<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.lexblog.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
   <channel>
      <title>Workplace Privacy, Data Management &amp; Security Report</title>
      <link>http://www.workplaceprivacyreport.com/</link>
      <description>Privacy Lawyers &amp; Attorneys : Jackson Lewis Law Firm : Data Security, HIPAA &amp; Confidentiality Issues</description>
      <language>en</language>
      <copyright>Copyright 2013</copyright>
      <lastBuildDate>Wed, 22 May 2013 11:07:34 -0800</lastBuildDate>
      <pubDate>Wed, 22 May 2013 11:07:34 -0800</pubDate>
      <generator>http://www.movabletype.org</generator>
      <docs>http://blogs.law.harvard.edu/tech/rss</docs> 

            <feedburner:info uri="workplaceprivacydatamanagementsecurityreport" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.workplaceprivacyreport.com/index.xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://www.workplaceprivacyreport.com/index.xml" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Fwww.workplaceprivacyreport.com%2Findex.xml" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
         <title>Plaintiff in Privacy Suit over LinkedIn Account Gets Zero Damages</title>
         <description>&lt;p&gt;Our colleague John A. Snyder &lt;a href="http://www.noncompetereport.com/2013/04/26/plaintiff-in-dispute-over-linkedin-account-gets-zero-damages/"&gt;writes&amp;nbsp;on our non-compete blog&lt;/a&gt;&amp;nbsp;about the case of &lt;em&gt;Eagle v. Morgan&lt;/em&gt;, No. 11-403 (E. D. Pa. March 12, 2013) in which the plaintiff sued her former employer for misappropriating her LinkedIn account and was awarded zero damages.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/Mx1Jj-cjDwk" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/Mx1Jj-cjDwk/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/plaintiff-in-privacy-suit-over-linkedin-account-gets-zero-damages/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">LinkedIn</category><category domain="http://www.workplaceprivacyreport.com/articles">Social Networking</category><category domain="http://www.workplaceprivacyreport.com/tags">common law privacy</category><category domain="http://www.workplaceprivacyreport.com/tags">social media</category>
         <pubDate>Fri, 26 Apr 2013 06:36:48 -0800</pubDate>
         <dc:creator>V. John Ella</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/plaintiff-in-privacy-suit-over-linkedin-account-gets-zero-damages/</feedburner:origLink></item>
            <item>
         <title>HIPAA Preempts Less Protective State Law Concerning Medical Records of Deceased Nursing Home Residents, Eleventh Circuit Rules</title>
         <description>&lt;p&gt;Written by &lt;a href="http://www.jacksonlewis.com/people.php?PeopleID=1275"&gt;&lt;strong&gt;Lillian Moon&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In addition to requirements to safeguard increasingly vast amounts of patient data, healthcare providers also need to be mindful of when that data can be used and disclosed. One key challenge in that area is understanding whether state or federal law applies.&amp;nbsp;The U.S. Eleventh Circuit Court of Appeals (which covers&amp;nbsp;Florida, Georgia, and Alabama), held that the federal Health Insurance Portability and Accountability Act of 1996 (&amp;ldquo;HIPAA&amp;rdquo;) preempted a Florida law, Section 400.145, that allowed&amp;nbsp;for the release of medical records of deceased residents of nursing homes to specified individuals without prior authorization. &lt;a href="http://www.workplaceprivacyreport.com/uploads/file/Opis 11th Cir Preemption 201212593.pdf"&gt;&lt;strong&gt;Opis Management Resources, LLC et al. v. Secretary Florida Agency for Health Care Administration&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The plaintiffs, comprised of several nursing home facilities, filed suit in federal district court challenging the Florida Agency for Health Care Administration&amp;rsquo;s (&amp;ldquo;AHCA&amp;rdquo;) citations to the facilities for their refusal to disclose deceased residents&amp;rsquo; medical records to surviving spouses, family members, and attorneys-in-fact who were not personal representatives under the relevant HIPAA provisions. The nursing homes asked a federal district court judge to declare that Florida Statute &amp;sect; 400.145 was preempted by HIPAA. The district (trial) court granted summary judgment in favor of the nursing facilities finding that the Florida law provided nursing home residents &lt;u&gt;less&lt;/u&gt; protection than required under HIPAA.&lt;/p&gt;
&lt;p&gt;On appeal, the Eleventh Circuit affirmed the district court&amp;rsquo;s grant of summary judgment concluding that Section 400.145&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;impedes the accomplishment and execution of the full purposes and objectives of HIPAA and the Privacy Rule in keeping an individual&amp;rsquo;s protected health information confidential.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As the court explained, HIPAA includes a preemption clause providing that HIPAA supersedes any contrary state law provision, including any state law which &amp;ldquo;stands as an obstacle to the accomplishment and execution of [HIPAA&amp;rsquo;s] full purposes and objectives.&amp;rdquo; In other words, if a state law provides for less stringent protection than that already provided by HIPAA, it is preempted or superseded by HIPAA. HIPAA, however, does not preempt state laws providing more stringent protections.&lt;/p&gt;
&lt;p&gt;Since 2000, the federal Department of Health and Human Services has issued extensive regulations, known as the Privacy Rule, that establish procedures by which protected health information (&amp;ldquo;PHI&amp;rdquo;) may be used or disclosed by a covered entity or business associate. Under the most recent &lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaahitech-privacy-and-security-regulations-released/"&gt;&lt;strong&gt;set of regulations issued in January&lt;/strong&gt;&lt;/a&gt;, HIPAA protection of PHI for deceased individuals remains in effect for a period of fifty (50) years after the individual&amp;rsquo;s death. The Privacy Rule further provides that PHI may be disclosed to a personal representative (one who under applicable state law is an executor, administrator or other individual with the authority to act on behalf of a deceased person or the individual&amp;rsquo;s estate). Additionally, a covered entity may disclose&amp;nbsp;a decedent&amp;rsquo;s PHI to family members and others who were involved in the care or payment for care of the decedent prior to death, unless doing so is inconsistent with any prior expressed preference of the individual that is known to the covered entity. In such a case, PHI of the deceased can be released to the extent it is relevant to such person&amp;rsquo;s involvement in the care or payment for the care.&lt;/p&gt;
&lt;p&gt;Section 400.145, Florida Statutes, provides in pertinent part that &amp;ldquo;[u]nless expressly prohibited by a legally competent resident, any nursing home licensed pursuant to this part shall furnish to the spouse, guardian, surrogate, proxy, or attorney in fact . . . of a current resident, . . . or of a former resident, . . . a copy of that resident&amp;rsquo;s records which are in the possession of the facility.&amp;rdquo; The court found that although the statute lists a number of individuals to whom records could be disclosed, it &amp;ldquo;does not empower or require an individual to act on behalf of a deceased resident,&amp;rdquo; and, therefore, does not identify any of those individuals to qualify as personal representatives under HIPAA. Therefore, the statute provides a much broader class of individuals than under HIPAA to whom the deceased&amp;rsquo;s PHI may be disclosed without authorization. Additionally, the Florida statute does not contain the same limitations or restrictions as the Privacy Rule with regard to releasing PHI of a deceased individual to those involved in the individual&amp;rsquo;s care or who paid for it and only to the extent the information is relevant to the person&amp;rsquo;s involvement or payment. Accordingly, the court found HIPAA provided more stringent protections of PHI than the Florida statute and held HIPAA preempts Section 400.145.&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/yeuSyYkjRTg" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/yeuSyYkjRTg/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/hipaa-1/hipaa-preempts-less-protective-state-law-concerning-medical-records-of-deceased-nursing-home-residents-eleventh-circuit-rules/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">FL</category><category domain="http://www.workplaceprivacyreport.com/tags">Florida</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">decedent</category><category domain="http://www.workplaceprivacyreport.com/tags">nursing home</category><category domain="http://www.workplaceprivacyreport.com/tags">personal representative</category><category domain="http://www.workplaceprivacyreport.com/tags">preemption</category>
         <pubDate>Tue, 16 Apr 2013 05:39:23 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/hipaa-1/hipaa-preempts-less-protective-state-law-concerning-medical-records-of-deceased-nursing-home-residents-eleventh-circuit-rules/</feedburner:origLink></item>
            <item>
         <title>California Considers Broader and Tougher Data Disclosure Requirements for Use of Customer Personal Information</title>
         <description>&lt;p&gt;By:&amp;nbsp; &lt;a href="http://www.jacksonlewis.com/people.php?PeopleID=1275"&gt;Lillian Chaves Moon&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In the face of increasing incidences of and rising public concern regarding identity theft, the California Legislature is considering a bill with new personal information data disclosure requirements for California businesses and a broad definition of what constitutes personal information.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB1291"&gt;California Assembly Bill 1291&lt;/a&gt;, would require businesses who have customer personal information and have disclosed such information to provide each such customer with notice of the names and contact information of all third parties who received personal information from the business and provide a designated request address at which to receive requests from customers as provided for under the bill. Additionally, the business must make available, free of charge, access to or copies of all of the customer&amp;rsquo;s personal information that the business holds.&amp;nbsp;Also, if the business has any online privacy policies, each privacy policy must also include a statement of the customer&amp;rsquo;s rights as provided in the legislation and a designated request address.&lt;/p&gt;
