Friday, March 28, 2008
FTC Announces Settlement With TJX, Lexis
The FTC agreed to settle charges with discount retailer TJX and data broker Reed Elsevier. The FTC had sued each of the companies for failing to adequately protect the security of consumer data. Both of the FTC's suits were brought under the unfair trade practices theory under Section 5(a) of the Federal Trade Commission Act, 15 U.S.C § 45(a). The TJX Complaint is available here; the Reed Elsevier Complaint is available here.
Wednesday, March 26, 2008
Patient Data Exposed Online
Today's Baltimore Sun reports on an incident involving Dental Network, a CareFirst BlueCross BlueShield dental HMO, in which the company accidentally exposed personal information, including Social Security numbers, of about 75,000 members on a public website. A Maryland Law (SB 194) enacted last year requires that businesses notify consumers of a breach of their personal information "as soon as reasonably practicable after the business discovers or is notified of the breach." In this case, it took 3 weeks before CareFirst notified customers of the breach.
Thursday, March 20, 2008
Goal Financial Settles Charges Of Failing To Safeguard Sensitive Information
Student loan company Goal Financial LLC has agreed to settle with the FTC over charges that it failed to adequately safeguard sensitive customer information. The FTC's Complaint alleges a number of violations, including violations of the Commission’s Standards for Safeguarding Customer Information Rule, 16 C.F.R. Part 314, and the Commission’s Privacy of Customer Financial Information Rule, 16 C.F.R. Part 313. Also see the Consent Order Agreement.
Tuesday, March 04, 2008
Identity Theft At Major Financial Institutions
Until recently, there has been no way to compare the relative incidence of identity theft at major financial institutions. Chris Hoofnagle's study "Measuring Identity Theft at Top Banks" uses a novel approach: he compared complaint data from various banks submitted by victims of identity theft, obtained through FOIA requests. The study makes clear that the incidence of identity theft is alarmingly high at our major financial institutions, but that some institutions faired better than others.
More Data Breach Resources
CSOonline has a number of interesting articles on the subject of security breach legislation. First, check out their interactive map of security breach legislation. Also see their articles "What's New With Disclosure Legislation?" (interview with Proskauer Rose attorney Tanya Forsheit) and "The Dos And Don'ts of Disclosure Letters." Finally, see this blog posting on what a federal databreach law would look like.
Monday, March 03, 2008
Anti Cybersquatting Suits Becoming Increasingly Popular
A recent article in the National Law Journal entitled "Suits a new weapon to fight cybersquatters" (subscription) reports that companies are increasingly filing suits under the Anticybersquatting Consumer Protection Act of 1999 (codified at 15 USC 1125(d)) to deal with cybersquatters who profit from their brand names. Traditionally, the preferred route for companies to resolve this type of dispute would have been through arbitration. That method has proved ineffective against increasingly sophisticated cybersquatters. As a results, many companies have begun filing law suits.
Monday, February 18, 2008
Wireless Security Whitepaper
Finish IT security firm Codenomicon recently posted this white paper on the current status of wireless security.
Businesses Generally Ignoring E-Discovery Rules
According to this article from eweek, a little over a year after the ediscovery rules went into effect, "about two-thirds of U.S. businesses remain unprepared to meet strict court requirements for the discovery and handling of electronic evidence."
Friday, February 15, 2008
E-Discovery Guidelines In US District Courts
The Electronic Discovery Law blog compiled a list of links to the 38 US District Courts that have adopted (or at least considered) local ediscovery rules and guidelines.
Thursday, February 14, 2008
Identity Theft Tops FTC Complaint List
According to the FTC's annual report on the subject, identity theft topped the list of FTC complaints for the 7th year in a row. Roughly 32% (or over 260,000) of the Agency's 2007 complaints were due to identity theft. The report also demonstates that the most frequent type of identity theft complaint in 2007 was credit card fraud (23%). The metropolitan areas reporting the highest per capita rates of identity theft were Napa, California; Madera, California; and Greeley, Colorado.
Tuesday, February 12, 2008
Annonymity On The Net
Is there a First Amendment right to speak annonymously on the internet? A recent California Appellate (Krinsky v. Doe 6) case holds that, under certain circumstances, there is. In that case, plaintiffs argued that the identity of a individual who posted "scathing verbal attacks" on an online message board against corporate officers of a Florida company should be exposed. Plaintiffs served a subpoena to have the identity of "Doe 6" disclosed but the request was denied.
