Friday, October 22, 2010

We've moved! Note our URL change!

After a "summer hiatus," we have relaunched the Privacy and Security MATTERS Blog on a new platform.

Note our new blog address and make sure to change your favorites to reflect the same.

http://www.privacyandsecuritymatters.com/

If you are prompted by a browser security warning to accept the URL redirection, please accept by clicking yes.

Friday, August 6, 2010

Patient privacy group welcomes HHS withdrawal of HITECH Act breach notification rule

The Patient Privacy Rights Foundation welcomed last week’s announcement by the Department of Health and Human Services (HHS) that it was withdrawing the health data breach notification rule.

The Foundation called the withdrawal a "huge step in the right direction" and reiterated its disappointment with the 'harm threshold' provision, which allows health care providers to conduct a risk assessment of any data breach, before deciding whether it is necessary to report the breach to HHS. "The broad discretion granted to industry goes far beyond Congressional intent", read the Foundation's submission sent to HHS during the 2009 public comment period. "There was no mention of any consideration of a harm standard in HHS previous Request for Information, thus thwarting any opportunity for public debate." Several Congressmen also submitted comments to the HHS, expressing concerns over the breadth of discretion that would be given to companies, "particularly with regard to determining something as subjective as harm from the release of sensitive and personal information."

HHS is expected to publish a final rule in the Federal Register in the coming months.

Friday, July 30, 2010

Online Behavioral Advertising: The European Union Controversy

On June 24, 2010, the European Union's body that addresses data protection issues, the so-called Article 29 Working Party, adopted Opinion 2/2010 (the “Opinion”) providing further clarification on the amended e-Privacy Directive (below) as applied to online behavioral advertising. The Working Party also issued a press release on this topic.

Although the scope of the Opinion is limited to online profiling, its interpretation of Article 5(3) of the amended e-Privacy Directive provides some useful clarifications regarding the legal framework applicable to online behavioral advertising and the use of cookies. There has been much heat generated by the Directive and the Opinion, and little light. Our friends at Osborne Clarke have published an excellent overview.

Read Regulating Online Behavioural Advertising for some insight into the discussion. U.S.-based online businesses will need to start paying close attention to this - the global nature of the Internet means that the actions of the Article 29 Working Party will have significant ripple effects here.

HHS Withdraws Breach Notification Final Rule (but breach notification still effective)

Interesting press release from the Department of Health and Human Services (HHS) relating to the HITECH Breach Notification Final Rule. The Interim Final Rule is still effective, but one can't help but wonder what HHS may be reconsidering given the numbers of breaches reported since September 2009.


Breach Notification Final Rule Update

The Interim Final Rule for Breach Notification for Unsecured Protected Health Information, issued pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act, was published in the Federal Register on August 24, 2009, and became effective on September 23, 2009. During the 60-day public comment period on the Interim Final Rule, HHS received approximately 120 comments.

HHS reviewed the public comment on the interim rule and developed a final rule, which was submitted to the Office of Management and Budget (OMB) for Executive Order 12866 regulatory review on May 14, 2010. At this time, however, HHS is withdrawing the breach notification final rule from OMB review to allow for further consideration, given the Department's experience to date in administering the regulations. This is a complex issue and the Administration is committed to ensuring that individuals' health information is secured to the extent possible to avoid unauthorized uses and disclosures, and that individuals are appropriately notified when incidents do occur. We intend to publish a final rule in the Federal Register in the coming months.

Wednesday, July 28, 2010

Improper Disposal Costs Rite Aid $1 Million

Written by Dianne Bourque

Rite Aid has agreed to pay $1 million to settle allegations that it violated HIPAA by disposing of labeled pill bottles in unsecured dumpsters accessible to the public. The $1 million fine settles a joint Office of Civil Rights (OCR)/Federal Trade Commission (FTC) investigation prompted by televised media reports of pharmacies disposing of pill bottles containing patient information. Rite Aid and several other retail pharmacies in cities throughout the United Sates were highlighted in the report.

The improper disposal of patient labels violates the HIPAA Privacy Rule (not the security rule, because the labels are paper) and exposes patients to the risk of identity theft and other crimes.

