<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Privacy Compliance &amp; Data Security</title>
      <link>http://dataprivacy.foxrothschild.com/</link>
      <description />
      <language>en</language>
      <copyright>Copyright 2012</copyright>
      <lastBuildDate>Tue, 24 Apr 2012 13:20:27 -0500</lastBuildDate>
      <pubDate>Tue, 24 Apr 2012 13:20:27 -0500</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="privacycompliancedatasecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://dataprivacy.foxrothschild.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://dataprivacy.foxrothschild.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.yourminis.com/subscribe.aspx?u=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.yourminis.com/images/addtoyourminisbadge.gif">Subscribe with Yourminis.com</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://hub.netomat.net/account/account.autoSubscribe.jspa?urls=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.netomat.net/blogger/images/icon_netomat_feedbutton.gif">Subscribe with netomat Hub</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
         <title>Vernick on Cyber Security in the Huffington Post</title>
         <description>&lt;p&gt;The FBI reports that cyberattacks could overtake terrorism as the major threat to the country.&amp;nbsp;&lt;a href="http://www.nytimes.com/2012/03/14/us/new-interest-in-hacking-as-threat-to-us-security.html"&gt;According to the Department of Homeland Security&lt;/a&gt;, between October 2011 and February 2012, there were 86 reported attacks on U.S. computer systems that control critical infrastructure, factories and databases, compared with 11 over the same period a year ago.&lt;/p&gt;
&lt;p&gt;Now more than ever, the focus should be on securing and insulating our nation's computer and Internet infrastructure from both internal and external attacks. The first step in anticipating large-scale cyberattacks is to start thinking of them more like the proverbial disaster waiting to happen -- not a question of if, but when. Planning requires going beyond the limitations of current thinking and considering worst case scenarios.&lt;/p&gt;
&lt;p&gt;To keep reading my full article visit &amp;ldquo;&lt;a href="http://www.huffingtonpost.com/scott-vernick/internet-privacy-debate_b_1447355.html"&gt;The Internet Privacy Debate Misses the Point&lt;/a&gt;,&amp;rdquo; published April 23 by the&amp;nbsp;&lt;i&gt;Huffington Post&lt;b&gt;.&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/zmp6JVQsSms" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/zmp6JVQsSms/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/04/articles/vernick-on-cyber-security-in-the-huffington-post/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/">Articles</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category>
         <pubDate>Tue, 24 Apr 2012 10:11:48 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/04/articles/vernick-on-cyber-security-in-the-huffington-post/</feedburner:origLink></item>
            <item>
         <title>An Example of the Right Way to Handle a Data Breach: Motorola Xoom</title>
         <description>&lt;p&gt;You may have read that &lt;a href="http://mediacenter.motorola.com/Press-Releases/Motorola-Mobility-Notifies-Certain-Purchasers-of-Refurbished-Motorola-XOOM-Wi-Fi-Tablets-of-Refurbishment-Process-Error-39d6.aspx"&gt;Motorola announced&lt;/a&gt; on February 3rd that it inadvertently sold around 100 refurbished &lt;a href="http://www.motorola.com/Consumers/US-EN/Consumer-Product-and-Services/Tablets/MOTOROLA-XOOM-with-WiFi-US-EN"&gt;Motorola Xoom tablets&lt;/a&gt; through &lt;a href="http://www.woot.com"&gt;Woot.com&lt;/a&gt; without putting the tablets through the typical process of doing a factory reset and wiping any personal data that may have been left by the original owner(s). &amp;nbsp;Specifically, there were approximately 6,200 tablets sold between October and December 2011, of which 100 tablets were affected.&lt;/p&gt;
&lt;p&gt;The announcement was interesting in and of itself because it highlighted the notification obligation that arose even though Motorola (likely) had no actual knowledge that refurbished tablets went out that actually contained data. &amp;nbsp;Apparently, Motorola only knew that there was a breakdown in its internal processes and some 100 tablets were not wiped, possibly resulting in the resale of some tablets with data not erased by a customer prior to returning the tablet.&lt;/p&gt;
&lt;p&gt;Purchasers of the 6,200 tablets through Woot.com were notified by email to go to a Motorola web site and type in the serial number (or some similar identifier), at which point you would be told if your tablet was affected. &amp;nbsp;If your tablet was affected, Motorola asked that you agree to part with your tablet for four to five business days so that it could be factory wiped.&lt;/p&gt;
&lt;p&gt;As to turns out, I owned one of the 100 tablets affected. &amp;nbsp;I never win anything, except the Affected Xoom Tablet Lottery. &amp;nbsp;A day or so later a package with easy-to-follow instructions, very protective packaging and a prepaid envelope arrived at my work. &amp;nbsp;In went the tablet, out went the package. &amp;nbsp;On the fourth business day the tablet was returned in working order with a thank you and restore instructions.&lt;/p&gt;
&lt;p&gt;And an American Express gift card for $100!!!&lt;/p&gt;
&lt;p&gt;Did I have to return the tablet for a factory wipe? &amp;nbsp;No. &amp;nbsp;Was it a burden for me to return the tablet? &amp;nbsp;Hardly. &amp;nbsp;Was I impressed by Motorola giving me a gift card? &amp;nbsp;Damn right I was, and that is my point. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;As someone that deals with data breaches, and clients that have to make tough decisions regarding data breaches, on an almost daily basis, this situation struck me. &amp;nbsp;Motorola did the right thing, went above and beyond what was required, and solidified good will with me. &amp;nbsp;I was not even the party with the affected data. &amp;nbsp;I was just the guy that got the great deal on Woot.com for a refurbished tablet.&lt;/p&gt;
&lt;p&gt;That Droid Bionic MAXX suddenly is even more appealing to me. &amp;nbsp;Motorola is suddenly more appealing to me (not that I had any particular problem with them before).&lt;/p&gt;
&lt;p&gt;It is possible that Woot.com gave me the gift card, and for that reason my patronage to Woot.com also has been strengthened. &amp;nbsp;This is a great example of partners working together to deal with data breach situations. &amp;nbsp;Making the best of a difficult situation, and earning some good will along the way.&lt;/p&gt;
&lt;p&gt;Kudos to Motorola and Woot.com for their handling of this situation.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/D2xQM3vsamI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/D2xQM3vsamI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/02/articles/data-security-breach-response/an-example-of-the-right-way-to-handle-a-data-breach-motorola-xoom/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category>
         <pubDate>Tue, 14 Feb 2012 19:24:08 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/02/articles/data-security-breach-response/an-example-of-the-right-way-to-handle-a-data-breach-motorola-xoom/</feedburner:origLink></item>
            <item>
         <title>Data Breach Potentially Affects Up to 100,000 Students, 3,000 Employees</title>
         <description>&lt;p&gt;&amp;nbsp;The San Francisco Chronicle &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/13/MN4Q1MO9JK.DTL&amp;amp;type=education"&gt;reported yesterday&lt;/a&gt; that officials at the City College of San Francisco discovered a few days after Thanksgiving 2010 that certain&amp;nbsp;computers of the college have been&amp;nbsp;infested with active malware for more than a decade. &amp;nbsp;Up to 100,000 students and 3,000 employees could be affected, and that number may rise based on further, ongoing investigation.&lt;/p&gt;
&lt;p&gt;The problem was detected when the college's data security monitoring service discovered very high traffic and alerted the college. &amp;nbsp;Initially thought to be limited to one computer lab (Cloud Hall at the Phelan Avenue campus), further investigated revealed that the problem was more widespread. &amp;nbsp;The San Francisco Chronicle's &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/13/MN4Q1MO9JK.DTL&amp;amp;type=education"&gt;article&lt;/a&gt; reported:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Each night at about 10 p.m., at least seven viruses begin trolling the college networks and transmitting data to sites in Russia, China and at least eight other countries, including Iran and the United States, Hotchkiss and his team discovered. Servers and desktops have been infected across the college district's administrative, instructional and wireless networks. It's likely that personal computers belonging to anyone who used a flash drive during the past decade to carry information home were also affected.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Investigation continues to determine which other computer networks at the college may have been infected, such as accounting, admissions and/or payroll systems. &amp;nbsp;Apparently, 17 different computer systems are presently being analyzed. &amp;nbsp;The college's server with medical information appears to be unaffected, although it is unclear whether any other system may also contain medical information (such as the admissions system).&lt;/p&gt;
