<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Privacy Compliance &amp; Data Security</title>
      <link>http://dataprivacy.foxrothschild.com/</link>
      <description />
      <language>en</language>
      <copyright>Copyright 2013</copyright>
      <lastBuildDate>Wed, 03 Apr 2013 06:14:20 -0500</lastBuildDate>
      <pubDate>Wed, 03 Apr 2013 06:14:20 -0500</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="privacycompliancedatasecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://dataprivacy.foxrothschild.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://dataprivacy.foxrothschild.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.yourminis.com/subscribe.aspx?u=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.yourminis.com/images/addtoyourminisbadge.gif">Subscribe with Yourminis.com</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://hub.netomat.net/account/account.autoSubscribe.jspa?urls=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.netomat.net/blogger/images/icon_netomat_feedbutton.gif">Subscribe with netomat Hub</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Fdataprivacy.foxrothschild.com%2Findex.xml" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
         <title>California Legislature Advances Groundbreaking Privacy "Right to Know Act"</title>
         <description>&lt;p&gt;In what amounts to a potential, unprecedented victory for consumers&amp;rsquo; right to know how their personal information is used by businesses, California's &amp;quot;&lt;a href="http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB1291"&gt;Right to Know Act of 2013&lt;/a&gt;&amp;quot; (AB 1291)&amp;nbsp;made further headway by being re-read and amended a second time on Monday, April 1&lt;sup&gt;st&lt;/sup&gt;.&amp;nbsp; As reported by &lt;a href="http://arstechnica.com/tech-policy/2013/04/california-lawmaker-introduces-unprecedented-personal-data-disclosure-bill/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+arstechnica%2Findex+%28Ars+Technica+-+All+content%29"&gt;Ars Technica&lt;/a&gt;,&amp;nbsp;the Right to Know Act, which was introduced by California&amp;nbsp;Assembly Member&amp;nbsp;Bonnie Lowenthal, was the result of &lt;a href="https://www.eff.org/deeplinks/2013/04/new-california-right-know-act-would-let-consumers-find-out-who-has-their-personal"&gt;significant lobbying&lt;/a&gt;&amp;nbsp;by the Electronic Frontier Foundation and the American Civil Liberties Union of Northern California.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB1291"&gt;current summary&lt;/a&gt;&amp;nbsp;of the bill states:&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;(1)&amp;nbsp;Existing law requires a business to ensure the privacy of a customer&amp;rsquo;s personal information, as defined, contained in records by destroying, or arranging for the destruction of, the records, as specified. Any customer injured by a business&amp;rsquo; violation of these provisions is entitled to recover damages, obtain injunctive relief, or seek other remedies.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;This bill would&lt;i&gt;&amp;nbsp;create the Right to Know Act of 2013,&amp;nbsp;would&lt;/i&gt;&amp;nbsp;repeal and reorganize certain provisions of existing law&lt;i&gt;, and would provide legislative findings in support thereof&lt;/i&gt;.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;(2)&amp;nbsp;Existing law also requires a business that collects customer information for marketing purposes and that discloses a customer&amp;rsquo;s personal information to a 3rd party for direct marketing purposes, to provide the customer with whom it had a business relationship, as defined, within 30 days after the customer&amp;rsquo;s request, as specified, in writing or by e-mail, the names and addresses of the recipients of that information and specified details regarding the information disclosed, except as specified. Existing law requires a business subject to these provisions to provide an address, electronic address, or toll-free telephone or facsimile number that a customer may use to deliver requests for copies of his or her personal information.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;This bill would instead require any business that&amp;nbsp;has&lt;i&gt;&amp;nbsp;retains&lt;/i&gt;&amp;nbsp;a customer&amp;rsquo;s personal information, as defined,&lt;i&gt;&amp;nbsp;or discloses that information to a 3rd party,&lt;/i&gt;&amp;nbsp;to provide at no charge, within 30 days of the customer&amp;rsquo;s specified request, a copy of that information to the customer as well as the names and contact information for all 3rd parties with which the business has shared the information during the previous 12 months, regardless of any business relationship with the customer. This bill would require that a business subject to these provisions choose one of several specified options to provide the customer with a designated address for use in making a request for copies of information under these provisions.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;(3)&amp;nbsp;Existing law also requires a business that is required to comply with these provisions to provide information to customers regarding its privacy policy and to provide a designated means of preventing disclosure of personal information.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;This bill would require a business that is required to comply with these provisions to provide specified notice to the customer of its privacy policies.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;(4)&amp;nbsp;Existing law provides that a customer who sustains injury as a result of a violation of these provisions is entitled to specified remedies, including civil penalties.&lt;/p&gt;
&lt;p style="margin-left: 40px;"&gt;This bill would also provide that a violation of these provisions is deemed to constitute an injury to the customer for purposes of seeking remedies available under law.&lt;/p&gt;
&lt;p&gt;In other words, the Act also provides a private right of action to consumers for businesses that do not comply with the Act.&lt;/p&gt;
&lt;p&gt;The EFF appears to be quite pleased with the bill, as noted in its &lt;a href="https://www.eff.org/deeplinks/2013/04/new-california-right-know-act-would-let-consumers-find-out-who-has-their-personal"&gt;press release&lt;/a&gt;&amp;nbsp;on April 2&lt;sup&gt;nd&lt;/sup&gt;.&amp;nbsp; The EFF noted that the point of the law if to allow consumers to better understand the vast economy that is data sharing: &amp;quot;This law is about transparency and access, not new restrictions on data sharing. The proposed law wouldn't limit or restrict sales of data, and it wouldn't provide additional security measures for how data is stored or new requirements for anonymization. While those are all important issues to consider, the law is actually far more basic. It helps consumers, regulators, policymakers, and the world at large shine a light onto the largely hidden, highly lucrative world of the personal data economy.&amp;quot;&lt;/p&gt;
&lt;p&gt;It will be interesting to see (1) if the Act continues toward enactment, (2) how companies outside of California, but with information regarding California residents, implement the law, and (3) if this very European-style law catches on in other states. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/qEf1eYstBTI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/qEf1eYstBTI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2013/04/articles/proposed-law/california-legislature-advances-groundbreaking-privacy-right-to-know-act/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Bonnie Lowenthal</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/articles">Proposed Law</category><category domain="http://dataprivacy.foxrothschild.com/tags">Right to Know Act of 2013</category>
         <pubDate>Wed, 03 Apr 2013 06:03:15 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2013/04/articles/proposed-law/california-legislature-advances-groundbreaking-privacy-right-to-know-act/</feedburner:origLink></item>
            <item>
         <title>In Massachusetts, ZIP Codes Constitute Personal Identification Information</title>
         <description>&lt;p&gt;&lt;span class="470163212-15032013"&gt;&lt;font size="2"&gt;In connection with a class action lawsuit filed against Michaels Stores Inc., the United States District Court for the District of Massachusetts certified to the Supreme Judicial&amp;nbsp;Court of Massachusetts three questions: (1) whether a ZIP code constitutes personal identification information; (2) whether, under the Massachusetts statute prohibiting collection of personal identification information during a credit&amp;nbsp;card transaction,&amp;nbsp;a plaintiff may pursue a claim without any evidence of identity theft; and (3) whether, under the statute a &amp;quot;credit card transaction form&amp;quot; includes an electronic transaction form.&amp;nbsp; Earlier this week, the Supreme Court&amp;nbsp;answered &amp;quot;yes&amp;quot; to all three of these questions.&amp;nbsp;&amp;nbsp;A copy of the Court's opinion is attached &lt;a href="http://dataprivacy.foxrothschild.com/uploads/file/Tyler v_ Michaels Stores(1).pdf"&gt;here&lt;/a&gt;.&amp;nbsp; The Supreme Court's decision will likely open the door to more lawsuits against retailers in Massachusetts.&amp;nbsp; Plaintiffs may now file actions against retailers who collect ZIP&amp;nbsp;code information during a credit card transaction and, consistent with the Supreme Court's broad&amp;nbsp;interpretation of personal identification information, plaintiffs may try to expand the definition of personal identification information&amp;nbsp;even further to include other types of information.&amp;nbsp; In addition, the Supreme Court's decision has lowered the bar for plaintiffs who struggle to prove that they have been injured in these cases.&amp;nbsp;&amp;nbsp;Under the Supreme Court's ruling, a plaintiff no longer needs to demonstrate that he or she has suffered identity theft in order to maintain a cause of action.&amp;nbsp; Significantly, the Court stated that receipt of unwanted marketing materials or the sale of a consumer's personal identification information to a third-party can constitute an injury sufficient to maintain an action.&amp;nbsp; As a result of the Supreme Court's decision, retailers in Massachusetts should review and evaluate their data collection practices.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/VKKf4cLhROM" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/VKKf4cLhROM/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2013/03/articles/data-protection-law-compliance/in-massachusetts-zip-codes-constitute-personal-identification-information/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Protection Law Compliance</category><category domain="http://dataprivacy.foxrothschild.com/tags">PII</category><category domain="http://dataprivacy.foxrothschild.com/tags">ZIP code</category><category domain="http://dataprivacy.foxrothschild.com/tags">credit card</category><category domain="http://dataprivacy.foxrothschild.com/tags">massachusetts</category><category domain="http://dataprivacy.foxrothschild.com/tags">personal identification information</category>
         <pubDate>Fri, 15 Mar 2013 08:20:43 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2013/03/articles/data-protection-law-compliance/in-massachusetts-zip-codes-constitute-personal-identification-information/</feedburner:origLink></item>
            <item>
         <title>California Supreme Court Permits Apple To Collect Personal Information Online</title>
         <description>&lt;p&gt;On February 4, 2013, the California Supreme Court held that Apple&amp;nbsp;Inc.&amp;nbsp;is permitted to request a customer's address and telephone number in connection with an online purchase. The Supreme Court reversed the trial court's decision and found that the Song-Beverly Credit Card Act does not apply to online transactions.&amp;nbsp; The Supreme Court stated that &amp;quot;[t]he safeguards against fraud that are provided in [the act] are not available to the online retailer selling an eletronically downloadable product.&amp;nbsp; Unlike a brick-and-mortar retailer, an online retailer cannot visually inspect the credit card, the signature on the back of the card or the customer's photo identification.&amp;quot;&amp;nbsp;&amp;nbsp; The case is Apple Inc. v. The Superior Court of Los Angeles County, Case No. S199348.&amp;nbsp; &lt;a href="http://dataprivacy.foxrothschild.com/uploads/file/CA Supr Crt S199384 Apple v_ Superior Crt.pdf"&gt;Attached is a copy of the Court's opinion.&amp;nbsp;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/hI8brZUFqlc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/hI8brZUFqlc/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2013/02/articles/electronic-data-security/california-supreme-court-permits-apple-to-collect-personal-information-online/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Song-Beverly Credit Card Act</category><category domain="http://dataprivacy.foxrothschild.com/tags">credit card transaction</category><category domain="http://dataprivacy.foxrothschild.com/tags">online purchases</category><category domain="http://dataprivacy.foxrothschild.com/tags">online transactions</category><category domain="http://dataprivacy.foxrothschild.com/tags">personal information</category>
         <pubDate>Tue, 05 Feb 2013 10:06:42 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2013/02/articles/electronic-data-security/california-supreme-court-permits-apple-to-collect-personal-information-online/</feedburner:origLink></item>
            <item>