&lt;p&gt;Personal information broadly includes, but is not limited to, any of the following: (1) identity information such as real name, alias, nickname, and user name; (2) address information, including but not limited to, postal address, e-mail, internet protocol address; (3) telephone number; (4) account name; (5) social security number or other government-issued identification number, such as a driver&amp;rsquo;s license number, identification card number, and passport number; (6) birthdate or age; (7) physical characteristic information such as height and weight; (8) sexual information, including but not limited to, sexual orientation, sex, gender status, gender identity, and gender expression; (9) race or ethnicity; (10) religious affiliation or activity; (11) political affiliation or activity; (12) professional or employment-related information; (13) educational information; (14) medical information; (15) financial information; (16) commercial information; (17) location information; (18) internet or mobile activity information; (19) content including text, photographs, audio or video recordings, or other material generated by or provided by the customer; and (20) any of the above information as it relates to the customer&amp;rsquo;s children.&lt;/p&gt;
&lt;p&gt;Customer is defined as an individual who is a resident of California and provides personal information to a business &amp;ldquo;in the course of purchasing, viewing, accessing, renting, leasing, or otherwise using real or personal property, or any interest therein, or obtaining a product or service from the business including advertising or any other content.&amp;rdquo;&amp;nbsp;Customers also include individuals for whom the business obtained personal information from another business.&amp;nbsp;Accordingly, the bill would cover individuals who are not traditionally thought of as customers and may also include a business&amp;rsquo; employees.&lt;/p&gt;
&lt;p&gt;All businesses, including employers, with operations in California or with California customers must stay abreast of these developments and, given the breadth of personal information implicated, no such business can be exempt from the requirements. In preparation for the passing of this or a similar bill, it is important to determine how customer personal information is disclosed and set forth a compliance plan to meet the pending disclosure and access requirements.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/LT9siMylc6Q" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/LT9siMylc6Q/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/identity-theft/california-considers-broader-and-tougher-data-disclosure-requirements-for-use-of-customer-personal-information/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">1291</category><category domain="http://www.workplaceprivacyreport.com/tags">Assembly Bill 1291</category><category domain="http://www.workplaceprivacyreport.com/tags">California</category><category domain="http://www.workplaceprivacyreport.com/tags">Identity</category><category domain="http://www.workplaceprivacyreport.com/articles">Identity Theft</category><category domain="http://www.workplaceprivacyreport.com/tags">bill</category><category domain="http://www.workplaceprivacyreport.com/tags">business</category><category domain="http://www.workplaceprivacyreport.com/tags">customer</category><category domain="http://www.workplaceprivacyreport.com/tags">legislation</category><category domain="http://www.workplaceprivacyreport.com/tags">legislature</category><category domain="http://www.workplaceprivacyreport.com/tags">personal information</category><category domain="http://www.workplaceprivacyreport.com/tags">social security numbers</category><category domain="http://www.workplaceprivacyreport.com/tags">theft</category>
         <pubDate>Fri, 12 Apr 2013 11:03:41 -0800</pubDate>
         <dc:creator>Jason C. Gavejian </dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/identity-theft/california-considers-broader-and-tougher-data-disclosure-requirements-for-use-of-customer-personal-information/</feedburner:origLink></item>
            <item>
         <title>California Appellate Court Expands Common Law Right of Privacy</title>
         <description>&lt;p&gt;The Fourth District Court of Appeal for the State of California expanded the tort of &amp;quot;public disclosure of private facts&amp;quot; under that state's common law right to privacy in a case involving a claim by an employee against her supervisor and employer. &lt;em&gt;&lt;a href="http://www.workplaceprivacyreport.com/uploads/file/Ignat.pdf"&gt;Ignat v. Yum! Brands, Inc.&lt;/a&gt;&lt;/em&gt; et al, No. G046434, (Cal. Ct. App. March 18, 2013). The plaintiff in that case suffered from bi-polar disorder and occasionally missed work due to the side effects of medication adjustments.&amp;nbsp; After returning from such an absence, the plaintiff alleged that her supervisor had informed everyone in her department about her medical condition and that, as a result, she was &amp;quot;shunned&amp;quot; and a co-worker asked if she was going to &amp;quot;go postal.&amp;quot;&amp;nbsp; The plaintiff filed suit alleging a single cause of action for invasion of privacy by public disclosure of private facts. The trial court dismissed her claim on summary judgment because the disclosure of her condition was not in writing, relying on California case law from the early&amp;nbsp;1930's.&lt;/p&gt;
&lt;p&gt;On appeal, the court reversed the dismissal, concluding that &amp;quot;limiting liability for public disclosure of private facts to those recorded in writing is contrary to the tort's purpose, which has been since its inception to allow a person to control the kind of information about himself made available to the public - in essence to define his public persona.&amp;quot;&amp;nbsp; The court went on to note that, &amp;quot;[w]hile this restriction may have made sense in the 1890's - when no one dreamed of talk radio or confessional television - it certainly makes no sense now.&amp;quot;&lt;/p&gt;
&lt;p&gt;The court also clarified that the common law tort of invasion of privacy was not based on the guarantee of privacy which was added to the California Constitution in 1972 and noted that the two legal theories (common law and the State Constitution) provide &amp;quot;separate, albeit related ways to ensure privacy.&amp;quot;&lt;/p&gt;
&lt;p&gt;Different states have interpreted the common law right of privacy in the workplace in different ways. In Minnesota, for example, a district court rejected a&amp;nbsp;lawsuit by an employee who claimed that her employer violated her right to privacy when it informed approximately 12 to 15 individuals that she suffered from multiple sclerosis. That court determined that because the disclosure was not &amp;quot;accessible to the public at large,&amp;quot; it did not qualify as public in nature for purposes of maintaining an invasion of privacy claim. &lt;em&gt;Johnson v. Cambell Mithun&lt;/em&gt;, 401 F. Supp.2d 964 (Minn. 2005).&lt;/p&gt;
&lt;p&gt;If an employee is out on medical leave or requires an accommodation, employers may be asked what information, if any, can be disclosed to co-workers and supervisors about that employee's medical condition, and the reason for her leave or accommodation. HIPAA is probably not implicated in such situations because most employers are not covered entities in this context. Both the Americans with Disabilities Act (ADA) and the Family Medical Leave Act (FMLA), however, require employers to maintain confidentiality of medical information. See 29 C.F.R. Section 1630.14(c) (relating to ADA) and 29 C.F.R. Section 825.500 (relating to FMLA).&lt;/p&gt;
&lt;p&gt;Employees asserting a common law claim for invasion of privacy&amp;nbsp;against their employer based on the disclosure of medical information have not often been successful, but &lt;em&gt;Ignat &lt;/em&gt;suggests the tide may be changing. The best practice is to reveal as little as possible to those with a need to know.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/UtAEiERENEE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/UtAEiERENEE/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/workplace-privacy/california-appellate-court-expands-common-law-right-of-privacy/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">ADA</category><category domain="http://www.workplaceprivacyreport.com/tags">California</category><category domain="http://www.workplaceprivacyreport.com/tags">FMLA</category><category domain="http://www.workplaceprivacyreport.com/">Featured</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/tags">common law privacy</category>
         <pubDate>Thu, 11 Apr 2013 15:19:52 -0800</pubDate>
         <dc:creator>V. John Ella</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/workplace-privacy/california-appellate-court-expands-common-law-right-of-privacy/</feedburner:origLink></item>
            <item>
         <title>Deletion of Facebook Page = Spoliation</title>
         <description>&lt;p&gt;A &lt;a href="http://www.workplaceprivacyreport.com/uploads/file/119176988970b939f98.pdf"&gt;New Jersey District Court has sanctioned &lt;/a&gt;a personal injury plaintiff for spoliation following the plaintiff&amp;rsquo;s deletion of his &lt;a href="http://www.facebook.com"&gt;Facebook &lt;/a&gt;account which defendants were trying to access.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The defendant&amp;rsquo;s discovery requests asked for documents or records of &amp;ldquo;wall posts, comments, status updates or personal information posted or made by plaintiff on Facebook and/or any social media website from 2008 through the present.&amp;rdquo;&amp;nbsp;Later, the defendant sent forms for plaintiff to execute which would authorize Facebook and other sites to release plaintiff&amp;rsquo;s information.&amp;nbsp;The plaintiff executed all the authorizations except the one for Facebook.&lt;img hspace="3" alt="" vspace="3" align="right" style="width: 167px; height: 182px" src="http://www.workplaceprivacyreport.com/uploads/image/Facebook_Logo_Motion_Graphics_Element.jpg" /&gt;&lt;/p&gt;