&lt;p&gt;The good news, besides that the college notified those potentially affected in what most would agree was a prompt timeframe, is that there are no known cases of identity theft originating from this extremely lengthy data breach.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/NzjsSw9bvy4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/NzjsSw9bvy4/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/data-breach-potentially-affects-up-to-100000-students-3000-employees/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">City College of Francisco</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Hacking</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Sat, 14 Jan 2012 08:27:28 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/data-breach-potentially-affects-up-to-100000-students-3000-employees/</feedburner:origLink></item>
            <item>
         <title>Personal Information Data Breaches - Not if, but When?</title>
         <description>&lt;p&gt;&lt;strong&gt;By &lt;/strong&gt;&lt;a href="http://www.foxrothschild.com/attorneys/bioDisplay.aspx?id=3640"&gt;&lt;strong&gt;Elizabeth Litten&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.nytimes.com/2011/12/26/technology/hackers-breach-the-web-site-of-stratfor-global-intelligence.html?_r=1 "&gt;widely publicized&lt;/a&gt; pre-Christmas breach of confidential data held by Stratfor Global Intelligence Service (&amp;ldquo;Stratfor&amp;rdquo;), a company specializing in data security, reminded me that very little (if any) electronic information is truly secure.&amp;nbsp;If Stratfor&amp;rsquo;s data can be hacked into, and the health information of nearly 5 million military health plan (TRICARE) members maintained by multi-billion dollar Department of Defense contractor Science Applications International Corporation (SAIC) (the subject of a five-part series of blog postings found on&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/"&gt;&lt;span&gt;Fox Rothschild&amp;rsquo;s HIPAA, HITECH and HIT Blog&lt;/span&gt;&lt;/a&gt;.&amp;nbsp;Parts&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-with-some-words-on-the-nemours-phi-breach-part-1/"&gt;1&lt;/a&gt;,&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-part-2/"&gt;2&lt;/a&gt;,&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-part-3/"&gt;3&lt;/a&gt;,&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/11/articles/breaches/did-tricaredod-make-a-proactive-response-or-a-preemptive-strike-with-saic-in-the-phi-breach-matter-whose-risk-is-it-anyway-part-4/"&gt;4&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/12/articles/breaches/congressional-inquiry-or-autopsy-for-saic-breach-disaster-part-5/"&gt;5&lt;/a&gt;  ) can be accessed, can we trust that any electronically transmitted or stored information is really safe?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I had the pleasure of having lunch with my friend Al yesterday, an IT guru who has worked in hospitals for years.&amp;nbsp;Al understands and appreciates the need for privacy and security of information, and has the technological expertise to know where and how data can be hacked into or leaked out.&amp;nbsp;Perhaps not surprisingly, Al does not do his banking on-line, and tries to avoid making on-line credit card purchases.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Al and I discussed the proliferation of the use of iPhones and other mobile technology by physicians and staff in hospitals and other settings, a topic recently discussed in a &lt;a href="http://www.ama-assn.org/amednews/2011/12/19/bil21219.htm "&gt;newsletter&lt;/a&gt; published by the American Medical Association.&amp;nbsp;Quick access to a patient&amp;rsquo;s electronic health record (EHR) is convenient and may even be life-saving in some circumstances, but use of these mobile devices creates additional portals for access to personal information that should be protected and secured.&amp;nbsp;Encryption technology and, perhaps most significantly, use of this technology, barely keeps pace with the exponential rate at which we are creating and/or transmitting data electronically.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;On the other hand, trying to reverse the exponential growth of electronic communications and transactions would be futile and probably counter-productive.&amp;nbsp;The horse is out of the gate, and expecting it to stop mid-stride and retreat back with a false-start call is irrational.&amp;nbsp;The horse will race ahead just as surely as my daughter will text and check her Facebook page, my son will recharge his iPad, and I will turn around and head back to my office if I forget my iPhone.&amp;nbsp;We want and need technology, but seem to forget or fail to fully understand the vast, unprotected and ever-expanding universe into which we send information when we use this technology.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If we expect breaches or, at least, question our assumptions that personal information will be protected, perhaps we will get better at discerning how and when we disclose our personal information.&amp;nbsp;An in-person conversation or transaction (for example, when Al goes to his bank in person or when a physician speaks directly to another physician about a patient&amp;rsquo;s care) is less likely to be accessed and used inappropriately than an electronic one.&amp;nbsp;We can better assess the risks and benefits of communicating information electronically when we appreciate the security frailties inherent in electronic communication and storage.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Perhaps Congress should take the lead in enacting laws that will help protect against data breaches that could compromise &amp;ldquo;critical infrastructure systems&amp;rdquo;&amp;nbsp;(as proposed in the &amp;ldquo;&lt;a href="http://homeland.house.gov/sites/homeland.house.gov/files/Cybersecurity.pdf"&gt;PRECISE Act&lt;/a&gt;&amp;rdquo; introduced by Rep. Daniel E. Lungren (R-CA)), but more comprehensive, potentially expensive, and/or use-impeding cybersecurity laws might have the effect of tripping the racehorse mid-lap rather than controlling its pace or keeping it safely on course.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/YkRkXzz0VJI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/YkRkXzz0VJI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/personal-information-data-breaches-not-if-but-when/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Department of Defense</category><category domain="http://dataprivacy.foxrothschild.com/tags">DoD</category><category domain="http://dataprivacy.foxrothschild.com/tags">EHR</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI security breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">PRECISE Act</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy &amp; Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Rep. Daniel E. Lungren, SAIC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Science Applications International Corporation</category><category domain="http://dataprivacy.foxrothschild.com/tags">Stratfor Global Intelligence Service</category><category domain="http://dataprivacy.foxrothschild.com/tags">Tricare</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">electronic health record</category><category domain="http://dataprivacy.foxrothschild.com/tags">protected health information</category>
         <pubDate>Tue, 03 Jan 2012 16:29:57 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/personal-information-data-breaches-not-if-but-when/</feedburner:origLink></item>
            <item>
         <title>2011 Data Breach Summary</title>
         <description>&lt;p&gt;&lt;a href="http://blogs.smartmoney.com/paydirt/2011/12/28/the-top-5-data-breaches-of-2011/?mod=rss_&amp;amp;link=SM_home_blogsum"&gt;Smart Money&lt;/a&gt; just ran a story about the top five data breaches of 2011. &amp;nbsp;While I do not necessarily agree that these are the top five (&lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/"&gt;students&lt;/a&gt;, &lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/"&gt;students&lt;/a&gt;,&lt;a href="http://dataprivacy.foxrothschild.com/2011/03/articles/data-theft/health-data-for-17-million-nyc-hospital-patients-staff-and-others-at-risk/"&gt; NYC hospital patients&lt;/a&gt;, not to mention the Stratfor breach), the takeaway is interesting: none of them have the same source for the breach:&lt;/p&gt;
&lt;p&gt;1. &amp;nbsp;Epsilon. &amp;nbsp;What more needs to be said to keep contract attorneys up at night than &amp;quot;Epsilon&amp;quot;? &amp;nbsp;This &lt;a href="http://www.cioinsight.com/c/a/Security/Breach-Notification-Time-for-a-Wake-Up-Call-581657/"&gt;data breach&lt;/a&gt; involved a third party losing data about its customers' customers. &amp;nbsp;Stated another way, the owner of the information did nothing wrong...other than hiring a contractor that mishandled information. &amp;nbsp;Indemnification mean more to you now? &amp;nbsp;The takeaway from this breach: come clean, come clean, come clean. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;2. &amp;nbsp;Sony. &amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2011/04/articles/data-security-breach-response/sony-hit-by-data-breach-affecting-77-million-gamers/"&gt;Massive breach&lt;/a&gt; of the online gaming network. &amp;nbsp;Lots of data lost, lots of downtime for pasty, sun-adverse gamers. &amp;nbsp;Hackers targeting the network to blame. &amp;nbsp;The takeaway from this breach: do not handle it the way Sony handled it.&lt;/p&gt;
&lt;p&gt;3. &amp;nbsp;Tricare. &amp;nbsp;A Science Applications International Corp. has data backup tapes stolen from a car. &amp;nbsp;SAIC is a defense contractor for the military. &amp;nbsp;Approximately &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/12/articles/breaches/congressional-inquiry-or-autopsy-for-saic-breach-disaster-part-5/"&gt;4.9 million veterans affected&lt;/a&gt;. &amp;nbsp;Hackers targeting lax security to blame. &amp;nbsp;The takeaway from this breach: don't leave the data tapes in the car (come on, people!).&lt;/p&gt;