         <title>HIPAA "Mega Rule", Meet "Super BAA":  The CMS Data Use Agreement</title>
         <description>&lt;p&gt;[This blog posting was previously posted on the &lt;a href="http://hipaahealthlaw.foxrothschild.com/"&gt;HIPAA, HITECH&amp;nbsp;and Health Information&lt;/a&gt; blog.]&lt;/p&gt;
&lt;p&gt;The recent &lt;a href="https://www.federalregister.gov/articles/2013/01/25/2013-01073/hipaa-privacy-security-enforcement-and-breach-notification-rules"&gt;release&lt;/a&gt; of the HIPAA/HITECH &amp;ldquo;mega rule&amp;rdquo; or &amp;ldquo;omnibus rule&amp;rdquo; has given bloggers and lawyers like us plenty of topics for analysis and debate, as well as some tools with which to prod covered entities, business associates and subcontractors to put HIPAA/HITECH-compliant Business Associate Agreements (&amp;ldquo;BAAs&amp;rdquo;) in place.&amp;nbsp;It&amp;rsquo;s also a reminder to read BAAs that are already in place, and to make sure the provisions accurately describe how and why protected health information (&amp;ldquo;PHI&amp;rdquo;) is to be created, received, maintained, and/or transmitted.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;If you are an entity that participates in the &lt;a href="http://www.cms.gov/Medicare/Medicare-Fee-for-Service-Payment/sharedsavingsprogram/index.html?redirect=/sharedsavingsprogram/"&gt;Medicare Shared Savings Program&lt;/a&gt;&amp;nbsp;as a Medicare Accountable Care Organization (&amp;ldquo;ACO&amp;rdquo;), your ability to access patient data from Medicare depends on your having signed the &lt;a href="http://www.cms.gov/Medicare/Medicare-Fee-for-Service-Payment/sharedsavingsprogram/Downloads/Data-Use-Agreement.pdf"&gt;CMS Data Use Agreement&lt;/a&gt; (the &amp;ldquo;Data Use Agreement&amp;rdquo;).&amp;nbsp;Just as covered entities, business associates, and subcontractors should read and fully understand their BAAs, Medicare ACOs should make sure they are aware of several Data Use Agreement provisions that are more stringent than provisions typically included in a BAA and that may come as a surprise.&amp;nbsp;Here are ten provisions from the Data Use Agreement worth reviewing, whether you are a Medicare ACO or any other business associate or subcontractor, as these may very well resurface in some form in the &amp;ldquo;Super BAA&amp;rdquo; of the future:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CMS (the covered entity) retains ownership rights in the patient data furnished to the ACO.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO may only use the patient data for the purposes enumerated in the Data Use Agreement.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO may not grant access to the patient data except as authorized by CMS.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees that, within the ACO and its agents, access to patient data will be limited to the minimum amount of data and minimum number of individuals necessary to achieve the stated purposes.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO will only retain the patient data (and any derivative data) for one year or until 30 days after the purpose specified in the Data Use Agreement is completed, whichever is earlier, and the ACO must destroy the data and send written certification of the destruction to CMS within 30 days.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO must establish administrative, technical, and physical safeguards that meet or exceed standards established by the Office of Management and Budget and the National Institute of Standards and Technology.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO acknowledges that it is prohibited from using unsecured telecommunications, including the Internet, to transmit individually identifiable, bidder identifiable or deducible information derived from the patient files.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees not to disclose any information derived from the patient data, even if the information does not include direct identifiers, if the information can, by itself or in combination with other data, be used to deduce an individual&amp;rsquo;s identity.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;9.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees to abide by CMS&amp;rsquo;s cell size suppression policy (which stipulates that no cell of 10 or less may be displayed).&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;And last, but certainly not least:&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;10. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACO agrees to report to CMS any breach of personally identifiable information from the CMS data file(s), loss of these data, or disclosure to an unauthorized person by telephone or email &lt;b&gt;within one hour.&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;While the undertakings of a Medicare ACO and the terminology in the Data Use Agreement for protection of patient data may differ from those of covered entities, business associates and subcontractors and their BAAs under the HIPAA/HITECH regulations, they have many striking similarities and purposes.&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/XDHKOyB5Ky4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/XDHKOyB5Ky4/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2013/01/articles/electronic-data-security/hipaa-mega-rule-meet-super-baa-the-cms-data-use-agreement/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">ACO</category><category domain="http://dataprivacy.foxrothschild.com/tags">Accountable  Care Organization</category><category domain="http://dataprivacy.foxrothschild.com/tags">BAA</category><category domain="http://dataprivacy.foxrothschild.com/tags">CMS</category><category domain="http://dataprivacy.foxrothschild.com/tags">CMS Data Use Agreement</category><category domain="http://dataprivacy.foxrothschild.com/tags">Centers for Medicare and Medicaid Services</category><category domain="http://dataprivacy.foxrothschild.com/tags">Data Use Agreement</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">HIPAA</category><category domain="http://dataprivacy.foxrothschild.com/tags">HIPAA Mega Rule</category><category domain="http://dataprivacy.foxrothschild.com/tags">HIPAA Omnibus Rule</category><category domain="http://dataprivacy.foxrothschild.com/tags">HITECH</category><category domain="http://dataprivacy.foxrothschild.com/tags">Medicare</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI</category><category domain="http://dataprivacy.foxrothschild.com/">Protected Health Information</category><category domain="http://dataprivacy.foxrothschild.com/tags">business associate agreements</category><category domain="http://dataprivacy.foxrothschild.com/tags">patient data</category>
         <pubDate>Thu, 24 Jan 2013 11:36:37 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2013/01/articles/electronic-data-security/hipaa-mega-rule-meet-super-baa-the-cms-data-use-agreement/</feedburner:origLink></item>
            <item>
         <title>The SAIC Breach and a Look Across the Chasm Between Significant Risk and Actual Harm Resulting from a HIPAA Breach</title>
         <description>&lt;p&gt;The following was recently posted in substantially the same form on the Fox Rothschild LLP HIPAA, HITECH and Health Information Technology &lt;a href="http://hipaahealthlaw.foxrothschild.com/"&gt;blog&lt;/a&gt;.&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;st2:givenname w:st="on"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;a href="http://www.foxrothschild.com/attorneys/elizabeth-litten.html "&gt;Elizabeth&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;/st2:givenname&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;st2:sn w:st="on"&gt;&lt;a href="http://www.foxrothschild.com/attorneys/elizabeth-litten.html "&gt;Litten&lt;/a&gt;&lt;/st2:sn&gt; and &lt;st1:personname w:st="on"&gt;&lt;a href="http://www.foxrothschild.com/attorneys/michael-kline.html"&gt;&lt;st2:givenname w:st="on"&gt;Michael&lt;/st2:givenname&gt; &lt;st2:sn w:st="on"&gt;Kline&lt;/st2:sn&gt;&lt;/a&gt;&lt;/st1:personname&gt; write:&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;We have posted several blogs, including those &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-with-some-words-on-the-nemours-phi-breach-part-1/"&gt;here&lt;/a&gt; and &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/11/articles/breaches/did-tricaredod-make-a-proactive-response-or-a-preemptive-strike-with-saic-in-the-phi-breach-matter-whose-risk-is-it-anyway-part-4/"&gt;here&lt;/a&gt;, tracking the reported 2011 theft of computer tapes from the car of an employee of Science Applications International Corporation (&amp;ldquo;SAIC&amp;rdquo;) that contained the protected health information (&amp;ldquo;PHI&amp;rdquo;) affecting approximately 5 million military clinic and hospital patients (the &amp;ldquo;SAIC Breach&amp;rdquo;).&amp;nbsp; SAIC&amp;rsquo;s recent Motion to Dismiss (the &amp;ldquo;Motion&amp;rdquo;) the Consolidated Amended Complaint filed in federal court in Florida as a putative class action (the &amp;ldquo;SAIC Class Action&amp;rdquo;) highlights the gaps between an incident (like a theft) involving PHI, a determination that a breach of PHI has occurred, and the realization of harm resulting from the breach.&amp;nbsp;SAIC&amp;rsquo;s Motion&amp;nbsp;emphasizes this gap between the incident and the realization of harm, making it appear like a chasm so wide it practically swallows the breach into oblivion.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;SAIC, a giant publicly-held government contractor that provides information technology (&amp;ldquo;IT&amp;rdquo;) management and, ironically, cyber security services, was engaged to provide IT management services to TRICARE Management Activity&lt;/span&gt;&lt;span style="font-size: 13pt; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;, &lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;a component of TRICARE, the military health plan (&amp;ldquo;TRICARE&amp;rdquo;) for active duty service members working for the U.S. Department of Defense&lt;/span&gt;&lt;span style="font-size: 13pt; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt; (&amp;ldquo;&lt;/span&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;DoD&amp;rdquo;).&amp;nbsp; SAIC employees had been contracted to transport backup tapes containing TRICARE members&amp;rsquo; PHI from one location to another.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;According to the original statement &lt;a href="http://www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf"&gt;published&lt;/a&gt; in late September of 2011 ( the &amp;ldquo;TRICARE/SAIC Statement&amp;rdquo;) the PHI &amp;ldquo;may include Social Security numbers, addresses and phone numbers, and some personal health data such as clinical notes, laboratory tests and prescriptions.&amp;rdquo; However, the TRICARE/SAIC Statement said that there was no financial data, such as credit card or bank account information, on the backup tapes.&amp;nbsp;Note 17 to the audited financial statements (&amp;ldquo;Note 17&amp;rdquo;) contained in the SAIC Annual Report on &lt;a href="http://investors.saic.com/phoenix.zhtml?c=193857&amp;amp;p=irol-SECText&amp;amp;TEXT=aHR0cDovL2lyLmludC53ZXN0bGF3YnVzaW5lc3MuY29tL2RvY3VtZW50L3YxLzAwMDExOTMxMjUtMTItMTMzNjk3L3htbA%3d%3d "&gt;Form 10-K&lt;/a&gt; for the fiscal year ended January 31, 2012, dated March 27, 2012&amp;nbsp;(the &amp;ldquo;2012 Form 10-K&amp;rdquo;), filed with the Securities and Exchange Commission (the &amp;quot;SEC&amp;rdquo;), includes the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 1in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;There is no evidence that any of the data on the backup tapes has actually been accessed or viewed by an unauthorized person.&amp;nbsp;In order for an unauthorized person to access or view the data on the backup tapes, it would require knowledge of and access to specific hardware and software and knowledge of the system and data structure. &amp;nbsp;The Company [SAIC] has notified potentially impacted persons by letter and is offering one year of credit monitoring services to those who request these services and in certain circumstances, one year of identity restoration services.&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 1in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;While the TRICARE/SAIC Statement contained similar language to that quoted above from Note 17, the earlier TRICARE/SAIC Statement also said, &amp;ldquo;The risk of harm to patients is judged to be low despite the data elements . . . .&amp;rdquo;&amp;nbsp;Because Note 17 does not contain such &amp;ldquo;risk of harm&amp;rdquo; language, it would appear that (i) there may have been a change in the assessment of risk by SAIC six months after the SAIC&amp;nbsp;Breach or (ii) SAIC did not want to&amp;nbsp;state such a judgment in an SEC filing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;Note 17 also discloses that SAIC has reflected a $10 million loss provision in its financial statements relating to the &amp;nbsp;SAIC Class Action and various other putative class actions respecting the SAIC Breach filed between October 2011 and March 2012 (for a total of seven such actions filed in four different federal District Courts).&amp;nbsp; In Note 17 SAIC states&amp;nbsp;that the $10 million loss provision represents the &amp;ldquo;low end&amp;rdquo; of SAIC&amp;rsquo;s estimated loss and is the amount of SAIC&amp;rsquo;s deductible under insurance covering judgments or settlements and defense costs of litigation respecting the SAIC Breach. &amp;nbsp;SAIC expresses the belief in Note 17 that any loss experienced in excess of the $10 million loss provision would not exceed the insurance coverage.