In addition to paying the $1 million resolution amount to OCR, Rite Aid has agreed to implement “a strong corrective action program” including:

· Revising its policies and procedures related to the disposal of PHI and sanctioning workers who do not follow them

· Training workforce members on new policies and procedures

· Conducting internal monitoring

· Engaging a qualified, independent third party assessor to review its compliance efforts and report to HHS

A link to the resolution agreement is available here: http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/riteaidres.pdf

Tuesday, July 13, 2010

Analysis of Proposed HHS Regulations Implementing HITECH Act

As promised last week in an earlier post, here is our first Mintz Levin client advisory analyzing the 234 pages of regulations issued on Thursday by the Department of Health and Human Services. Thanks to colleagues Alden Bianchi, Dianne Bourque and Stephen Bentfield.

The regulations are slated to be published in the Federal Register tomorrow, which will trigger the start of the 60-day comment period. We will continue to post further analysis of these regulations and discussion relating to particular points of interest. Stay tuned.

Australian Privacy Commissioner Concludes Google Breached Privacy Act

Written by Jillian Collins

Australian Privacy Commissioner Karen Curtis has concluded her investigation into Google's collection of unsecured WiFi payload data in Australia using Street View vehicles and finds that such collection violated Australian law.

"On the information available I am satisfied that any collection of personal information would have breached the Australian Privacy Act,” she said. "Collecting personal information in these circumstances is a very serious matter. Australians should reasonably expect that private communications remain private.”

For its part, Google has promised to publish an apology to Australians for its collection of unsecured WiFi 'payload' data. Google will also conduct a Privacy Impact Assessment (PIA) on any new Street View data collection activities in Australia that include personal information and regularly consult with the Australian Privacy Commissioner about personal data collection activities arising from significant product launches in Australia.

The apology, posted on the official Google Australia blog, states in part:

“To be clear, we did not want and have never used any payload data in our products or services--and as soon as we discovered our error, we announced that we would stop collecting all WiFi data via our Street View vehicles and removed all WiFi reception equipment from them…

We want to reiterate to Australians that this was a mistake for which we are sincerely sorry. Maintaining people's trust is crucial to everything we do and we have to earn that trust every single day. We are acutely aware that we failed badly here.”

Google admitted in May that it had collected certain WiFi content information--known as "payload data"--in some 33 countries, including in Australia, with special equipment mounted on its Street View photographic image collection vehicles.

Google may not get away so easily in other countries for the privacy breach. German authorities are leading an investigation that may result in criminal penalties, there is a class-action lawsuit against the company in the U.S., and Federal Trade Commission has said it will "a very close look" at the company's behavior. In some other countries, including Britain, Germany, France, and Italy, authorities have demanded that Google hand over the payload data so that it can be used in possible legal cases against the company.

Related Links:

http://www.businessweek.com/technology/content/jul2010/tc2010079_071459.htm

http://www.smh.com.au/technology/technology-news/google-wifi-snooping-broke-the-law-privacy-watchdog-20100709-103eh.html

Google’s apology: http://google-au.blogspot.com/2010/07/were-sorry.html

Statement from the Australian Privacy Commissioner: http://www.privacy.gov.au/materials/a-z?fullsummary=7103

Monday, July 12, 2010

No Harm, No Foul; Ninth Circuit Affirms Dismissal of Data Breach Case Against The Gap

Written by Kevin McGinty

It’s a distressingly common scenario. A corporate laptop containing job applicant data, including social security numbers, is stolen from an employee who has taken the laptop off of corporate premises. Access to the social security numbers makes it possible for wrongdoers to engage in identity theft. Is an applicant’s fear that data will be misused enough to support claims for negligence and breach of contract against the company? The federal Ninth Circuit Court of Appeals has joined a growing number of courts in answering that question in the negative. In Ruiz v. Gap, Inc., the court held that California law requires actual damages to support claims for negligence and breach of contract, and that time and effort that the applicant allegedly expended to monitor for identity theft were insufficient to constitute actual damages. The court reached similar conclusions as to the claim under California’s consumer protection statute and, significantly, the claim for invasion of privacy. As to the latter, the court ruled that increased threat of a breach of privacy does not constitute an actual invasion of privacy.