&lt;p&gt;4. &amp;nbsp;Sutter. &amp;nbsp;A simple stolen desktop computer containing information about possibly 3.3 million patients goes missing. &amp;nbsp;The takeaway from this breach: encrypt! &amp;nbsp;Chances are they had zero intention to stealing the actual information, but you can be sure it was still a breach notification scenario.&lt;/p&gt;
&lt;p&gt;5. &amp;nbsp;Texas Comptroller. &amp;nbsp;This is number three in my book. &amp;nbsp;Personal information of 3.5 million people left publicly available for over one year. &amp;nbsp;Information about persons required to hand over that information, not information voluntarily handed over. &amp;nbsp;Total disaster. &amp;nbsp;Anyone could have found this information, given its availability. &amp;nbsp;The takeaway from this breach: hire IT staff that is security conscious and, more importantly, give those people the budget to do their jobs.&lt;/p&gt;
&lt;p&gt;BONUS: not a data breach, but a significant ruling this year. &amp;nbsp;Corporations have no right to privacy. &amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2011/03/articles/right-to-privacy/supreme-court-tells-att-it-has-no-right-to-privacy/"&gt;This Supreme Court ruling&lt;/a&gt; impacts corporate decisions on so many levels...or it should.&lt;/p&gt;
&lt;p&gt;Happy New Year to our readers.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/50-2E1Mi4zE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/50-2E1Mi4zE/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/12/articles/data-security-breach-response/2011-data-breach-summary/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Epsilon</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Sony</category><category domain="http://dataprivacy.foxrothschild.com/tags">Sutter</category><category domain="http://dataprivacy.foxrothschild.com/tags">Texas Comptroller</category><category domain="http://dataprivacy.foxrothschild.com/tags">Tricare</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Wed, 28 Dec 2011 18:30:33 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/12/articles/data-security-breach-response/2011-data-breach-summary/</feedburner:origLink></item>
            <item>
         <title>FTC Settles With Facebook, Agrees to Whopping 20-Year Consent Order</title>
         <description>&lt;p&gt;According to a &lt;a href="http://ftc.gov/opa/2011/11/privacysettlement.shtm"&gt;press release&lt;/a&gt; issued yesterday, November 29, 2011, by the Federal Trade Commission, Facebook settled charges that Facebook &amp;ldquo;deceived consumers by telling them they could keep their information on Facebook private, and then repeatedly allowing it to be shared and made public.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://ftc.gov/os/caselist/0923184/111129facebookcmpt.pdf"&gt;complaint&lt;/a&gt; (PDF link) lists a litany of bad practices by Facebook. One allegation that stands out, largely because of the media firestorm that it created at the time, was Facebook&amp;rsquo;s change in privacy settings to users&amp;rsquo; accounts in December 2009. The foregoing settings change was, in the FTC&amp;rsquo;s opinion, particularly egregious because Facebook undertook the changes without any notice or consent from users.&lt;/p&gt;
&lt;p&gt;Another allegation that stands out, again both because&amp;nbsp;of the media firestorm and the falsehood, was Facebook&amp;rsquo;s assertion that information from deactivated user accounts would not be accessible.&lt;/p&gt;
&lt;p&gt;And what grueling punishment must Facebook endure for its privacy-related bad acts? According to Jon Leibowitz, Chairman of the FTC, &amp;quot;Facebook is obligated to keep the promises about privacy that it makes to its hundreds of millions of users.&amp;quot; Rough justice.&lt;/p&gt;
&lt;p&gt;In all seriousness, there is some substance to the settlement. Facebook must not make any further deceptive privacy claims. Facebook must also get consumers' approval before it changes the way it shares their data. Finally, Facebook must obtain periodic assessments of its privacy practices by independent, third-party auditors for the next 20 years.&lt;/p&gt;
&lt;p&gt;Frankly, the foregoing requirements on Facebook are all steps that a company like Facebook, if not substantially all companies handling consumer personal information, should be undertaking.&lt;/p&gt;
&lt;p&gt;Specifically, under the proposed settlement, Facebook is:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;barred from making misrepresentations about the privacy or security of consumers' personal information;&lt;/li&gt;
    &lt;li&gt;required to obtain consumers' affirmative express consent before enacting changes that override their privacy preferences;&lt;/li&gt;
    &lt;li&gt;required to prevent anyone from accessing a user's material more than 30 days after the user has deleted his or her account;&lt;/li&gt;
    &lt;li&gt;required to establish and maintain a comprehensive privacy program designed to address privacy risks associated with the development and management of new and existing products and services, and to protect the privacy and confidentiality of consumers' information; and&lt;/li&gt;
    &lt;li&gt;required, within 180 days, and every two years after that for the next 20 years, to obtain independent, third-party audits certifying that it has a privacy program in place that meets or exceeds the requirements of the FTC order, and to ensure that the privacy of consumers' information is protected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The proposed order also contains standard record-keeping provisions to allow the FTC to monitor compliance with its order.&lt;/p&gt;
&lt;p&gt;The proposed settlement is not yet final. The proposed settlement will be open to public comment for thirty days, ending on December 30, 2011. The terms of the proposed settlement is published in the Federal Register shortly. After the close of the comment period, the FTC will decide whether to make the proposed consent order final.&lt;/p&gt;
&lt;p&gt;Interested in submitting your comments to the FTC? According to the &lt;a href="http://ftc.gov/opa/2011/11/privacysettlement.shtm"&gt;press release&lt;/a&gt;: Interested parties can submit comments online or in paper form by following the instructions in the &amp;quot;Invitation To Comment&amp;quot; part of the &amp;quot;Supplementary Information&amp;quot; section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/OLgMUvaHMws" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/OLgMUvaHMws/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/11/ftc-1/ftc-settles-with-facebook-agrees-to-whopping-20year-consent-order/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/">FTC</category><category domain="http://dataprivacy.foxrothschild.com/articles">Facebook</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">federal trade commission</category>
         <pubDate>Wed, 30 Nov 2011 06:52:38 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/11/ftc-1/ftc-settles-with-facebook-agrees-to-whopping-20year-consent-order/</feedburner:origLink></item>
            <item>
         <title>Comparison of Major Carriers' Retention of Mobile Device Usage</title>
         <description>&lt;p&gt;The Computer Crime and Intellectual Property Section of the U.S. Department of Justice compiled a summary in August 2010&amp;nbsp;of the retention periods of major cellular service providers of data transmitted to and from users' mobile devices.&amp;nbsp; The report is &lt;a href="http://www.wired.com/images_blogs/threatlevel/2011/09/retentionpolicy.pdf"&gt;here&lt;/a&gt;. (PDF&amp;nbsp;link)&amp;nbsp; The American Civil Liberties Union (ACLU) obtained a copy of the foregoing report through a Freedom of Information Act (FOIA) request.&amp;nbsp; The contents of the report are interesting, to say the least.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Mobile Carriers Data Retention Summary" align="right" width="250" height="720" src="http://dataprivacy.foxrothschild.com/uploads/image/mobile carriers retention summary(1).gif" /&gt;As reported by&amp;nbsp;Cory Doctorow on the terrific&amp;nbsp;&lt;a href="http://boingboing.net"&gt;Boing Boing&lt;/a&gt;&amp;nbsp;in this&amp;nbsp;&lt;a href="http://boingboing.net/2011/09/29/which-of-americas-mobile-carriers-keeps-the-most-intel-on-you.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;article&lt;/a&gt;, and by David Kravets of Wired.com in this &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;article&lt;/a&gt; titled &amp;quot;Which Telecoms Store Your Data the Longest? Secret Memo Tells All,&amp;quot; it is unclear which major cellular carrier treats our usage data with the most respect.&amp;nbsp; On the one hand, Verizon stores text message details (just the transmission receipt details, such as recipient and time) only one year, compared to as long as 5-7 years for post-paid subscribers of AT&amp;amp;T.&amp;nbsp; On the other hand, AT&amp;amp;T, Sprint and T-Mobile store none of the contents of text messages, whereas Verizon stores that information for 3-5 days.&amp;nbsp; The IP&amp;nbsp;Session information may be the most interesting, because of the additional information that can be gleaned from the raw data, the question of why it is stored (billing disputes?) and the disparity in length of storage.&amp;nbsp; One of the excellent infographics posted on Wired's web site is posted here, but a &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;full Wired article&lt;/a&gt; is a must read.&lt;/p&gt;