&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;Such insurance coverage&amp;nbsp;would, however,&amp;nbsp;likely&amp;nbsp;not be available for any civil monetary penalties or counsel fees that may result from the current investigation of the SAIC Breach being conducted by the Office of Civil Rights of the Department of Health and Human Services (&amp;ldquo;HHS&amp;rdquo;) as described in Note 17.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;Initially, SAIC did not deem it necessary to offer credit monitoring to the almost 5 million reportedly affected individuals.&amp;nbsp;However, SAIC urged anyone suspecting they had been affected to contact the Federal Trade Commission&amp;rsquo;s identity theft website.&amp;nbsp;Approximately 6 weeks later, the DoD &lt;a href="http://www.defense.gov/releases/release.aspx?releaseid=14905"&gt;issued&lt;/a&gt; a press release stating that TRICARE had &amp;ldquo;directed&amp;rdquo; SAIC to take a &amp;ldquo;proactive&amp;rdquo; response by covering a year of free credit monitoring and restoration services for any patients expressing &amp;ldquo;concern about their credit as a result of the data breach.&amp;rdquo;&amp;nbsp;&amp;nbsp; The cost of such a proactive response easily can run into millions of dollars in the SAIC Breach.&amp;nbsp;It is unclear the extent, if any, to which insurance coverage would be available to cover the cost of the proactive response mandated by the DoD, even if the credit monitoring, restoration services and other remedial activities of SAIC were to become part of a judgment or settlement in the putative class actions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;We have blogged about what constitutes an impermissible acquisition, access, use or disclosure of unsecured PHI that poses a &amp;ldquo;significant risk&amp;rdquo; of &amp;ldquo;financial, reputational, or other harm to the individual&amp;rdquo; amounting to a reportable HIPAA breach, and when that &amp;ldquo;significant risk&amp;rdquo; develops into harm that may create claims for damages by affected individuals.&amp;nbsp;Our partner &lt;st2:givenname w:st="on"&gt;William&lt;/st2:givenname&gt; &lt;st2:sn w:st="on"&gt;Maruca&lt;/st2:sn&gt;, &lt;st2:namesuffix w:st="on"&gt;Esq.&lt;/st2:namesuffix&gt;, artfully borrows a phrase from former &lt;st1:personname w:st="on"&gt;Defense Secretary &lt;st2:givenname w:st="on"&gt;Donald&lt;/st2:givenname&gt; &lt;st2:sn w:st="on"&gt;Rumsfeld&lt;/st2:sn&gt;&lt;/st1:personname&gt; in &lt;a href="http://hipaahealthlaw.foxrothschild.com/2012/11/articles/breaches/known-unknowns-and-data-losses/"&gt;discussing&lt;/a&gt; a recent disappearance of unencrypted backup tapes reported by Women and &lt;st1:placename w:st="on"&gt;Infants&lt;/st1:placename&gt; &lt;st1:placetype w:st="on"&gt;Hospital&lt;/st1:placetype&gt; in &lt;st1:state w:st="on"&gt;&lt;st1:place w:st="on"&gt;Rhode Island&lt;/st1:place&gt;&lt;/st1:state&gt;.&amp;nbsp;If one knows PHI has disappeared, but doubts it can be accessed or used (due to the specialized equipment and expertise required to access or use the PHI), there is a &amp;ldquo;known unknown&amp;rdquo; that complicates the analysis as to whether a breach has occurred.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 0pt"&gt;&lt;span style="mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-US"&gt;As we await publication of the &amp;ldquo;mega&amp;rdquo; HIPAA/HITECH regulations, continued tracking of the SAIC Breach and ensuing class action litigation (as well as SAIC&amp;rsquo;s SEC filings and other government filings and reports on the &lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html "&gt;HHS list&lt;/a&gt; of large PHI security breaches) provides some insights as to how covered entities and business associates respond to incidents involving the loss or theft of, or possible access to, PHI.&amp;nbsp;&amp;nbsp; If a covered entity or business associate concludes that the incident poses a &amp;ldquo;significant risk&amp;rdquo; of harm, but no harm actually materializes, perhaps (as the SAIC Motion repeatedly asserts) claims for damages are inappropriate.&amp;nbsp;When the covered entity or business associate takes a &amp;ldquo;proactive&amp;rdquo; approach in responding to what it has determined to be a &amp;ldquo;significant risk&amp;rdquo; (such as by offering credit monitoring and restoration services), perhaps the risk becomes less significant.&amp;nbsp;But once the incident (a/k/a, the ubiquitous laptop or computer tape theft from an employee&amp;rsquo;s car) has been deemed a breach, the chasm between incident and harm seems to open wide enough to encompass a mind-boggling number of privacy and security violation claims and issues.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/ES7yGeRd3qg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/ES7yGeRd3qg/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/12/articles/data-security-breach-response/the-saic-breach-and-a-look-across-the-chasm-between-significant-risk-and-actual-harm-resulting-from-a-hipaa-breach/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Department of Defense</category><category domain="http://dataprivacy.foxrothschild.com/tags">Department of Health and Human Services</category><category domain="http://dataprivacy.foxrothschild.com/tags">DoD</category><category domain="http://dataprivacy.foxrothschild.com/tags">HHS</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI security breach</category><category domain="http://dataprivacy.foxrothschild.com/">Protected Health Information</category><category domain="http://dataprivacy.foxrothschild.com/tags">SAIC</category><category domain="http://dataprivacy.foxrothschild.com/tags">SEC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Science Applications International Corporation</category><category domain="http://dataprivacy.foxrothschild.com/tags">Securities and Exchange Commission</category><category domain="http://dataprivacy.foxrothschild.com/tags">Security Breach Notification</category><category domain="http://dataprivacy.foxrothschild.com/tags">breach notification rule</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Fri, 07 Dec 2012 15:08:38 -0500</pubDate>
         <dc:creator>Elizabeth Litten</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/12/articles/data-security-breach-response/the-saic-breach-and-a-look-across-the-chasm-between-significant-risk-and-actual-harm-resulting-from-a-hipaa-breach/</feedburner:origLink></item>
            <item>
         <title>FTC "History Sniffing" Settlement Meaningless or the Start of Something Bigger</title>
         <description>&lt;p&gt;
&lt;p style="line-height: 120%; background: none repeat scroll 0% 0% white;"&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;The Federal Trade Commission announced yesterday a &lt;a href="http://ftc.gov/opa/2012/12/epic.shtm"&gt;settlement with Epic Marketplace&lt;/a&gt;&lt;/span&gt;&lt;span style=""&gt;, an online advertising network, which prohibits Epic from further collection of data obtained by &amp;quot;browser sniffing&amp;quot; the surfing history of &lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;Internet users &lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;and requires Epic to destroy all previously collected data.&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;According to the FTC complaint, Epic was collecting information from millions of individuals by &amp;ldquo;browser sniffing,&amp;rdquo; which is a practice that allowed Epic to &lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;color:black;"&gt;determine whether the user had previously visited more than 54,000 websites, including &lt;/span&gt;&lt;span style="color:black;"&gt;websites &lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy&lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;color:black;"&gt;.&amp;nbsp;Once Epic had this information, it would then send targeted advertisements to the user.&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;Many users have no idea that this technology even exists, and the FTC&amp;rsquo;s main gripe appears to be that the user did not have knowledge this was occurring on sites outside of Epic's advertising network.&amp;nbsp;Epic&amp;rsquo;s privacy policy promised that Epic would collect information about users only for use in &lt;/span&gt;&lt;span style="color:black;"&gt;Epic&amp;rsquo;s 45,000 website network.&amp;nbsp;A&lt;/span&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;pparently, the FTC was not concerned with the practice but it&amp;rsquo;s concern was centered around Epic collecting information from users about visits to websites not in Epic&amp;rsquo;s website network.&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&amp;quot;Consumers searching the Internet shouldn't have to worry about whether someone is going to go sniffing through the sensitive, personal details of their browsing history without their knowledge,&amp;quot; FTC Chairman Jon Leibowitz said in a statement. &amp;quot;This type of unscrupulous behavior undermines consumers' confidence, and we won't tolerate it.&amp;quot;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;Stated another way, the FTC is saying that Epic could collect information about whether consumers visited sites in its advertising network having to do with &lt;span style="color:black;"&gt;fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy, and then use that information to serve that consumer advertisements.&amp;nbsp;The problem was that Epic went beyond its own advertising network.&amp;nbsp;That makes sense.&amp;nbsp; A company breaching the representations in its own privacy policy is low hanging fruit.&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;What the FTC is NOT saying is that consumers would never know what the heck Epic&amp;rsquo;s privacy policy says, so how could they consent to this collection and use of their information.&amp;nbsp;Online advertisers are in this wonderful position where the consumer never really &amp;ldquo;gets&amp;rdquo; to them, the consumer only sees the advertisements that are served. .&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;span style="Times New Roman&amp;quot;;Times New Roman&amp;quot;;Times New Roman&amp;quot;;
color:black;"&gt;So is the take away that any company besides Epic can use &amp;ldquo;browser sniffing&amp;rdquo; as long as its use is disclosed in its privacy policy (which consumers would not even know existed) and followed by that company?&amp;nbsp; The FTC is certainly not taking a contrary position.&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height: 120%; background: none repeat scroll 0% 0% white;"&gt;&lt;span style=""&gt;The FTC press release follows:&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;&lt;p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;span style="font-size:8.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;For Release:&lt;/span&gt;&lt;span style="font-size:8.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt; 12/05/2012&lt;/span&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;b&gt;&lt;span style="Verdana&amp;quot;,&amp;quot;sans-serif&amp;quot;;
color:#194579;"&gt;FTC Settlement Puts an End to &amp;quot;History Sniffing&amp;quot; by Online Advertising Network Charged With Deceptively Gathering Data on Consumers&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="line-height:120%;background:white"&gt;&lt;b&gt;&lt;span style="font-size:11.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;Network Tracked Interest in Sensitive Medical and Financial Issues, Agency Says&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;An online advertising company agreed to settle Federal Trade Commission charges that it used &amp;ldquo;history sniffing&amp;rdquo; to secretly and illegally gather data from millions of consumers about their interest in sensitive medical and financial issues ranging from fertility and incontinence to debt relief and personal bankruptcy. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;The FTC settlement order &lt;a href="http://ftc.gov/os/caselist/1123182/121205epicorder.pdf"&gt;&lt;span style="color:#006699;text-decoration:none;text-underline:none"&gt;bars the company, Epic Marketplace Inc., from continuing to use history sniffing technology&lt;/span&gt;&lt;/a&gt;, which allows online operators to &amp;ldquo;sniff&amp;rdquo; a browser to see what sites consumers have visited in the past. It also bars future misrepresentations by Epic and requires the company to destroy information that it gathered unlawfully.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;&amp;ldquo;Consumers searching the Internet shouldn&amp;rsquo;t have to worry about whether someone is going to go sniffing through the sensitive, personal details of their browsing history without their knowledge,&amp;rdquo; said FTC Chairman Jon Leibowitz. &amp;ldquo;This type of unscrupulous behavior undermines consumers&amp;rsquo; confidence, and we won&amp;rsquo;t tolerate it.&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;
