Wednesday, May 26, 2010

Congressmen Question Google on Wi-Fi

Today, Congressmen Joe Barton (R-TX), Edward Markey (D-MA), and Henry Waxman (D-CA)wrote to Google Chairman and CEO Eric Schmidt seeking answers to the company’s collection of private information over Wi-Fi networks.

“We are concerned that Google did not disclose until long after the fact that consumers’ Internet use was being recorded, analyzed and perhaps profiled. In addition, we are concerned about the completeness and accuracy of Google’s public explanations about this matter,” wrote the lawmakers. “For example, on April 27, 2010, a Google blog post contained inaccurate information about whether payload data was collected. However, a Google executive on May 14, 2010, admitted in Google’s official blog that the company had ‘been mistakenly collecting samples of payload data from open (i.e., non-password-protected) Wi-Fi networks.’”

Barton and Markey, co-chairmen of the House Privacy Caucus, separately wrote last week to Federal Trade Commission Chairman Jon Liebowitz about Google’s recent revelation that it gathered the network information.

The lawmakers asked Schmidt to respond to the following questions:

What percentage of United States roads have been documented for Google Street View?

Over what time period did the collection of information for Google Street View take place or, if roads are visited by Google Street View vehicles more than once, what is the schedule for return visits to roads?

Have all Street View vehicles documenting United States roads been engaged in the monitoring or data collection of Wi-Fi transmissions at all times during those activities? If the answer is no, please explain in detail in what communities the monitoring or data collection was conducted and the reasons that these communities were chosen for monitoring or data collection.

How many Wi-Fi networks across the country have been logged since Google began its Street View program? How many consumers were subject to the data collection?

Was any notification of this monitoring and data collection made to affected communities prior to deploying Street View vehicles, and was consent sought from consumers? If so, please explain the notice and consent procedures involved. If not, please explain why this was not done.

Has Google at any time conducted a legal analysis regarding the applicability of consumer privacy laws on the monitoring and data collection of Wi-Fi transmissions? If so, please provide a copy of this analysis.

Please explain why Google chose to collect the data and how it intended to use the data.

What is the status of the consumer data collected? Has it been analyzed and used in any way? Does Google have plans to use it in the future? Please explain in detail.

Has the collected data been destroyed? If yes, when and by which method(s)? If not, why not?

What is the status of Google’s internal review of Street View’s monitoring and data collection practices to ensure adequate controls? What is the methodology? When did the review start? Who is conducting the review? Are there any interim findings? When is it expected to be completed? Will the review, or portions of it, be made available to the public?

What is Google’s process to ensure that data collection associated with new products and services offered by the company is adequately controlled?

Has Google asked a third party to review the software at issue? If so, who is the third party, and what is the nature of the review?

A copy of the letter to Schmidt can be found here. A copy of the letter to the FTC on the Google can be found here.

Monday, May 24, 2010

Red Flags Rule Compliance Date Approaching - American Medical Association Sues

It’s been a while since we have visited the Federal Trade Commission’s Red Flags Rule here in this blog. The oft-postponed deadline is now fast approaching on June 1. Except, that is, for lawyers and now, doctors.

On Friday, the American Medical Association filed a lawsuit against the FTC for defining physicians as “creditors” and claiming that requiring physicians to comply with the Red Flags Rule could jeopardize the doctor-patient confidential relationship. The Red Flags Rule (to refresh your memory) requires that “creditors” establish identity theft protection programs and would likely require physicians to obtain positive identification of patient identity – before providing treatment, as argued by the AMA.

The lawsuit argues that the FTC acted beyond its authority because physicians are not creditors and patients are neither accountholders nor customers under the Fair and Accurate Credit Transactions Act (FACTA). The latter is a more likely argument than the former. Under FACTA, an “entity that regularly defers payment for goods or services” can be considered to be a creditor and physicians routinely bill patients after the completion of services, including for the remainder of medical fees not reimbursed by insurance. I have been in doctor’s offices over the last 6 months where new patients are asked for their insurance card, and their driver’s license or a photo ID. This would seem to be a small step towards controlling medical identity theft.

Read about medical identity theft at World Privacy Forum Medical Identity Theft Page

Thursday, May 13, 2010

Facebook Holding Privacy Summit

As a follow-on to yesterday's posts regarding the public face of the Facebook privacy brouhaha, at this hour Facebook is holding an “all-hands” meeting to discuss the company’s overall privacy strategy. PC World suggests that perhaps today’s company meeting is the beginning of Facebook's effort to improve user guidance on issues of sharing and privacy, or maybe the company is considering a roll back of new features. Stay tuned.