&lt;p&gt;Besides this information being eye opening on a personal level, it can be crucial evidence in the case of a corporate&amp;nbsp;data breach.&amp;nbsp; While we all hope that law enforcement will use all tools available to it when investigating a corporate crime, knowing the tight time constraints under which businesses investigating a potential crime is crucial.&amp;nbsp; To be clear, I am referring to use of these tools as an option for ethical investigations into criminal activity through law enforcement.&amp;nbsp; These are not tools to assist a company in sacking an employee that is surfing the web on her mobile phone while on the clock.&amp;nbsp; In any event, these time frames should be considered when investigating a suspected data breach.&lt;/p&gt;
&lt;p&gt;If you are getting that &amp;quot;eye in the sky is watching me&amp;quot; feeling, I will be sure not to mention the warrantless&amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2009/12/articles/right-to-privacy/alleged-that-sprint-provided-law-enforcement-customer-gps-data-over-8-million-times/"&gt;GPS and triangulation tracking capabilities&lt;/a&gt; of the major mobile carriers available to law enforcement.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Source:&amp;nbsp;&lt;a href="http://boingboing.net/2011/09/29/which-of-americas-mobile-carriers-keeps-the-most-intel-on-you.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;BoingBoing.net&lt;/a&gt;; &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;Wired.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/S1IFM2vRM_8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/S1IFM2vRM_8/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/09/articles/electronic-data-security/comparison-of-major-carriers-retention-of-mobile-device-usage/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">ACLU</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Mobile Data Storage</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Retention Periods of Major Cellular Service Providers</category><category domain="http://dataprivacy.foxrothschild.com/tags">U.S. Department of Justice</category>
         <pubDate>Fri, 30 Sep 2011 04:59:31 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/09/articles/electronic-data-security/comparison-of-major-carriers-retention-of-mobile-device-usage/</feedburner:origLink></item>
            <item>
         <title>Purdue Notifies 7,000 Students of SSN Theft 16 Months After Discovering the Breach</title>
         <description>&lt;p&gt;Purdue University &lt;a href="http://www.law360.com/privacy/articles/265560?utm_source=newsletter&amp;amp;utm_medium=email&amp;amp;utm_campaign=privacy"&gt;informed&lt;/a&gt; 7,093 former students on Monday that their Social Security numbers may have been stolen from servers at the University on April 5, 2010.&amp;nbsp; The notification comes 16 months after the discovery of the breach.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.jconline.com/article/20110817/NEWS0501/108170320/Purdue-warns-ex-students-data-breach?odyssey=mod|newswell|text|FRONTPAGE|s"&gt;According to&lt;/a&gt; the (Indiana) Journal &amp;amp;&amp;nbsp;Courier, the server contained 6.6 million nine-digit numbers in the accessed files.&amp;nbsp; After spending six months analyzing those&amp;nbsp;numbers, Purdue determined that approximately 65,000 of those number combinations could be Social&amp;nbsp;Security numbers.&amp;nbsp; An additional four months was spent reanalyzing the numbers and performing forensic analysis.&amp;nbsp; Based on those efforts, the University had matched 7,093 of those number combinations&amp;nbsp;to&amp;nbsp;Social Security numbers of former students.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The breach was discovered only three days after it occurred, approximately April 8, 2010.&amp;nbsp; Fourteen months after discovery of the breach, Purdue notified the Office of the Indiana Attorney General.&amp;nbsp; Now, approximately two months later, the affected former students were notified.&lt;/p&gt;
&lt;p&gt;Purdue did not offer any sort of credit monitoring and, instead, recommended to those affected to be vigilant and keep and eye on their credit activity.&lt;/p&gt;
&lt;p&gt;The announcement by Purdue comes on the heals of an announcement by The University of Wisconsin-Milwaukee on August 10th&amp;nbsp;that 75,000 of its students had been exposed to a hacking incident in May 2011, as reported earlier &lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;While the delay of three months may have seemed excessive last week, at least UWM beat Purdue's delay by almost 14 months.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/MrpVt1dUCck" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/MrpVt1dUCck/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">7,000 SSN</category><category domain="http://dataprivacy.foxrothschild.com/tags">7,000 Social Security numbers</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Purdue University</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Thu, 18 Aug 2011 05:43:59 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/</feedburner:origLink></item>
            <item>
         <title>PSA: LinkedIn Assumes You "Opt-In" to Social Media Advertising</title>
         <description>&lt;p&gt;Boing Boing has an excellent how-to located &lt;a href="http://boingboing.net/2011/08/11/linkedin-opts-you-into-being-used-in-advertisements-heres-how-to-opt-out.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;here&lt;/a&gt;&amp;nbsp;on how to opt out of being included in LinkedIn's social media advertising.&amp;nbsp; Briefly, LinkedIn assumes that you consent to LinkedIn's use of your image in the adverstising of its sponsor's products.&amp;nbsp; If you recommend your CPA firm, and your CPA firm purchases advertising on LinkedIn, your photo may appear in that advertising.&lt;/p&gt;
&lt;p&gt;This approach may be fine in certain cases. However, besides just the general creepiness of it,&amp;nbsp;employers should be aware that it creates a potential association between your company (not just the individual) and that third party. I can imagine a scenario where a company is suing its former CPA firm and an advertisement appears with the Controller's image in a LinkedIn advertisement for the same CPA firm.&lt;/p&gt;
&lt;p&gt;If your company's social media policy allows employees to participate in LinkedIn and other social media sites, consider whether the policy needs an update to require opting-out of this social media advertising.&lt;/p&gt;
&lt;p&gt;&lt;img alt="" width="450" height="288" src="http://dataprivacy.foxrothschild.com/uploads/image/linkedin.JPG" /&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/5SfA3IppRBg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/5SfA3IppRBg/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/employee-social-media-use-1/psa-linkedin-assumes-you-optin-to-social-media-advertising/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Employee Social Media Use</category><category domain="http://dataprivacy.foxrothschild.com/">LinkedIn</category><category domain="http://dataprivacy.foxrothschild.com/tags">Opt-Out</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Social Media Advertising</category>
         <pubDate>Fri, 12 Aug 2011 06:25:16 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/employee-social-media-use-1/psa-linkedin-assumes-you-optin-to-social-media-advertising/</feedburner:origLink></item>
            <item>
         <title>HACKED: 75,000 Social Security Numbers at Risk at University of Wisconsin</title>
         <description>&lt;p&gt;The University of Wisconsin-Milwaukee (&amp;ldquo;UWM&amp;rdquo;) &lt;a href="http://www4.uwm.edu/univ_rel/computer_security.cfm"&gt;announced on Wednesday&lt;/a&gt; that a malware-infected, university server was discovered on May 25th that allowed hackers, apparently seeking research data, to access several types of scanned documents. Included in the potentially accessed documents were student applications from past and present students, which applications contained Social Security numbers.&lt;/p&gt;
&lt;p&gt;At this time, UWM has not been able to confirm that any of the documents were actually taken by the hackers. UWM reports that &amp;ldquo;[t]he university learned of the installation of malware on May 25, and immediately shut down the system and began to investigate. During the course of the investigation, on June 30, 2011, we discovered that the database containing social security numbers was included in the compromised system.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;UWM wants to assure students that although names and Social Security numbers were possibly taken,&amp;nbsp;the potentially accessed documents&amp;nbsp;did not contain any financial data or academic information such as student grades. At least students don&amp;rsquo;t have to worry about having embarrassing grades posted.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www4.uwm.edu/univ_rel/computer_security.cfm"&gt;announcement&lt;/a&gt; asks &amp;ldquo;[s]houldn&amp;rsquo;t the university be offering free credit monitoring?&amp;rdquo; After all, free credit monitoring is expected these days, although certainly no required. The response? &amp;ldquo;We have no evidence that anyone&amp;rsquo;s personal information was retrieved or that any information was misused. However, it is recommended that everyone should monitor their financial information by:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Reviewing bank and credit card statements regularly, and looking for unusual or suspicious activities.&lt;/li&gt;
    &lt;li&gt;Contacting appropriate financial institutions immediately upon noticing any irregularity in a credit report or account.&lt;/li&gt;
    &lt;li&gt;Request a free credit report and carefully inspect your own credit scores.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That is one approach, I suppose.&amp;nbsp; It is certainly different.&lt;/p&gt;