None of this is to say that a company is immune from state law liability and can simply elect to do nothing when a data breach occurs. Although not detailed in the Ninth Circuit’s decision, The Gap took affirmative steps to protect applicants from potential harm arising from theft of their data. Not only did The Gap notify the applicants about the theft of the computer containing their personal information, but it also offered to provide twelve months of credit monitoring and fraud assistance without charge, plus $50,000 worth of identity theft insurance. The lesson of the Ruiz decision is that companies that do take reasonable steps to mitigate against potential misuse of stolen data will have a strong defense against further liability. It also reinforces the commonsense proposition that has bedeviled many attempts to parlay data breaches into class actions – the mere threat of bad consequences is not the same as actually suffering bad consequences. Thieves generally steal computers because they want the hardware, not the data. The loss of a computer containing personal data does not inevitably mean that such data will be misused. As such, claims arising from data breaches are unlikely to succeed unless there has also been identity theft and resulting adverse consequences for individuals whose identities have been stolen.

Thursday, July 8, 2010

REMINDER - HITECH/201 CMR 17.00 Compliance Workshop

Just a reminder of the FREE upcoming data security compliance workshop - Space is limited, so register today at http://tinyurl.com/35pk3yr!

On July 13, Mintz Levin will be joined by Sophos, Six Weight Consulting, and MFA Cornerstone Consulting to hold a free compliance workshop focused on both the gaps and overlap of Massachusetts’ data protection regulation 201 CMR 17.oo and the recent updates to federal health and medical data privacy found in the HITECH Act. We'll have an interactive hands-on workshop that will help you to address some critical questions within your organization:

What are my organization and business partner’s obligations?
What kind of information do I need to protect and how do identify it?
Is data encryption necessary?
What is a WISP?
What is a data breach and what is my responsibility and liability if I have one?

First Ever State-initiated HIPAA Enforcement Action Settled

Written by Dianne Bourque

Connecticut Attorney General Richard Blumenthal has settled the first state-initiated HIPAA enforcement action. The settlement totals $250,000 in statutory damages and Health Net's agreement to implement a variety of measures to improve the security of consumer health and personal information. Health Net also agreed to provide two years of credit monitoring to affected individuals, $1 million of identity theft insurance and reimbursement for the costs of security freezes.


As we reported in this space, Blumenthal sued Health Net and its affiliates after they allegedly lost a computer disk drive in May 2009 containing protected health and other private information on more than 500,000 Connecticut residents and 1.5 million consumers nationwide. The missing disk drive contained names, addresses, social security numbers, protected health information and financial information. Blumenthal also alleged that Health Net failed to promptly notify consumers endangered by the breach even after learning that the disk drive was stolen.
The Health Net case is the first action by a state attorney general for HIPAA violations since the Health Information Technology for Economic and Clinical Health Act (HITECH) authorized state attorneys general to enforce HIPAA.


The full text of the settlement is available here:
http://www.ct.gov/ag/lib/ag/fraud/soctvhealthnetstipjudgment.pdf

HHS (Finally!) Issues Proposed HIPAA Privacy & Security Rule Changes

The long-awaited proposed changes to the HIPAA Privacy Rules have finally been released by the Department of Health and Human Services (HHS).

A joint statement issued today by the HHS and the Office of Civil Rights (OCR) says that the proposed regulations “would expand individuals’ rights to access their information and restrict certain disclosures of protected health information to health plans, extend the applicability of certain of the Privacy and Security Rules’ requirements to the business associates of covered entities, establish new limitations on the use and disclosure of protected health information for marketing and fundraising purposes, and prohibit the sale of protected health information without patient authorization. In addition, the proposed rule is designed to strengthen and expand OCR’s ability to enforce HIPAA’s Privacy and Security provisions. This rulemaking will strengthen the privacy and security of health information, and is an integral piece of the Administration’s efforts to broaden the use of health information technology in health care today. We urge consumers, providers, and other stakeholders to read these proposals and offer comments during the 60-day comment period, which will officially open on July 14, 2010. Information about posting comments will be available at http://www.regulations.gov.”