Related links:

GigaOM » Facebook Needs to Find Its Voice on Privacy
Facebook's Eroding Privacy Policy: A Timeline Electronic Frontier Foundation

Wednesday, May 12, 2010

The back-and-forth on Facebook's privacy travails

Whether the terse discussions in the public arena over Facebook’s privacy “changes” demonstrate that the world’s largest social network is playing fast and loose with the truth about its internal controls on user privacy, or whether it is just an example of poor corporate communication of policies to end users is still a matter of debate. See Glitch Brings New Worries About Facebook’s Privacy - NYTimes.com.

Last week, the author of the Times’ technology blog Bits invited readers to submit questions for Facebook's vice president for public policy, Elliot Schrage. She probably got more than she (or Schrage) expected – in fact, over 300 of them. Schrage’s response is published in today’s blog entry: Facebook Executive Answers Reader Questions - Bits Blog - NYTimes.com.

For a completely different view of Mr. Schrage’s comments, I found Catharine Taylor’s post at Social Media Insider to raise some important questions.

Two privacy issues from North of the Border

Ann Cavoukian, Ontario’s information and privacy commissioner, has issued her 2009 Annual Report, entitled “Access & Privacy, A Time for Innovation.” One of Cavoukian’s main subjects this year is the smart grid and the associated privacy issues, including the collection of knowledge about personal habits via “smart” appliances communicating with the grid. Cavoukian is a thought leader in building privacy into processes and controls and we’ve blogged about some of her writings in past issues. Her latest publication is worth consideration as we move further along with technological development – and before the grid becomes too smart.

Related link:
Smart grid data must be protected: Privacy czar - thestar.com

And, Canada’s Assistant Privacy Commissioner is expressing concerns about the U.S. Secure Flight Program that will complete implementation and be fully operational by December. Under the program, passengers of any nationality who raise suspicions of U.S. authorities can be prevented from boarding flights that fly over U.S. airspace. Chantal Bernier told the Canadian Parliament yesterday that there is little Canada can do about it except urge the U.S. government to address extremely long data retention periods and other privacy concerns of Canadians. Under the program, Homeland Security may retain information collected (including name, birth date, flight information, itinerary and passport number) for periods ranging from a week up to 99 years.

Related link:
Vancouver Sun

Thursday, May 6, 2010

Privacy Events Calendar

Symposium on Privacy and Innovation

Tomorrow
, the Commerce Department is hosting a day-long symposium called “A Dialogue on Privacy and Innovation.” It will include several panel discussions to discuss stakeholder views and to facilitate further public discussion on privacy policy in the United States. The event will seek participation and comment from all Internet stakeholders, including the commercial, academic, and civil society sectors, on the impact of current privacy laws in the United States and around the world on the pace of innovation in the information economy. The event will be webcast at
http://www.ntia.doc.gov/InternetPolicyTaskForce/privacy/webcast.html

This Symposium is related to Commerce’s ongoing Notice of Inquiry seeking comment on the impact of current privacy laws in the United States and around the world on the pace of innovation in the internet economy. The Notice of Inquiry is at Internet Policy Task Force and comments are due June 7, 2010.


Roundtable on COPPA

FTC has announced that it will host a public roundtable on June 2, 2010, to examine whether technology changes warrant revisions to the Children’s Online Privacy Protection Rule. The Rule was enacted in 2000 and requires website operators to obtain parental consent before collecting, using, or disclosing personal information from children under the age of 13. Topics will include whether the Rule should be applied to emerging media, a potential expansion of the Rule to cover additional types of information, and the review of the verification methods used by websites. The roundtable will be held at the FTC Conference Center at 601 New Jersey Avenue, NW in Washington, DC. It is free and open to the public. No advanced registration is required

20th Annual CFP Conference

The 20th Conference on Computers, Freedom, and Privacy will be held on June 15-18 in San Jose, CA. Keynote speakers include Peter Cullen of Microsoft and David Drummond of Google. "Hot topics" sessions covering the latest news in freedom, privacy, and networks, and CFP's first "Unconference". Other highlights include sessions focusing on consumer advocacy, human rights, business perspectives, and cutting-edge intersections between technology and policy.

Monday, May 3, 2010

Welcome to the Privacy Revolution

This is "Choose Privacy Week" – an initiative by the American Library Association to raise awareness about sharing information online. The Association has launched a new website, Privacy Revolution, offering tips for educators and parents on ways to address privacy concerns with children.