&lt;p&gt;While the details of the investigation by this public institution remains under wraps, it does raise interesting questions. To be clear, there may be excellent bases for not making the disclosure earlier. However,&amp;nbsp;we have seen more and more experts commenting on how huge delays in public announcements are justified. Sure,&amp;nbsp;delays in notification&amp;nbsp;can sometimes be justified where only an intrusion is known and it is unclear whether personal information is accessible through that intrusion.&lt;/p&gt;
&lt;p&gt;We have come to the point where using the &amp;ldquo;ongoing internal investigation&amp;rdquo; excuse is habitually abused. In this case, based on facts known, it took 35 days for a &amp;ldquo;national computer security consultant&amp;rdquo; to determine the source and extent of the breach. In other words, it took experts 35 day to conclude that if a certain port on a server was exposed, then access to a certain, non-encrypted database was possible. I asked our network guys about this, and they said it should take about 30 minutes to determine what was exposed if a port was left open.&lt;/p&gt;
&lt;p&gt;After confirmation of the possibility that the sensitive documents could have been accessed, it too another 41 days to make a public announcement.&lt;/p&gt;
&lt;p&gt;Okay, so maybe law enforcement delayed the notification. Certainly possible. These comments are not meant to be an indictment of UWM specifically, but of the new approach to data breach notification that is occurring more often than not.&lt;/p&gt;
&lt;p&gt;In the cases where delay notification is grossly delayed, it is more often that company executives and their counsel decide that if the breach was announced, and it was later determined that access to the potentially accessed documents did not occur, then the &amp;ldquo;bad press&amp;rdquo; would be worse than delaying notification for 77 days.&amp;nbsp; Stated another way, they don't want to unnecessarily worry potentially affected persons.&lt;/p&gt;
&lt;p&gt;Again, we do not know all the facts. In all likelihood the sensitive documents were not accessed.&amp;nbsp; However, more and more we all are seeing HUGE delays in notifying those affected. If I received a breach notification 77 days after discovery I would be mad as hell. That is 77 days when identity theft could have occurred and I was not being vigilant because I was unaware of a breach. This is the exploding Pinto approach to data breaches.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/dXwCwPhh0ec" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/dXwCwPhh0ec/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags"> University of Wisconsin-Milwaukee</category><category domain="http://dataprivacy.foxrothschild.com/tags">75,000 social security numbers</category><category domain="http://dataprivacy.foxrothschild.com/tags">Breach Notification</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category>
         <pubDate>Fri, 12 Aug 2011 05:39:46 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/</feedburner:origLink></item>
            <item>
         <title>UCLA Health System Hospitals To Pay $865,000 For Privacy Breaches</title>
         <description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="512555313-08072011"&gt;From 2005 through 2009, UCLA Health System Hospitals (&amp;quot;UCLA&amp;quot;) received complaints that its employees had viewed celebrities' medical records without authorization.&amp;nbsp;&amp;nbsp;After an investigation, federal health regulators&amp;nbsp;determined that UCLA employees reviewed patients' electronic medical records &amp;quot;repeatedly and without a permissible reason.&amp;quot;&amp;nbsp; Federal health regulators found that UCLA failed to remedy the problem and discipline or retrain its staff.&amp;nbsp; Ultimately, UCLA entered into a settlement agreement with federal health regulators.&amp;nbsp; Under the settlement agreement, UCLA must pay a fine of $865,000.&amp;nbsp; The settlement agreement further requires UCLA to: (1) submit a plan to federal regulators outlining how it plans to prevent future privacy breaches; (2) retrain its staff about privacy protections; (3) institute privacy policies; (4) appoint a representative to oversee its privacy improvements; and (5) report to federal regulators for the next three years.&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/jN6FDDkufJo" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/jN6FDDkufJo/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/07/articles/data-protection-law-compliance/ucla-health-system-hospitals-to-pay-865000-for-privacy-breaches/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Compliance</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Protection Law Compliance</category><category domain="http://dataprivacy.foxrothschild.com/tags">Electronic</category><category domain="http://dataprivacy.foxrothschild.com/tags">data privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">data security</category><category domain="http://dataprivacy.foxrothschild.com/tags">fines</category><category domain="http://dataprivacy.foxrothschild.com/tags">medical records</category>
         <pubDate>Fri, 08 Jul 2011 09:41:57 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/07/articles/data-protection-law-compliance/ucla-health-system-hospitals-to-pay-865000-for-privacy-breaches/</feedburner:origLink></item>
            <item>
         <title>Citibank Data Breach: Even the Banks Can't Get It Right</title>
         <description>&lt;p&gt;The breaches about which we normally hear have to do with retailers and service providers. &amp;nbsp;Those businesses are the ones that do not appreciate the importance of protecting data, feel they could use the money necessary to create good security in better ways and are the easy targets for hackers. &amp;nbsp;Thankfully, what we generally do not hear about are data breaches at large financial institutions. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Citigroup announced yesterday that its servers were hacked into in early May and the names, addresses account numbers and other account information of 200,000 credit card customers were stolen. &amp;nbsp;Citigroup further reported that social security numbers, CVV security codes and dates of birth were NOT stolen. &amp;nbsp;This data breach affects approximately 1% of all of Citigroup's customers.&lt;/p&gt;
&lt;p&gt;There is no information about how the hackers were able to access Citigroup's servers. &amp;nbsp;It is unclear whether information on this security breakdown will ever be released, but the occurrence is a stark contrast to the normal data loss involving systems that are not as well-protected as financial company systems. &amp;nbsp;Generally speaking, retailers are easy targets, financial institutions are not.&lt;/p&gt;
&lt;p&gt;The current delay in notifying affected individuals may be the result of Citigroup's cooperation with law enforcement, considering that Citigroup is otherwise required to notify those affected individuals almost immediately. &amp;nbsp;Some are speculating that the delay may (finally) result in federal legislation detailing data breach response guidelines. &amp;nbsp;You know, because the massive prior data breaches were not enough to make federal legislation a priority.&lt;/p&gt;
&lt;p&gt;In any event, if you are a Citigroup customer you should keep your eyes out of an email notifying you of the breach. &amp;nbsp;That being said, it would not be surprising to see a phishing effort undertaken to have unsuspecting Citigroup customers that may or may not actually be affected by the breach click on links in email in order to steal usernames and passwords. &amp;nbsp;In other words, if you do receive a notice from Citigroup about the breach, make sure that the email really is from Citigroup by confirming the links take you to a genuine Citigroup web site or navigating to the Citigroup web site manually and looking for information on the data breach.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/YlGvnebW4zM" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/YlGvnebW4zM/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/06/articles/data-security-breach-response/citibank-data-breach-even-the-banks-cant-get-it-right/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">200,000</category><category domain="http://dataprivacy.foxrothschild.com/tags">Citigroup</category><category domain="http://dataprivacy.foxrothschild.com/tags">Data Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category>
         <pubDate>Fri, 10 Jun 2011 05:56:46 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/06/articles/data-security-breach-response/citibank-data-breach-even-the-banks-cant-get-it-right/</feedburner:origLink></item>
            <item>
         <title>Sony Hit By Data Breach Affecting 77 Million Gamers</title>
         <description>&lt;p&gt;Sony announced yesterday that its PlayStation Network and Qriocity services were compromised by an &amp;quot;unauthorized&amp;quot; person.&amp;nbsp; What was the haul?&amp;nbsp; &lt;a href="http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/"&gt;According to Sony&lt;/a&gt;, the &amp;quot;name, address (city, state, zip), country, email address, birthdate, PlayStation Network/Qriocity password and login, and handle/PSN online ID&amp;quot; and the &amp;quot;profile data, including purchase history and billing address (city, state, zip), and your PlayStation Network/Qriocity password security answers&amp;quot; of 77 million individuals.&lt;/p&gt;
