Thursday, January 28, 2010
Happy Data Privacy Day! Tip #1
And don’t forget, the March 1 deadline for compliance with the sweeping Massachusetts data security regulations is fast approaching. Click here for complete information and FAQs. We'll be posting additional tips through the day in honor of Data Privacy Day 2010.
Friday, January 15, 2010
Connecticut Attorney General Brings Charges Against Health Net for HIPAA Violations
Written by Dianne Bourque
On January 13, Connecticut Attorney General Richard Blumenthal filed charges against Health Net of Connecticut, Inc., for violating federal privacy law. Blumenthal is the first state attorney general to file such a suit using HIPAA enforcement authority granted to states under the HITECH provisions of the American Recovery and Reinvestment Act of 2009.
The law suit was prompted by Health Net’s loss of a portable disk drive from a Connecticut office. The unencrypted drive contained health and other personal information for approximately 1.5 million current and former Health Net members. Almost one-half million of the affected members were Connecticut residents.
In a statement, Health Net said that it would cooperate with the Attorney General and that there is no evidence that any of the lost data had been misused.
Monday, January 11, 2010
New Settlement Agreement in Heartland Breach
Heartland disclosed last week in a filing with the Securities and Exchange Commission that it has agreed to pay a maximum of $60 million to Visa Inc. and Visa card-issuing banks to settle claims arising out of the massive payment card data breach last January.
The proposed settlement is conditioned on 80% of eligible banks accepting the settlement offers. Under the agreement, some $59.2 million of the maximum settlement amount would be available to pay Visa card-issuing banks for their costs associated with the data breach. An additional $780,000 would be used to clear fines related to the breach collected by Visa from banks. According to the agreement, settlement offers will go out to eligible Visa-issuing banks next week and must be accepted by January 29.
More information: The full text of the Settlement Agreement
Friday, January 8, 2010
Security Bits and Bytes
Gonzalez Pleads Guilty in December 2009 - but this piece from Retail Research Systems explains why retailers should not be sanguine about data security: Privacy Risks for 2010
RFID in 2010: The New Hampshire House of Representatives voted this week to prohibit the implantation of tracking devices in humans without their written consent. The bill,also includes a provision banning the use of radio frequency identification (RFID) tags to track consumers, and would require consumer notice for any goods implanted with an RFID tag. Furthermore, the bill would prohibit cloning of RFID-enabled debit and credit cards. The RFID 24-7 Newsletter highlights some additional trends to watch in 2010.
After Heartland - "Mere Compliance" with Standards Enough? Interesting article in Computerworld reports that nearly a year following the disclosure of a Heartland Payment Systems data breach affecting 130 million credit and debit card holders, the debate over the effectiveness of basic compliance continues to rage.
Federal Trade Commission - New COPPA Safe Harbor Guidelines? The Federal Trade Commission (FTC) this week issued a call for public comment on a set of proposed guidelines to help businesses comply with the Children's Online Privacy Protection Act (COPPA). The proposed guidelines were submitted by iSafe, a nonprofit organization dedicated to promoting a safe online experience for children. If adopted by the FTC, the guidelines--designed to encourage better self regulation among Web sites targeting children under the age of 13, or sites that knowingly collect information from children under the age of 13--would constitute a safe harbor program under COPPA. The public comment period will last 45 days from January 6.
Thursday, January 7, 2010
Maine - New Year, New Legislative Session, New Version of the Marketing to 'Tweens Law
New Maine Legislation
Privacy and Security Information - Privacy MATTERS: Lawsuit Filed to Block New Maine Marketing Law
Wednesday, January 6, 2010
Happy 2010 - Data Breach du Jour
Officials at Eastern Washington University (EWU) are notifying up to 130,000 current and former students that their personal information may have been exposed in a security breach, reports the Seattle Times. The data involved includes names, Social Security numbers and dates of birth for students going back to the year 1987. Information technology staff discovered the breach during a network assessment.
The takeaway here: A good New Year's resolution should be to conduct a network assessment of your own enterprise during Q1 and if you do not have a records retention policy in place ---> get one. Keeping personal information for more than 20 years is a data breach waiting to happen.
Link
Local News Hacker may have accessed EWU student information Seattle Times Newspaper
Monday, January 4, 2010
New Regulations Propose a Definition of 'Meaningful Use'
On December 30, 2009, the Centers for Medicare & Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued interim final rules necessary to implement electronic health record (EHR) incentive programs enacted under the American Recovery and Reinvestment Act of 2009. The ONC rule sets initial standards, implementation specifications, and certification criteria for EHR technology. The CMS rule provides a long-awaited definition of the concept of “meaningful use” of EHR technology. Both regulations are open to public comment.