Epic Marketplace is a large advertising network that has a presence on 45,000 websites. Consumers who visited any of the network&amp;rsquo;s sites received a cookie, which stored information about their online practices including sites they visited and the ads they viewed. The cookies allowed Epic to serve consumers ads targeted to their interests, a practice known as online behavioral advertising. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;In its privacy policy, Epic claimed that it would collect information only about consumers&amp;rsquo; visits to sites in its network. However, according to the FTC, Epic was employing history-sniffing technology that allowed it to collect data about sites outside its network that consumers had visited, including sites relating to personal health conditions and finances. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;According to the FTC complaint, the history sniffing was deceptive and allowed Epic to determine whether a consumer had visited any of more than 54,000 domains, including pages relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;The FTC complaint alleges that depending on which domains a consumer had visited, Epic assigned the consumer an interest segment, including categories such as &amp;ldquo;Incontinence,&amp;rdquo; &amp;ldquo;Arthritis,&amp;rdquo; &amp;ldquo;Memory Improvement,&amp;rdquo; and &amp;ldquo;Pregnancy-Fertility Getting Pregnant.&amp;rdquo; Epic used these categories to send consumers targeted ads.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;The consent order bars Epic Marketplace, Inc., and Epic Media Group, LLC from using history sniffing, and requires that they delete and destroy all data collected using it. It also bars misrepresentations about the extent to which they maintain the privacy or confidentiality of data from or about a particular consumer, computer or device, including misrepresenting how that data is collected, used, disclosed or shared. It bars misrepresentations about the extent to which software code on a webpage determines whether a user has previously visited a website. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;The Commission vote to accept the consent agreement package containing the proposed consent order for public comment was 5-0. The FTC will publish a description of the consent agreement package in the Federal Register shortly. The agreement will be subject to public comment for 30 days, beginning today and continuing through January 7, 2013, after which the Commission will decide whether to make the proposed consent order final. Interested parties can &lt;a href="https://ftcpublic.commentworks.com/ftc/epicmarketplaceconsent"&gt;&lt;span style="color:#006699;text-decoration:none;text-underline:none"&gt;submit written comments electronically&lt;/span&gt;&lt;/a&gt; or in paper form by following the instructions in the &amp;ldquo;Invitation To Comment&amp;rdquo; part of the &amp;ldquo;Supplementary Information&amp;rdquo; section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;strong&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;NOTE:&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt; The Commission issues an administrative complaint when it has &amp;ldquo;reason to believe&amp;rdquo; that the law has been or is being violated, and it appears to the Commission that a proceeding is in the public interest. The complaint is not a finding or ruling that the respondent has actually violated the law. A consent order is for settlement purposes only and does not constitute an admission by the respondent that the law has been violated. When the Commission issues a consent order on a final basis, it carries the force of law with respect to future actions. Each violation of such an order may result in a civil penalty of up to $16,000.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
12.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;The Federal Trade Commission works for consumers to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them. To file a complaint in English or Spanish, visit the FTC's online &lt;a href="https://www.ftccomplaintassistant.gov/"&gt;&lt;span style="color:
#006699;text-decoration:none;text-underline:none"&gt;Complaint Assistant&lt;/span&gt;&lt;/a&gt; or call 1-877-FTC-HELP (1-877-382-4357). The FTC enters complaints into Consumer Sentinel, a secure, online database available to more than 2,000 civil and criminal law enforcement agencies in the U.S. and abroad. The FTC&amp;rsquo;s website provides &lt;a href="http://www.ftc.gov/consumer"&gt;&lt;span style="color:#006699;
text-decoration:none;text-underline:none"&gt;free information on a variety of consumer topics&lt;/span&gt;&lt;/a&gt;. Like the FTC on &lt;a href="http://www.ftc.gov/leaving/facebook/index.shtml"&gt;&lt;span style="color:#006699;
text-decoration:none;text-underline:none"&gt;Facebook&lt;/span&gt;&lt;/a&gt;, follow us on &lt;a href="http://www.ftc.gov/leaving/twitter/index.shtml"&gt;&lt;span style="color:#006699;
text-decoration:none;text-underline:none"&gt;Twitter&lt;/span&gt;&lt;/a&gt;, and &lt;a href="https://www.ftc.gov/opa/subscribe.shtm#pr"&gt;&lt;span style="color:#006699;
text-decoration:none;text-underline:none"&gt;subscribe to press releases&lt;/span&gt;&lt;/a&gt; for the latest FTC news and resources.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
6.0pt;margin-left:0in;line-height:120%;background:white"&gt;&lt;b&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;MEDIA CONTACT: &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin-top:0in;margin-right:0in;margin-bottom:3.0pt;
margin-left:.5in;line-height:120%;background:white"&gt;&lt;em&gt;&lt;span style="font-size:
9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;Office of Public Affairs&lt;/span&gt;&lt;/em&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;&lt;br /&gt;
202-326-2180 &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin-top:12.0pt;margin-right:0in;margin-bottom:
6.0pt;margin-left:.5in;line-height:120%;background:white"&gt;&lt;b&gt;&lt;span style="font-size:9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;STAFF CONTACT: &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin-top:0in;margin-right:0in;margin-bottom:3.0pt;
margin-left:.5in;line-height:120%;background:white"&gt;&lt;span style="font-size:
9.0pt;line-height:120%;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;Kate White&lt;br /&gt;
Bureau of Consumer Protection&lt;br /&gt;
202-326-2878&lt;/span&gt;&lt;/p&gt;
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/JDihf7CIJUY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/JDihf7CIJUY/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/12/articles/privacy-rights/ftc-history-sniffing-settlement-meaningless-or-the-start-of-something-bigger/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Epic Marketplace</category><category domain="http://dataprivacy.foxrothschild.com/">FTC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/articles">Privacy Policy</category><category domain="http://dataprivacy.foxrothschild.com/articles">Privacy Rights</category><category domain="http://dataprivacy.foxrothschild.com/tags">federal trade commission</category>
         <pubDate>Thu, 06 Dec 2012 09:49:59 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/12/articles/privacy-rights/ftc-history-sniffing-settlement-meaningless-or-the-start-of-something-bigger/</feedburner:origLink></item>
            <item>
         <title>Podcast: An Overview of P2P Data Breaches</title>
         <description>&lt;p&gt;&lt;a href="http://www.foxrothschild.com/attorneys/john-gotaskie.html"&gt;John R. Gotaskie&lt;/a&gt;, Partner in Fox Rothschild's &lt;a href="http://www.foxrothschild.com/practiceareas/litigation/index.html"&gt;Litigation Practice&lt;/a&gt; and editor of the firm's &lt;a href="http://franchiselaw.foxrothschild.com/"&gt;Franchise Law Update&lt;/a&gt; blog, recently published a &lt;a href="http://www.foxrothschild.com/WorkArea/DownloadAsset.aspx?id=15032387896"&gt;podcast&lt;/a&gt; discussing the growing concern over data breaches involving peer-to-peer networks. Using the recent example of Franklin Toyota, a Georgia car dealership that was hit with a breach, as his backdrop, John discusses how companies can steer clear of running afoul of the law and comply with federal regulations.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.foxrothschild.com/WorkArea/DownloadAsset.aspx?id=15032387896"&gt;Click here&lt;/a&gt; to listen to the podcast.  If you prefer to download the transcript, &lt;a href="http://www.foxrothschild.com/WorkArea/DownloadAsset.aspx?id=15032387850"&gt;click here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For additional material on the subject, please see John's article &amp;quot;&lt;a href="http://www.foxrothschild.com/newspubs/newspubsArticle.aspx?id=15032387493"&gt;User Beware: Data Breaches Involving Peer-to-Peer Networks May Result in FTC Enforcement Action&lt;/a&gt;&amp;quot; from the &lt;em&gt;Banking &amp;amp; Financial Services Policy Report&lt;/em&gt;, and visit our &lt;a href="http://www.foxrothschild.com/practiceareas/media/index.html"&gt;practice's page&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/v5GgjnB_VW8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/v5GgjnB_VW8/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/12/articles/podcast-an-overview-of-p2p-data-breaches/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/">Articles</category>
         <pubDate>Wed, 05 Dec 2012 09:10:03 -0500</pubDate>
         <dc:creator>John Witts</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/12/articles/podcast-an-overview-of-p2p-data-breaches/</feedburner:origLink></item>
            <item>
         <title>Hacking and Reading Someone's Online Email Just Got Easier in South Carolina</title>
         <description>&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Earlier this week the South Carolina Supreme Court ruled that accessing another person&amp;rsquo;s online (personal) email is not a violation of the federal Stored Communications Act (the &lt;a href="http://www.law.cornell.edu/uscode/text/18/part-I/chapter-121"&gt;Act&lt;/a&gt; and the &lt;a href="http://en.wikipedia.org/wiki/Stored_Communications_Act"&gt;Wikipedia summary&lt;/a&gt;).&amp;nbsp;This holding is in direct opposition to what the Ninth Circuit Court of Appeals held in 2004 in &lt;a href="http://ftp.resource.org/courts.gov/c/F3/359/359.F3d.1066.02-15742.03-15301.html"&gt;&lt;i&gt;Theofel v. Farey-Jones&lt;/i&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;At the outset you should keep in mind that this is a civil case, which differs from a criminal case.&amp;nbsp;In this post we are looking at solely the Stored Communications Act (&amp;ldquo;SCA&amp;rdquo;), and a limited aspect thereof.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Facts of This Case&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The facts of this case, &lt;a href="http://www.judicial.state.sc.us/opinions/HTMLFiles/SC/27177.pdf"&gt;&lt;em&gt;Jennings v. Jennings&lt;/em&gt;&lt;/a&gt; (PDF link) are actually pretty surprising, considering the outcome.&amp;nbsp;A wife suspected that her husband was carrying on an affair.&amp;nbsp;The daughter-in-law, with more free time than common sense, could not resist inserting herself into the situation and accessed the husband&amp;rsquo;s Yahoo! account by guessing his secret questions.&amp;nbsp;Soon thereafter emails between the husband and the girlfriend were found and became what divorce attorneys refer to as &amp;ldquo;leverage.&amp;rdquo;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The husband would have none of this, and brought several causes of action against the soon-to-be ex-wife, her attorney and his private investigator, including the SCA.&amp;nbsp;The lower court dismissed all counts against the defendants, the appeals court overturned the lower court decision with respect to violations of the SCA, and the Supreme Court of South Carolina took up the appeal.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The court focused on the definition of &amp;ldquo;electronic storage&amp;rdquo; under the SCA: &lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; margin: 0in 0in 0pt 55.5pt; line-height: normal; text-indent: -19.5pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;(A)&amp;nbsp;&lt;/span&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;any temporary, intermediate storage of a wire or electronic communication incidental to the electronic transmission thereof; and&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; margin: 0in 0in 0pt 55.5pt; line-height: normal; text-indent: -19.5pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;(B)&lt;span style="font: 7pt/normal &amp;quot;Times New Roman&amp;quot;; font-size-adjust: none; font-stretch: normal;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;any storage of such communication by an electronic communication service for purposes of backup protection of such communication.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The justices advanced two theories in arriving at the same conclusion.&amp;nbsp;On the one hand, some justices held that because the husband did not download any copies of the email (he read and left the &amp;ldquo;original&amp;rdquo; copy on Yahoo&amp;rsquo;s servers), the second component of the definition was not satisfied.&amp;nbsp;They wanted to see two copies of the same email, and storing the email on the server was not the intended &amp;ldquo;backup&amp;rdquo; under the SCA.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The one other justice read an &amp;ldquo;or&amp;rdquo; between (A) and (B) of the definition, concluded that transmission of the email for viewing was not sufficient storage, and otherwise held that there was no backup of the email.&amp;nbsp;These facts satisfied neither (A) nor (B).&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Now I am Confused&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;This decision leaves an obvious split in the courts with respect to the SCA, which should be addressed by amending the legislation or by the United States Supreme Court.