&lt;p&gt;That's right, 77 million people.&amp;nbsp; This is one of the largest Internet data losses in history.&amp;nbsp; We can assume that the data was not encrypted, otherwise we would hear little or nothing about the data loss (most states exempt encrypted data from disclosure requirements), or else Sony would be screaming &amp;quot;Don't fret too much, the data was encrypted and we did not lose the decryption key.&amp;quot;&amp;nbsp; Sony is not making either claim at this time.&lt;/p&gt;
&lt;p&gt;Well, data breaches happen, you may be thinking.&amp;nbsp; We have seen companies with best practices still suffer at the hands of hackers or rogue employees.&amp;nbsp; Sony is taking the most heat not from the data loss, but from the timing of the disclosure to those affected.&amp;nbsp; The disclosure of the data breach to customers directly was on April 26th.&amp;nbsp; The data breach apparently occurred between April 17 and April 19.&amp;nbsp; It has been reported that Sony discovered the breach on April 20th.&amp;nbsp; There was a gap of six days between discovery and disclosure.&amp;nbsp; Six days may be an eternity when you are a gamer and your network is down (there are likely millions of teenagers with fresh sunburns), but how long is six days in the data breach world?&lt;/p&gt;
&lt;p&gt;Six days between discovery and disclosure may be acceptable, especially to the extent that Sony was working with law enforcement and was requested/told not to make a public announcement.&amp;nbsp; To clarify the preceding sentence, six days may not be too long when working with law enforcement as long as Sony was truly working with law enforcement and the delay had a genuine purpose.&amp;nbsp; However, Sony&amp;nbsp;did not&amp;nbsp;explain that law enforcement cooperation was the reason for the delay.&amp;nbsp; It is not likely that Sony ran afoul of any state statute timing requirements, which have quite a bit of leeway built in.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you or your children are on one of these services, you need to pay particular attention to this story as it develops.&amp;nbsp; You (the keyword being &amp;quot;you&amp;quot;) need to monitor your bank accounts and credit cards - frankly, any account into which a third party can back into knowing your security question or your password on this service (remember, if you use the same password for your email account AND this service, somebody may have both of those right now).&amp;nbsp; For now, Sony has not offered any type of monitoring service, so your financial/credit monitoring is currently your responsibility.&lt;/p&gt;
&lt;p&gt;Hopefully Sony will continue to come out with more information, or we will learn that the data is in &amp;quot;safe&amp;quot; hands (think Matthew Broderick in War Games - almost nothing went wrong in that movie).&amp;nbsp; In any event, your children that go to business school will enjoy reading the future case study on this one.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/10y4z5D6eDQ" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/10y4z5D6eDQ/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/04/articles/data-security-breach-response/sony-hit-by-data-breach-affecting-77-million-gamers/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">77 Million</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">PlayStation</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Sony</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Wed, 27 Apr 2011 05:01:41 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/04/articles/data-security-breach-response/sony-hit-by-data-breach-affecting-77-million-gamers/</feedburner:origLink></item>
            <item>
         <title>Doing the Math: Average Data Breach Cost Now Up to $214 Per Record</title>
         <description>&lt;p&gt;The cost per customer record in a data breach increased $10 over the &lt;a href="http://dataprivacy.foxrothschild.com/2010/01/articles/data-security-breach-response/data-breach-costs-increase-to-204-per-compromised-record/"&gt;2009 average&lt;/a&gt; to $214 per customer record compromised in a data breach, which is $12 more than the 2008 average of $202 per customer record. &lt;a href="http://www.ponemon.org/index.php"&gt;The Poneman Institute&lt;/a&gt;, which conducts independent research on privacy, data protection and information security policy, released its&amp;nbsp;sixth Annual&amp;nbsp;Study: U.S. Cost of Data Breach&amp;nbsp;(&lt;a href="http://www.symantec.com/content/en/us/about/media/pdfs/symantec_ponemon_data_breach_costs_report.pdf?om_ext_cid=biz_socmed_twitter_facebook_marketwire_linkedin_2011Mar_worldwide_costofdatabreach"&gt;Available Here&lt;/a&gt;&amp;nbsp;- PDF link), declaring that the average cost per compromised customer record rose to $214.&amp;nbsp; The report is sponsored by Symantec Corporation.&amp;nbsp; Excellent materials such as an infographic, summaries, blog entries, a podcast and slide presentation can be found on Symantec's web site &lt;a href="http://www.symantec.com/about/news/resources/press_kits/detail.jsp?pkid=ponemon&amp;amp;om_ext_cid=biz_socmed_twitter_facebook_marketwire_linkedin_2011Mar_worldwide_costofdatabreach"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Before getting into the numbers, you should note that Symantec is offering a &lt;a href="http://www.databreachcalculator.com/"&gt;Data Breach Risk Calculator&lt;/a&gt;.&amp;nbsp; The foregoing calculator is NOT for the feint of heart, so consider yourself warned.&amp;nbsp; That being said, the calculator is a powerful tool that considers several factors when estimating data breach costs to businesses.&lt;/p&gt;
&lt;p&gt;The report is based on&amp;nbsp;51 reported data breaches in the United States (other country reports are also published) in 2010, ranging from&amp;nbsp;4,200 to approximately 105,000 records in 15 different industries. Of the breaches studied, organizations paid a low of $780,000 ($750,000 in 2009), and a high of $35.3 Million ($31 Million in 2009)&amp;nbsp;in connection with the breach response. The average cost to an organization from a data breach increased from $6.65 Million in &lt;a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2008-2009%20US%20Cost%20of%20Data%20Breach%20Report%20Final.pdf"&gt;2008&lt;/a&gt;, and $6.75 Million in &lt;a href="http://www.pgp.com/insight/newsroom/press_releases/2009_annual_study_cost_of_data_breach.html"&gt;2009&lt;/a&gt;, to $7.2 Million in&amp;nbsp;2010&amp;nbsp;(&lt;a href="http://www.symantec.com/about/news/resources/press_kits/detail.jsp?pkid=ponemon&amp;amp;om_ext_cid=biz_socmed_twitter_facebook_marketwire_linkedin_2011Mar_worldwide_costofdatabreach"&gt;Summary&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;The cost breakdown for breach response among lost business, ex-post response, notification and detection &amp;amp; escalation is eye-opening and, if nothing else, should be motivational to businesses to address problems before they arise.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Response Cost Chart" style="width: 409px; height: 296px" src="http://dataprivacy.foxrothschild.com/uploads/image/Breach Average Cost.JPG" /&gt;&lt;/p&gt;
&lt;p&gt;Source: Poneman Institute/Symantec Corporation&lt;/p&gt;
&lt;p&gt;According to the report and &lt;a href="http://www.symantec.com/content/en/us/about/media/pdfs/symantec_ponemon_data_breach_costs.pdf?om_ext_cid=biz_socmed_twitter_facebook_marketwire_linkedin_2011Mar_worldwide_costofdatabreach"&gt;infographic&lt;/a&gt; that was published, the source of the data breach was related to negligence in 41% of the cases. 31% of the data breaches were the cause of intentional and malicious&amp;nbsp;attacks, up seven percent from 2009.&amp;nbsp; Breaches due to third party mistakes dropped three percent to 39%.&amp;nbsp;&amp;nbsp;Encryption as a post-breach remedy remained the most popular, up three percent to 61%&lt;/p&gt;
&lt;p&gt;As in prior years,&amp;nbsp;those organizations that move quickly tend to experience a higher cost per record for the data response. Organizations that move quickly tend to do so in a disorganized manner with little efficiency (&lt;em&gt;e.g.&lt;/em&gt;, they do not have a breach response plan in place), and spend on average $268 per record, up significantly from the 2009 average of $219 per record. Those organizations that took longer to respond paid $174 per record on average.&lt;/p&gt;
&lt;p&gt;The news regarding data breach costs and impacts continues to worsen and shows no sign of improving or slowing.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/TcM-kzp0w-A" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/TcM-kzp0w-A/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/03/articles/data-security-breach-response/doing-the-math-average-data-breach-cost-now-up-to-214-per-record/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">$204 per Record</category><category domain="http://dataprivacy.foxrothschild.com/tags">2010 Cost of a Data Breach</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Institute'</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Symantec</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">oneman</category>
         <pubDate>Wed, 09 Mar 2011 06:42:39 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/03/articles/data-security-breach-response/doing-the-math-average-data-breach-cost-now-up-to-214-per-record/</feedburner:origLink></item>
            <item>
         <title>Online Privacy in the Open - Who Cares About the Faux Fight?</title>
         <description>&lt;p&gt;Much ado has been made in recent weeks about the FTC&amp;rsquo;s Do Not Track proposal, the &lt;a href="http://mashable.com/2011/02/11/do-not-track-bill/"&gt;push from Congress&lt;/a&gt; to protect consumers, and the &lt;a href="http://blogs.wsj.com/digits/2011/02/28/microsoft-executive-urges-online-ad-industry-to-police-itself/"&gt;response from Google, Microsoft and Mozilla, as well as the online ad industry&lt;/a&gt;, about the risks and rewards of self-regulation. But what has seemed to be missing from the debate is the public&amp;rsquo;s own outcry. Amidst the churning discussions there has not been a sense that the general online population is overly concerned about whether an advertiser can track their preferences... at least until the information they share leads to a distinct invasion of privacy with repercussions.&lt;/p&gt;