The ONC Rule
The ONC rule calls for the industry to standardize the way in which EHR information is exchanged between organizations, and sets forth criteria required for an EHR technology to be certified. These standards will support meaningful use and data exchange among providers who must use certified EHR technology to qualify for Medicare and Medicaid incentives.
The proposed rule relies heavily on existing standards for the interoperability of health information technologies, including those established and/or promoted by Health Level 7, Inc. (HL7), the National Institute of Standards and Technology (NIST), and Integrating the Healthcare Enterprise (IHE). The standards also rely on existing classification and nomenclature systems including SNOMED CT, ICD-9 and 10, X12, LOINC, NCPDP, and RxNorm.
ONC’s interim final rule may be viewed at http://www.federalregister.gov/inspection.aspx#special.. There is a 60 day comment period.
The CMS Rule
CMS’ proposed regulation defines and specifies how to demonstrate 'meaningful use' of EHR technology, which is a prerequisite for receiving incentive payments. The rule also outlines proposed payment methodologies for the Medicare and Medicaid EHR incentive programs.
The proposed criteria for meaningful use focus on electronically capturing health information in a coded format, using that information to track key clinical conditions, communicating that information for care coordination purposes, and initiating the reporting of clinical quality measures and public health information.
The criteria are based on a series of specific objectives, each of which is tied to a proposed measure that all eligible professionals and hospitals must meet in order to demonstrate that they are meaningful users of certified EHR technology. For Stage 1, which begins in 2011, CMS proposes 25 objectives/measures for eligible professionals and 23 objectives/measures for eligible hospitals that must be met to be deemed a meaningful EHR user.
CMS’ proposed rule may be viewed at http://www.cms.hhs.gov/Recovery/11_HealthIT.asp. There is a 60 day comment period.
Happy New Year - New Health Care Reform Issues
The world of health care reform also has significant impact on all of us, and my colleagues here at Mintz published an important advisory right at the stroke of midnight -- Health Care Reform Advisory: Assessing the Impact of Federal Health Care Reform on Employers and Group Health Plans
Tuesday, December 22, 2009
Data Security Roundtable
http://www.businesswire.com/portal/site/home/permalink/?ndmViewId=news_view&newsId=20091222005345&newsLang=en
Some very interesting discussions with folks who are on the cutting edge of data security. I'll post the other segments as they are released.
Monday, December 21, 2009
The real cost of data breaches - Heartland to pay Amex $3.5 million
This settlement is likely to be only the first over the compromise of tens of millions of debit
and credit card accounts by malicious software planted on Heartland's computers
that the Princeton, N.J.-based payment card processor revealed in January of this year.
On November 12, Heartland filed a Form 8-K with the SEC, stating that it had doubled from $35.6 million to $73.3 million its anticipated breach expenses for 2009, because it expected to settle litigation related to the breach.
Heartland faced a total of 17 consumer class actions and 10 bank and credit union class actions related to the breach, which were consolidated in the U.S. District Court for the Southern District of Texas. According to the Form 8-K filing, the newly announced settlement agreement
would release Heartland from any claims raised by AmEx or its issuing banks. The filing did not indicate whether the settlement is subject to court approval and did not include a copy of the agreement.
Wednesday, December 16, 2009
More Detail on Quan Case
ELB Law Information: Supreme Court to Hear Case re Employer's Access to Employee's Text Messages
Tuesday, December 15, 2009
Supreme Court will review some issues in Quon Case, denied review to other issues
The Court will consider whether a police sergeant assigned to a SWAT team had a reasonable expectation of privacy under the Fourth Amendment in text messages transmitted on a department-issued pager and stored by an outside service providerk even in the face of the City of Ontario's "general practice" of non-monitoring of such communications. The Court denied review (known as "certiorari") to questions of whether the surrender to the city in the first instance by Arch Wireless (the service provider) of those messages violated the Stored Communications Act.
The questions for review are limited, then, to three:
• Does a SWAT team member have a reasonable expectation of privacy in text
messages transmitted on his SWAT pager, when the police department has an
official no-privacy policy but a non-policymaking lieutenant announced an
informal policy of allowing some personal use of pagers?
• Did the Ninth Circuit contravene Fourth Amendment precedents and create
circuit conflict by analyzing whether the police department could have used
'less intrusive methods' of reviewing text messages transmitted by the SWAT
team member on his SWAT pager?
• Do individuals who send text messages to a SWAT team member's SWAT pager
have a reasonable expectation that their messages will be free from review by
the recipient's government employer?