The 234 pages of proposed regulations can be found at Notice of Proposed Rulemaking to Implement HITECH Act Modifications and we are in the process of reviewing these regulations to provide our readers with further information.

Thursday, July 1, 2010

Data Breaches du Jour

Information regarding the latest reports of data breaches -- common thread: it is taking a startingly long time for entities to (a) discover that they have been breached, and (b) to then take action to notify affected customers of potential compromises to personal information.

Update on Major Data Breach at California Health Insurer

Updating a previous blog post (link) from Monday, WellPoint, the country's largest health insurer, has now sent notice to 470,000 members and applicants for individual health insurance nationwide informing them of a breach to a web site used by individuals to apply for insurance and track the status of their applications. The web site system run by WellPoint subsidiary Anthem Blue Cross of California was allegedly manipulated by attorneys looking to bolster a class action lawsuit against the insurer. WellPoint indicated that although the breach may have affected 230,000 California customers as previously reported, data for other applicants could have been obtained and accessed by anyone merely by altering the URL, thus prompting the additional notices.

While initially saying that personal information was unsecure for "a relatively short period of time," WellPoint now explains that five months passed before the company learned in March that a failed security update to the Anthem web site left customers' data vulnerable.

Related Link:
http://www.govinfosecurity.com/articles.php?art_id=2690


Unencrypted Patient Information Goes Missing from NY Hospital

A New York hospital is notifying some 130,000 patients that their personal information may have been compromised. Patient information stored on seven CDs belonging to New York's Lincoln Medical and Mental Health Center was lost in transit after a hospital contractor shipped them, Bloomberg reports. The unencrypted data includes Social Security numbers, dates of birth, drivers' license numbers and procedure information. In a letter sent to victims earlier this month, the hospital suggested the CDs may have been displaced at a shipping facility and destroyed.

Yet another good example for encryption of all PHI and PI in transit.

Related Link:

http://www.businessweek.com/idg/2010-06-29/new-york-hospital-loses-data-on-130-000-via-fedex.html

Continuing Data Breach Over Eight Year Period Exposes Personal and Medical Records of Students at University of Maine Counseling Center

According to the Auburn-Lewiston Sun Journal, the University of Maine Police Department is investigating a data breach that exposed nearly 5,000 students' personal and medical information. Starting in 2002 and spanning eight years, hackers accessed the UMaine counseling center database, the Sun Journal reports. The database stored information including names, Social Security numbers and clinical information. The university has hired a company to monitor the credit of those potentially affected, though there is no indication the hacked data has been viewed or used. "This is a serious breach and we are profoundly sorry that this has happened," said a university spokesman.

Related Link:
http://www.sunjournal.com/state/story/870870

Tuesday, June 29, 2010

Latest Postponements and Exemptions of FTC Enforcement of ‘Red Flags’ Rule

Written by Kenneth Gantz

At the urging of congressional lawmakers, the Federal Trade Commission has for the fifth time delayed enforcement of the “Red Flags” Rule – this time through December 31, 2010. In the interim, Congress plans to consider legislation that would alter the scope of entities covered under the Rule.

Under the Fair and Accurate Credit Transactions Act, Congress directed the FTC and other agencies to develop regulations requiring financial institutions and creditors to address the risk of identity theft. The FTC in turn sought to impose the Red Flags Rule, requiring all such entities to develop and implement written identity theft prevention programs.

In a news release issued on the organization’s website, “[the FTC] urges Congress to act quickly to pass legislation that will resolve any questions as to which entities are covered by the Rule and obviate the need for further enforcement delays.” The Commission goes on to explain that it will begin enforcement sooner should Congress pass legislation limiting the scope of the Red Flags Rule with an effective date earlier than December 31, 2010.

Additionally, the FTC agreed on June 25 to temporarily exempt physicians from the Red Flags Rule. Per a joint stipulation with the American Medical Association and other health organizations, the FTC will wait until the U.S. Court of Appeals for the District of Columbia resolves questions concerning the Rule’s scope before it seeks enforcement against physicians. The AMA, American Osteopathic Association, and the Medical Society of the District of Columbia had filed a lawsuit on May 21 to prevent the FTC from applying the rule to physicians (AMA v. FTC, D.D.C., No. 1:10-cv-00843), arguing that the FTC exceeded its statutory powers and acted in a manner that is “arbitrary, capricious, and contrary to the law.”