&amp;nbsp;&lt;a href="http://www.arstechnica.com"&gt;Ars Technica&lt;/a&gt; has an excellent article &lt;a href="http://arstechnica.com/tech-policy/2012/10/reading-someones-gmail-doesnt-violate-federal-statute-court-finds/"&gt;here&lt;/a&gt; discussing the case in more detail and offering more insight into how to correct this split. The article is a great read if this topic is of interest to you.&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Unfortunately, there are no clear answers and accessing another person&amp;rsquo;s email remains a very, very dangerous activity.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;How Relevant to You&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Why does this matter for your business?&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO: &amp;nbsp;We just let Johnson go, and I think he uploaded trade secrets to his personal email.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;General Counsel:&amp;nbsp;We need some reasonable basis to accuse Johnson of this.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO:&amp;nbsp;I don&amp;rsquo;t know why I hired you.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;i&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;(Calling the IT guy)&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO:&amp;nbsp;Bill, give me Johnson&amp;rsquo;s computer password.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Bill:&amp;nbsp;It is iLovePonies44.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;i&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;(CEO accesses the machine, finds that Johnson is still logged into Gmail, finds evidence that trade secrets were uploaded by Johnson to his personal email account.&amp;nbsp;CEO calls the General Counsel.)&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO:&amp;nbsp;Ted, I caught Johnson red-handed.&amp;nbsp;Johnson sent emails with our customer lists and contact information to his personal email account.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;General Counsel:&amp;nbsp;Unbelievable.&amp;nbsp;How did you find out?&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO:&amp;nbsp;He left his Gmail open on his work computer.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;General Counsel:&amp;nbsp;I don&amp;rsquo;t think you can read his personal email.&amp;nbsp;Let me check with outside counsel.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Outside Counsel:&amp;nbsp;It is dangerous and may violate federal law.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt; margin-left: 40px;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;CEO:&amp;nbsp;You are both fired.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;The South Carolina decision throws some doubt on the above conclusion, and on some level these hypothetical facts are not as nefarious as the Johnson case because there was no password guessing/hacking.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&lt;span style="color: rgb(38, 48, 52); font-size: 12pt;"&gt;Before, if an employee had downloaded mail to a mail client resident on her computer (&lt;i&gt;e.g.&lt;/i&gt;, POP3 or IMAP), the issue was much clearer because the correspondence was deemed abandoned (it was not a complete green light, but things looked better for the non-account owner).&amp;nbsp;Webmail, by definition, completely changes the above analysis (or so we thought).&amp;nbsp;The information is stored on the mail provider&amp;rsquo;s servers, always accessible and never downloaded unless a mail client is used.&lt;/span&gt;&lt;/p&gt;
&lt;p style="background: white; line-height: normal; margin-bottom: 0pt;"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: rgb(38, 48, 52); line-height: 115%; font-size: 12pt;"&gt;This decision should not be viewed as the only obstacle to accessing an employee&amp;rsquo;s personal email.&amp;nbsp;Putting the ethical issues aside, there are many laws lurking for the unwary.&amp;nbsp;The point really is that the SCA is a bit of a mess in this regard, and like many laws touching the online world is in need of some freshening up to deal with current technology.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/Ex9A3oWUiXs" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/Ex9A3oWUiXs/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/10/articles/privacy-rights/hacking-and-reading-someones-online-email-just-got-easier-in-south-carolina/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Personal Email</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/articles">Privacy Rights</category><category domain="http://dataprivacy.foxrothschild.com/tags">Security Questions</category><category domain="http://dataprivacy.foxrothschild.com/tags">Stored Communications Act</category>
         <pubDate>Fri, 12 Oct 2012 07:03:46 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/10/articles/privacy-rights/hacking-and-reading-someones-online-email-just-got-easier-in-south-carolina/</feedburner:origLink></item>
            <item>
         <title>Website Operators With U.K. Directed Websites or Web Pages Now Subject to "Cookie Law"</title>
         <description>&lt;p&gt;In its continuing efforts to give the State of California a run for its money when it comes to privacy rights, the United Kingdom&amp;rsquo;s &amp;ldquo;cookie law&amp;rdquo; is now in effect. Websites for European companies with European visitors, or non-European companies that are directed at European users, must now inform users of any tracking technology used on the website, and the purpose of the use of that tracking technology. &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;The Law&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The new law is part of the European Union's &amp;quot;e-Privacy&amp;quot; Directive.  Implementation of the e-Privacy Directive requires that each member state incorporate the e-Privacy Directive into its own law in 2011. The United Kingdom accomplished the foregoing by creating the amended Privacy and Electronic Communication Regulations (PECR) Act 2011, which became effective on May 26, 2011.  The disclosure of the use of user tracking technology is only one element of PECR.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Types of Tracking Technology&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The use of cookies on a website is only one practice covered by the cookie law. Uses of advertising tracking and analytics, for example are covered practices.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected Businesses&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
If you have only a U.S.-based web site, with no web page directed explicitly at the United Kingdom, then the cookie law should not affect you. However, if you have a website or web page directed specifically to residents of the United Kingdom, you almost certainly are subject to the cookie law.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Opt-Out or Opt-In&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Good question. Originally the cookie law was interpreted to mean that a user must explicitly opt-in to the tracking technology. However, just before the cookie law went into effect the Information Commissioner's Office (&amp;ldquo;ICO&amp;rdquo;), the United Kingdom&amp;rsquo;s data protection agency, updated its guidance to say that &amp;ldquo;implied consent&amp;rdquo; was acceptable, and that continued use of the subject website would meet the consent requirement.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Compliance Deadline&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The cookie law is currently in effect, but it is no secret that many, many organizations are not currently in compliance. Those websites that are in compliance with the cookie law will present users with a dialogue similar to this:&lt;/p&gt;
&lt;p&gt;&lt;img width="318" height="225" src="http://dataprivacy.foxrothschild.com/uploads/image/cookies(1).jpg" alt="" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Mobile Applications&lt;br /&gt;
&lt;/strong&gt;&lt;br /&gt;
Just to keep things interesting, the cookie law applies to mobile applications as well. Because mobile applications have just as many, if not more, opportunities for user tracking, and because that user tracking is not always obvious, it &lt;a href="http://www.computing.co.uk/ctg/news/2175933/android-ios-apps-subject-eu-privacy-regulations-ico"&gt;has already been made clear&lt;/a&gt; that the ICO will pay particular attention to mobile application compliance&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
Penalties&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The ICO has the authority to fine non-compliant organizations up to $780,000 (or 500,000 pounds) for not complying with the cookie law. Fortunately, the ICO is not going to be in a big rush to penalize non-compliant organizations and, instead, is focusing on educating companies regarding compliance requirements.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/xokhjMC-NNI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/xokhjMC-NNI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/05/articles/european-union/website-operators-with-uk-directed-websites-or-web-pages-now-subject-to-cookie-law/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Cookie law</category><category domain="http://dataprivacy.foxrothschild.com/articles">European Union</category><category domain="http://dataprivacy.foxrothschild.com/tags">Information Commissioner</category><category domain="http://dataprivacy.foxrothschild.com/tags">Office'</category><category domain="http://dataprivacy.foxrothschild.com/tags">PERC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy and Electronic Communication Regulations</category><category domain="http://dataprivacy.foxrothschild.com/tags">e-Privacy Directive</category><category domain="http://dataprivacy.foxrothschild.com/tags">s</category>
         <pubDate>Wed, 30 May 2012 13:36:12 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/05/articles/european-union/website-operators-with-uk-directed-websites-or-web-pages-now-subject-to-cookie-law/</feedburner:origLink></item>
            <item>
         <title>Vernick on Cyber Security in the Huffington Post</title>
         <description>&lt;p&gt;The FBI reports that cyberattacks could overtake terrorism as the major threat to the country.&amp;nbsp;&lt;a href="http://www.nytimes.com/2012/03/14/us/new-interest-in-hacking-as-threat-to-us-security.html"&gt;According to the Department of Homeland Security&lt;/a&gt;, between October 2011 and February 2012, there were 86 reported attacks on U.S. computer systems that control critical infrastructure, factories and databases, compared with 11 over the same period a year ago.&lt;/p&gt;
&lt;p&gt;Now more than ever, the focus should be on securing and insulating our nation's computer and Internet infrastructure from both internal and external attacks. The first step in anticipating large-scale cyberattacks is to start thinking of them more like the proverbial disaster waiting to happen -- not a question of if, but when. Planning requires going beyond the limitations of current thinking and considering worst case scenarios.&lt;/p&gt;
&lt;p&gt;To keep reading my full article visit &amp;ldquo;&lt;a href="http://www.huffingtonpost.com/scott-vernick/internet-privacy-debate_b_1447355.html"&gt;The Internet Privacy Debate Misses the Point&lt;/a&gt;,&amp;rdquo; published April 23 by the&amp;nbsp;&lt;i&gt;Huffington Post&lt;b&gt;.&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/zmp6JVQsSms" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/zmp6JVQsSms/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/04/articles/vernick-on-cyber-security-in-the-huffington-post/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/">Articles</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category>
         <pubDate>Tue, 24 Apr 2012 10:11:48 -0500</pubDate>
         <dc:creator>Scott L. Vernick</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/04/articles/vernick-on-cyber-security-in-the-huffington-post/</feedburner:origLink></item>
            <item>
         <title>An Example of the Right Way to Handle a Data Breach: Motorola Xoom</title>
         <description>&lt;p&gt;You may have read that &lt;a href="http://mediacenter.motorola.com/Press-Releases/Motorola-Mobility-Notifies-Certain-Purchasers-of-Refurbished-Motorola-XOOM-Wi-Fi-Tablets-of-Refurbishment-Process-Error-39d6.aspx"&gt;Motorola announced&lt;/a&gt; on February 3rd that it inadvertently sold around 100 refurbished &lt;a href="http://www.motorola.com/Consumers/US-EN/Consumer-Product-and-Services/Tablets/MOTOROLA-XOOM-with-WiFi-US-EN"&gt;Motorola Xoom tablets&lt;/a&gt; through &lt;a href="http://www.woot.com"&gt;Woot.com&lt;/a&gt; without putting the tablets through the typical process of doing a factory reset and wiping any personal data that may have been left by the original owner(s). &amp;nbsp;Specifically, there were approximately 6,200 tablets sold between October and December 2011, of which 100 tablets were affected.&lt;/p&gt;
&lt;p&gt;The announcement was interesting in and of itself because it highlighted the notification obligation that arose even though Motorola (likely) had no actual knowledge that refurbished tablets went out that actually contained data. &amp;nbsp;Apparently, Motorola only knew that there was a breakdown in its internal processes and some 100 tablets were not wiped, possibly resulting in the resale of some tablets with data not erased by a customer prior to returning the tablet.&lt;/p&gt;
&lt;p&gt;Purchasers of the 6,200 tablets through Woot.com were notified by email to go to a Motorola web site and type in the serial number (or some similar identifier), at which point you would be told if your tablet was affected. &amp;nbsp;If your tablet was affected, Motorola asked that you agree to part with your tablet for four to five business days so that it could be factory wiped.&lt;/p&gt;
