Friday, November 13, 2009

Breakfast and social media policies

Related to the last post -- is your company working on its social media employee policy? If not, you should be. If you happen to be in Boston, Mintz Levin is hosting a breakfast briefing on social media in the workplace next week.

Register here

Some startling statistics regarding social networking issues in the workplace......

You might be surprised to know that social networking policies, governing employee use of blogging, Facebook, Twitter and the like, are still a rarity at many business, including teaching hospitals. And, you might be equally surprised to hear that studies are revealing that medical students are displaying cavalier attitudes towards the protection of patient confidentiality.

The Journal of the American Medical Association published a the results of an eye-popping study in the September issue. In response to a survey conducted by the Health Care Compliance Association (HCCA) and the Society of Corporate Compliance and Ethics (SCCE), only 38 percent of survey respondents said that they have policies to cover online conduct. The “status update” features of social media platforms encourages people to record what they’re working on or who they are meeting with -- jeopardizing personal information and confidentiality.

Related Links

Mintz Levin Client Alert - HCCA/SCCE Survey
Social media behavior could threaten your reputation, job prospects :: Oct. 12, 2009 ... American Medical News
Medical students using Facebook and Twitter can get expelled

Thursday, November 12, 2009

Massachusetts Attorney General proposes privacy regulations to apply to her office

Written by Cynthia and Elissa

An oft-cited criticism of the Massachusetts data security regulations (201 CMR 17.00), effective March 1, 2010, is that the regulations specifically do not apply to government entities -- the only reason being that the Office of Consumer Affairs and Business Regulation does not have the authority or jurisdiction to enact regulations over governmental entities in Massachusetts.

One agency is seeking to correct that. The Massachusetts Office of the Attorney General has released draft privacy regulations to apply to the AG’s office, effective December 31, 2009. The regulations mirror the obligations imposed upon private business by 201 CMR 17.00.

This post would not be complete if we did not also take note of the fact that Attorney General Martha Coakley is a candidate for the U.S. Senate seat left vacant by the death of Senator Edward Kennedy.

Tuesday, November 10, 2009

Remember the school-days admonition that something might end up on your "permanent record"?

A Fordham Law School study found that state educational databases across the country have severely inadequate privacy protections for the nation's school children. The study, prepared by the Center on Law and Information Policy, reports that at least 32% of states warehouse children's social security numbers; at least 22% of states record student pregnancies; and at least 46% of the states track mental health, illness, and jail sentences as part of the children's educational records. Almost all states with known programs collect family wealth indicators.

According to the study, most states use third party vendors for at least part of their data collecting and reporting needs. Some states outsource the data processing without any restrictions on use or confidentiality for children's information. The Fordham study therefore recommended that states which outsource data processing have comprehensive agreements explicitly addressing the privacy obligations of the third party vendors. Furthermore, access to the information and the disclosure of personal data may occur for decades and follow children well into their adult lives. More than 80% of states fail to have data-retention policies and may retain the information indefinitely. Thus, the study recommended that states should limit data collection to necessary information and should have specific data retention policies and procedures.

The Fordham report also recommended that data at the state level be made anonymous, that the collection of information by the state be minimized and specifically tied to an articulated audit or evaluation purpose, and that states should have a Chief Privacy Officer in the department of education who monitors the privacy protections of educational record databases and who publicly reports privacy impact assessments.


Study Website:
http://law.fordham.edu/childrensprivacy

Monday, November 9, 2009

When employee handbooks don't tell the whole story.....

Written by Cynthia and Jennifer

The discussion of employer access to employee emails in our September 21 blog entry continues with another appellate court decision about workplace privacy rights.


In Stengart v. Loving Care Agency, Inc., the court completely rejected an employer's attempt to rely upon an email policy to gain access to an employee's confidential communications with her attorney conducted through the employer's email system. The court found that the employer could have no legitimate interest in reviewing an employee's private communications with her attorney, noting that "[p]roperty rights are no less offended when an employer examines documents stored on a computer as when an employer rifles through a folder containing an employee's private papers or reaches in and examines the contents of an employee's pockets; indeed, even when a legitimate business purpose could support such a search, we can envision no valid precept of property law that would convert the employer's interest in determining what is in those locations with a right to own the contents of the employee's folder of private papers or the contents of his pocket." The court went on to reject the notion that emails relating to an anticipated lawsuit against her employer would seem to be an illegitimate business use of the computer system: "the company had no greater interest in those communications than it would if it had engaged in the highly impermissible conduct of electronically eavesdropping on a conversation between plaintiff and her attorney while she was on a lunch break." Additionally, the court sanctioned the employer's law firm for not returning the emails to the employee as soon as the law firm became aware they were privileged communications.