&lt;p&gt;All in all, this debate remains self-contained, and raises more questions than it answers.&lt;/p&gt;
&lt;p&gt;From the political front, the Congressional proposals present an issue that is easy to support. Who is &amp;ldquo;against&amp;rdquo; privacy? Perhaps the same people who want to bring down apple pie and stop Veterans Day parade...&lt;/p&gt;
&lt;p&gt;Technology executives and startups being buffeted about by the concern of over impending government regulation, agreeing on a self-implemented system, and &lt;a href="http://online.wsj.com/article/SB10001424052748703529004576160764037920274.html"&gt;monetizing so -called &amp;quot;privacy assets&amp;quot;&lt;/a&gt; for those opting to share more. But how much of the genie is already out of the bottle? Is it possible to truly claw back or sanitize people&amp;rsquo;s data that is already out there?&lt;/p&gt;
&lt;p&gt;There is certainly cause for public concern, though it seems that is not the case until an actual situation occurs. If a website, social forum or third party advertiser holding your personal information is hacked or breached, the potential invasion of privacy on personal preferences could be huge. Finances, sexual preference, and many items that could lead to identity theft are all put at risk. Yet we continue to &amp;quot;like&amp;quot; and &amp;quot;share&amp;quot; and post pictures because living online has become an extension to daily life.&lt;/p&gt;
&lt;p&gt;Is this public acceptance? Maybe we won&amp;rsquo;t know until there is a problem that draws attention on a national scale. The public has control over their own activity online, and the amount of information they wish to share.&lt;/p&gt;
&lt;p&gt;If the public is truly concerned about online privacy, it is a matter of self-regulation on a personal level. In the meantime, the government and the industry will continue to swirl in a cycle that perhaps will only end with a set of regulations and authorizations that create more unenforceable layers than there were before. Data thieves will always find ways to game the system, there will always be a risk when sharing personal information online, and advertising will not stop being the fuel that runs much of the internet.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/oT7tHEkHb4w" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/oT7tHEkHb4w/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/03/articles/privacy-rights/online-privacy-in-the-open-who-cares-about-the-faux-fight/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Do Not Track</category><category domain="http://dataprivacy.foxrothschild.com/tags">FTC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Google</category><category domain="http://dataprivacy.foxrothschild.com/tags">Mozilla</category><category domain="http://dataprivacy.foxrothschild.com/articles">Privacy Rights</category><category domain="http://dataprivacy.foxrothschild.com/tags">microsoft</category><category domain="http://dataprivacy.foxrothschild.com/tags">online privacy</category>
         <pubDate>Mon, 07 Mar 2011 09:56:40 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/03/articles/privacy-rights/online-privacy-in-the-open-who-cares-about-the-faux-fight/</feedburner:origLink></item>
            <item>
         <title>Health Data for 1.7 Million NYC Hospital Patients, Staff and Others At Risk</title>
         <description>&lt;p&gt;On February 10, 2011, the New York City public hospital system filed a lawsuit against its records management contractor over allegations that the contractor permitted the theft of unencrypted data tapes storing health information and other personal data on some 1.7 million patients and staff. The New York City hospital system disclosed the breach, which occurred on December 23, 2010, for the first time in a February 11, 2011, statement. The complaint alleges that six data tapes, storing HIPAA protected information and other personal data for approximately 1.7 million patients at three facilities, as well as for employees, vendors, contractors and other service providers, were stolen from a van left unlocked in Manhattan by the hospital system's records management contractor. In a statement, the hospital system said that, while the stolen tapes have not been found, no fraud has been reported and the tapes are protected by a proprietary system that makes the data difficult to access.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/b_ZZcjKNxK0" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/b_ZZcjKNxK0/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/03/articles/data-theft/health-data-for-17-million-nyc-hospital-patients-staff-and-others-at-risk/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">HIPAA</category><category domain="http://dataprivacy.foxrothschild.com/tags">New York City</category><category domain="http://dataprivacy.foxrothschild.com/tags">data encryption</category><category domain="http://dataprivacy.foxrothschild.com/tags">health data</category><category domain="http://dataprivacy.foxrothschild.com/tags">records management</category>
         <pubDate>Thu, 03 Mar 2011 08:50:21 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/03/articles/data-theft/health-data-for-17-million-nyc-hospital-patients-staff-and-others-at-risk/</feedburner:origLink></item>
            <item>
         <title>Supreme Court Tells AT&amp;T It Has No Right to Privacy</title>
         <description>&lt;p&gt;&lt;span style="font-size: 10pt"&gt;The Supreme Court of the United States has ruled in &lt;a href="http://www.supremecourt.gov/opinions/10pdf/09-1279.pdf"&gt;&lt;font color="#800080"&gt;Federal Communications Commission, &lt;em&gt;et al.&lt;/em&gt; v. AT&amp;amp;T&amp;nbsp;Inc., &lt;em&gt;et al&lt;/em&gt;.&lt;/font&gt;&lt;/a&gt; (slip opinion - PDF&amp;nbsp;link) that business entities have no personal privacy rights under the &lt;a href="http://www.justice.gov/oip/foia_guide09/foia-final.pdf"&gt;&lt;font color="#800080"&gt;Freedom of Information Act&lt;/font&gt;&lt;/a&gt; (FOIA) (PDF link).&amp;nbsp; The ruling was unanimous and arose from a&amp;nbsp;Third Circuit decision.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt"&gt;There are several exemptions built into the FOIA, whereby federal agencies do not have to make certain information available when requested.&amp;nbsp; &lt;span style="color: black"&gt;Exemption 7(C) pertains to law enforcement records that, if disclosed, &amp;ldquo;could reasonably be expected to constitute an unwarranted invasion of personal privacy.&amp;rdquo; 5 U. S. C. &amp;sect;552(b)(7)(C).&amp;nbsp; The issue addressed was whether corporations have &amp;quot;personal privacy&amp;quot; for purposes of exemption 7(C).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black; font-size: 10pt"&gt;AT&amp;amp;T was investigated by the Federal Communications Commission in connection with AT&amp;amp;T's participation in the FCC's E-Rate (Education-Rate) program for schools and libraries.&amp;nbsp;&amp;nbsp;As a result, AT&amp;amp;T disclosed to the FCC that it may have overcharged the Government for its services in connection with the E-Rate program.&amp;nbsp;&amp;nbsp;During the resulting&amp;nbsp;investigation, AT&amp;amp;T disclosed various information to the Government, including billing information, name and job descriptions of employees involved and AT&amp;amp;T's conclusion regarding wrongdoing by its&amp;nbsp;own employees.&amp;nbsp; The matter was resolved&amp;nbsp;in December 2004 and AT&amp;amp;T&amp;nbsp;paid&amp;nbsp;$500,000&amp;nbsp;and instituted a plan to ensure the incorrect billing did not occur again.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black; font-size: 10pt"&gt;CompTel, &amp;quot;a trade association representing some of AT&amp;amp;T's competitors,&amp;quot; submitted a FOIA request in connection with the E-Rate program investigation.&amp;nbsp; The FCC's Enforcement Bureau did withhold some competitive information, as well as names and other personal information related to AT&amp;amp;T's employees.&amp;nbsp;&amp;nbsp;However, the Enforcement Bureau did not apply exemption 7(C) to AT&amp;amp;T itself because &amp;quot;businesses do not possess 'personal privacy' interests as required by the exemption.&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black; font-size: 10pt"&gt;AT&amp;amp;T took the position the root term &amp;ldquo;person&amp;rdquo; in the phrase &amp;quot;personal privacy&amp;quot; refers to &amp;quot;persons&amp;quot; as defined under the Administrative Procedures Act.&amp;nbsp;The definition of &amp;quot;person&amp;quot; under the Administrative Procedures Act includes several types of business entities, specifically, corporations.&amp;nbsp; The FCC concluded that AT&amp;amp;T's position that it is &amp;ldquo;a &amp;lsquo;private corporate citizen&amp;rsquo; with personal privacy rights that should be protected from disclosure that would &amp;lsquo;embarrass&amp;rsquo; it . . . within the meaning of Exemption 7(C) . . . at odds with established [FCC] and judicial precedent,&amp;rdquo; and concluded that &amp;ldquo;Exemption 7(C) has no applicability to corporations such as [AT&amp;amp;T].&amp;rdquo; &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black; font-size: 10pt"&gt;The Court of Appeals for the Third Circuit agreed with AT&amp;amp;T, and the FCC petitioned the United States Supreme Court for review, and the Third Circuit holding was overturned.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black; font-size: 10pt"&gt;Chief Justice Roberts delivers a thoughtful analysis of why the terms &amp;quot;person&amp;quot; and &amp;quot;personal&amp;quot; should not be read to give business entities &amp;quot;personal privacy rights,&amp;quot; which you can read in detail in the &lt;a href="http://www.supremecourt.gov/opinions/10pdf/09-1279.pdf"&gt;&lt;font color="#800080"&gt;opinion&lt;/font&gt;&lt;/a&gt; (PDF link).&amp;nbsp; In a final wink, nudge and affirmation of his reasoning, Chief Justice Roberts concludes the analysis by stating that &amp;quot;[w]e trust that AT&amp;amp;T will not take it personally.&amp;quot;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/MkZvNxbKSjw" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/MkZvNxbKSjw/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/03/articles/right-to-privacy/supreme-court-tells-att-it-has-no-right-to-privacy/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">AT&amp;T</category><category domain="http://dataprivacy.foxrothschild.com/tags">CompTel</category><category domain="http://dataprivacy.foxrothschild.com/tags">FOIA</category><category domain="http://dataprivacy.foxrothschild.com/tags">Freedom of Information Act</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/articles">Right to Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">United States Supreme Court</category>