&lt;p&gt;Plaintiff&amp;rsquo;s failure to execute the Facebook authorization was raised before the Court and the Court ordered plaintiff to execute the authorization.&amp;nbsp;&amp;nbsp;Plaintiff agreed to enable access by changing his password to a certain word.&amp;nbsp;Thereafter, defense counsel accessed the account to confirm the password change and printed some of the accounts content.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The following day, Facebook notified plaintiff of the account access from an unknown IP address in New Jersey.&amp;nbsp;Plaintiff notified his counsel who contacted defense counsel to confirm that the records would be sought from Facebook headquarters.&amp;nbsp;Defense &amp;nbsp;counsel responded, explaining the account was accessed to confirm the password change but would not be accessed again as the authorization was sent to Facebook.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;Facebook responded to the authorization advising that the Stored Communications Act barred it from disclosing the data but suggested having plaintiff download the content himself.&amp;nbsp;&amp;nbsp;&amp;nbsp; Counsel for the parties agreed that plaintiff would do so and turn over a copy, along with a certification that he had made no changes since he was first ordered to execute the authorization.&amp;nbsp;However, plaintiff&amp;rsquo;s counsel later advised defendants that plaintiff had deactivated the account and could not reactivate it.&amp;nbsp;The plaintiff claimed he deactivated the account because of the notification he received that unknown people were accessing his account without his permission.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;The defendants moved for sanctions claiming that the deletion was intentional as postings contained in the deleted account would have helped refute plaintiff&amp;rsquo;s damages claim.&amp;nbsp;Defendants based this assertion on content printed from the account prior to deactivation.&amp;nbsp; The Court rejected plaintiff&amp;rsquo;s argument that the information contained in the account was not intentionally suppressed and found that even if plaintiff did not intend to deprive defendants of the data, he intentionally deleted the account and thereby failed to preserve relevant evidence.&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt"&gt;This case, as well as the case discussed &lt;a href="http://www.workplaceprivacyreport.com/2010/06/articles/social-networking-1/employees-claiming-emotional-distress-must-produce-social-network-facebook-and-myspace-information-in-discovery/"&gt;here&lt;/a&gt;, provide valuable authority for accessing social media content in litigation.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/1BMd8SsYpMo" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/1BMd8SsYpMo/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/deletion-of-facebook-page-spoliation/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">District Court</category><category domain="http://www.workplaceprivacyreport.com/tags">Facebook</category><category domain="http://www.workplaceprivacyreport.com/tags">Gatto</category><category domain="http://www.workplaceprivacyreport.com/articles">Social Networking</category><category domain="http://www.workplaceprivacyreport.com/tags">Stored Communications Act</category><category domain="http://www.workplaceprivacyreport.com/tags">United</category><category domain="http://www.workplaceprivacyreport.com/tags">United Air Lines</category><category domain="http://www.workplaceprivacyreport.com/tags">access</category><category domain="http://www.workplaceprivacyreport.com/tags">attorney</category><category domain="http://www.workplaceprivacyreport.com/tags">authorization</category><category domain="http://www.workplaceprivacyreport.com/tags">court</category><category domain="http://www.workplaceprivacyreport.com/tags">discovery</category><category domain="http://www.workplaceprivacyreport.com/tags">media</category><category domain="http://www.workplaceprivacyreport.com/tags">networking</category><category domain="http://www.workplaceprivacyreport.com/tags">opinion</category><category domain="http://www.workplaceprivacyreport.com/tags">social</category><category domain="http://www.workplaceprivacyreport.com/tags">social media</category>
         <pubDate>Thu, 11 Apr 2013 11:19:57 -0800</pubDate>
         <dc:creator>Jason C. Gavejian </dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/deletion-of-facebook-page-spoliation/</feedburner:origLink></item>
            <item>
         <title>New Mexico Joins Other States That Have Passed Social Media Privacy Laws</title>
         <description>&lt;p&gt;Shortly after &lt;a href="http://Employers also are not prohibited under the law from viewing, accessing, or using information that is publicly available on the Internet, although there may be other risks to employers engaging in these activities, such as under the Genetic Information Nondiscrimination Act"&gt;&lt;strong&gt;Utah inked its own law&lt;/strong&gt;&lt;/a&gt;, New Mexico Governor Susana Martinez signed &lt;a href="http://www.workplaceprivacyreport.com/uploads/file/New Mexico SB0371.pdf"&gt;&lt;strong&gt;S371&lt;/strong&gt;&lt;/a&gt; into law on &lt;a href="http://www.nmlegis.gov/lcs/_session.aspx?chamber=S&amp;amp;legtype=B&amp;amp;legno= 371&amp;amp;year=13"&gt;&lt;strong&gt;April 5, 2013&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;Similar to the provisions in other states (such as, California, Illinois, Maryland and Michigan), S371 makes it illegal for employers to request or require&amp;nbsp;applicants&amp;nbsp;to provide a password, or demand access in any manner,&amp;nbsp;to&amp;nbsp;an&amp;nbsp;applicant's&amp;nbsp;social media account or profile. Unlike some of the laws in other states, the New Mexico statute appears to apply only to prospective employees, but not current employees.&lt;/p&gt;
&lt;p&gt;Additionally, S371 makes clear that certain activities by employers are &lt;u&gt;&lt;strong&gt;not&lt;/strong&gt;&lt;/u&gt; affected by the law, namely:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;having electronic communication policies in the workplace addressing&amp;nbsp;internet use, social networking activity and email,&lt;/li&gt;
    &lt;li&gt;monitoring use of the employer&amp;rsquo;s information systems and networks,&lt;/li&gt;
    &lt;li&gt;using information that is publicly available on the Internet, although as noted in&amp;nbsp;prior posts there may be other risks to employers engaging in these activities, such as under the Genetic Information Nondiscrimination Act.&lt;/li&gt;
&lt;/ul&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/_eHi2zSBULY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/_eHi2zSBULY/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/new-mexico-joins-other-states-that-have-passed-social-media-privacy-laws/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">Identity Theft</category><category domain="http://www.workplaceprivacyreport.com/articles">Monitoring</category><category domain="http://www.workplaceprivacyreport.com/tags">New Mexico</category><category domain="http://www.workplaceprivacyreport.com/articles">Social Networking</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Investigations</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/tags">applicant</category><category domain="http://www.workplaceprivacyreport.com/tags">password</category><category domain="http://www.workplaceprivacyreport.com/tags">prospective employee</category>
         <pubDate>Wed, 10 Apr 2013 03:20:28 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/social-networking-1/new-mexico-joins-other-states-that-have-passed-social-media-privacy-laws/</feedburner:origLink></item>
            <item>
         <title>Utah Enacts "Internet Employment Privacy Act"</title>
         <description>&lt;p&gt;Following a handful of other states (such as, California, Illinois, Maryland and Michigan), a new Utah labor law places limits on&amp;nbsp;employers' ability to access the &amp;quot;personal Internet accounts&amp;quot; of employees and applicants. Gov. Gary R. Herbert&amp;nbsp;signed the state's &amp;quot;&lt;a href="http://www.workplaceprivacyreport.com/uploads/file/Utah Internet Employment Privacy Act HB0100.pdf"&gt;&lt;strong&gt;Internet Employment Privacy Act&lt;/strong&gt;&lt;/a&gt;&amp;quot; (IEPA) on March 26, 2013, together with the &amp;quot;Internet Postsecondary Institution Privacy Act&amp;quot; applying similar&amp;nbsp;restrictions on postsecondary&amp;nbsp;institutions with respect to their students and prospective students.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The IEPA&amp;nbsp;prohibits an employer from asking an employee or applicant to disclose&amp;nbsp;the username and password that allows access to his or her &amp;quot;personal Internet account,&amp;quot; as well as taking adverse action against the individual for failing to do so. There are some qualifications and exceptions, however.&lt;/p&gt;
&lt;p&gt;First, &amp;quot;personal Internet accounts&amp;quot; are defined to mean&amp;nbsp;online accounts that are used by an&lt;br /&gt;
employee or applicant &amp;quot;&lt;em&gt;&lt;strong&gt;exclusively for personal communications unrelated to any business&lt;br /&gt;
purpose of the employer&lt;/strong&gt;&lt;/em&gt;.&amp;quot; In fact, the statute specifically excludes accounts that are &amp;quot;&lt;em&gt;&lt;strong&gt;created, maintained, used,&amp;nbsp;or accessed&lt;/strong&gt;&lt;/em&gt; by an employee or applicant for business related communications or for a business&amp;nbsp;purpose of the employer.&amp;quot; Of course, employees frequently use their personal online accounts for business purposes, so it is unclear how widespread the protections under this new law will be.&lt;/p&gt;
&lt;p&gt;Consider that most employees' LinkedIn or Facebook accounts likely include some business contacts for their current employer, setting up the argument that the account is maintained or used for a business purpose of the employer. Perhaps the practical effect of the law will be to provide greater protection for applicants who seem less likely to have online personal accounts created, maintained, used or accessed for a business purpose of the employer.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Second, the IEPA sets out some specific exceptions, such as:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Employers may request or require employees to provide their usernames and passwords to enable the employer to access &lt;em&gt;company-issued&lt;/em&gt; (or paid for, in whole or in part) smartphones and other devices, as well as online accounts&lt;em&gt; provided&amp;nbsp;by the&amp;nbsp;employer&lt;/em&gt;.&lt;/li&gt;
    &lt;li&gt;Employers may discipline employees for making unauthorized transfers of proprietary or confidential company information or financial data to the employee's&amp;nbsp;personal Internet account.&lt;/li&gt;
    &lt;li&gt;Employers also may conduct and require employees to cooperate with certain investigations (such as concerning compliance or work-related employee misconduct) when there is specific information about related activity on the employee's personal Internet account.&lt;/li&gt;
    &lt;li&gt;Perhaps to address the concerns of those employers who have adopted &amp;quot;BYOD&amp;quot; programs, the law does &lt;u&gt;not&lt;/u&gt; prohibit the &amp;quot;monitoring, reviewing, accessing, or blocking electronic data stored on an electronic communications device supplied by, or paid for in whole or in part by, the employer, or stored on an employer's network, in accordance with state and federal law.&amp;quot;&lt;/li&gt;
    &lt;li&gt;Employers also are not prohibited under the law from viewing, accessing,&amp;nbsp;or using information that is publicly available on the Internet, although there may be other&amp;nbsp;risks to employers engaging in these activities, such as under the Genetic Information Nondiscrimination Act.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Employees and applicants may sue employers for violating this law, but damages&amp;nbsp;are limited to&amp;nbsp;$500 per violation.&lt;/p&gt;