Monday, February 11, 2008
Spam Ring Indicted
A federal indictment was recently unsealed in Detroit, charging 11 people with violations of the CAN SPAM Act. The DOJ release alleges that the defendants set up "an international scheme to make money by manipulating stock prices through illegal spam e-mail promotions." The indictment also alleges that the defendants tried to send their spam through the use of botnets.
Thursday, February 07, 2008
Red Flag Regulations
The most recent National Law Journal features an article entitled "Scrambing With ID Theft Programs" (subscription) discussing the so-called "Red Flag Regulations" which implement two sections of the Fair and Accurate Credit Transactions Act. The regulations, formally termed
"Identity Theft Red Flags and Address Discrepancies under the Fair and Accurate Credit Transactions Act of 2003," require financial institutions and companies offering consumer credit to institute identity theft prevention programs to detect "red flags" which might signal possible foul play. The regs go into effect Nov. 1 of this year.
"Identity Theft Red Flags and Address Discrepancies under the Fair and Accurate Credit Transactions Act of 2003," require financial institutions and companies offering consumer credit to institute identity theft prevention programs to detect "red flags" which might signal possible foul play. The regs go into effect Nov. 1 of this year.
Tuesday, February 05, 2008
FTC Settlement With Life Is Good, Inc.
The FTC recently announced a Proposed Settlement with clothing company Life Is Good, Inc. The FTC's Complaint against the company had alleged that the company, contrary to it's privacy policy, failed to adequately protect and secure the sensitive information it maintained about its customers. The proposed settlement requires, among other things, that the company designate at least one employee to coordinate the security program and that the company develop reasonable procedures for selecting and supervising service providers that handle customers’ personal information.
Monday, February 04, 2008
Preparing For A Data Breach
Philip Gordon of the Workplace Privacy Counsel blog provides 5 key points for employers to consider as they prepare for the possibility of a data breach: be prepared, train your HR professionals, determine your notice obligations, help your employees, and learn from your mistakes.
Thursday, January 31, 2008
MD Identity Theft Task Force Issues Report
The Maryland Task Force to study Identity Theft recent published it's report. Over 230 pages, the report recommends, among other things, that the penalties for felony identity theft be increased, that the State ban credit card skimming devices, and that the State should enact legislation to enable a court to order the forfeiture of all property of a criminal convicted of identity theft obtained from the crime.
Wednesday, January 30, 2008
EDD In Criminal Investigations
The DOJ's publication, "Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations," provides a comprehensive guide to the legal issues that arise when federal law enforcement agents search and seize computers during criminal investigations. Topics covered include the Electronic Communications Privacy Act, workplace privacy, and the law of electronic surveillance.
Thursday, January 24, 2008
EDD Opinions By Judge Grimm
In the past few years, Judge Paul W. Grimm of the US District Court in Maryland has issued a couple of groundbreaking electronic discovery opinions: Lorraine v. Markel American Insurance Company (DMd May 4, 2007) and Hopson v. Mayor and City Council of Baltimore (D.Md.2005). For more on Lorraine see here and here. For a summary of the Hopson decision see here. Judge Grimm has also authored a Suggested Protocol For Discovery of Electronically Stored Information discussed in an earlier post.
Wednesday, January 09, 2008
Sears Sued For Failing To Adequately Protect Website
This Washington Post article reports on a class action suit against Sears for failing to adequately secure the personal information on its website managemyhome.com. The site's security vulnerabilities came to light after Ben Edelman pointed out the ease with which anyone could access the purchase history of the site's users. See here for a copy of the Complaint filed in Cook County, Illinois.
Thursday, January 03, 2008
Google Not Required To Disclose Identity of Blogger
Google has no obligation to disclose the identity of a blogger who used Blogger.com to allegedly defame a Long Island school board member. Judge Marcy S. Friedman of the New York County Supreme Court called the blogger's statements opinions rather than actionable statements of fact. As such, there is no case for defamation and Google has no obligation to turn over the records. Greenbaum v. Google Inc. (N.Y. Sup. Ct., N.Y. County Oct. 23, 2007).
Subscribe to:
Posts (Atom)