This is a very interesting pro-employee decision but its lesson is clear: even email policies that notify employees that they are waiving certain privacy rights in the workplace do not give employers carte blanche to access or take ownership of all of those communications. Employers who access (intentionally or not) such information should promptly seek counsel before proceeding further.

Tuesday, November 3, 2009

Privacy Class Actions....Waiting for Hannaford

My colleague, Kevin McGinty, has penned an interesting analysis of the latest in the class action litigation arising out of the Hannaford supermarket chain data breach.

Specifically, Maine’s highest court is being asked to determine whether the law recognizes the time and effort payment cardholders spend trying to protect themselves after a data breach as a “substantial injury” for which they can be compensated. Kevin analyzes how the Maine Supreme Court's decision could affect the protections that zero-liability programs afford retailers involved in data breaches because consumers do not experience actual out-of-pocket damages.

Links:

Mintz Levin Privacy and Class Action Alert
Motion to Dismiss
Complaint

Friday, October 30, 2009

Happy Halloween - No Red Flags Enforcement Until June 1, 2010.........

Yet again, at the last minute, the Federal Trade Commission has announced that it is delaying enforcement of the Red Flags Rule. This time, the postponement is until June 1, 2010 and comes "[a]t the request of Congress."

This is the FOURTH time that the FTC has delayed "enforcement" of the controversial rules intended to detect and mitigate identity theft. It follows yesterday's federal court ruling that the Red Flags Rule does not apply to lawyers. It also follows on the heels of a 400-0 vote in favor of a House bill (H.R.3763) exempting certain small businesses from compliance with the Red Flags Rule.

As we have discussed in this blog on many occasions, the Red Flags Rule has been plagued with misunderstanding, controversy, and objections from the business community since its enactment in July of 2006. In the meantime, according to the FTC and other compilations of ID theft reports, nearly 25 million U.S. residents have reportedly been victims of identity theft. The regulatory effort is in danger of losing credibility.



Links:

Federal Trade Commission: www.ftc.gov/opa/2009/10/redflags.shtm
Privacy and Security MATTERS: www.privacyandsecuritymatters.blogspot.com/2009/10/changes-to-red-flag-rules-may-be-coming.html
Identity Theft Statistics: www.privacyrights.org/ar/idtheftsurveys

Thursday, October 29, 2009

BREAKING NEWS: Lawyers Need Not Implement Red Flag Program

Just before noon today, Judge Walton granted summary judgment from the bench in favor of the American Bar Association in the ABA lawsuit over application of Red Flag Rules to legal profession. We’ll post the decision as soon as it is available.

$1.8 Million Verdict in Pretexting Case

Written by Cynthia and Michael

A Cook County, Illinois jury recently awarded $1.8 million dollars to Kathy Lawlor, who claimed that her former employer, North American Corp. of Illinois, violated her privacy rights by hiring a private investigator who fraudulently obtained her telephone records through the use of “pretexting” – or by pretending to be Lawlor herself. Some of you might be familiar with the concept of pretexting from the Hewlett Packard scandal in 2006 where HP’s Chairwoman directed independent security experts to investigate the source of an information leak. The security experts obtained the personal phone records of journalists and HP board members by pretexting – or by pretending to be them - and it ultimately allowed HP to determine the source of leak. HP’s efforts caused an uproar, including leading to criminal charges, a congressional investigation and the passage state and federal laws prohibiting pretexting.