&lt;p&gt;As to turns out, I owned one of the 100 tablets affected. &amp;nbsp;I never win anything, except the Affected Xoom Tablet Lottery. &amp;nbsp;A day or so later a package with easy-to-follow instructions, very protective packaging and a prepaid envelope arrived at my work. &amp;nbsp;In went the tablet, out went the package. &amp;nbsp;On the fourth business day the tablet was returned in working order with a thank you and restore instructions.&lt;/p&gt;
&lt;p&gt;And an American Express gift card for $100!!!&lt;/p&gt;
&lt;p&gt;Did I have to return the tablet for a factory wipe? &amp;nbsp;No. &amp;nbsp;Was it a burden for me to return the tablet? &amp;nbsp;Hardly. &amp;nbsp;Was I impressed by Motorola giving me a gift card? &amp;nbsp;Damn right I was, and that is my point. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;As someone that deals with data breaches, and clients that have to make tough decisions regarding data breaches, on an almost daily basis, this situation struck me. &amp;nbsp;Motorola did the right thing, went above and beyond what was required, and solidified good will with me. &amp;nbsp;I was not even the party with the affected data. &amp;nbsp;I was just the guy that got the great deal on Woot.com for a refurbished tablet.&lt;/p&gt;
&lt;p&gt;That Droid Bionic MAXX suddenly is even more appealing to me. &amp;nbsp;Motorola is suddenly more appealing to me (not that I had any particular problem with them before).&lt;/p&gt;
&lt;p&gt;It is possible that Woot.com gave me the gift card, and for that reason my patronage to Woot.com also has been strengthened. &amp;nbsp;This is a great example of partners working together to deal with data breach situations. &amp;nbsp;Making the best of a difficult situation, and earning some good will along the way.&lt;/p&gt;
&lt;p&gt;Kudos to Motorola and Woot.com for their handling of this situation.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/D2xQM3vsamI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/D2xQM3vsamI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/02/articles/data-security-breach-response/an-example-of-the-right-way-to-handle-a-data-breach-motorola-xoom/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category>
         <pubDate>Tue, 14 Feb 2012 19:24:08 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/02/articles/data-security-breach-response/an-example-of-the-right-way-to-handle-a-data-breach-motorola-xoom/</feedburner:origLink></item>
            <item>
         <title>Data Breach Potentially Affects Up to 100,000 Students, 3,000 Employees</title>
         <description>&lt;p&gt;&amp;nbsp;The San Francisco Chronicle &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/13/MN4Q1MO9JK.DTL&amp;amp;type=education"&gt;reported yesterday&lt;/a&gt; that officials at the City College of San Francisco discovered a few days after Thanksgiving 2010 that certain&amp;nbsp;computers of the college have been&amp;nbsp;infested with active malware for more than a decade. &amp;nbsp;Up to 100,000 students and 3,000 employees could be affected, and that number may rise based on further, ongoing investigation.&lt;/p&gt;
&lt;p&gt;The problem was detected when the college's data security monitoring service discovered very high traffic and alerted the college. &amp;nbsp;Initially thought to be limited to one computer lab (Cloud Hall at the Phelan Avenue campus), further investigated revealed that the problem was more widespread. &amp;nbsp;The San Francisco Chronicle's &lt;a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2012/01/13/MN4Q1MO9JK.DTL&amp;amp;type=education"&gt;article&lt;/a&gt; reported:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Each night at about 10 p.m., at least seven viruses begin trolling the college networks and transmitting data to sites in Russia, China and at least eight other countries, including Iran and the United States, Hotchkiss and his team discovered. Servers and desktops have been infected across the college district's administrative, instructional and wireless networks. It's likely that personal computers belonging to anyone who used a flash drive during the past decade to carry information home were also affected.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Investigation continues to determine which other computer networks at the college may have been infected, such as accounting, admissions and/or payroll systems. &amp;nbsp;Apparently, 17 different computer systems are presently being analyzed. &amp;nbsp;The college's server with medical information appears to be unaffected, although it is unclear whether any other system may also contain medical information (such as the admissions system).&lt;/p&gt;
&lt;p&gt;The good news, besides that the college notified those potentially affected in what most would agree was a prompt timeframe, is that there are no known cases of identity theft originating from this extremely lengthy data breach.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/NzjsSw9bvy4" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/NzjsSw9bvy4/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/data-breach-potentially-affects-up-to-100000-students-3000-employees/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">City College of Francisco</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Hacking</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Sat, 14 Jan 2012 08:27:28 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/data-breach-potentially-affects-up-to-100000-students-3000-employees/</feedburner:origLink></item>
            <item>
         <title>Personal Information Data Breaches - Not if, but When?</title>
         <description>&lt;p&gt;&lt;strong&gt;By &lt;/strong&gt;&lt;a href="http://www.foxrothschild.com/attorneys/bioDisplay.aspx?id=3640"&gt;&lt;strong&gt;Elizabeth Litten&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www.nytimes.com/2011/12/26/technology/hackers-breach-the-web-site-of-stratfor-global-intelligence.html?_r=1 "&gt;widely publicized&lt;/a&gt; pre-Christmas breach of confidential data held by Stratfor Global Intelligence Service (&amp;ldquo;Stratfor&amp;rdquo;), a company specializing in data security, reminded me that very little (if any) electronic information is truly secure.&amp;nbsp;If Stratfor&amp;rsquo;s data can be hacked into, and the health information of nearly 5 million military health plan (TRICARE) members maintained by multi-billion dollar Department of Defense contractor Science Applications International Corporation (SAIC) (the subject of a five-part series of blog postings found on&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/"&gt;&lt;span&gt;Fox Rothschild&amp;rsquo;s HIPAA, HITECH and HIT Blog&lt;/span&gt;&lt;/a&gt;.&amp;nbsp;Parts&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-with-some-words-on-the-nemours-phi-breach-part-1/"&gt;1&lt;/a&gt;,&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-part-2/"&gt;2&lt;/a&gt;,&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/10/articles/breaches/saic-and-its-military-millions-march-flooding-the-parade-with-possible-phi-breaches-part-3/"&gt;3&lt;/a&gt;,&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/11/articles/breaches/did-tricaredod-make-a-proactive-response-or-a-preemptive-strike-with-saic-in-the-phi-breach-matter-whose-risk-is-it-anyway-part-4/"&gt;4&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/12/articles/breaches/congressional-inquiry-or-autopsy-for-saic-breach-disaster-part-5/"&gt;5&lt;/a&gt;  ) can be accessed, can we trust that any electronically transmitted or stored information is really safe?&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I had the pleasure of having lunch with my friend Al yesterday, an IT guru who has worked in hospitals for years.&amp;nbsp;Al understands and appreciates the need for privacy and security of information, and has the technological expertise to know where and how data can be hacked into or leaked out.&amp;nbsp;Perhaps not surprisingly, Al does not do his banking on-line, and tries to avoid making on-line credit card purchases.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Al and I discussed the proliferation of the use of iPhones and other mobile technology by physicians and staff in hospitals and other settings, a topic recently discussed in a &lt;a href="http://www.ama-assn.org/amednews/2011/12/19/bil21219.htm "&gt;newsletter&lt;/a&gt; published by the American Medical Association.&amp;nbsp;Quick access to a patient&amp;rsquo;s electronic health record (EHR) is convenient and may even be life-saving in some circumstances, but use of these mobile devices creates additional portals for access to personal information that should be protected and secured.&amp;nbsp;Encryption technology and, perhaps most significantly, use of this technology, barely keeps pace with the exponential rate at which we are creating and/or transmitting data electronically.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;On the other hand, trying to reverse the exponential growth of electronic communications and transactions would be futile and probably counter-productive.&amp;nbsp;The horse is out of the gate, and expecting it to stop mid-stride and retreat back with a false-start call is irrational.&amp;nbsp;The horse will race ahead just as surely as my daughter will text and check her Facebook page, my son will recharge his iPad, and I will turn around and head back to my office if I forget my iPhone.&amp;nbsp;We want and need technology, but seem to forget or fail to fully understand the vast, unprotected and ever-expanding universe into which we send information when we use this technology.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If we expect breaches or, at least, question our assumptions that personal information will be protected, perhaps we will get better at discerning how and when we disclose our personal information.&amp;nbsp;An in-person conversation or transaction (for example, when Al goes to his bank in person or when a physician speaks directly to another physician about a patient&amp;rsquo;s care) is less likely to be accessed and used inappropriately than an electronic one.&amp;nbsp;We can better assess the risks and benefits of communicating information electronically when we appreciate the security frailties inherent in electronic communication and storage.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Perhaps Congress should take the lead in enacting laws that will help protect against data breaches that could compromise &amp;ldquo;critical infrastructure systems&amp;rdquo;&amp;nbsp;(as proposed in the &amp;ldquo;&lt;a href="http://homeland.house.gov/sites/homeland.house.gov/files/Cybersecurity.pdf"&gt;PRECISE Act&lt;/a&gt;&amp;rdquo; introduced by Rep. Daniel E. Lungren (R-CA)), but more comprehensive, potentially expensive, and/or use-impeding cybersecurity laws might have the effect of tripping the racehorse mid-lap rather than controlling its pace or keeping it safely on course.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/YkRkXzz0VJI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/YkRkXzz0VJI/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/personal-information-data-breaches-not-if-but-when/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Department of Defense</category><category domain="http://dataprivacy.foxrothschild.com/tags">DoD</category><category domain="http://dataprivacy.foxrothschild.com/tags">EHR</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI</category><category domain="http://dataprivacy.foxrothschild.com/tags">PHI security breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">PRECISE Act</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy &amp; Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Rep. Daniel E. Lungren, SAIC</category><category domain="http://dataprivacy.foxrothschild.com/tags">Science Applications International Corporation</category><category domain="http://dataprivacy.foxrothschild.com/tags">Stratfor Global Intelligence Service</category><category domain="http://dataprivacy.foxrothschild.com/tags">Tricare</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category><category domain="http://dataprivacy.foxrothschild.com/tags">electronic health record</category><category domain="http://dataprivacy.foxrothschild.com/tags">protected health information</category>
         <pubDate>Tue, 03 Jan 2012 16:29:57 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2012/01/articles/data-security-breach-response/personal-information-data-breaches-not-if-but-when/</feedburner:origLink></item>
            <item>
         <title>2011 Data Breach Summary</title>
         <description>&lt;p&gt;&lt;a href="http://blogs.smartmoney.com/paydirt/2011/12/28/the-top-5-data-breaches-of-2011/?mod=rss_&amp;amp;link=SM_home_blogsum"&gt;Smart Money&lt;/a&gt; just ran a story about the top five data breaches of 2011. &amp;nbsp;While I do not necessarily agree that these are the top five (&lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/"&gt;students&lt;/a&gt;, &lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/"&gt;students&lt;/a&gt;,&lt;a href="http://dataprivacy.foxrothschild.com/2011/03/articles/data-theft/health-data-for-17-million-nyc-hospital-patients-staff-and-others-at-risk/"&gt; NYC hospital patients&lt;/a&gt;, not to mention the Stratfor breach), the takeaway is interesting: none of them have the same source for the breach:&lt;/p&gt;
