Archive for the ‘Privacy and Compliance’ Category

RFID Silliness: Is The Eagle on Your Coin Watching You?

Friday, January 12th, 2007

I saw an article on Yahoo news yesterday, “U.S. warns about Canadian spy coins,” that pointed out a warning issued by the U.S. Defense Security Service about Canadian coins being used to track U.S. government contractors.
The CIA has information about similar types of coins: “This hollow container, fashioned to look like an Eisenhower silver dollar, is still used today to hide and send messages or film without being detected. Because it resembles ordinary pocket change, it is virtually undetectable as a concealment device.”

(more…)

Outsourcing: Dubai Strengthens Data Protection Law

Thursday, January 11th, 2007

On Monday (1/8) the Dubai International Financial Centre (DIFC) implemented a stronger Data Protection Law and appointed a Data Protection Commission to oversee the DIFC.

“The Data Protection Law, which has been amended following a period of public consultation, ensures the protection of all personal information, including any sensitive personal data, and is compliant with the provisions of the laws and directives of the European Union and the guidelines of the Organisation for Economic Co-operation and Development (OECD), including the transfer of data.”

(more…)

HIPAA Mobile and Remote Computing Security Guidance from CMS

Wednesday, January 10th, 2007

Today I received notice that the Centers for Medicare & Medicaid Services (CMS) just issued a new publication, “Security Guidance for Remote Use‚Äù which is actually dated 12/28/2006.

“This document is intended to provide HIPAA covered entities with general information on the risks and possible mitigation strategies for remote use of Electronic Protected Health Information (EPHI).”

(more…)

12 Privacy-Impacting U.S. Federal Bills Introduced on January 4

Wednesday, January 10th, 2007

On January 4th the 110th U.S. congress convened for the first time, and they did not waste any time introducing many new bills. 12 of them have privacy impacts. You can find more information about each of these at the THOMAS (Library of Congress) site. However, as of today (1/10/2007), the full texts for most of these bills are not yet available online.
From the Senate:

(more…)

Identity Theft Examples: Used for Illegal Immigrants

Monday, January 8th, 2007

In the past month around 1,300 employees of Swift & Company were detained during immigrations raids in Iowa, Nebraska, texas, Utah, Minnesota and Colorado.
As many as 220 of those detained face identity theft charges.

(more…)

Michigan Inacts New Identity Theft and Breach Notice Law

Thursday, January 4th, 2007

Yesterday (January 3) Michigan’s governor, Jennifer M. Granholm, signed a new identity theft and breach notification law, SB 309.

“Today’s technology has taken commerce and communication to new heights, but it also puts citizens at additional risk of identity theft as ever-increasing amounts of personal information are stored and transmitted electronically,” Granholm said. “While I am pleased to sign legislation that provides critical information to consumers, we must do more to provide our citizens with the tools they need to truly protect themselves.”

(more…)

Potential Personal Data Breach of 5.38 Million Individuals at Nissan in Japan

Tuesday, January 2nd, 2007

I ran across an interesting news report,”Nissan data leak puts 5 million at risk
I was surprised I did not see this report on any of U.S. news sites. The report is very vague. It just indicates a “leak” occurred between May 2003 and February 2004. A small excerpt:

(more…)

Regulatory Compliance Actions Must Include Effective, ongoing Awareness and Training Efforts

Friday, December 29th, 2006

A great article was published on Law.com today written by Ryan Sulkin, “First Line of Defense Against Data Security Breaches: Employees.”
There are several points made that I hope business leaders read and take to heart.

(more…)

Psychotherapy Notes Fiasco and HIPAA: Bad Legislation, Bad Enforcement, or Bad Covered Entity?

Thursday, December 28th, 2006

The Pittsburgh Post-Gazette ran an interesting story today, “Spread of records stirs fears of privacy erosion.”
Basically this describes the trials and tribulations of a woman was denied disability benefits from her insurer following a car accident because of notes made by her psychologist. Reportedly the psychologist notes were intermingled with her general medical records.

(more…)

US SAFE WEB Act Signed Into Law Today

Tuesday, December 26th, 2006

Today the FTC announced President G.W. Bush signed the US SAFE WEB Act into law.

“Statement by Federal Trade Commission Chairman Deborah Platt Majoras On US SAFE WEB Act Being Signed Into Law by President George W. Bush
I am grateful to President Bush for signing the US SAFE WEB Act into law. The Act will help the Federal Trade Commission fight a range of practices that harm
American consumers – including fraudulent spam, spyware, misleading health and safety advertising, privacy and security breaches, and telemarketing fraud.
These practices are increasingly global in nature, and the US SAFE WEB Act will improve the FTC’s ability to cooperate with its foreign counterparts to combat them.”

(more…)