&lt;p&gt;This development only highlights the increasing regulation of employee (and applicant) privacy in cyberspace, particularly for multi-state employers where the laws vary significantly. Employers need to keep on top of these developments, and ensure their managers and supervisors have been trained so they know their limitations in attracting, managing and disciplining&amp;nbsp;employees.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/YiRCjBW0GgI" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/YiRCjBW0GgI/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/04/articles/workplace-privacy/utah-enacts-internet-employment-privacy-act/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">Internet Employment Privacy Act</category><category domain="http://www.workplaceprivacyreport.com/tags">Utah</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category>
         <pubDate>Mon, 08 Apr 2013 02:59:12 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/04/articles/workplace-privacy/utah-enacts-internet-employment-privacy-act/</feedburner:origLink></item>
            <item>
         <title>New Tennessee Law Requires Destruction of Certain PHI Following Medical Malpractice Litigation</title>
         <description>&lt;p&gt;In 2012, medical malpractice defendants and their defense attorneys earned the right to petition the court for a qualified protective order that would allow them to&amp;nbsp;interview plaintiffs' health care providers without the presence of the claimants or their attorneys. At that time, one of the conditions for the order was that it limit the disclosure of any protected health information to the litigation before the court.&lt;/p&gt;
&lt;p&gt;That law was amended on March 20, 2013, when Tennessee Gov. Bill Haslam signed &lt;a href="http://www.workplaceprivacyreport.com/uploads/file/TN pc0023.pdf"&gt;&lt;strong&gt;S.B. 273. &lt;/strong&gt;&lt;/a&gt;The new law requires the defendants to return or destroy the protected health information obtained under such an order, including &lt;u&gt;&lt;strong&gt;all&lt;/strong&gt;&lt;/u&gt; copies,&amp;nbsp;when the&amp;nbsp;litigation ends. This new requirement, similar&amp;nbsp;to the requirement that exists under HIPAA,&amp;nbsp;applies to litigations that begin on and after July 1, 2013.&amp;nbsp;Defendants in these cases - health care providers - will need to be sure they keep track of all this health information they obtain under these orders, including all electronic versions, to ensure they are returned or destroyed as required under the new law.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/7yAmrY9JqZ0" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/7yAmrY9JqZ0/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/new-tennessee-law-requires-destruction-of-certain-phi-following-medical-malpractice-litigation/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">Tennessee</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">destruction</category><category domain="http://www.workplaceprivacyreport.com/tags">medical malpractice</category>
         <pubDate>Sun, 31 Mar 2013 22:40:39 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/new-tennessee-law-requires-destruction-of-certain-phi-following-medical-malpractice-litigation/</feedburner:origLink></item>
            <item>
         <title>Utah Requires Statement About Disclosures in HIPAA Notice of Privacy Practices</title>
         <description>&lt;p&gt;In response to a massive data breach in 2012 involving over 700,000 people, Utah's Governor Gary R. Herbert signed a new law (&lt;a href="http://www.workplaceprivacyreport.com/uploads/file/Utah SB0020.pdf"&gt;&lt;strong&gt;S.B. 20&lt;/strong&gt;&lt;/a&gt;)&amp;nbsp;to ensure Utah residents will be&amp;nbsp;notified of the possibility that their individually identifiable health information may be&amp;nbsp;shared with&amp;nbsp;the eligibility databases for Medicaid and the Children's Health Insurance Program (CHIP). The law becomes effective July 1, 2013.&lt;/p&gt;
&lt;p&gt;To notify residents, the law requires health care providers in the state to include this information in their notices of privacy practices (NPP)&amp;nbsp;that they are required to provide under the HIPAA&amp;nbsp;Privacy Rule. &lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaahitech-privacy-and-security-regulations-released/"&gt;&lt;strong&gt;HIPAA-covered&amp;nbsp;health care providers&amp;nbsp;should already be updating their NPPs&lt;/strong&gt; &lt;/a&gt;following the final HIPAA regulations issued in January, although&amp;nbsp;S.B. 20 may require&amp;nbsp;Utah providers&amp;nbsp;to act more quickly in updating their NPPs than is required under the HIPAA final regulations,&amp;nbsp;which has&amp;nbsp;September 23, 2013 compliance date. S.B. 20 also requires Medicare and CHIP to check that the notices are in place, and to deny providers&amp;nbsp;access to their eligibility databases if the notices are not in place. The law also gives the state's Department of Health the authority to develop model language for the NPP.&lt;/p&gt;
&lt;p&gt;Because of the seriousness of the breach,&amp;nbsp;S.B. 20 also lays the groundwork&amp;nbsp;to assemble a group&amp;nbsp;that will be charged with establishing best practices for data security.&amp;nbsp;Utah providers will need to monitor this development closely,&amp;nbsp;particularly if the&amp;nbsp;&amp;quot;best practices&amp;quot; create standards that are more stringent&amp;nbsp;than those under the HIPAA&amp;nbsp;privacy and security regulations.&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/R8fy6kv02sM" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/R8fy6kv02sM/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/utah-requires-statement-about-disclosures-in-hipaa-notice-of-privacy-practices/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">Notice of Privacy Practices</category><category domain="http://www.workplaceprivacyreport.com/tags">Utah</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category>
         <pubDate>Sun, 31 Mar 2013 22:03:58 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/utah-requires-statement-about-disclosures-in-hipaa-notice-of-privacy-practices/</feedburner:origLink></item>
            <item>
         <title>We have to disclose patient records in response to a subpoena/attorney letter, right?</title>
         <description>&lt;p&gt;One of the more common issues faced by healthcare practices (and businesses generally) is how to respond to subpoenas or other requests for medical records of patients and employees. Those who receive these requests often feel compelled to respond in a timely fashion, particularly when it is an attorney subpoena or letter. Unfortunately, responses are made before fully considering critical legal and professional risks.&lt;/p&gt;
&lt;p&gt;Consider the following examples:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;A New Jersey physician was forced to defend his access to family medical records without consent or authorization before the New Jersey Board of Medical Examiners resulting in defense costs and ultimately continuing education requirements for the physician;&lt;/li&gt;
    &lt;li&gt;An Illinois hospital incurred significant legal fees to defend its disclosure of medical records in connection with the plaintiff&amp;rsquo;s divorce action.&lt;/li&gt;
    &lt;li&gt;Ohio's Cleveland Clinic could not convince a federal district court to dismiss a patient's claim for invasion of privacy following the clinic&amp;rsquo;s disclosure of medical records to a grand jury in response to a subpoena. The court found the state's patient-physician privilege more protective than HIPAA. Turk v. Oiler, No. 09-CV-381 (N.D. Ohio Feb. 1, 2010).&lt;/li&gt;
    &lt;li&gt;An Alabama patient's claim that his physician impermissibly disclosed his medical records to his employer survived a motion for summary judgment because the physician made the disclosure without having received a written request, as required under state law.&lt;/li&gt;
    &lt;li&gt;In Wisconsin, a pharmacist was sued after disclosing an employee's prescription history to his employer. The pharmacist's ignorance of the states privacy laws and the employee's attorneys false pretenses to obtain the information were not a sufficient defense. The court found the release was knowing and willful and held the pharmacist must be familiar with the technical requirements for releasing patient data.&lt;/li&gt;
    &lt;li&gt;A Court held another New Jersey doctor liable when he released a patient's records to opposing counsel pursuant to an improper subpoena, even though the subpoena's defects were of a technical nature. Again, the Court required the doctor to know the laws regarding patient privacy, &lt;strong&gt;specifically noting it was the doctor's burden to consult with legal counsel to ensure the release is proper&lt;/strong&gt;. Crescenzo v. Crane, 350 N.J. Super. 531 (App. Div. 2002), cert. den. 174 N.J. 364 (2002).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Responding to these requests often is a delicate balance between avoiding being hauled into court for non-compliance with the subpoena/request and violating patient rights, such as by responding to a subpoena that may be improper or invalid, or otherwise failing to take into account applicable federal and state requirements before releasing the records.&lt;/p&gt;
&lt;p&gt;Some of the most common issues which must be considered are:&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;What type of information is contained within the records requested?&lt;/li&gt;
    &lt;li&gt;What statutory, regulatory or common law protections apply to some or all of the information requested, such as the patient-physician privilege?&lt;/li&gt;
    &lt;li&gt;Is the authorization valid?&lt;/li&gt;
    &lt;li&gt;Whether responding to the subpoena is appropriate without patient authorization or providing the patient an opportunity to object to the disclosure?&lt;/li&gt;
    &lt;li&gt;Is a court order, including an order with specific findings, needed for some or all of the responsive information?&lt;/li&gt;
    &lt;li&gt;Is&amp;nbsp;the requesting party authorized to be acting for the individual/patient/employee?&lt;/li&gt;
    &lt;li&gt;What safeguards should be taken to ensure the disclosure is made in a secure manner?&lt;/li&gt;
    &lt;li&gt;Must the business keep a record/account for the disclosure?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;As more and more individuals, entities and attorneys seek medical information, including&amp;nbsp;through discovery in litigation, these issues will only become more prevalent. Most healthcare practices look to HIPAA as the governing law that determines the proper use and disclosure of patient data, &lt;em&gt;&lt;u&gt;&lt;strong&gt;but state laws and professional obligations also must also be considered&lt;/strong&gt;&lt;/u&gt;&lt;/em&gt;. Under HIPAA, a covered entity generally may not use or disclose an individual&amp;rsquo;s protected health information without a written authorization or providing the individual the opportunity to agree or object. There are, however, a number of thorny exceptions, such as for requests made in the course of judicial or administrative proceedings, or disclosures to law enforcement.&lt;/p&gt;
