Showing posts with label data accountability. Show all posts
Showing posts with label data accountability. Show all posts

Wednesday, January 13, 2010

Deadlines for data security requirements



This advisory provides a brief summary of new data security requirements with effective and enforcement dates in early 2010 that will affect innumerable businesses.

State Data Security Developments

January 1, 2010: New Amendment to Nevada Privacy Law
A new amendment to Nevada privaQQcy law that became effective January 1, 2010 requires companies doing business in Nevada that accept payment cards to comply with the Payment Card Industry Data Security Standards (“PCI DSS”).

The new amendment also requires QQthat other data collectors doing business in Nevada encrypt personal information contained in certain kinds of transmissions and when stored on a data storage device.

While Nevada appears to be the QQfirst state to require such compliance, others may follow.

March 1, 2010: Massachusetts Security Regulation Affecting All Companies with Personal Information of Massachusetts Residents

Under the Massachusetts Security QQRegulation (201 CMR 17.00) (the “Regulation”), every person or company that owns or licenses certain personal information about a Massachusetts resident must develop, implement, maintain and monitor a comprehensive written information security program (“WISP”).

The applicability of the Regulation QQis very broad, extending to any company that has personal information of Massachusetts residents, whether or not the company is doing business in Massachusetts. The Regulation does not exempt any industry, sector or out-of-state business, and does not exempt a de-minimus number of Massachusetts customers, employees or other residents. Compliance is required by March 1, QQ2010.


Federal Data Security Developments

February 17, 2010: Expanded Reach of Federal HITECH Act Protecting Health Information
The HITECH Act imposed substantial QQparts of the HIPAA privacy rule and the HIPAA information security rule directly on business associates.

HITECH imposed changes to the QQ“minimum necessary rule” for the use and disclosure of protected health information for uses and disclosures other than treatment, with the limited data set serving as a “safe harbor” pending further regulations. The Act also requires covered entities to provide patients with a copy of their electronic protected health information (“PHI”) in electronic format, or to transmit electronic PHI to other providers in electronic format at the patient’s request. Also, new restrictions on the use and disclosure of protected health information for marketing purposes will take effect. Covered entities should have new business associate agreements in place that reflect new privacy and security requirements by this date.

February 22, 2010: Full Enforcement of Health Data Breach Notification Rules
Full enforcement of the HIPAA data QQbreach notification rule for covered entities and business associates will begin on February 22, 2010. Similarly, the Federal Trade Commission will begin enforcing the data breach rules applicable to personal health record vendors and their contractors on February 22, 2010.

June 1, 2010: Broad Upcoming Federal Requirements – Red Flags Rule
The federal Red Flags Rule (16 CFR QQ681.1) requires that financial institutions and “creditors” (which is very broadly defined) develop and implement written Identity Theft Prevention Programs in order to detect, prevent, and mitigate identity theft.

For financial institutions, comQQpliance has been required since November 28, 2008.
For “creditors” that maintain “covQQered accounts,” the Red Flags Rule will go into effect June 1, 2010. The term “creditor” is broadly defined, causing concern that the Red Flags Rule reaches entities other than traditional financial institutions or creditors that engage in regular loans or advances, including businesses that offer forbearance in the collection of debts or bills, or which allow multiple or extended payments for goods or services that have been previously provided.

European Data Security Developments
In addition to complying with US data protection, most US companies with subsidiaries in the European Union need to be aware of the data protection laws in the EU, enforcement, and the penalties for non-compliance. There are new penalties for data protection violations and breaches in Germany, and a proposal for increased penalties pending in the UK, as noted below. Further, those publicly traded firms implementing whistleblowing programs for subsidiaries in the EU in order to comply with two important US laws, the Sarbanes-Oxley Act of 2002 and the Foreign Corrupt Practices Act, should also take note of recent important whistleblower decisions, guidelines or directions in France, Denmark, Sweden, Portugal, Austria, and Hungary.

United Kingdom
Pending the outcome of a recent QQMinistry of Justice consultation, the Information Commissioner’s Office (ICO) in the UK may be given increased statutory powers to impose fines up to £500,000.

This would apply when the ICO is QQsatisfied that: (i) there has been a serious breach of one or more of the data protection principles of the organizations; and (ii) the breach was likely to cause substantial damage/distress, i.e., if the breach was deliberate or the organization knew or should have known there was a risk, such as by the reckless handling of personal data.

As some data breaches may include QQindividual names in other countries, the fine levels of those authorities become increasingly important.

Germany
The German Federal Parliament QQpassed comprehensive amendments to the Federal Data Protection Act, effective September 1, 2009, that cover a broad variety of data protection issues and give fine authority of € 50,000 for simple violations and € 300,000 for serious violations.

The data protection authorities QQhave been given these new powers to enable them to impose higher fines for failure to comply with data protection requirements, especially on the security side. lexology

Monday, September 21, 2009

What to Know About Red Flags, Notification Laws and the Hi Tech Act


Data breaches have hit an all time high and with that have been a dramatic increase in new data security and privacy laws and regulations. Both state and federal regulations have been in place for several years with regards to security and privacy of Personal Identifiable Information (PII) and Protected Health Information (PHI). However, new regulations have popped up at a rapid pace. Just a few years ago there were only a handful of states that had data breach notification laws. Today, 44 states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted data breach privacy laws and federal legislation is well on its way.