In the summer of 2005, prior to the HP scandal, North American terminated Ms. Lawlor’s employment because she would not agree to modify her salesperson commission agreement prior to landing the biggest account of her career. As a result, Ms. Lawlor sued North American seeking to recover certain commissions and for a judgment to lift her non-compete agreement. Ms. Lawlor did not know that at the time she sued North American, it had decided to hire a private investigator to investigate whether Ms. Lawlor’s was stealing its confidential information and clients, and that it had provided certain personal information about Ms. Lawlor to the private investigator, including her Social Security number and phone numbers. During its investigation, in addition to stationing individuals outside Ms. Lawlor’s home, the private investigator arranged for a third party vendor to obtain Ms. Lawlor’s personal phone records by pretexting. When Ms. Lawlor later discovered that North American was investigating her activities she added a claim for invasion of privacy to her lawsuit.


At trial, North American denied that it knew that its private investigator had engaged in pretexting, but the jury was unsympathetic and awarded Ms. Lawlor $1.8 million, most of it coming in the form of punitive damages. North American is contesting the jury’s decision, and the parties continue to litigate North American’s claim that Ms. Lawlor misappropriated its trade secrets, but this case should serve as a warning to employers considering whether and how to conduct investigations of their employees. The North American case confirms that any time an employer conducts an investigation into an employee’s activities it runs the risk of violating that employee’s rights and a resulting lawsuit. Employers must takes steps to ensure that any investigation, whether it be conducted internally or through the use of third party investigators, do not utilize unlawful or other inappropriate methods, including the use of pretexting, which is now prohibited by state and federal law.

Wednesday, October 21, 2009

Changes to the "Red Flag" Rules may be coming -- and so is the November 1 compliance deadline

By an overwhelming vote of 400-0, the U.S. House yesterday approved legislation that will exempt certain businesses from the Federal Trade Commission’s Red Flag Rules. As we have reported, the Red Flag Rules require a broadly-defined class of “creditors” to implement identity theft prevention programs by November 1st. Under H.R. 3763, health care, accounting, and legal practices with 20 or fewer employees will be excluded from the definition of “creditor.” The measure also requires the FTC to issue new regulations allowing any business -- regardless of size -- to apply for an exemption.

New Exemption Provision
Under the exemption provision, the bill allows any business to be exempted if the FTC determines that the organization knows all of its customers or clients individually, only performs services in or around the residences of its customers, or has not experienced incidents of identity theft and is part of an industry that rarely experiences the problem. The FTC will be required to issue regulations setting out the exemption process.

ABA Still Not Happy

The American Bar Association says the legislation does not go far enough and
is demanding a full exemption for law firms. The ABA also continues
asking a federal court to bar the FTC from enforcing the rules against
attorneys. Besides the ABA, the FTC's broad interpretation of the creditor
category has prompted objections from the American Medical Association and the AICPA.
It is unlikely that this legislation will be finalized by the current November 1st enforcement deadline, and it remains to be seen whether this will cause the FTC to announce another delay.

Wednesday, October 7, 2009

More on the real cost of the Heartland breach

Nearly 10 months after disclosing a months-long data breach that affected millions of consumers, the financial impact of the Heartland data breach continues to unfold. InformationWeek reports that Heartland stock prices plunged more than $500 million following the breach, and while shareholder value has rebounded, other breach related costs have thus far totaled $32 million, with numerous lawsuits against the company still pending.

When the "Safe Harbor" is Not So Safe

If your company transfers personal data cross-border and you participate in the Safe Harbor program, it’s time to check the status of your certification. For the second time in a month, the Federal Trade Commission has announced enforcement actions against companies under Safe Harbor, the international privacy framework that provides a means for U.S. companies to transfer data from the European Union to the United States in keeping with EU and U.S. law.

In September, the first ever Safe Harbor enforcement action was announced against a California company, Balls of Kryptonite, which had falsely represented that it had self-certified to the Safe Harbor program, when apparently it never had. Yesterday, the FTC continued the trend by announcing six separate enforcement actions in one fell swoop.

According to the six separate complaints, the companies deceptively claimed they held current certifications under the Safe Harbor framework, when in fact the companies had allowed those certifications to expire. Under the proposed settlement agreements, which are subject to public comment, the companies are prohibited from misrepresenting the extent to which they participate in any privacy, security, or other compliance program sponsored by a government or any third party. To participate in Safe Harbor, a company must self-certify annually to the Department of Commerce that it complies with a defined set of privacy principles. The proposed settlements do not include any monetary penalties nor any admission of guilt, but would require compliance monitoring for 20 years.