Monday, December 14, 2009
Good data protection sense from the Brits
Stephen Alambritis, Head of Public Affairs at the Federation of Small Businesses, said: “Small businesses do not have time for pages and pages of jargon and gobbledegook, but getting data protection right makes good business sense. Data protection lapses cost reputations and can affect the bottom line. But, many organisations tell us that data protection law is difficult to understand. This new no-nonsense guide will help the business community to understand and comply with the law.”
This Guide will also be helpful for non-UK companies to understand their data protection obligations when doing business in the UK with the data of UK citizens. Clear, straight-forward and unambiguous. Makes sense.
Supreme Court To Decide Privacy of Employee Texts
The case--City of Ontario v. Quon--could have profound implications on employee privacy rights, according to a Baltimore Sun report. It involves an Ontario, California police officer who sent sexually explicit messages to another officer using the department-issued device. The messages were discovered during an audit, and a lawsuit claiming privacy violations followed. California's Ninth Circuit Court of Appeals ruled in favor of the sender of the messages, but dissent by a number of judges prompted an appeal to the Supreme Court.
9th Circuit Opinion:
Quon v. Arch Wireless (9th Circuit)
Additional reports:
Washington Post
The Curmudgeon's Comments - City of Ontario v. Quon — USSC
Pittsburgh Tribune-Review
Tuesday, December 8, 2009
National Public Radio 3-part special series on privacy
Part 1: Online Data Present a Privacy Minefield
Part 2: Is Your Facebook Profile as Private as You Think?
Part 3: Digital Bread Crumbs: Following Your Cell Phone Trail
Holiday Privacy Watch: Take care before you donate that cell phone
Some tips -
1) Don't forget to remove the SIM card!
2) Call logs, photos, memos, and other information might reside in the phone's internal memory, and are often difficult to delete if you rely on the phone's manual (and who keeps those, anyway??). The folks at ReCellular - a cell phone recycling service - have a great solution called The Cell Phone Data Eraser. It lets you choose the brand and model number of your phone, and then displays the precise commands you need to delete every piece of data from it. The ReCellular website is http://www.recellular.com/recycling/data_eraser/default.asp. If you can't find the info you need here, most cell phone manuals are available online at the manufacturer website for download.
If you think you can circumvent the privacy threat by sending your phone back to your service provider, you could be mistaken. According to one report, a Cingular customer who received a refurbished phone as a replacement for one that malfunctioned found the new phone was filled with the previous owner's private data, including account numbers, user names, and passwords. In December, an old BlackBerry sold at a McCain campaign garage sale for 20 dollars was found to be preloaded with a mountain of Republican donor information, emails, and more.
Don't let this discourage you from turning those paperweights back into useable technology for folks who need it -- just take some extra time to protect your personal information.
Happy Holidays!
Monday, December 7, 2009
House scheduled to act today on several privacy bills
Federal Trade Commission hosts privacy roundtable today
The event is being streamed live at the FTC website.
Live Webcast here
Friday, December 4, 2009
Privacy and Security Bits and Bytes
U.S. to Join Fingerprint Sharing -- CBC News - Canada reports that the U.S. will join Canada, Australia and Britain in sharing fingerprints and other data to help authorities discern people's true identities in cracking down on asylum shopping and unlawful immigration.
Another site thinks "Privacy Matters" --
The Interactive Advertising Bureau yesterday launched an online campaign aimed at educating consumers about targeted advertising. On its website, IAB Privacy Matters, the IAB describes how marketers collect and use information about users' Web activities. IAB Senior Vice President David Doty said the site describes "in plain English" how online advertising works and includes guidance on how users can adjust their settings to control their information. The site is part of a broader effort among ad industry trade groups to head off potential regulation, the report states.
Facebook Changing -- Again -- Facebook will roll out new privacy controls in the coming weeks, reports itnews. The new options will let users control who sees their posts on a per-post basis. In an open letter to users, CEO Mark Zuckerberg said: "We're adding something that many of you have asked for--the ability to control who sees each individual piece of content you create or upload." The company will also roll out a simplified privacy settings page with a "walk-through" option where users can get recommendations from Facebook. In addition, the company will shutter its regional networks.
Thursday, December 3, 2009
Court issues written opinion explaning decision regarding applicability of Red Flags Rule to attorneys
On October 31, the FTC extended the Red Flags enforcement deadline for the fourth time to June 1, 2010.
Related Link:
Privacy and Security Information - Privacy MATTERS: Happy Halloween - No Red Flags Enforcement Until June 1, 2010.........