&lt;p&gt;Nevertheless, HIPAA generally provides that these exceptions can be trumped by more stringent state laws that prohibit uses or disclosures of PHI without certain additional protections. In fact, courts routinely look to not only generally applicable state statutory requirements, but also protections under the &amp;quot;common law.&amp;quot; This fact has been highlighted in decisions from courts throughout the country, as well as decisions by state boards of medical examiners, including those summarized above. In addition to fines and penalties which can be extensive, the cost of litigation to defend these suits can run into the tens of thousands of dollars, all for &amp;ldquo;simply&amp;rdquo; responding to what appears to be a lawfully issued subpoena or request.&lt;/p&gt;
&lt;p&gt;Medical offices, clinics and practices, in particular,&amp;nbsp;need to have a comprehensive,&amp;nbsp;easy to understand plan that addresses what to do&amp;nbsp;when staff receive&amp;nbsp;requests for patient records. The plan should anticipate the kinds of requests&amp;nbsp;that are likely to be received and the acceptable responses, including approved form&amp;nbsp;documents to be used, as well as a means for documenting the request, verification steps taken&amp;nbsp;and the response. Of course, the plan should alert the user to situations where additional guidance might be advisable to ensure the disclosure itself is proper, as well as the method of disclosure.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/VvjnRzyy0bU" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/VvjnRzyy0bU/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/we-have-to-disclose-patient-records-in-response-to-a-subpoenaattorney-letter-right/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">GINA</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">Turk</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">accounting for disclosure</category><category domain="http://www.workplaceprivacyreport.com/articles">e-Discovery</category><category domain="http://www.workplaceprivacyreport.com/tags">subpoena</category>
         <pubDate>Sun, 31 Mar 2013 21:35:18 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/03/articles/hipaa-1/we-have-to-disclose-patient-records-in-response-to-a-subpoenaattorney-letter-right/</feedburner:origLink></item>
            <item>
         <title>New York's Highest Court To Say Whether Medical Practice Can Be Sued For Wrongful Texts By Non-Physician Employee</title>
         <description>&lt;p&gt;In this case (&lt;a href="http://www.workplaceprivacyreport.com/uploads/file/DoeGuthrie3-25.pdf"&gt;&lt;strong&gt;Doe v Guthrie Clinic, Ltd, March 25, 2013&lt;/strong&gt;&lt;/a&gt;), the&amp;nbsp;Second Circuit Court of Appeals (covering New York, Connecticut and Vermont) is asking New York's highest court to determine whether the common law permits a&amp;nbsp;medical corporation to be sued for a&amp;nbsp;breach of the fiduciary duty of confidentiality concerning patient medical records when&amp;nbsp;a non-physician employee makes an&amp;nbsp;unauthorized disclosure of those&amp;nbsp;records. The position&amp;nbsp;the New York Court of Appeals&amp;nbsp;takes will be watched closely by&amp;nbsp;health care providers across the Empire State as the requirements for securing patient data continue to tighten with, among other things,&amp;nbsp;the final HIPAA&amp;nbsp;regulations being issued under HITECH&amp;nbsp;this past January.&lt;/p&gt;
&lt;p&gt;Here, Doe (patient) sued Guthrie&amp;nbsp;Clinic because one of the clinic's&amp;nbsp;nurses&amp;nbsp;(and sister-in-law of Doe's girlfriend) texted Doe's girlfriend about Doe's treatment for&amp;nbsp;a sexually transmitted disease (STD). All of the patient's claims, including a claim for&amp;nbsp;common law breach of fiduciary duty to maintain the confidentiality of personal health information, were dismissed by the lower court. Doe appealed the dismissal to&amp;nbsp;the Second Circuit.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The federal appellate court reversed the dismissal of the fiduciary breach claim, noting&amp;nbsp;that New York courts have not addressed this situation. That is, there are no decisions in New York that specifically address&amp;nbsp;whether a medical practice could be liable under a&amp;nbsp;breach of fiduciary duty theory when its non-physician employee&amp;nbsp;wrongfully&amp;nbsp;discloses confidential medical information. Employers in New York generally are liable for the foreseeable actions of their employees which are within the scope of employment, but usually not when those actions are driven by personal reasons of the employee.&lt;/p&gt;
&lt;p&gt;Under the facts in this case, New York's high court may find no cause of action exists, leaving patients/plaintiffs with one less avenue to sue. The risks and&amp;nbsp;exposures remain, however, for health care providers who will incur significant costs defending these actions in court and addressing complaints before state and federal agencies. Strong policies and employee training&amp;nbsp; will not prevent patient claims and complaints, but they will help to put providers in a&amp;nbsp;better position to defend their actions.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/t0na9VJbUg8" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/t0na9VJbUg8/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/03/articles/information-risk-1/new-yorks-highest-court-to-say-whether-medical-practice-can-be-sued-for-wrongful-texts-by-nonphysician-employee/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/tags">Guthrie</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/tags">HITECH</category><category domain="http://www.workplaceprivacyreport.com/tags">Health Information for Economic and Clinical Health Act</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">New York</category><category domain="http://www.workplaceprivacyreport.com/tags">Second Circuit</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category>
         <pubDate>Sun, 31 Mar 2013 20:32:55 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/03/articles/information-risk-1/new-yorks-highest-court-to-say-whether-medical-practice-can-be-sued-for-wrongful-texts-by-nonphysician-employee/</feedburner:origLink></item>
            <item>
         <title>Protecting Trade Secrets with a Mobile Workforce</title>
         <description>&lt;p&gt;With all of the recent&amp;nbsp;discussion about working from home, Cliff Atlas, Co-Chair of&amp;nbsp;the Jackson&amp;nbsp;Lewis&amp;nbsp;Non-competes and Protection against Unfair Competition Practice Group, has posted an article about &lt;a href="http://www.noncompetereport.com/2013/03/18/protecting-trade-secrets-wih-mobile-workforce-and-telecomuters/"&gt;Protecting Trade Secrets with a Mobile Workforce and Telecommuters&lt;/a&gt;. Check it out.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/aA92NaPJl0A" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/aA92NaPJl0A/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/03/articles/data-security/protecting-trade-secrets-with-a-mobile-workforce/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">BOYD</category><category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/tags">Trade</category><category domain="http://www.workplaceprivacyreport.com/tags">secrets</category><category domain="http://www.workplaceprivacyreport.com/tags">telecommuting</category>
         <pubDate>Thu, 21 Mar 2013 11:03:08 -0800</pubDate>
         <dc:creator>V. John Ella</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/03/articles/data-security/protecting-trade-secrets-with-a-mobile-workforce/</feedburner:origLink></item>
            <item>
         <title>President Obama Issues Executive Order On Cybersecurity</title>
         <description>&lt;p&gt;Unwilling to wait for Congress to act,&amp;nbsp;President Obama signed an &lt;a href="http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity"&gt;&lt;strong&gt;executive order&lt;/strong&gt;&lt;/a&gt; on Feb. 12, 2013,&amp;nbsp;the&amp;nbsp;same date that he delivered the State of the Union address.&amp;nbsp;The executive order directs certain&amp;nbsp;federal agencies to develop voluntary standards for achieving&amp;nbsp;cybersecurity, an effort to be led, in part,&amp;nbsp;by the National Institute of Standards and Technology, a component of the Commerce Department.&lt;/p&gt;
&lt;p&gt;Citing national&amp;nbsp;security concerns, the President's order seeks cooperation&amp;nbsp;and collaboration with the private sector. It is unclear at this point how far the &amp;quot;voluntary&amp;quot; standards will reach,&amp;nbsp;or how much the President can force compliance absent Congressional action. However,&amp;nbsp;once in place, companies may feel compelled to comply in order to remain competitive and to ensure a stronger defensible position in litigation involving lapses in security of critical data.&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/hGCr8zdo2jA" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/hGCr8zdo2jA/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/02/articles/information-risk-1/president-obama-issues-executive-order-on-cybersecurity/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/tags">Executive Order</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">NIST</category><category domain="http://www.workplaceprivacyreport.com/tags">National Institute of Standards and Technology</category><category domain="http://www.workplaceprivacyreport.com/tags">Obama</category><category domain="http://www.workplaceprivacyreport.com/articles">Photos, Videos and Surveillance</category><category domain="http://www.workplaceprivacyreport.com/tags">President Obama</category><category domain="http://www.workplaceprivacyreport.com/tags">State of the Union</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">cybersecurity</category>
         <pubDate>Thu, 14 Feb 2013 05:55:35 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/02/articles/information-risk-1/president-obama-issues-executive-order-on-cybersecurity/</feedburner:origLink></item>
            <item>
         <title>NHS Wants Patient Records</title>
         <description>&lt;p&gt;The &lt;a href="http://www.commissioningboard.nhs.uk/"&gt;&lt;strong&gt;National Health Service&lt;/strong&gt;&lt;/a&gt;, which represents a significant part of the United Kingdom's government-run health system, is looking to go paperless. In the process, as part of its &amp;quot;Everyone Counts&amp;quot; initiative, it&amp;nbsp;has plans to require doctors to turn over to NHS significant amounts of patient data. (&lt;a href="http://www.commissioningboard.nhs.uk/files/2012/12/clinical-datasets.pdf"&gt;&lt;strong&gt;Read more about NHS' plan)&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;For example, NHS&amp;nbsp;providers would be required to turn over a patient's&amp;nbsp;NHS number, date of birth, gender, post code, ethnicity code and date of death, among other data elements including diagnosis code, smoking status, alcohol use and so on.&lt;/p&gt;