If you have put Safe Harbor (either compliance or certification) on the “back burner” because it appeared that the FTC was not enforcing the program, the time for change has come. You should check what representations are being made on public-facing websites and privacy policies regarding Safe Harbor certification and ensure that these representations are accurate and up-to-date. In the cases announced yesterday, the defendant companies had been certified, but had let those certifications lapse. The exhibits to the FTC’s complaints included pages from their websites (see links below), and their own words were used against them.

For more information:
To file a public comment in the FTC proceeding - http://www.ftc.gov/os/2009/10/sixcasespubliccomment.pdf and follow the instructions at that site.

FTC Complaints:
In the Matter of World Innovators, Inc.
In the Matter of ExpatEdge Partners, LLC
In the Matter of Onyx Graphics, Inc.
In the Matter of Directors Desk LLC
In the Matter of Progressive Gaitways LLC
In the Matter of Collectify LLC

Safe Harbor List
To check the status of your company’s Safe Harbor certification - Safe Harbor List

Tuesday, October 6, 2009

Vets Data At Risk? Again?

Wired.com reports on a possible breach at -- of all places -- the National Archives and Records Administration (NARA) that, if verified, could affect tens of millions of records about U.S. military veterans. It appears that it may involve an issue that I call “Data Security 101” -- the failure of a contractor to wipe clean a defective hard drive returned to it by NARA . The contractor determined that the drive could not be fixed, and sent it elsewhere to be recycled --- without following ordinary industry procedures (and U.S. Government policy) requiring that hard drives be degaussed before recycling or other disposition.

According to the Wired piece, the incident was reported to NARA’s inspector general by Hank Bellomy, a NARA IT manager, “who charges that the move put 70 million veterans at risk of identity theft, and that NARA’s practice of returning hard drives unsanitized was symptomatic of an irresponsible security mindset unbecoming to America’s record-keeping agency.”

The Veterans Administration settled a class action earlier this year at a cost of $20 million over the 2006 loss of a laptop containing records with personal information of up to 26.5 million veterans and active duty personnel.

Tuesday, September 29, 2009

Save the Date - Safe Harbor/Cross Border Data Transfer Conference in Washington

If you have cross-border privacy issues as part of your portfolio, you should mark your calendar for November 16th. The Department of Commerce has just announced that the 2009 International Conference on Cross Border Data Flows, Data Protection and Privacy will be held on that date in Washington.

“Cross the Divide: Successfully Navigating Safe Harbor” will include discussions of issues such as

• progress on the Safe Harbor framework;
• changes in the binding corporate rules approval process;
• new privacy compliance paradigms;
• sharing data across borders during pandemics;
• privacy management in social networks;
• behavioral advertising in cloud computing; and
• civil litigation e-discovery.

The Conference will be hosted by the Department of Commerce, with the cooperation of the European Commission and the Article 29 Working Party on Data Protection, made up of data protection officials from each of the European Union Member States.

Further information on the conference is available at
www.regonline.com/safeharbor2009.

Friday, September 25, 2009

Privacy and Security Bits and Bytes

After a bit of a hiatus, our Friday afternoon feature is back:

  • Do you know what your information is worth on the black market? It may just surprise you. Good piece on a new Symantec tool to let you do the calculations. See Information Security Resources - What Are You Worth On The Black Market?
  • Despite all of the public flurry surrounding security breaches, and customer expectations that the information entrusted to vendors will be secure, a new survey finds that an astounding 71 percent of those companies surveyed said they still weren't making data security a top initiative in their IT budgets, even though 79 percent of them admitted that they had been hit by one or more data breaches since the PCI DSS standard was enacted in 2005. Companies Still Not Securing Customer Data - InternetNews.com.
  • Companies around the world are preparing for the swine flu pandemic and putting policies and procedures in place for workers and business continuity. What, if anything, are people doing about the privacy issues that need to be addressed in that planning?
    Good article, with links to resources here - Protecting Your Privacy During a Pandemic
  • Remember our blog posts on the demise of the Clear program? Next week, the Committee on Homeland Security is holding a hearing on "The Future of the Registered Traveler Program"
    Wednesday, September 30, 2009 @ 2pm
    311 Cannon House Office Building
    The hearing will evaluate the recent cessation of operations by Registered Traveler (RT) providers, actions undertaken by the Transportation Security Administration (TSA), and the impact on airports. There will be a webcast of this hearing.