The District Court previously barred the FTC from applying the Red Flags Rule to attorneys following a similar challenge by the American Bar Association. The FTC appealed that decision, and the health group’s lawsuit will now be put on hold until the Court of Appeals issues its opinion in the ABA case.

Related Links:
http://www.ftc.gov/opa/2010/05/redflags.shtm

http://www.healthdatamanagement.com/news/red-flags-rule-identity-theft-lawsuit-physicians-40572-1.html

http://www.ama-assn.org/ama1/pub/upload/mm/395/red-flags-lawsuit.pdf (AMA’s complaint)

Monday, June 28, 2010

Major Data Breach at California Health Insurer

Written by Kenneth Gantz

Anthem Blue Cross is notifying approximately 230,000 members and applicants for individual health insurance of a breach involving a web site used by individuals to apply for insurance and track the status of their applications. Anthem claims that attorneys managed to manipulate the web address within the web site in order to obtain information in support of a class action lawsuit against the insurer.

The attorneys were apparently able to access medical information in addition to Social Security and credit card numbers, resulting from a failure to reinstate security mechanisms following an October 2009 upgrade to the web site.As part of a statement issued by the company, Anthem offered the following: "The ability to manipulate the web address (URL) was available for a relatively short period of time following an upgrade to the system. After the upgrade was completed, a third party vendor validated that discovered, we made the necessary security changes to prevent it from happening again."We have requested both by letter and in court filings that the attorneys return all information improperly obtained from the individual application system and as a result, that information has been delivered to a court approved custodian who will ensure its security.”

Interestingly, Anthem said that “out of an abundance of caution” it is providing a detailed notification explaining what happened to individuals who might be affected by the breach, but apparently no legal obligation from its point of view. California law requires that affected residents be notified of breaches of health information. See http://www.mintz.com/newsletter/2007/PrivSec-DataBreachLaws-02-07/state_data_breach_matrix.pdf. The insurer will also offer notified individuals a year of free identity protection services. Meanwhile, Anthem is weighing legal action it might take “with respect to the data, the impact—if any—on our members, and the remediation costs incurred as a result of these actions.”

Related Links:http://www.insurancenetworking.com/news/health_insurance_technology_Anthem_Blue_Cross_data_security_risk-25114-1.html

Friday, June 25, 2010

July 13 Data Security Workshop - FREE

On July 13, Mintz Levin will be joined by Sophos, Six Weight Consulting, and MFA Cornerstone Consulting to hold a free compliance workshop focused on both the gaps and overlap of Massachusetts’ data protection regulation 201 CMR 17.oo and the recent updates to federal health and medical data privacy found in the HITECH Act. We'll have an interactive hands-on workshop that will help you to address some critical questions within your organization:
  • What are my organization and business partner’s obligations?
  • What kind of information do I need to protect and how do identify it?
  • Is data encryption necessary?
  • What is a WISP?
  • What is a data breach and what is my responsibility and liability if I have one?

    For information or to register to attend the event, which will be hosted by Mintz Levin in our downtown Boston office, please click this link: http://tinyurl.com/35pk3yr

Thursday, June 24, 2010

Twitter Settles With FTC

Twitter has reached a settlement with the Federal Trade Commission (FTC) over charges that it “deceived consumers and put their privacy at risk by failing to safeguard their personal information.” In the Matter of Twitter, Inc.,

The FTC had alleged that “serious lapses” in Twitter’s security last year "allowed hackers to obtain administrative control of Twitter, including access to tweets that consumers had designated private, and the ability to send out phony tweets pretending to be from then-President-elect Barack Obama and Fox News, among others." The two incidents mentioned involved hackers using password-guessing tools to gain access to administrative functions. Under the settlement, Twitter must maintain a comprehensive information security program, to be assessed by a third-party every other year for 10 years. It also will be prohibited from misleading consumers about the extent to which it maintains and protects the security, privacy and confidentiality of nonpublic consumer information.
Related links:

Twitter Settles Charges that it Failed to Protect Consumers' Personal Information; Company Will Establish Independently Audited Information Security Program

Twitter settles with US regulators over privacy breach - Yahoo! News

Twitter settles with FTC for privacy breach Forrester Blogs

Tuesday, June 22, 2010

FTC Highlights Need for Privacy and Security in Internet Commerce

Written by Jillian Collins

The Federal Trade Commission has weighed in as part of the Department of Commerce's public comment process on privacy and security issues. According to the FTC's comment, consumers trusting that their personal information will be safeguarded is essential to the success of e-commerce, and innovation is essential to ensuring privacy in the fast-paced, ever-changing world of the Internet economy. The topic of innovation and internet privacy controls has been, and continues to be, one of the FTC’s "highest consumer protection priorities for more than a decade," according to the comment.

In the comment, the FTC laid out several aspects of its privacy program. The agency led nearly 30 enforcement cases challenging business practices that allegedly failed to secure consumers' personal information and made efforts at educating consumers and businesses about privacy and security in an online world. The FTC also has several policy initiatives including promoting self-regulation in online behavioral advertising and participates in international privacy programs. The agency hosted several privacy roundtables and plans to public privacy and security proposals for public comment later this year.

Related links:
http://www.ftc.gov/opa/2010/06/foodinternet.shtm

The Google Payload Data Fallout Continues

Written by Jillian Collins

Connecticut Attorney General Richard Blumenthal says he will lead a multistate investigation into Google Street View cars’ unauthorized collection of personal data from WiFi networks. The Connecticut AG said he expects a significant number of states to participate. More than 30 states participated in a recent conference call regarding the Connecticut investigation.
In a statement released yesterday, Blumenthal called Google’s data collection a “deeply disturbing invasion of personal privacy,” and said that consumers have a right to know what personal information, including potentially emails, web browsing habits and passwords, Google may have collected. “Google must come clean, explaining how and why it intercepted and saved private information broadcast over personal and business wireless networks,” he said. Google maintains that it did not collect the payload data intentionally and never used it , but the company may be facing not only domestic consequences but also investigations in the UK and other affected countries. Google says it stopped collecting Wi-Fi data from its Street View vehicles when it discovered the data collection problem last month following an inquiry by German regulators. The Google payload data incident is just one recent PR problem related to privacy concerns for the internet giant. Google took harsh criticism for the launch of Buzz because the feature initially revealed information about the names of users' email contacts. Google has significantly revised the service; now, it merely suggests followers, rather than automatically creating them.

Related links:http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=130619http://www.foxnews.com/world/2010/06/22/uk-police-investigating-alleged-google-privacy-breach-public-wi-fi-networks/

More on Supreme Court Ruling in Quon

And as promised in our last post, here is the latest Client Advisory on the Supreme Court's ruling in the Quon case.

Thursday, June 17, 2010

Breaking News: Supreme Court Issues Decision in Employee Privacy Case

Written by Martha Zackin

As we’ve blogged in this space,, back in December, the Supreme Court agreed to hear City of Onatario v. Quon, a case on the privacy of text messages sent by a government employee on employer-provided devices. Specifically, the Court agreed to consider whether a police sergeant assigned to a Ontario, California SWAT team had a reasonable expectation of privacy under the Fourth Amendment in sexually-explicit, non-work related text messages transmitted on a department-issued pager and stored by an outside service provider even in the face of the City’s "general practice" of non-monitoring of such communications.

Today, the Court issued its opinion, finding that the City’s search of Sergeant Quon’s text messages to his colleagues and the woman with whom he was having an affair was reasonable. Although the Court did not reach agreement on whether and to what extent government workers have any reasonable expectation of privacy in communications such as those at issue here, the Court did agree that the search was reasonable.

The impact of this decision may be limited to Sergeant Quon and his co-workers; the Court explicitly cautioned against using the facts of the case to establish “far-reaching premises that define the existence, and extent, of privacy expectations enjoyed by employees when using employer-provided communication devices.”

More to come.