&lt;p&gt;1. &amp;nbsp;Epsilon. &amp;nbsp;What more needs to be said to keep contract attorneys up at night than &amp;quot;Epsilon&amp;quot;? &amp;nbsp;This &lt;a href="http://www.cioinsight.com/c/a/Security/Breach-Notification-Time-for-a-Wake-Up-Call-581657/"&gt;data breach&lt;/a&gt; involved a third party losing data about its customers' customers. &amp;nbsp;Stated another way, the owner of the information did nothing wrong...other than hiring a contractor that mishandled information. &amp;nbsp;Indemnification mean more to you now? &amp;nbsp;The takeaway from this breach: come clean, come clean, come clean. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;2. &amp;nbsp;Sony. &amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2011/04/articles/data-security-breach-response/sony-hit-by-data-breach-affecting-77-million-gamers/"&gt;Massive breach&lt;/a&gt; of the online gaming network. &amp;nbsp;Lots of data lost, lots of downtime for pasty, sun-adverse gamers. &amp;nbsp;Hackers targeting the network to blame. &amp;nbsp;The takeaway from this breach: do not handle it the way Sony handled it.&lt;/p&gt;
&lt;p&gt;3. &amp;nbsp;Tricare. &amp;nbsp;A Science Applications International Corp. has data backup tapes stolen from a car. &amp;nbsp;SAIC is a defense contractor for the military. &amp;nbsp;Approximately &lt;a href="http://hipaahealthlaw.foxrothschild.com/2011/12/articles/breaches/congressional-inquiry-or-autopsy-for-saic-breach-disaster-part-5/"&gt;4.9 million veterans affected&lt;/a&gt;. &amp;nbsp;Hackers targeting lax security to blame. &amp;nbsp;The takeaway from this breach: don't leave the data tapes in the car (come on, people!).&lt;/p&gt;
&lt;p&gt;4. &amp;nbsp;Sutter. &amp;nbsp;A simple stolen desktop computer containing information about possibly 3.3 million patients goes missing. &amp;nbsp;The takeaway from this breach: encrypt! &amp;nbsp;Chances are they had zero intention to stealing the actual information, but you can be sure it was still a breach notification scenario.&lt;/p&gt;
&lt;p&gt;5. &amp;nbsp;Texas Comptroller. &amp;nbsp;This is number three in my book. &amp;nbsp;Personal information of 3.5 million people left publicly available for over one year. &amp;nbsp;Information about persons required to hand over that information, not information voluntarily handed over. &amp;nbsp;Total disaster. &amp;nbsp;Anyone could have found this information, given its availability. &amp;nbsp;The takeaway from this breach: hire IT staff that is security conscious and, more importantly, give those people the budget to do their jobs.&lt;/p&gt;
&lt;p&gt;BONUS: not a data breach, but a significant ruling this year. &amp;nbsp;Corporations have no right to privacy. &amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2011/03/articles/right-to-privacy/supreme-court-tells-att-it-has-no-right-to-privacy/"&gt;This Supreme Court ruling&lt;/a&gt; impacts corporate decisions on so many levels...or it should.&lt;/p&gt;
&lt;p&gt;Happy New Year to our readers.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/50-2E1Mi4zE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/50-2E1Mi4zE/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/12/articles/data-security-breach-response/2011-data-breach-summary/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Data Security Breach Response</category><category domain="http://dataprivacy.foxrothschild.com/tags">Epsilon</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Sony</category><category domain="http://dataprivacy.foxrothschild.com/tags">Sutter</category><category domain="http://dataprivacy.foxrothschild.com/tags">Texas Comptroller</category><category domain="http://dataprivacy.foxrothschild.com/tags">Tricare</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Wed, 28 Dec 2011 18:30:33 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/12/articles/data-security-breach-response/2011-data-breach-summary/</feedburner:origLink></item>
            <item>
         <title>FTC Settles With Facebook, Agrees to Whopping 20-Year Consent Order</title>
         <description>&lt;p&gt;According to a &lt;a href="http://ftc.gov/opa/2011/11/privacysettlement.shtm"&gt;press release&lt;/a&gt; issued yesterday, November 29, 2011, by the Federal Trade Commission, Facebook settled charges that Facebook &amp;ldquo;deceived consumers by telling them they could keep their information on Facebook private, and then repeatedly allowing it to be shared and made public.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://ftc.gov/os/caselist/0923184/111129facebookcmpt.pdf"&gt;complaint&lt;/a&gt; (PDF link) lists a litany of bad practices by Facebook. One allegation that stands out, largely because of the media firestorm that it created at the time, was Facebook&amp;rsquo;s change in privacy settings to users&amp;rsquo; accounts in December 2009. The foregoing settings change was, in the FTC&amp;rsquo;s opinion, particularly egregious because Facebook undertook the changes without any notice or consent from users.&lt;/p&gt;
&lt;p&gt;Another allegation that stands out, again both because&amp;nbsp;of the media firestorm and the falsehood, was Facebook&amp;rsquo;s assertion that information from deactivated user accounts would not be accessible.&lt;/p&gt;
&lt;p&gt;And what grueling punishment must Facebook endure for its privacy-related bad acts? According to Jon Leibowitz, Chairman of the FTC, &amp;quot;Facebook is obligated to keep the promises about privacy that it makes to its hundreds of millions of users.&amp;quot; Rough justice.&lt;/p&gt;
&lt;p&gt;In all seriousness, there is some substance to the settlement. Facebook must not make any further deceptive privacy claims. Facebook must also get consumers' approval before it changes the way it shares their data. Finally, Facebook must obtain periodic assessments of its privacy practices by independent, third-party auditors for the next 20 years.&lt;/p&gt;
&lt;p&gt;Frankly, the foregoing requirements on Facebook are all steps that a company like Facebook, if not substantially all companies handling consumer personal information, should be undertaking.&lt;/p&gt;
&lt;p&gt;Specifically, under the proposed settlement, Facebook is:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;barred from making misrepresentations about the privacy or security of consumers' personal information;&lt;/li&gt;
    &lt;li&gt;required to obtain consumers' affirmative express consent before enacting changes that override their privacy preferences;&lt;/li&gt;
    &lt;li&gt;required to prevent anyone from accessing a user's material more than 30 days after the user has deleted his or her account;&lt;/li&gt;
    &lt;li&gt;required to establish and maintain a comprehensive privacy program designed to address privacy risks associated with the development and management of new and existing products and services, and to protect the privacy and confidentiality of consumers' information; and&lt;/li&gt;
    &lt;li&gt;required, within 180 days, and every two years after that for the next 20 years, to obtain independent, third-party audits certifying that it has a privacy program in place that meets or exceeds the requirements of the FTC order, and to ensure that the privacy of consumers' information is protected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The proposed order also contains standard record-keeping provisions to allow the FTC to monitor compliance with its order.&lt;/p&gt;
&lt;p&gt;The proposed settlement is not yet final. The proposed settlement will be open to public comment for thirty days, ending on December 30, 2011. The terms of the proposed settlement is published in the Federal Register shortly. After the close of the comment period, the FTC will decide whether to make the proposed consent order final.&lt;/p&gt;
&lt;p&gt;Interested in submitting your comments to the FTC? According to the &lt;a href="http://ftc.gov/opa/2011/11/privacysettlement.shtm"&gt;press release&lt;/a&gt;: Interested parties can submit comments online or in paper form by following the instructions in the &amp;quot;Invitation To Comment&amp;quot; part of the &amp;quot;Supplementary Information&amp;quot; section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/OLgMUvaHMws" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/OLgMUvaHMws/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/11/ftc-1/ftc-settles-with-facebook-agrees-to-whopping-20year-consent-order/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/">FTC</category><category domain="http://dataprivacy.foxrothschild.com/articles">Facebook</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">federal trade commission</category>
         <pubDate>Wed, 30 Nov 2011 06:52:38 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/11/ftc-1/ftc-settles-with-facebook-agrees-to-whopping-20year-consent-order/</feedburner:origLink></item>
            <item>
         <title>Comparison of Major Carriers' Retention of Mobile Device Usage</title>
         <description>&lt;p&gt;The Computer Crime and Intellectual Property Section of the U.S. Department of Justice compiled a summary in August 2010&amp;nbsp;of the retention periods of major cellular service providers of data transmitted to and from users' mobile devices.&amp;nbsp; The report is &lt;a href="http://www.wired.com/images_blogs/threatlevel/2011/09/retentionpolicy.pdf"&gt;here&lt;/a&gt;. (PDF&amp;nbsp;link)&amp;nbsp; The American Civil Liberties Union (ACLU) obtained a copy of the foregoing report through a Freedom of Information Act (FOIA) request.&amp;nbsp; The contents of the report are interesting, to say the least.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Mobile Carriers Data Retention Summary" align="right" width="250" height="720" src="http://dataprivacy.foxrothschild.com/uploads/image/mobile carriers retention summary(1).gif" /&gt;As reported by&amp;nbsp;Cory Doctorow on the terrific&amp;nbsp;&lt;a href="http://boingboing.net"&gt;Boing Boing&lt;/a&gt;&amp;nbsp;in this&amp;nbsp;&lt;a href="http://boingboing.net/2011/09/29/which-of-americas-mobile-carriers-keeps-the-most-intel-on-you.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;article&lt;/a&gt;, and by David Kravets of Wired.com in this &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;article&lt;/a&gt; titled &amp;quot;Which Telecoms Store Your Data the Longest? Secret Memo Tells All,&amp;quot; it is unclear which major cellular carrier treats our usage data with the most respect.&amp;nbsp; On the one hand, Verizon stores text message details (just the transmission receipt details, such as recipient and time) only one year, compared to as long as 5-7 years for post-paid subscribers of AT&amp;amp;T.&amp;nbsp; On the other hand, AT&amp;amp;T, Sprint and T-Mobile store none of the contents of text messages, whereas Verizon stores that information for 3-5 days.&amp;nbsp; The IP&amp;nbsp;Session information may be the most interesting, because of the additional information that can be gleaned from the raw data, the question of why it is stored (billing disputes?) and the disparity in length of storage.&amp;nbsp; One of the excellent infographics posted on Wired's web site is posted here, but a &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;full Wired article&lt;/a&gt; is a must read.&lt;/p&gt;
&lt;p&gt;Besides this information being eye opening on a personal level, it can be crucial evidence in the case of a corporate&amp;nbsp;data breach.&amp;nbsp; While we all hope that law enforcement will use all tools available to it when investigating a corporate crime, knowing the tight time constraints under which businesses investigating a potential crime is crucial.&amp;nbsp; To be clear, I am referring to use of these tools as an option for ethical investigations into criminal activity through law enforcement.&amp;nbsp; These are not tools to assist a company in sacking an employee that is surfing the web on her mobile phone while on the clock.&amp;nbsp; In any event, these time frames should be considered when investigating a suspected data breach.&lt;/p&gt;
&lt;p&gt;If you are getting that &amp;quot;eye in the sky is watching me&amp;quot; feeling, I will be sure not to mention the warrantless&amp;nbsp;&lt;a href="http://dataprivacy.foxrothschild.com/2009/12/articles/right-to-privacy/alleged-that-sprint-provided-law-enforcement-customer-gps-data-over-8-million-times/"&gt;GPS and triangulation tracking capabilities&lt;/a&gt; of the major mobile carriers available to law enforcement.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Source:&amp;nbsp;&lt;a href="http://boingboing.net/2011/09/29/which-of-americas-mobile-carriers-keeps-the-most-intel-on-you.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;BoingBoing.net&lt;/a&gt;; &lt;a href="http://www.wired.com/threatlevel/2011/09/cellular-customer-data/"&gt;Wired.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/S1IFM2vRM_8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/S1IFM2vRM_8/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/09/articles/electronic-data-security/comparison-of-major-carriers-retention-of-mobile-device-usage/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">ACLU</category><category domain="http://dataprivacy.foxrothschild.com/articles">Electronic Data Security</category><category domain="http://dataprivacy.foxrothschild.com/tags">Mobile Data Storage</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Retention Periods of Major Cellular Service Providers</category><category domain="http://dataprivacy.foxrothschild.com/tags">U.S. Department of Justice</category>
         <pubDate>Fri, 30 Sep 2011 04:59:31 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/09/articles/electronic-data-security/comparison-of-major-carriers-retention-of-mobile-device-usage/</feedburner:origLink></item>
            <item>