Today, more than ever, it is difficult for business owners and chief information officers (CIO) to navigate the ever expanding minefield of data breach privacy laws. Just as we have begun to get comfortable understanding laws like HIPAA, Gramm-Leach-Bliley and the Fair Credit Reporting Act, businesses now have to decipher the Red Flags Rule, Hi Tech Act and a myriad of state notification laws. Following is a list of current regulations that business owners and CIOs should be familiar with, including some key compliance dates.

State Notification Laws

The majority of states (44 as of this writing plus the District of Columbia, Puerto Rico and the Virgin Islands) have enacted data breach notification laws. These laws require businesses to timely notify any customer or patient that may be affected by a data breach. Every state has their own unique requirements as to the format of notification, time frame with which to notify, and content of the notification letter. In many cases, failure to notify pursuant to a particular state's notification law may lead to fines and penalties imposed upon the business owner.

Red Flags Rule

In November 2007, Federal Banking Agencies and the Federal Trade Commission (FTC) created an addition to the Fair Credit Reporting Act called the "Red Flags Rule". The Red Flags Rule applies to "financial institutions" and "creditors" with "covered accounts," as defined by the regulation. The intent was to have affected businesses implement an identity theft prevention program. However, there has been a tremendous amount of controversy over the terms "creditors" and "covered accounts." The law is not perfectly clear as to what these terms mean and has a number of business groups concerned about their requirement to comply with the regulation. For example, it has been debated if a health care provider, such as a physician or dentist, is considered a "creditor" under the rule. A "creditor" is defined as any entity that regularly extends, renews or continues credit or any entity that regularly arranges for the extension, renewal or continuation of credit. Under this description, many businesses may be required to comply with the Red Flags Rule. Recently, the FTC has extended the date for compliance to Aug. 1, 2009.

Massachusetts 201 CMR 17.00 (Standards for the Protection of Personal Information of Residents of the Commonwealth)

In September 2008 the Massachusetts Office of Consumer Affairs & Business Regulation issued a regulation intended to protect the unauthorized disclosure of personal information of Massachusetts residents. The regulation establishes very strict requirements for any "persons who own, license, store or maintain personal information about a resident of the Commonwealth of Massachusetts" with regards to ensuring the security and confidentiality of personal information.

What makes this specific state law so important is that it applies to any person or business, whether or not they are domiciled in the state of Massachusetts, that have personal information on even one resident of Massachusetts. This regulation mandates sweeping changes in the development of data security protection. In addition to the expanded data protection requirements, the new law also includes penalties for non-compliance (violators may be subject to a $5,000 civil penalty for each violation of each affected person). Compliance with the new regulation has been postponed until Jan. 1, 2010.

Hi-Tech Act

Part of the 2009 American Recovery and Reinvestment Act, otherwise known as the Stimulus package, the HITECH Act provides incentives for physicians who implement "meaningful use" of an Electronic Health Record system. While the exact criteria are still being defined, such systems must be able to electronically e-Prescribe, exchange information, and submit clinical quality measures. In short, the federal government is making it mandatory for health care providers to disclose and disperse reams of personal data electronically. What this act also does is create a federal notification requirement for the breach of Protected Health Information. So in addition to the 44 state notification requirements, health care professionals will have to comply with a federal mandate to notify patients if their records have been compromised. Since this regulation is still new, it is not known how this will impact health care providers in their expanded requirements to notify patients of potential breaches.

What's Around the Corner?

H.R. 2221, the Data Accountability and Trust Act, recently passed the House subcommittee on Commerce, Trade, and Consumer Protection by a voice vote during a markup session. The bill, which was introduced by House Subcommittee Chair Rep. Bobby Rush, D-Ill., would require businesses to notify affected customers when outside parties gain access to sensitive information due to a security breach. If this act is passed it will create yet another data breach notification law for businesses to comply with and, additional costs imposed upon them in the event of a data breach.

Insurance and Risk Management Solutions

With this rapid expansion of data breach laws, the insurance industry has responded by introducing innovative new insurance products to protect businesses from data security breaches and failure to protect personal information of customers and patients. Cyber liability or security and privacy insurance has been developed by a number of insurance carriers to provide coverage for exposures, such as:

•First Party Coverages — network attack business income and extra expense; cyber extortion; crisis management expenses; and notification costs and credit monitoring expenses.

•Third Party Coverages — network security liability; privacy liability; regulatory defense coverage (including fines and penalties); and Internet and media liability.

The policy forms that exist in the marketplace today are not all alike and there are no standard policy forms. Each policy requires extensive review and analysis in order to determine the coverage needs of each prospective insured.

In addition to the insurance policies provided by insurance carriers, there are also risk management services that are provided via third party vendors. There are a number of third party vendors that offer services, including: network security policy and procedure development; network security exposure analysis; crisis management services; forensic investigation services; credit monitoring services, among other services.

With the number of known data breaches and data breach costs on the rise, the increase in legislation and the availability of insurance and risk management solutions, it is imperative that business owners review and analyze the costs associated with compliance of these new laws and the cost to transfer the risk.

Insurance Journal