Showing posts with label breach notification. Show all posts
Showing posts with label breach notification. Show all posts

Friday, March 20, 2009

HITECH, common sense and where's my bailout?

Full disclosure, I am not a lawyer - and you should work with your legal cousel to determine proper courses of action.

If you haven't been following the ARRA (American Recovery and Reinvestment Act of 2009) and the provisions within it you should. Even there you'll find a focus on increased information technology in human services, cybersecurity and consumer rights.

Signed into law March 17 2009, the ARRA includes the HITECH (Health Information Technology for Economic and Clinical Health) provisions which serve to not only urge physicians to adopt the use of electronic health records, but also tweak the original language of HIPAA. Some of these tweaks are good for consumers, as it provides them more control over their private information while at the same time work intensive for health IT professionals, vendors and Business Associates. The latter is so because the HITECH provisions now require an accountability for all disclosures of PHI. This means that any disclosure or use of PHI now must be accounted for within treatment, payment and operations , whereas before the information could be shared without account for these purposes.

While this may seem trivial, the original language providing for unaccountable exchange of your information, allowed EHR vendors or Business Associates to develop and operate systems without the features needed to provide a full account of every disclosure. While the legislation does not kick into force until 2014, patients will be able to request an accounting of disclosures for up to the last three years - read you might need to be ready by January 1, 2011.

Also updated are the breach disclosure provisions which will now require practices to post information about security breaches if a breach affects 10 or more patients. If a larger security breach occurs, one affecting 500 or more patients, practices must notify all of their patients, a local media outlet, and the HHS secretary. This now brings HIPAA regulations in line with many state's legislation regarding breach disclosure.

And then there's the money. HITECH/ARRA also calls for increased enforcement rules and a new fervor in leveeing financial penalties. Fines for security breaches start at $100 and can go as high as $1.5 million. In addition, the legislation empowers state attorneys general to enforce some HIPAA elements and gives them the authority to bring class action suits.

While there are obvious implications for practices small and large - the affect will be felt throughout the health IT community for years to come. If you or the company(ies) you support work at all with medical information (covered entity or not) you should take the time to review this new legislation, audit your systems and review your policies and procedures.

Sunday, March 2, 2008

Fighting data exposure in small claims court

StorefrontBacktalk's Eric Schuman writes about Theodore Karantsalis's pursuit of Wells Fargo and Sprint Nextel for exposing his personally identifiable information. Interestingly, in this case Karansalis went after both companies in small claims court, claiming that class action rarely saw any real return to the consumer, and that it was often not in a reasonable timeframe.

Schuman asks an interesting question - what happens to large corporations if consumers begin to sidestep the normal process of litigation and take their claims to small claims court. Often, large companies will settle rather than fight, as their costs are higher than the small payouts requested. Karatansalis requested three times the cost of a PGP license ($597) in his claim, and received it. If this became a standard practice, corporations would have to defend themselves more actively, or establish precedent against such claims - something that would be difficult to do if consumers can show real costs associated with the loss of their data.

The original StorefrontBacktalk article can be found here.

Thursday, February 21, 2008

Data Breach Notification requirements, state by state

The Consumerist, an online customer advocacy website pointed out that CSOOnline has put together a comprehensive list of the breach notification laws for each state - 38 states are represented on their map. While the map only covers highlights of each state's laws, it is an interesting way to visualize and review current requirements. The Consumerist article also points out CSO's coverage of current laws moving through Congress in Washington - perhaps we will see a national breach notification law enacted in the next year or two.

Wednesday, April 25, 2007

If you're still shopping here, do you mind if we lose your data again?

There's a post at Emergent Chaos about how many customers you may lose if you lose their data more than once. I recently asked if you would still shop at a company that lost your data. These statistics are interesting, as they show that at least in some populations, there is a direct churn rate effect from repeated data loss. The question remains: what about institutions that you're not a customer of, but instead belong to a population that they service.

How is that different? Well, there are organizations like universities and the VA that will retain records on you long after your a bank, credit card company, or other institution would have hopefully destroyed your data. You will always be a graduate of your alma mater, and you will always be a veteran - and they will retain your data. Another group that we have little choice in dealing with is credit monitoring and reporting agencies - a breach of one of the major agencies could have serious repercussions. We've already seen third party processors announce compromises.

How can you protect yourself in this case? The responsibility lies with the data holder, and that is what should concern us - in some of these cases, there is no motivation to retain customers, we have no way to remove our data from their databases, and in many cases, there are few penalties for losing data that isn't protected via legislation. We may at least hear about it thanks to legislation that requires reporting- and that's a start.

Wednesday, April 18, 2007

Would you shop at a store that lost your data?

Would you shop at a store that lost your data? Would you attend a university that exposed your SSN? Would you donate to that university? If you were a veteran, what would you do if the VA lost your data and didn't know where it went? Do you feel better knowing that your data is out there, and does it worry you to think that many organizations don't announce breaches of your private data?

There seems to be a split between consumers response when polled and their actual behaviors. In the articles I've linked about consumers in the UK, the majority of those polled claimed that they would take their business elsewhere if their data was exposed. The counter article notes that TJ Maxx has gained sales in the past year - in fact, they saw 6% gains in March alone. It may be that notification requirements won't kill our organizations, even if they are embarrassing.

Does this point to consumers accepting data security breaches as commonplace? Stories of people receiving multiple notifications from different organizations in a day or two are floating around, and consumers rail against irresponsible companies. Even if consumers are fed up, it seems that we, as consumers, may be reaching the point that we become used to our data being exposed. The cost of doing business in our current information society is that our data is at risk, and we frequently cannot control how much data companies gather about us. Even if we limit what we give one company, our data can be correlated to data in other databases.

What is the moral of the story for organizations? Is it "Consumers will come back" or is it "Breaches can kill you"? Only time will tell. It may be that in the near term, the huge numbers of organizations leaking data will cause consumers to become inured to the data losses. The legislative backlash that we are seeing nationwide will surely have some effect, both due to required reporting and due to more stringent requirements.

Where does that leave the security professional? With questions, of course:

  1. Are you required by state or federal law to notify, and if so, how, under what circumstances, and how quickly?
  2. What is your organization's breach notification policy?
  3. Do you have procedures in place to handle breach notification?
  4. Do you have an internal communications plan?
  5. Have you looked at insurance? Data breach and information security insurance is just becoming available, and it may be worthwhile for your organization. Dennis Trinkle mentioned insurance in his presentation at the Indiana Higher Education Security Summit - the insurance is out there if you're looking for it.
For now, security folks need to keep track of the laws - both those that are on books, and the bills entering both state and federal legislatures. If you have vendor requirements like PCI you need to make sure that you meet or exceed them. You also need to make sure that our own policies and procedures keep up with both law and other requirements.