at many business, including teaching hospitals. And, you might be equally surprised to hear that studies are revealing that medical students are displaying cavalier attitudes towards the protection of patient confidentiality.The Journal of the </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6076774275274663463'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6076774275274663463'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/11/have-you-looked-at-your-social.html' title='Some startling statistics regarding social networking issues in the workplace......'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-5378177248412909099</id><published>2009-11-12T16:34:00.001-05:00</published><updated>2009-11-12T16:37:13.768-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Massachusetts data security regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='201 CMR 17.00'/><title type='text'>Massachusetts Attorney General proposes privacy regulations to apply to her office</title><summary type='text'>Written by Cynthia and ElissaAn oft-cited criticism of the Massachusetts data security regulations (201 CMR 17.00), effective March 1, 2010, is that the regulations specifically do not apply to government entities -- the only reason being that the Office of Consumer Affairs and Business Regulation does not have the authority or jurisdiction to enact regulations over governmental entities in </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5378177248412909099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/5378177248412909099'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/11/massachusetts-attorney-general-proposes.html' title='Massachusetts Attorney General proposes privacy regulations to apply to her office'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-4927465590485742283</id><published>2009-11-10T13:54:00.004-05:00</published><updated>2009-11-10T13:58:25.430-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='state education departments'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='personal information'/><category scheme='http://www.blogger.com/atom/ns#' term='student information'/><title type='text'>Remember the school-days admonition that something might end up on your "permanent record"?</title><summary type='text'>A Fordham Law School study found that state educational databases across the country have severely inadequate privacy protections for the nation's school children. The study, prepared by the Center on Law and Information Policy, reports that at least 32% of states warehouse children's social security numbers; at least 22% of states record student pregnancies; and at least 46% of the states track </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4927465590485742283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/4927465590485742283'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/11/remember-school-days-admonition-that.html' title='Remember the school-days admonition that something might end up on your &quot;permanent record&quot;?'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3645697380824919280.post-6230922041097360001</id><published>2009-11-09T14:39:00.003-05:00</published><updated>2009-11-09T14:44:44.068-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='employee privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='workplace privacy'/><title type='text'>When employee handbooks don't tell the whole story.....</title><summary type='text'>Written by Cynthia and JenniferThe discussion of employer access to employee emails in our September 21 blog entry continues with another appellate court decision about workplace privacy rights.  In Stengart v. Loving Care Agency, Inc., the court completely rejected an employer's attempt to rely upon an email policy to gain access to an employee's confidential communications with her attorney </summary><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6230922041097360001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3645697380824919280/posts/default/6230922041097360001'/><link rel='alternate' type='text/html' href='http://privacyandsecuritymatters.blogspot.com/2009/11/when-employee-handbooks-dont-tell-whole.html' title='When employee handbooks don&apos;t tell the whole story.....'/><author><name>Cynthia</name><uri>http://www.blogger.com/profile/02952358185499075658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://3.bp.blogspot.com/_-vSGrIkXG1E/SghioYt79FI/AAAAAAAAAAM/f2zArmCvCik/S220/CJLarose.jpg'/></author></entry></feed>