&lt;p&gt;Just as concerns in the U.S. led to the HIPAA&amp;nbsp;privacy and security regulations, &lt;a href="http://www.guardian.co.uk/world/2013/feb/02/nhs-patient-confidentiality-risk-datbase"&gt;&lt;strong&gt;the Guardian is reporting&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;privacy advocates in the UK are concerned about this collection of personal health information by the government. And there are reasons for concern - it has been &lt;a href="http://www.databreachtoday.co.uk/uk-health-records-breached-18-million-a-5261"&gt;&lt;strong&gt;reported&lt;/strong&gt;&lt;/a&gt; that for the 12-month period&amp;nbsp;ending July 2012, NHS had 16 breaches that exposed 1.8 million health records. It&amp;nbsp;remains to be seen how secure&amp;nbsp;this information will be.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/ouUWaL7CnsA" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/ouUWaL7CnsA/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/02/articles/health-information-technology/nhs-wants-patient-records/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">Everyone Counts</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/tags">NHS</category><category domain="http://www.workplaceprivacyreport.com/tags">National Health Service</category>
         <pubDate>Mon, 04 Feb 2013 05:46:07 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/02/articles/health-information-technology/nhs-wants-patient-records/</feedburner:origLink></item>
            <item>
         <title>Maryland Attorney General Gansler Forms Internet Privacy Unit</title>
         <description>&lt;p&gt;Linking his announcement to &lt;a href="http://www.staysafeonline.org/data-privacy-day/"&gt;&lt;strong&gt;National Privacy Day&lt;/strong&gt;&lt;/a&gt;, January 28, 2013, Maryland Attorney General Douglas F. Gansler &lt;a href="http://www.oag.state.md.us/Press/2013/012813.html"&gt;&lt;strong&gt;informed the public&lt;/strong&gt;&lt;/a&gt; that his office has formed an Internet Privacy Unit. (See &lt;a href="http://www.workplaceprivacyreport.com/2011/09/articles/information-risk-1/connecticut-attorney-general-establishes-privacy-task-force/"&gt;&lt;strong&gt;similar step taken by Connecticut AG&lt;/strong&gt;&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;The stated purpose of the Unit is to protect the&amp;nbsp;privacy of online users. The Unit will be charged with &amp;quot;monitor[ing] companies to ensure they are in compliance with state and federal consumer protection laws.&amp;quot;&amp;nbsp;In addition, the Unit will &amp;quot;examine weaknesses in online privacy policies&amp;quot; and help to create awareness about privacy&amp;nbsp;rights. Of&amp;nbsp;course, the Unit also will&amp;nbsp;pursue enforcement actions&amp;nbsp;to ensure consumer protection.&lt;/p&gt;
&lt;p&gt;As in other states, such as&amp;nbsp;Massachusetts and California, Maryland has a Personal Information Protection Act.&amp;nbsp;&amp;nbsp;The Act provides, in part:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;To protect personal information from unauthorized access, use, modification, or disclosure, a business that owns or licenses personal information of an individual residing in the State &lt;u&gt;shall implement and maintain reasonable security procedures and practices&lt;/u&gt; that are appropriate to the nature of the personal information owned or licensed and the nature and size of the business and its operations.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Md. Code Ann. Comm. Section 14-3503.&amp;nbsp;The Attorney General's Office has published &lt;a href="http://www.oag.state.md.us/idtheft/businessGL.htm"&gt;&lt;strong&gt;some guidance about the data breach provisions of the law&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Maryland businesses and businesses which maintain personal information about Maryland residents should review their online privacy statements, as well as&amp;nbsp;the&amp;nbsp;policies and procedures&amp;nbsp;for&amp;nbsp;safeguarding personal information. In his press release, Attorney General Gansler acknowledged &amp;quot;the emergence and evolution of the Digital Age has created new and significant privacy risks for both consumers and businesses.&amp;quot;&amp;nbsp;Businesses need to&amp;nbsp;be prepared to address these risks and&amp;nbsp;defend&amp;nbsp;against&amp;nbsp;enforcement activities.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/vTUWM56-Gbk" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/vTUWM56-Gbk/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/information-risk-1/maryland-attorney-general-gansler-forms-internet-privacy-unit/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">Internet Privacy Unit</category><category domain="http://www.workplaceprivacyreport.com/tags">MD</category><category domain="http://www.workplaceprivacyreport.com/tags">Maryland</category><category domain="http://www.workplaceprivacyreport.com/tags">Personal Information Protection Act</category><category domain="http://www.workplaceprivacyreport.com/tags">Privacy Day</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category>
         <pubDate>Wed, 30 Jan 2013 14:49:23 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/information-risk-1/maryland-attorney-general-gansler-forms-internet-privacy-unit/</feedburner:origLink></item>
            <item>
         <title>A Summary of the Final HIPAA Rule</title>
         <description>&lt;p&gt;As we continue to examine the final HIPAA privacy and security regulations, as amended by the HITECH Act and the Genetic Information Nondiscrimination Act, &lt;a href="http://www.jacksonlewis.com/resources.php?NewsID=4362"&gt;&lt;strong&gt;we pulled together a summary of some of the key points&lt;/strong&gt;&lt;/a&gt;. We fully expect additional sub-regulatory guidance to be provided by OCR, such as frequently asked questions and&amp;nbsp;&lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractprov.html"&gt;&lt;strong&gt;sample business associate agreement provisions&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/LlW-0a84cQE" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/LlW-0a84cQE/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/a-summary-of-the-final-hipaa-rule/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">GINA</category><category domain="http://www.workplaceprivacyreport.com/tags">Genetic Information Nondiscrimination Act</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/tags">HITECH Act</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/tags">Health Information for Economic and Clinical Health Act</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category>
         <pubDate>Tue, 29 Jan 2013 14:09:44 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/a-summary-of-the-final-hipaa-rule/</feedburner:origLink></item>
            <item>
         <title>Top 13 for 2013 - Happy Privacy Day</title>
         <description>&lt;p&gt;Prepared by &lt;a href="http://www.jacksonlewis.com/people.php?PeopleID=1092"&gt;Jason Gavejian&lt;/a&gt; and &lt;a href="http://www.jacksonlewis.com/people.php?PeopleID=809"&gt;Joseph Lazzarotti&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In honor of National &lt;a href="http://staysafeonline.org/data-privacy-day"&gt;&lt;strong&gt;Data Privacy Day&lt;/strong&gt;&lt;/a&gt;, we have laid out 13 key issues affecting businesses in 2013. While the list is by no means exhaustive, it does provide critical areas businesses will need to consider in 2013.&lt;img align="right" alt="" vspace="3" hspace="3" style="width: 248px; height: 208px;" src="http://www.workplaceprivacyreport.com/uploads/image/DPD-Champion.jpg" /&gt;&lt;/p&gt;
&lt;ol&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;BYOD&lt;/strong&gt;&lt;/u&gt;. As advancements in technology continue at a breakneck pace, many businesses are confronted with the idea of implementing a Bring Your Own Device (&amp;ldquo;BYOD&amp;rdquo;) program. Under these programs, employees are permitted to connect their own personal devices to the company&amp;rsquo;s networks and systems to complete job tasks either in the office or working remotely. While BYOD programs have advantages, they also have associated risks. Developing a thorough implementation strategy with appropriate policies is critical.&lt;/li&gt;
    &lt;li&gt;&lt;strong&gt;&lt;u&gt;Bans On Requesting Social Media Passwords&lt;/u&gt;&lt;/strong&gt;. &lt;a href="http://www.workplaceprivacyreport.com/2012/12/articles/social-networking-1/bans-on-employers-requesting-social-media-passwords-continue-as-new-year-approaches/"&gt;&lt;strong&gt;As we have previously discussed&lt;/strong&gt;&lt;/a&gt;&amp;nbsp; fourteen states introduced legislation in 2012 which would prohibit employers from requiring current, or prospective, employees to disclose a user name or password for a personal social media account. Six states have passed and/or enacted such legislation and it is anticipated that other states will pass similar measures in 2013.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Final HIPAA Regulations&lt;/strong&gt;&lt;/u&gt;. On January 17, 2012, the Office for Civil Rights released final privacy and security regulations under the Health Insurance Portability and Accountability Act. In addition to incorporating the HITECH Act which, among other things, expands the application of the rules to business associates, &lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaa-regulations-business-associates-include-subcontractors-data-storage-companies-cloud-providers/"&gt;&lt;strong&gt;the final rules also apply the rules to&amp;nbsp;subcontractors&lt;/strong&gt;&lt;/a&gt; and remove the risk of harm trigger for data breaches affecting unsecured protected health information.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Disaster Recovery Plans&lt;/strong&gt;&lt;/u&gt;. Hurricane Sandy caused extensive damage on the east coast in 2012, greatly affecting not only personal residences, but many businesses up and down the coast. Unfortunately, protecting information and technology assets from natural disasters and other emergencies is often an afterthought. However, developing a &lt;a href="http://www.workplaceprivacyreport.com/2012/10/articles/information-management/sandy-a-reminder-to-adoptreevaluate-your-disaster-recovery-plan/"&gt;&lt;strong&gt;comprehensive disaster recovery plan &lt;/strong&gt;&lt;/a&gt;now can avoid the significant expense, and often irretrievable loss of data, associated with natural disasters.