Should be fascinating viewing. I wonder if we'll hear anymore about whatever happened to all that data???

Check your employee handbook - what you might think is fraud and abuse may not be a federal case....

My colleagues over at the Employment Matters blog report on an
interesting decision drawing attention to the need for clear and explicit policies regarding "acceptable use" of computers and company information and the absolute necessity to terminate access once an employee or contractor is terminated.

Particularly in light of the upcoming Massachusetts data security regulations, permitting employees (contract or otherwise) to email unencrypted documents containing personal information of customers/clients/employees outside of the organization to be stored on a home computer (similarly unencrypted, one can presume) will be a violation of 201 CMR 17.00 if that list contains "Personal Information" of Massachusetts residents, and failing to have procedures as part of your information security plan that terminates access to such information for former employees will also be a violation. Similarly, because a health care provider and protected health information is involved here, this action would be in violation of the new HHS guidelines for the handling of PHI and, finally, because the defendant was no longer authorized to have the information, it was likely a reportable breach under HIPAA and many state laws.

For all that the incident is, it seems that the Ninth Circuit does not find that it was a violation of the federal Computer Fraud and Abuse Act.

Thursday, September 24, 2009

"Smart Grid" privacy issues to be examined by Federal Communications Commission

Smart Grid technology enables electric utilities to use communications and computing technology to glean consumer electric usage patterns to facilitate more efficient network management. It's been identified by the FCC as a promising way to use broadband to promote energy efficiency, reduce greenhouse gas emissions, and encourage energy independence.

These consumer electric usage patterns could conceivably do far more.... For example, marketing firms may find valuable market penetration data in consumer electric usage patterns and law enforcement could use information about electricity usage to pinpoint potential sites of criminal activity. Basically, the very characteristics that make smart grid information valuable to environmental efforts may also have serious implications for consumer privacy and are attracting the interest of regulators here in the U.S. and elsewhere.

Specifically, the FCC has sought comment by October 2, 2009 on the issue of how strong privacy and security requirements can be satisfied in deploying smart grid technology without stifling innovation.

The Colorado Public Utilities Commission just closed a comment period last week on the following issues and the comments received on these questions may help to further inform the debate at the national level:

1. What concerns surrounding the collection and analysis of detailed electricity usage information should the CPUC consider as it establishes policies governing access to and use of this information?
2. What, if any, are the trade-offs between protecting privacy and promoting innovation with regards to smart grid technology?
3. Should detailed electricity usage information be protected? If so, how?
4. How do constitutional or statutory protections impact the use of consumers’ detailed electricity usage information collected as part of smart grid initiatives? What protections should be put in place even if not covered by constitutional or statutory provisions?
5. What are the necessary components of effective privacy regulation of consumer electricity usage patterns? For example, should disclosure of consumer information to third-parties be on an opt-in or an opt-out basis, or should the consent-requirement depend on the nature of the party receiving the information?
6. How much information about consumer electricity usage do electric utilities and “edge service providers” require to facilitate more efficient network management, load forecasting, asset management, bill control, demand-side load management, efficiency consulting, energy savings contracting, etc.?
7. How do privacy regulations affect electric utilities and “edge service providers” in their efforts to provide enhanced electricity management services?
8. Who “owns” customer information?
9. What should be a utility’s obligation to “unbundle” metering in homes and businesses?

Tuesday, September 22, 2009

Your mother was right: the FTC confirms you don't get a second chance to make a first impression

Written by Cynthia and Michele

So you thought that if you made "full disclosure" in your online agreements with customers, you'd be OK -- well, it's time to think again.

The FTC recently confirmed in In re Sears Holdings Management Corp that even full disclosure of company practices in an end user license agreement (“EULA”) or terms of service (“TOS”) may be no defense to fraud claims. Nearly all online service providers require users to agree to terms of use. And, typically these terms of use are enforceable. However, the FTC’s recent order makes it clear that the adequacy of the disclosures in a EULA or TOS will be determined not by the completeness of the disclosure itself, but on a case-by-case basis in light of all of the other representations made to consumers. Thus, burying the use of marketing software with behavioral tracking capabilities, even though ultimately disclosed fully, in a multi-step sign-up and download process as Sears did will not necessarily shield a company from a fraud claim.