         <pubDate>Wed, 02 Mar 2011 06:47:08 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/03/articles/right-to-privacy/supreme-court-tells-att-it-has-no-right-to-privacy/</feedburner:origLink></item>
            <item>
         <title>Recent Enforcement Activity...</title>
         <description>&lt;p&gt;Last week, the federal government fined Cignet Health (Maryland) $43 million for violating the privacy rights of 41 patients by denying them access to their medical records.&amp;nbsp; The fine levied by the Department of Health and Human Services is the first under&amp;nbsp;HIPAA's privacy rule.&amp;nbsp; The Department of Health and Human Services' Office of Civil Rights&amp;nbsp;determined that, between September 2008 and October 2009, Cignet Health violated patients' rights by denying them access to their medical records.&amp;nbsp; Cignet Health also repeatedly failed to cooperate with the investigation conducted by the Office of Civil Rights and did not comply with a subpoena for medical records issued by the Office of Civil Rights until ordered to do so by a federal judge in March 2010.&lt;/p&gt;
&lt;p&gt;Separately, the&amp;nbsp; federal government reached a&amp;nbsp;$1M dollar settlement with Massachusetts General Hospital over potential violations of patient privacy laws when an employee lost patients records on local public transportation.&amp;nbsp; The lost&amp;nbsp;information concerned 192 patients in the hospital's Infectious Disease Associates outpatient practice, including information pertaining to patients with HIV/AIDS.&amp;nbsp; For 66 patients, the lost data included billing forms that recorded name, birth date, medical record number, health insurer and policy number and diagnosis.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/tlygvpZIlD4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/tlygvpZIlD4/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/02/articles/privacy-rights/recent-enforcement-activity/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Cignet Health</category><category domain="http://dataprivacy.foxrothschild.com/tags">HIV/AIDS</category><category domain="http://dataprivacy.foxrothschild.com/tags">Massachusetts General Hospital</category><category domain="http://dataprivacy.foxrothschild.com/articles">Privacy Rights</category><category domain="http://dataprivacy.foxrothschild.com/tags">medical records</category>
         <pubDate>Mon, 28 Feb 2011 14:01:55 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/02/articles/privacy-rights/recent-enforcement-activity/</feedburner:origLink></item>
            <item>
         <title>Moving to the Cloud: Making Sure You Know the Location of the Cloud</title>
         <description>&lt;p&gt;Over the last two years more and more clients have requested that we assist them with moving some or&amp;nbsp;all of their business services to the &amp;quot;cloud.&amp;quot;&amp;nbsp; Some of these clients want to use a service that would&amp;nbsp;result in sensitive information being stored on the servers of a third party service provider, such as&amp;nbsp;web-based email, Salesforce.com, Google Docs.&amp;nbsp; As much as each of these businesses have heavily debated the pros and cons of moving to the cloud, rarely do they consider where the cloud is physically located.&lt;/p&gt;
&lt;p&gt;Financial and health industries have always had a focus on thinking through where their protected data was located.&amp;nbsp; There is a sophisticated legal framework dealing with prohibitions on the storage of sensitive data on foreign soil, such as financial, import-export or healthcare rules and regulations.&amp;nbsp; For example, a well thought-out online services agreement for a financial institution&amp;nbsp;should have a strict prohibition on storage of data in certain countries or a country other than where the financial institution is located.&lt;/p&gt;
&lt;p&gt;However, businesses do not always consider that the information that is stored in a cloud-based service may be physically located on servers not situated in the United States.&amp;nbsp; Having your business information located in a foreign country can easily (very, very easily) lead to loss, unauthorized private and governmental access and the tripping of the myriad of existing laws, rules and regulations.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.softwareadvice.com/accounting/"&gt;The Software Advice Blog&lt;/a&gt;&amp;nbsp;has a&amp;nbsp;&lt;a href="http://www.softwareadvice.com/articles/enterprise/is-your-cloud-system-safe-from-the-law-01020911/"&gt;recent&amp;nbsp;blog post&lt;/a&gt;&amp;nbsp;that&amp;nbsp;highlights some of the considerations that a business should undertake when considering&amp;nbsp;the storage&amp;nbsp;of&amp;nbsp;data in a cloud-based service.&amp;nbsp; Because the decision making process for each business is unique,&amp;nbsp;no blog post is going to give you all of the&amp;nbsp;answers.&amp;nbsp; But the examples here and in the entry on&amp;nbsp;&lt;a href="http://www.softwareadvice.com/accounting/"&gt;Software Advice&lt;/a&gt; do give you some idea of what your business&amp;nbsp;should be considering.&lt;/p&gt;
&lt;p&gt;A final note is that the physical location of cloud-based servers is relevant at all times, not just when you have offices, employees or services based in other countries.&amp;nbsp; You may know that you are dealing with a company based in your home country, but you should not assume that the servers used by that company are also based in your home country.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/hOfyar49cXY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/hOfyar49cXY/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/02/articles/electronic-data-security/moving-to-the-cloud-making-sure-you-know-the-location-of-the-cloud/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Cloud Storage</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Server Location</category>
         <pubDate>Fri, 25 Feb 2011 10:18:50 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/02/articles/electronic-data-security/moving-to-the-cloud-making-sure-you-know-the-location-of-the-cloud/</feedburner:origLink></item>
            <item>
         <title>California's Simitian Moves to Bolster Data Breach Notices</title>
         <description>&lt;p&gt;California State Senator, Joe Simitian (D-Palo Alto), who authored the state's existing data breach law in 2002, has introduced Senate Bill 24 to strengthen the content of notices provided to individuals when their personal information has been hacked, stolen or lost. If passed, Senate Bill 24 proposes to offer individuals better protection against identity theft by standardizing the content for data breach notification, including (i) a general description of the incident, (ii) the type of information breached, (iii) the date and time of the breach and (iv) a toll-free telephone number of major credit reporting agencies for security breach notices in California. Senate Bill 24 would also require public agencies, businesses and others to send a copy of the breach notification to the California Attorney General if more than 500 Californians are affected by a single breach. Former Governor Arnold Swarzenegger vetoed similar legislation introduced by Senator Simitian.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/EGAE4DnwBMg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/EGAE4DnwBMg/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/02/articles/data-theft/californias-simitian-moves-to-bolster-data-breach-notices/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">24</category><category domain="http://dataprivacy.foxrothschild.com/tags">Breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">Data</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">Law</category><category domain="http://dataprivacy.foxrothschild.com/tags">bill</category><category domain="http://dataprivacy.foxrothschild.com/tags">california</category><category domain="http://dataprivacy.foxrothschild.com/tags">senate</category><category domain="http://dataprivacy.foxrothschild.com/tags">state</category>
         <pubDate>Mon, 14 Feb 2011 09:46:53 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/02/articles/data-theft/californias-simitian-moves-to-bolster-data-breach-notices/</feedburner:origLink></item>
      
   </channel>
</rss>