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Develop a Plan for Responding to a Breach Notification&lt;/strong&gt;&lt;/u&gt;. All state and federal data breach notification requirements currently in effect require notice be provided as soon as possible. Delays in notification viewed as unreasonable could trigger an inquiry by the state&amp;rsquo;s Attorney General, or in the case of HIPAA protected health information, the Office of Civil Rights. This is true &lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/small-hipaa-breach-affecting-fewer-than-500-leads-to-substantial-penalties/"&gt;&lt;strong&gt;even when the number of individuals affected is relatively small&lt;/strong&gt;&lt;/a&gt;.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Investigating Social Media&lt;/strong&gt;&lt;/u&gt;. As the use of social media continues to grow throughout the world, it is only natural that social media content is being sought to aid in litigation. While public content may generally be utilized without issue, if private content is accessed improperly, &lt;a href="http://www.workplaceprivacyreport.com/2012/09/articles/social-networking-1/friend-request-lands-attorneys-in-hot-water/print.html"&gt;&lt;strong&gt;serious repercussions can follow&lt;/strong&gt;&lt;/a&gt;. This is especially true for attorneys and their staff who attempt to aid their clients by accessing social media content.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;International Data Protection&lt;/strong&gt;&lt;/u&gt;. More and more company information is being stored in electronic format and shared with various corporate divisions through company intranets or email. While U.S. law requires some safeguarding of this information, international protections on personal information can be&amp;nbsp;much more stringent. When the transfer of data across international borders is possible, or actively occurring, &lt;a href="http://www.jacksonlewis.com/practices.php?PracticeID=28"&gt;&lt;strong&gt;companies should be advised&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;on the potential risks and requirements associated with same.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Develop a Written Information Security Program&lt;/strong&gt;&lt;/u&gt;. Even if &lt;a href="http://www.workplaceprivacyreport.com/2009/10/articles/written-information-security-p-1/wisp-do-you-have-a-plan-for-your-companys-sensitive-information/"&gt;&lt;strong&gt;adopting a written information security program (WISP)&lt;/strong&gt;&lt;/a&gt; to protect personal information is not an express statutory or regulatory mandate in your state, having one is critical to addressing information risk. Not only will a WISP better position a company when defending claims related to a data breach, but it will help the company manage and safeguard critical information, and may even help the company avoid whistleblower claims from employees. For some companies, a WISP can be a competitive advantage. Of course, in states like &lt;a href="http://www.workplaceprivacyreport.com/2009/11/articles/written-information-security-p-1/the-final-final-massachusetts-data-security-regulations-and-a-checklist-for-compliance/"&gt;&lt;strong&gt;Massachusetts&lt;/strong&gt;&lt;/a&gt;, Maryland, Oregon, Texas, Connecticut and others, a WISP in one form or another is required.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Risk Assessment&lt;/strong&gt;&lt;/u&gt;. Many businesses remain unaware of how much personal and confidential information they maintain, who has access to it, how it is used and disclosed, how it is safeguarded, and so on. &lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/information-management/start-2013-on-the-right-foot-assess-your-organizations-information-risk/"&gt;&lt;strong&gt;Getting a handle on a business' critical information assets must be the first step&lt;/strong&gt;&lt;/a&gt;, and is perhaps the most important step to tackling information risk. You simply can&amp;rsquo;t adequately safeguard something you are not aware exists. And failing to conduct a risk assessment may subject the business to penalties under federal and/or state law.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Insurance&lt;/strong&gt;&lt;/u&gt;. Like many other risks, information risk can be addressed in part through insurance. More carriers are developing products dealing with personal information risk, and specifically data breach response. This kind of coverage should be a part of any CIO, privacy officer or risk manager&amp;rsquo;s toolkit for safeguarding information.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Training&lt;/strong&gt;&lt;/u&gt;. A necessary component of any WISP and a required element under most federal and state laws mandating data security is training. In addition to meeting compliance requirements,&amp;nbsp;training&amp;nbsp;employees and supervisors also will aid in defending any potential breach of privacy claim that may be asserted against the company.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Carefully Integrate New Technologies&lt;/strong&gt;&lt;/u&gt;. As businesses look for new technologies to increase productivity, cut costs, and gain a competitive advantage, how those technologies address information risk must be a factor in the decision&amp;nbsp;to adopt.&lt;/li&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Watch for New Legislation&lt;/strong&gt;&lt;/u&gt;. Today, managing data and ensuring its privacy, security and integrity is critical for businesses and individuals, and is increasingly becoming the subject of broad, complex regulation. As no national law requiring the protection of personal information has yet to be passed in the U.S., companies are left to navigate the constantly evolving web of growing state legislation. Companies therefore need to stay tuned in order to continue to remain compliant and competitive in this regard.&lt;/li&gt;
&lt;/ol&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/I-W24Adm78s" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/I-W24Adm78s/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/data-security/top-13-for-2013-happy-privacy-day/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">BYOD</category><category domain="http://www.workplaceprivacyreport.com/tags">Data Privacy Day</category><category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/articles">Social Networking</category><category domain="http://www.workplaceprivacyreport.com/tags">WISP</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Investigations</category><category domain="http://www.workplaceprivacyreport.com/articles">Workplace Privacy</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">breach</category><category domain="http://www.workplaceprivacyreport.com/tags">breach notification</category><category domain="http://www.workplaceprivacyreport.com/tags">disaster</category><category domain="http://www.workplaceprivacyreport.com/tags">disaster recovery</category><category domain="http://www.workplaceprivacyreport.com/tags">final HIPAA regulations</category><category domain="http://www.workplaceprivacyreport.com/tags">insurance</category><category domain="http://www.workplaceprivacyreport.com/tags">media</category><category domain="http://www.workplaceprivacyreport.com/tags">risk assessment</category><category domain="http://www.workplaceprivacyreport.com/tags">social</category><category domain="http://www.workplaceprivacyreport.com/tags">social media</category>
         <pubDate>Mon, 28 Jan 2013 06:45:49 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/data-security/top-13-for-2013-happy-privacy-day/</feedburner:origLink></item>
            <item>
         <title>Final HIPAA Regulations: "Business Associates" Include Subcontractors, Data Storage Companies (Cloud Providers?)</title>
         <description>&lt;p&gt;Under the HITECH Act,&amp;nbsp;business associates are&amp;nbsp;subject to the HIPAA&amp;nbsp;privacy and security rules (the &amp;quot;HIPAA&amp;nbsp;Rules&amp;quot;) virtually to the same extent as covered entities. In addition to implementing this change for business associates (&amp;quot;BAs&amp;quot;), and providing additional&amp;nbsp;guidance concerning&amp;nbsp;what entities are business associates,&amp;nbsp;the&amp;nbsp;&lt;a href="http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaahitech-privacy-and-security-regulations-released/"&gt;&lt;strong&gt;final HIPAA&amp;nbsp;regulations&lt;/strong&gt;&lt;/a&gt; issued last week&amp;nbsp;also&lt;u&gt; treat certain subcontractors of BAs as BAs directly subject to the HIPAA&amp;nbsp;Rules&lt;/u&gt;. As a result of some of these changes, covered entities and BAs need to re-examine the relationships with their subcontractors to ensure they obtain the appropriate satisfactory assurances concerning the &amp;quot;protected health information&amp;quot; (PHI) they make available to those subcontractors.&lt;/p&gt;
&lt;p&gt;Below are some of the key points from the final regulations concerning BAs and subcontractors:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Subcontractors&lt;/strong&gt;&lt;/u&gt;.&amp;nbsp;The final HIPAA regulations provide that&amp;nbsp;subcontractors&amp;nbsp;that create, receive, maintain, or transmit&amp;nbsp;PHI on behalf of a BA&amp;nbsp;&lt;strong&gt;are business associates. &lt;/strong&gt;This is a significant expansion of the application of the HIPAA&amp;nbsp;Rules; it makes subcontractors directly liable under the HIPAA&amp;nbsp;Rules.&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="margin-left: 40px"&gt;As a result of this change,&amp;nbsp;just as covered entities&amp;nbsp;need to&amp;nbsp;ensure that they obtain satisfactory assurances&amp;nbsp;concerning compliance with the HIPAA&amp;nbsp;Rules (usually in the form of a business associate agreement, BAA) from their BAs,&amp;nbsp;BAs must do the same with regard to certain subcontractors. This must continue&amp;nbsp;no matter how far &amp;ldquo;down the chain&amp;rdquo; the&amp;nbsp;PHI flows.&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;strong&gt;&lt;u&gt;Business Associate Agreement&amp;nbsp;Not Necessary to Establish Status as Business Associate&lt;/u&gt;&lt;/strong&gt;. The final HIPAA&amp;nbsp;regulations confirm that persons&amp;nbsp;and entities&amp;nbsp;that meet the definition of&amp;nbsp;a BA have that status regardless of whether a &amp;quot;business associate agreement&amp;quot; is in place.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Data Storage Companies&lt;/strong&gt;&lt;/u&gt;. Entities that maintain PHI (digital or hard copy) on behalf of a covered entity are BAs, &lt;em&gt;&amp;quot;even if [they] do not actually view the [PHI].&amp;quot;&amp;nbsp;&lt;/em&gt;&amp;nbsp;This&amp;nbsp;provision&amp;nbsp;may create&amp;nbsp;significant compliance issues for cloud service providers, as well as hard copy document storage companies, that have access to the records of their clients&amp;nbsp;but&amp;nbsp;may never look at them.&lt;span id="1358659266187S" style="display: none"&gt;&amp;nbsp;The conduit exception is a narrow one&amp;nbsp;and only applies transmissions of data, not storage.&lt;/span&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;u&gt;&lt;strong&gt;Certain Groups Not Considered Business Associates&lt;/strong&gt;&lt;/u&gt;.