One sure way not to raise the issue was demonstrated by a principal in Ridgewood, New Jersey last week. According to a post by Christopher Dawson in ZDNet Education IT, principal Anthony Orsini sent parents an email strongly urging them to take the role of cyberpolice with their middle school children, because “…there is absolutely, positively no reason for any middle school student to be a part of a social networking site! None.” Raising the consciousness of parents to the risks and dangers inherent in social networking and encouraging discussion at home is one thing. This is on an entirely different level.

Related links:
New Jersey principal deputizes parents as cyber police Education IT ZDNet.comALA Launches Choose Privacy Week - 5/3/2010 - School Library Journal

Sunday, May 2, 2010

OT -- Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico

Off the privacy topic, but certainly an issue of national security. Mintz Levin client, InnoCentive, is crowdsourcing a solution to respond to the oil spill in the Gulf of Mexico. Over 250 people are currently working on the challenge posted to the site (link below) -- pass this on and get the collective wisdoms of the crowd moving!!

Emergency Response 2.0 : Solutions to Respond to Oil Spill in the Gulf of Mexico

Friday, April 30, 2010

Privacy and Security Bits and Bytes

On this last day of April, there are a couple of breaches and another clarion warning about copy machines --


We have blogged on this issue here and here -- and again, there is another warning about the treasure trove of information residing on the hard drive of your copy machine. A CBS Evening News investigation revealed just how much information is stored on copy machines that gets passed on when the machine’s lease is up and the machine is resold. Adding one more to the mounting pile of privacy-related investigation requests the Federal Trade Commission has received in recent days, U.S. Rep. Edward Markey (D-MA) requested the commission look into the issue in a statement released yesterday.

Make sure that you don’t violate data protection laws in Guernsey – the offshore banking center has amended its privacy law to include prison time for violations. Persons found guilty under Section 55 of the law of unlawfully obtaining (or disclosing) personal data without the consent of the data controller may now face a prison sentence. Previously, the most severe penalty available was a fine of up to £10,000 Data protection law amended - International Law Office

Add Mexico to the list of countries with a national comprehensive data protection law. Mexico's Senate on Tuesday unanimously approved the Federal Law of Protection of Personal Information. The law establishes the rights and principles of data protection in the private sector, and was nine years in the making.

And two “breaches du jour: The Louisville Courier-Journal reports that a flash drive containing the personal information of 24,600 patients of a psychiatric hospital has gone missing. According to the report, the drive contained patient names, admission and discharge dates and dates of birth. (Begs the question of why protected health information (or PHI) is on an unsecured flash drive in the first place…. ) And, in California, St. Jude Heritage Healthcare has notified 22,000 patients about the theft of five hospital computers containing their PHI.

Thursday, April 29, 2010

Connecticut Woman Files First Suit Under Federal Law Prohibiting Genetic Discrimination

Written by Jennifer Rubin

A Connecticut woman has filed a charge of discrimination under the Federal Genetic Information Nondiscrimination Act ("GINA"), which prohibits discrimination against employees based upon their status as carriers of genetic information. The woman claims her status as a carrier of the BRCA2 gene, a gene sometimes associated with the elevated risk of breast cancer, led to her termination after she had preventive surgery relating to her breast cancer risk.

GINA was passed to address concerns of individuals who might be reluctant to undergo genetic testing because the results, if disclosed to an employer, might be used in a discriminatory manner by employers. While it is premature to predict the probability of outcomes of this employment dispute, it reminds employers of their obligations to comply with GINA and other numerous other Federal and state laws concerning the management and use of health information in the workplace.

Related Links:

Hartford Courant
Woman claims genetic test led to firing at Stamford firm - StamfordAdvocate
Home WGGB abc40 News, Weather and Sports in Springfield Massachusetts

Monday, April 26, 2010

Proposed HITECH Regulations Out in May?

Buried in a part of today's Federal Register was the publication of the Department of Health and Human Services' regulatory agenda. The agenda presents a forecast of expected HHS rulemaking activities and suggests that in May of this year HHS will issue the long-awaited proposed rules to modify the HIPAA Privacy, Security, and Enforcement Rules as necessary to implement the privacy, security, and certain enforcement provisions of the HITECH Act (see our earlier blog posts).

The Department is also scheduled to issue a final rule in May of this year, addressing the certification standards and implementation criteria for electronic health record technology.

Thursday, April 15, 2010

Brokerage firm victim of elaborate extortion scheme - but also gets hit with a fine

Brokerage firm DA Davidson has agreed to pay a fine of $375,000 for failing to protect confidential client data from Latvian hackers who breached the company in 2007 in an online extortion scheme and the three have pleaded guilty in Montana.