Requiring online service providers to obtain express consent before employing marketing software is nothing new. For example, in a consent order reached with a company called Zango, the FTC said that express consent is required before employing tracking software with pop-ups --- and tagged Zango for $3 million. In another case, In re DirectRevenue LLC, the FTC required express consent before installing what they called “lureware,” along with a fine of $1.5 million.

What is notable about Sears, however, is the shift in focus from the completeness of disclosure itself to its completeness in light of all other representations. While a EULA disclosure may be complete in itself, it is now clear that even a full and complete disclosure will correct other representations if the overall impression is misleading. In short, service providers will not get a second chance to make a good first impression.

Practical advice -- take another look at your EULA or TOS and make sure that it is not just complete, but it is accurate.

Monday, September 21, 2009

What is "reasonable expectation of privacy" in an employment context?

Written by Cynthia and Jennifer

A recent decision by the Maine Supreme Court highlights the tension between an employee's reasonable expectation of privacy in conducting personal business through a company's computer system and the individual's right to prevent the company's publishing of such material. In Fiber Materials, Inc. v. Subilia, the Maine Supreme Court dismissed an interlocutory appeal by a former executive who charged the company with improperly accessing and publishing the executive's attorney-client privileged communications with his attorney which had been stored on the company's computer system. While the court dismissed the appeal for procedural reasons, the court criticized the company's counsel for taking the preemptive position that the material retrieved was appropriately disclosed publicly without first seeking advice from state bar counsel before publishing it in a complaint.

The issues in this case are similar to those raised in the Scott v. Beth Israel case, where a New York trial court concluded that an employee's use of the employer's email system to communicate with his attorney waived the privilege because the employer's policy expressly prohibited personal use of the email system.

While these cases appear to produce two different results, they dictate the care employees and employers alike must take with respect to accessing information on a company-owned computer system and the use of that system in the first instance to conduct any type of personal business, especially sensitive personal business.

Friday, September 18, 2009

Federal Breach Notification Rules -- NEXT WEEK. Are you ready?

Written by Cynthia and Dianne

New federal breach notification rules go into effect next week for covered entities and their business associates and also for vendors of personal health records.

Covered entities (organizations subject to the HIPAA privacy rule) and their business associates must report breaches of unsecured protected health information in accordance with new rules from the Department of Health and Human Services (HHS) starting Wednesday, September 23, 2009. Unsecured protected health information is information that has not been either encrypted or destroyed in accordance with HHS standards. Note that under the rules, a covered entity may not have to report a breach of unsecured protected health information if, after conducting a risk analysis, it believes in good faith that the unauthorized recipient of the PHI would not reasonably have been able to retain it (for example, if misdirected patient correspondence is returned as undeliverable and is unopened).

The breach notification regulations require prompt notification to affected individuals, as well as to the HHS Secretary and the media in cases where a breach affects more than 500 individuals. Breaches affecting fewer than 500 individuals must be reported to the HHS Secretary on an annual basis. The regulations also require business associates of covered entities to notify the covered entity of breaches by the business associate.

The HHS regulations were developed in close consultation with the Federal Trade Commission (FTC), which has issued companion breach notification regulations that apply to vendors of personal health records and certain others not covered by HIPAA. The FTC regulations are effective September 24, 2009. The rules are identical with respect to some provisions, similar in others, and completely different in a few others. Those differences can matter because some organizations will be covered by both regulations.

Both the FTC and HHS intend for their regulations’ notices to be combined with the state-required notices, so that a consumer would receive only a single notice. The agencies’ requirements for the content of the notices are practically identical, but the regulations have many differing requirements on a wide range of topics. For example, HHS’ requirements extend to breaches of health information in all formats, including paper, whereas the FTC’s requirements extend only to health information in electronic form. Also remember, there will be different state requirements for notice, some of which (particularly in Massachusetts) will conflict with the FTC/HHS content.

Links:
Text of HHS Breach Notification Rule
Text of FTC Breach Notification Rule
Mintz Matrix of State Data Breach Notification Laws, current as of August 31, 2009