    &lt;ul&gt;
        &lt;li&gt;Researchers generally are not considered BAs when performing research functions.&lt;/li&gt;
        &lt;li&gt;Banking institutions generally are not considered BAs&amp;nbsp;with respect to certain payment&amp;nbsp;processing activities (e.g.,&amp;nbsp;cashing a check or conducting a funds transfer)&lt;/li&gt;
        &lt;li&gt;Malpractice insurers generally are not considered BAs when providing services related to the insurance, but may be&amp;nbsp;BAs when providing risk management and similar services to covered entities.&lt;/li&gt;
    &lt;/ul&gt;
    &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;u&gt;&lt;strong&gt;Transition rule for compliance&lt;/strong&gt;&lt;/u&gt;. A transition rule under the final HIPAA&amp;nbsp;regulations permits covered entities and BAs to continue to operate under certain existing contracts for up to one year beyond the compliance date (September 23, 2013) of the final regulations. A qualifying business associate agreement will be deemed compliant until the earlier of (i)&amp;nbsp;the date such agreement is renewed or modified on or after September 23, 2013, or (ii) September 22, 2014. This rule only applies to the language in the agreements, the parties must operate as required under the HIPAA Rules in&amp;nbsp;accordance with the&amp;nbsp;applicable compliance dates.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Covered entities and business associates may want to act more quickly to identify and contract with those individuals and entities from whom they must obtain satisfactory assurances under HIPAA.&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/05uHh3RsqCY" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/05uHh3RsqCY/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaa-regulations-business-associates-include-subcontractors-data-storage-companies-cloud-providers/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">BA</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/tags">HITECH</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category><category domain="http://www.workplaceprivacyreport.com/tags">business associate</category><category domain="http://www.workplaceprivacyreport.com/tags">business associate agreement</category><category domain="http://www.workplaceprivacyreport.com/tags">subcontractor</category>
         <pubDate>Sat, 19 Jan 2013 20:38:13 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaa-regulations-business-associates-include-subcontractors-data-storage-companies-cloud-providers/</feedburner:origLink></item>
            <item>
         <title>Final HIPAA/HITECH Privacy and Security Regulations Released</title>
         <description>&lt;p&gt;The Office for Civil Rights released&amp;nbsp;on January 17, 2013, &lt;a href="http://www.workplaceprivacyreport.com/uploads/file/2013-01073 HIPAA rules modifiction 01172013.pdf"&gt;&lt;strong&gt;final&amp;nbsp;privacy and security regulations&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;(563 pages) under the Health Insurance Portability and Accountability Act. The rules address four key issues:&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Reflecting the changes made by&amp;nbsp;the Health Information for Economic and Clinical Health Act (HITECH);&lt;/li&gt;
    &lt;li&gt;Revisions to the&amp;nbsp;HIPAA enforcement rule;&lt;/li&gt;
    &lt;li&gt;Updates to the previously issued&amp;nbsp;data breach regulations; and&lt;/li&gt;
    &lt;li&gt;Incorporating the changes made by&amp;nbsp;the Genetic Information Nondiscrimination Act.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In general, covered entities and business associates will need to comply by&amp;nbsp;September&amp;nbsp;23, 2013. We expect to be&amp;nbsp;reporting on some of the key changes shortly. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;u&gt;&lt;a href="http://www.jacksonlewis.com/resources.php?NewsID=4362"&gt;ACCESS SUMMARY HERE&lt;/a&gt;&lt;/u&gt;&lt;/strong&gt;&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/SrfFIGPPrLc" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/SrfFIGPPrLc/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaahitech-privacy-and-security-regulations-released/</guid>
         <category domain="http://www.workplaceprivacyreport.com/articles">Data Security</category><category domain="http://www.workplaceprivacyreport.com/">Featured</category><category domain="http://www.workplaceprivacyreport.com/articles">HIPAA</category><category domain="http://www.workplaceprivacyreport.com/tags">HITECH</category><category domain="http://www.workplaceprivacyreport.com/articles">Health Information Technology</category><category domain="http://www.workplaceprivacyreport.com/tags">Health Information for Economic and Clinical Health Act</category><category domain="http://www.workplaceprivacyreport.com/tags">Health Insurance Portability and Accountability Act</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Management</category><category domain="http://www.workplaceprivacyreport.com/articles">Information Risk</category><category domain="http://www.workplaceprivacyreport.com/tags">OCR</category><category domain="http://www.workplaceprivacyreport.com/tags">Office for Civil Rights</category><category domain="http://www.workplaceprivacyreport.com/articles">Written Information Security Program</category>
         <pubDate>Thu, 17 Jan 2013 15:26:42 -0800</pubDate>
         <dc:creator>Joseph Lazzarotti</dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/hipaa-1/final-hipaahitech-privacy-and-security-regulations-released/</feedburner:origLink></item>
            <item>
         <title>Manti Te'o Story Highlights Reliability of Social Media</title>
         <description>&lt;p&gt;&lt;span style="color: black;"&gt;Unless you have been living under a rock from the past 24 hours, you are familiar with the story of Notre Dame linebacker, and Heisman Trophy runner up, Manti Te&amp;rsquo;o.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black;"&gt;As first &lt;a href="http://deadspin.com/5976517/manti-teos-dead-girlfriend-the-most-heartbreaking-and-inspirational-story-of-the-college-football-season-is-a-hoax"&gt;reported by Deadspin.com&lt;/a&gt; it appears that the story of &lt;a href="http://en.wikipedia.org/wiki/Manti_Te'o"&gt;Manti Te&amp;rsquo;o&amp;rsquo;s&lt;/a&gt; &amp;ldquo;girlfriend&amp;rdquo; and her &lt;img align="right" alt="" vspace="3" hspace="3" style="width: 267px; height: 300px;" src="http://www.workplaceprivacyreport.com/uploads/image/MT.jpg" /&gt;apparent death at the hands of leukemia were an elaborate hoax.&amp;nbsp; Deadspin&amp;rsquo;s article seems to imply that Manti Te&amp;rsquo;o was somehow involved in this hoax, while &lt;a href="http://edition.cnn.com/2013/01/17/sport/manti-teo-controversy/index.html"&gt;CNN.com reports&lt;/a&gt;&amp;nbsp;that both Te&amp;rsquo;o and Notre Dame have insisted that he was simply a victim.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black;"&gt;Lennay Kekua, the name of the &amp;ldquo;girlfriend,&amp;rdquo; is apparently only known through several social media accounts maintained in that name.&amp;nbsp; However, Deadspin reports that it was able to locate the woman whose picture was utilized as the profile picture for Kekua.&amp;nbsp; According to that woman, the picture used was her public Facebook profile shot.&amp;nbsp; Similarly, she informed Deadspin that other pictures reporting to be &amp;ldquo;Kekua,&amp;rdquo; were actual taken from several of her social media accounts.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color: black;"&gt;While the details of this story continue to unfold, the story highlights one of the biggest risks of&amp;nbsp;information obtained through social media; &lt;b&gt;&lt;i&gt;reliability&lt;/i&gt;&lt;/b&gt;.&amp;nbsp;&amp;nbsp; As evidenced by the Te&amp;rsquo;o story, it is not difficult for someone to obtain a photograph of an individual and begin social media interactions in either that person&amp;rsquo;s name, or utilizing that person&amp;rsquo;s likeness.&amp;nbsp; Although this story illustrates one way such a &amp;ldquo;hoax&amp;rdquo; could occur, it is easily conceivable that a &amp;ldquo;fake&amp;rdquo; social media account could be utilized to post discriminatory, hurtful, or insensitive comments in the name of another.&amp;nbsp; While we have previously &lt;a href="http://www.workplaceprivacyreport.com/2012/12/articles/social-networking-1/bans-on-employers-requesting-social-media-passwords-continue-as-new-year-approaches/"&gt;highlighted&lt;/a&gt; some of the issues surrounding an employer&amp;rsquo;s search of social media for employees or prospective employees, in this instance, &amp;ldquo;fake&amp;rdquo; comments could easily cost an individual a job, or a prospective job.&amp;nbsp; While the individual may lose out on employment, it is also possible that the employer is losing an excellent employee due to false information.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WorkplacePrivacyDataManagementSecurityReport/~4/jQ4x5XiQkyM" height="1" width="1"/&gt;</description>
         <link>http://feeds.lexblog.com/~r/WorkplacePrivacyDataManagementSecurityReport/~3/jQ4x5XiQkyM/</link>
         <guid isPermaLink="false">http://www.workplaceprivacyreport.com/2013/01/articles/social-networking-1/manti-teo-story-highlights-reliability-of-social-media/</guid>
         <category domain="http://www.workplaceprivacyreport.com/tags">CNN</category><category domain="http://www.workplaceprivacyreport.com/tags">Deadspin</category><category domain="http://www.workplaceprivacyreport.com/tags">Facebook</category><category domain="http://www.workplaceprivacyreport.com/">Featured</category><category domain="http://www.workplaceprivacyreport.com/tags">Kukua</category><category domain="http://www.workplaceprivacyreport.com/tags">Lennary Kukua</category><category domain="http://www.workplaceprivacyreport.com/tags">Manti Te'o</category><category domain="http://www.workplaceprivacyreport.com/tags">Notre Dame</category><category domain="http://www.workplaceprivacyreport.com/articles">Social Networking</category><category domain="http://www.workplaceprivacyreport.com/tags">Te'o</category><category domain="http://www.workplaceprivacyreport.com/tags">applicant</category><category domain="http://www.workplaceprivacyreport.com/tags">employee</category><category domain="http://www.workplaceprivacyreport.com/tags">employer</category><category domain="http://www.workplaceprivacyreport.com/tags">employment</category><category domain="http://www.workplaceprivacyreport.com/tags">media</category><category domain="http://www.workplaceprivacyreport.com/tags">risks</category><category domain="http://www.workplaceprivacyreport.com/tags">social</category><category domain="http://www.workplaceprivacyreport.com/tags">social media</category>
         <pubDate>Thu, 17 Jan 2013 08:03:16 -0800</pubDate>
         <dc:creator>Jason C. Gavejian </dc:creator>
      
      <feedburner:origLink>http://www.workplaceprivacyreport.com/2013/01/articles/social-networking-1/manti-teo-story-highlights-reliability-of-social-media/</feedburner:origLink></item>
      
   </channel>
</rss>