The hackers used a SQL injection attack to obtain access to the company’s database on Dec. 25 and 26, 2007.

The Financial Industry Regulatory Authority, which announced the fine agreement on Monday, said although the attack activity was reflected in the brokerage’s server logs, administrators failed to examine those logs. The intruders obtained data on about 192,000 customers, according to the press release announcing the fine. (Previous reports indicated that more than 300,000 customer files were stolen). The data included customer account numbers, Social Security numbers, names, addresses, dates of birth and other private information.

The company discovered the breach only after receiving an extortion e-mail from one of the hackers on Jan. 16, 2008, which contained an attachment with the records of 20,000 customers as proof of the intrusion. DA Davidson contacted the Secret Service, and the subsequent investigation led to four suspects, three of whom are Latvian nationals, who were extradited from the Netherlands to face charges in Montana. In a statement released yesterday by the U.S. Attorney for Montana, the three Latvians pleaded guilty to receipt of extortion proceeds.

More: Wired Magazine
Three Plead Guilty in Plot to Extort DA Davidson - Financial Planning
The United States Department of Justice - United States Attorney's Office

Federal Regulators Release Model Consumer Privacy Notice Online Form Builder

Last year, the eight federal regulators that regulate the financial services industry issued a "simplified" model privacy notice that was published in the Federal Register on December 1, 2009. Today, the regulators released an "Online Form Builder" to guide a covered institution to select the version of the model form that fits its practices, such as whether the institution provides an opt-out for consumers.

Under the new regulation, to obtain a legal "safe harbor" and satisfy the disclosure requirements under the Gramm-Leach-Bliley Act, institutions must follow the instructions in the model form regulation when using the Online Form Builder.

The form is available here: Online Form Builder

Friday, April 9, 2010

Privacy and Security Bits and Bytes

Our Friday afternoon feature --

Virginia Adds Medical Information Breach Law - The Commonwealth of Virginia has amended its data breach notification law to include breaches of medical information. For the text of the amendment, link here. Even if the data is encrypted, the law requires notice if the breach involved a person with access to the encryption key. The law requires notice to affected individuals (residents of Virginia) as well as Virginia's Office of Attorney General. The Attorney General can bring an action for violations of the law and impose civil penalties up to $150,000 per breach (or a series of similar breaches of a similar nature that are discovered in a single investigation). The law does not apply to persons or entities that must report the breach under the HITECH Act.

“Data Security – It’s a Responsibility, Not an Option” – interesting point of view from InfoSecIsland.


FTC Complaint Focuses on Tracking, Profiling of Consumers. -- Yesterday, the Center for Digital Democracy, the US Public Interest Research Group, and the World Privacy Forum filed a complaint with the FTC regarding two emerging trends in online advertising that they say pose growing threats to consumer privacy: auctioning of individual Internet users for targeted advertising opportunities and the combination of online and offline data about Internet users. The complaint describes what the group feels is a growing trend in online behavioral advertising that involves the real-time sale and trade of the right to target individual users with online ads through the use of data compiled about users via their Web surfing habits. The groups have asked the FTC to investigate the data and advertising exchanges operated by Google, Microsoft and Yahoo, as well as several firms that support the auctioning and data collection/targeting system, including AppNexus, BlueKai and Rubicon Project. Furthermore, the group has asked the FTC to require the firms involved in real-time online tracking and auction bidding to allow consumers to opt-in to participate in such activities; require firms to update their privacy policies so consumers are aware of these activities; and ensure consumers are compensated for the use of their data. Stay tuned.

Large UK Data Breach Penalty Takes Effect -- As we warned you in this space last month, this week marks the effective date of the new, substantially higher fines in the UK for data loss. Reports are that up to 65 percent of workers are unaware of the new penalties – which can quickly hit £500K for large scale breaches. If you’re operating in the UK, check out Data loss fines hit £500K from today • The Register or ICO vows to impose heavy fines for major data breaches - 07 Apr 2010 - Computing.

And Finally --

This item from Wired Magazine proves yet again that identity theft is not limited to computer hacking or interception of electronic messages. A 74-count indictment unsealed yesterday in Arizona details charges that a group of sophisticated identity thieves managed to steal millions of dollars by filing bogus tax returns using the names and Social Security numbers of other people, many of them deceased.

Thursday, April 8, 2010

Mississippi Becomes 46th State to Enact Data Breach Notification Law

It appears that Governor Haley Barbour has signed legislation sent to his desk by the Legislature on April 1, making Mississippi the 46th state to enact a data breach notification law.