         <title>Purdue Notifies 7,000 Students of SSN Theft 16 Months After Discovering the Breach</title>
         <description>&lt;p&gt;Purdue University &lt;a href="http://www.law360.com/privacy/articles/265560?utm_source=newsletter&amp;amp;utm_medium=email&amp;amp;utm_campaign=privacy"&gt;informed&lt;/a&gt; 7,093 former students on Monday that their Social Security numbers may have been stolen from servers at the University on April 5, 2010.&amp;nbsp; The notification comes 16 months after the discovery of the breach.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.jconline.com/article/20110817/NEWS0501/108170320/Purdue-warns-ex-students-data-breach?odyssey=mod|newswell|text|FRONTPAGE|s"&gt;According to&lt;/a&gt; the (Indiana) Journal &amp;amp;&amp;nbsp;Courier, the server contained 6.6 million nine-digit numbers in the accessed files.&amp;nbsp; After spending six months analyzing those&amp;nbsp;numbers, Purdue determined that approximately 65,000 of those number combinations could be Social&amp;nbsp;Security numbers.&amp;nbsp; An additional four months was spent reanalyzing the numbers and performing forensic analysis.&amp;nbsp; Based on those efforts, the University had matched 7,093 of those number combinations&amp;nbsp;to&amp;nbsp;Social Security numbers of former students.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The breach was discovered only three days after it occurred, approximately April 8, 2010.&amp;nbsp; Fourteen months after discovery of the breach, Purdue notified the Office of the Indiana Attorney General.&amp;nbsp; Now, approximately two months later, the affected former students were notified.&lt;/p&gt;
&lt;p&gt;Purdue did not offer any sort of credit monitoring and, instead, recommended to those affected to be vigilant and keep and eye on their credit activity.&lt;/p&gt;
&lt;p&gt;The announcement by Purdue comes on the heals of an announcement by The University of Wisconsin-Milwaukee on August 10th&amp;nbsp;that 75,000 of its students had been exposed to a hacking incident in May 2011, as reported earlier &lt;a href="http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;While the delay of three months may have seemed excessive last week, at least UWM beat Purdue's delay by almost 14 months.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/MrpVt1dUCck" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/MrpVt1dUCck/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">7,000 SSN</category><category domain="http://dataprivacy.foxrothschild.com/tags">7,000 Social Security numbers</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Purdue University</category><category domain="http://dataprivacy.foxrothschild.com/tags">data breach</category>
         <pubDate>Thu, 18 Aug 2011 05:43:59 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/purdue-notifies-7000-students-of-ssn-theft-16-months-after-discovering-the-breach/</feedburner:origLink></item>
            <item>
         <title>PSA: LinkedIn Assumes You "Opt-In" to Social Media Advertising</title>
         <description>&lt;p&gt;Boing Boing has an excellent how-to located &lt;a href="http://boingboing.net/2011/08/11/linkedin-opts-you-into-being-used-in-advertisements-heres-how-to-opt-out.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+boingboing%2FiBag+%28Boing+Boing%29"&gt;here&lt;/a&gt;&amp;nbsp;on how to opt out of being included in LinkedIn's social media advertising.&amp;nbsp; Briefly, LinkedIn assumes that you consent to LinkedIn's use of your image in the adverstising of its sponsor's products.&amp;nbsp; If you recommend your CPA firm, and your CPA firm purchases advertising on LinkedIn, your photo may appear in that advertising.&lt;/p&gt;
&lt;p&gt;This approach may be fine in certain cases. However, besides just the general creepiness of it,&amp;nbsp;employers should be aware that it creates a potential association between your company (not just the individual) and that third party. I can imagine a scenario where a company is suing its former CPA firm and an advertisement appears with the Controller's image in a LinkedIn advertisement for the same CPA firm.&lt;/p&gt;
&lt;p&gt;If your company's social media policy allows employees to participate in LinkedIn and other social media sites, consider whether the policy needs an update to require opting-out of this social media advertising.&lt;/p&gt;
&lt;p&gt;&lt;img alt="" width="450" height="288" src="http://dataprivacy.foxrothschild.com/uploads/image/linkedin.JPG" /&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/5SfA3IppRBg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/5SfA3IppRBg/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/employee-social-media-use-1/psa-linkedin-assumes-you-optin-to-social-media-advertising/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/articles">Employee Social Media Use</category><category domain="http://dataprivacy.foxrothschild.com/">LinkedIn</category><category domain="http://dataprivacy.foxrothschild.com/tags">Opt-Out</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">Social Media Advertising</category>
         <pubDate>Fri, 12 Aug 2011 06:25:16 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/employee-social-media-use-1/psa-linkedin-assumes-you-optin-to-social-media-advertising/</feedburner:origLink></item>
            <item>
         <title>HACKED: 75,000 Social Security Numbers at Risk at University of Wisconsin</title>
         <description>&lt;p&gt;The University of Wisconsin-Milwaukee (&amp;ldquo;UWM&amp;rdquo;) &lt;a href="http://www4.uwm.edu/univ_rel/computer_security.cfm"&gt;announced on Wednesday&lt;/a&gt; that a malware-infected, university server was discovered on May 25th that allowed hackers, apparently seeking research data, to access several types of scanned documents. Included in the potentially accessed documents were student applications from past and present students, which applications contained Social Security numbers.&lt;/p&gt;
&lt;p&gt;At this time, UWM has not been able to confirm that any of the documents were actually taken by the hackers. UWM reports that &amp;ldquo;[t]he university learned of the installation of malware on May 25, and immediately shut down the system and began to investigate. During the course of the investigation, on June 30, 2011, we discovered that the database containing social security numbers was included in the compromised system.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;UWM wants to assure students that although names and Social Security numbers were possibly taken,&amp;nbsp;the potentially accessed documents&amp;nbsp;did not contain any financial data or academic information such as student grades. At least students don&amp;rsquo;t have to worry about having embarrassing grades posted.&lt;/p&gt;
&lt;p&gt;The &lt;a href="http://www4.uwm.edu/univ_rel/computer_security.cfm"&gt;announcement&lt;/a&gt; asks &amp;ldquo;[s]houldn&amp;rsquo;t the university be offering free credit monitoring?&amp;rdquo; After all, free credit monitoring is expected these days, although certainly no required. The response? &amp;ldquo;We have no evidence that anyone&amp;rsquo;s personal information was retrieved or that any information was misused. However, it is recommended that everyone should monitor their financial information by:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Reviewing bank and credit card statements regularly, and looking for unusual or suspicious activities.&lt;/li&gt;
    &lt;li&gt;Contacting appropriate financial institutions immediately upon noticing any irregularity in a credit report or account.&lt;/li&gt;
    &lt;li&gt;Request a free credit report and carefully inspect your own credit scores.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That is one approach, I suppose.&amp;nbsp; It is certainly different.&lt;/p&gt;
&lt;p&gt;While the details of the investigation by this public institution remains under wraps, it does raise interesting questions. To be clear, there may be excellent bases for not making the disclosure earlier. However,&amp;nbsp;we have seen more and more experts commenting on how huge delays in public announcements are justified. Sure,&amp;nbsp;delays in notification&amp;nbsp;can sometimes be justified where only an intrusion is known and it is unclear whether personal information is accessible through that intrusion.&lt;/p&gt;
&lt;p&gt;We have come to the point where using the &amp;ldquo;ongoing internal investigation&amp;rdquo; excuse is habitually abused. In this case, based on facts known, it took 35 days for a &amp;ldquo;national computer security consultant&amp;rdquo; to determine the source and extent of the breach. In other words, it took experts 35 day to conclude that if a certain port on a server was exposed, then access to a certain, non-encrypted database was possible. I asked our network guys about this, and they said it should take about 30 minutes to determine what was exposed if a port was left open.&lt;/p&gt;
&lt;p&gt;After confirmation of the possibility that the sensitive documents could have been accessed, it too another 41 days to make a public announcement.&lt;/p&gt;
&lt;p&gt;Okay, so maybe law enforcement delayed the notification. Certainly possible. These comments are not meant to be an indictment of UWM specifically, but of the new approach to data breach notification that is occurring more often than not.&lt;/p&gt;
&lt;p&gt;In the cases where delay notification is grossly delayed, it is more often that company executives and their counsel decide that if the breach was announced, and it was later determined that access to the potentially accessed documents did not occur, then the &amp;ldquo;bad press&amp;rdquo; would be worse than delaying notification for 77 days.&amp;nbsp; Stated another way, they don't want to unnecessarily worry potentially affected persons.&lt;/p&gt;
&lt;p&gt;Again, we do not know all the facts. In all likelihood the sensitive documents were not accessed.&amp;nbsp; However, more and more we all are seeing HUGE delays in notifying those affected. If I received a breach notification 77 days after discovery I would be mad as hell. That is 77 days when identity theft could have occurred and I was not being vigilant because I was unaware of a breach. This is the exploding Pinto approach to data breaches.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/dXwCwPhh0ec" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/dXwCwPhh0ec/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags"> University of Wisconsin-Milwaukee</category><category domain="http://dataprivacy.foxrothschild.com/tags">75,000 social security numbers</category><category domain="http://dataprivacy.foxrothschild.com/tags">Breach Notification</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Theft</category><category domain="http://dataprivacy.foxrothschild.com/tags">Privacy</category>
         <pubDate>Fri, 12 Aug 2011 05:39:46 -0500</pubDate>
         <dc:creator>Mark McCreary</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/08/articles/data-theft/hacked-75000-social-security-numbers-at-risk-at-university-of-wisconsin/</feedburner:origLink></item>
            <item>
         <title>UCLA Health System Hospitals To Pay $865,000 For Privacy Breaches</title>
         <description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="512555313-08072011"&gt;From 2005 through 2009, UCLA Health System Hospitals (&amp;quot;UCLA&amp;quot;) received complaints that its employees had viewed celebrities' medical records without authorization.&amp;nbsp;&amp;nbsp;After an investigation, federal health regulators&amp;nbsp;determined that UCLA employees reviewed patients' electronic medical records &amp;quot;repeatedly and without a permissible reason.&amp;quot;&amp;nbsp; Federal health regulators found that UCLA failed to remedy the problem and discipline or retrain its staff.&amp;nbsp; Ultimately, UCLA entered into a settlement agreement with federal health regulators.&amp;nbsp; Under the settlement agreement, UCLA must pay a fine of $865,000.&amp;nbsp; The settlement agreement further requires UCLA to: (1) submit a plan to federal regulators outlining how it plans to prevent future privacy breaches; (2) retrain its staff about privacy protections; (3) institute privacy policies; (4) appoint a representative to oversee its privacy improvements; and (5) report to federal regulators for the next three years.&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/PrivacyComplianceDataSecurity/~4/jN6FDDkufJo" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/PrivacyComplianceDataSecurity/~3/jN6FDDkufJo/</link>
         <guid isPermaLink="false">http://dataprivacy.foxrothschild.com/2011/07/articles/data-protection-law-compliance/ucla-health-system-hospitals-to-pay-865000-for-privacy-breaches/</guid>
         <category domain="http://dataprivacy.foxrothschild.com/tags">Compliance</category><category domain="http://dataprivacy.foxrothschild.com/articles">Data Protection Law Compliance</category><category domain="http://dataprivacy.foxrothschild.com/tags">Electronic</category><category domain="http://dataprivacy.foxrothschild.com/tags">data privacy</category><category domain="http://dataprivacy.foxrothschild.com/tags">data security</category><category domain="http://dataprivacy.foxrothschild.com/tags">fines</category><category domain="http://dataprivacy.foxrothschild.com/tags">medical records</category>
         <pubDate>Fri, 08 Jul 2011 09:41:57 -0500</pubDate>
         <dc:creator>Amy C. Purcell</dc:creator>
      
      <feedburner:origLink>http://dataprivacy.foxrothschild.com/2011/07/articles/data-protection-law-compliance/ucla-health-system-hospitals-to-pay-865000-for-privacy-breaches/</feedburner:origLink></item>
      
   </channel>
</rss>