Similar to most of the other laws, the Mississippi law applies to any person who owns, licenses or maintains computerized personal information of any resident of that state. Breaches must be disclosed “without unreasonable delay.” It does not appear that the Mississippi law imposes any out-of –the-ordinary obligations on businesses, but the trend continues. The law becomes effective July 1, 2011.

Link to text of legislation:

HB 583 (As Sent to Governor) - 2010 Regular Session

Tuesday, April 6, 2010

More on last week's NJ Supreme Court decision -

The decision we blogged about in this space last week is creating quite a bit of buzz in both privacy and employment law circles. My employment law colleagues in our New York office have authored an analysis of the decision here: Employment Alert: New Jersey Supreme Court Finds Privacy Rights in Employee E-Mails

And, the International Association of Privacy Professionals' Daily Dashboard quoted my partner, Jen Rubin:

PRIVACY LAW -- U.S.
Employee E-mail Decision Spurs More Questions
Last week's New Jersey Supreme Court decision that employees should have an expectation of privacy when they use personal e-mail accounts on corporate computers is raising new questions, NetworkWorld reports. The court's decision specified that when it comes to monitoring employees' actions online, "employers have no need or basis to read the specific contents of personal, privileged, attorney-client communications in order to enforce corporate policy." Jen Rubin, attorney at Mintz Levin in New York, says the decision brings up new questions about employer ownership of e-mail created on company-issued computers and is likely to have businesses taking much closer looks at their e-mail policies. Full Story

This is an important decision with wide-reaching implications. If you are an employer and you have not looked at your "Acceptible Use Policy" or other such electronic systems policy in a while (or worse, if you don't have one at all.....), this case should motivate you to pull it out and look again.

Wednesday, March 31, 2010

BREAKING NEWS: NJ Court Upholds Employee E-mail Privacy

In a precedent-setting decision, the New Jersey Supreme Court today ruled that a company should not have read e-mails a former employee sent to her lawyer from a private Web account through her employer's computer (See November 5, 2009 Privacy and Security Information blog post). According to the Star-Ledger, the court, which determined the company's policy regarding e-mail use was vague, upheld the sanctity of attorney-client privilege in electronic communications.

Given the importance of this decision to both privacy issues and employer/employee workplace issues, we will provide a complete analysis.

Tuesday, March 30, 2010

Government "Outs" Mystery Retailers in Gonzalez Hack Case

Interesting post in today’s Wired: Threat Level blog about a motion in the Alberto Gonzalez hacking case that was unsealed on Monday. We now have the identities of the other two “mystery” retailers – J.C. Penney was “Company A” and Wet Seal was “Company B.”

J.C. Penney argued unsuccessfully last week to keep the company’s identity under seal, and that it (a corporation) was entitled to anonymity under the 2004 Crime Victims' Rights Act. That law was intended to protect the “dignity and privacy” of victims – and that is what Penney argued. but Judge Douglas P. Woodcock was not convinced -- and in fact was "astonished." The Judge said in the hearing that he believed both retailers should have announced their involvement from the start and that consumers had the right to know. Woodlock said he would not provide the companies “insulation from transparency.”

For more: StorefrontBacktalk » JC Penney, Wet Seal: Gonzalez Mystery Merchants

Motion of Government - http://www.wired.com/images_blogs/threatlevel/2010/03/09-cr-10382-14.pdf

Monday, March 29, 2010

More detail on Dave & Buster's FTC Settlement

As we blogged here last week, we were going to post our Client Alert with further details about the settlement and consent order reached by the restaurant chain Dave & Buster's and the Federal Trade Commission relating to the breach suffered by the chain. Here is the alert -- Privacy and Security Alert: Popular Restaurant Chain Settles Federal Trade Commission Data Breach Charges.

Tip: This breach was the result of malicious hacking. In fact, the hacker - Alberto Gonzalez - was just sentenced to 20 years in federal prison for his crime. However, the FTC's concern was that the restaurant chain did not have "reasonable security measures" in place to prevent the hacking in the first place, or to detect it as it was occurring. Time to take stock of the point-of-sale systems in your store/restaurant.

French Senate Passes Breach Notice Bill

The French Senate has overwhelmingly approved a major draft bill updating the country's 1978 data protection act to, among other things, create the European Union's strongest breach notification requirement and expand powers of the French data protection authority, known as "CNIL."

This bill also doubles monetary penalties for violations of the data protection law. It now moves on to the National Assembly.

The bill, as passed by the Senate is available, in French, at http://www.senat.fr/petite-loi-ameli/2009-2010/331.html