NEW YORK (CNNMoney) -- The government received more than a million
consumer complaints last year, with identity theft enraging the most
people.
The Federal Trade Commission counted 250,854 complaints about identity
theft in 2010, according to a report issued Tuesday. That was 19% of
the 1.3 million total complaints the agency received, putting it at
the top of the consumer complaint list for the 11th year in a row.
The most common form of identity theft was through fraudulent
government documents. Credit card fraud garnered the second highest
number of identity theft complaints, followed by phone and utilities
fraud. Overall, Florida residents reported the highest per capita rate
of identity thefts.
After identity theft, debt collection racked up the second highest
number of complaints, making up 11% of overall complaints. Internet
services and prizes, sweepstakes and lotteries each accounted for 5%
of complaints, followed by shop-at-home and catalog sales, which made
up 4%.
Fraud-related complaints accounted for 54% of total complaints, with
consumers reporting that they were scammed into paying more than $1.7
billion -- or a median of $594 per person -- last year.
About 45% of consumers reporting fraud said that transactions were
initiated by e-mail; 11% said they were lured through a website.
For the first time, imposter scams -- where scammers pose as friends,
family, government agencies or companies to trick consumers into
sending them money -- were also among the top 10 complaints.
Internet auctions, foreign money offers and counterfeit check scams,
telephone and mobile services and credit cards rounded off the list of
top ten things consumers complained about last year.
Friday, March 11, 2011
Midlands Tech warns employees of security breach
Midlands Technical College warned employees last month that a flash
drive containing some of their personal information was taken from a
human resources office at the college.
The flash drive, since returned — without the personal data it
previously held — could compromise the personal information of some of
the college’s 500 employees. But Midlands Tech spokesman Todd Gavin
said no problems have been reported by employees so far.
“There’s no reason to believe that anybody’s information was
compromised,” Gavin said. “The college is already working on an
internal audit of its security to make sure this doesn’t happen
again.”
The security breach at Midlands Tech is the second acknowledged by an
area college or university in the last week. The University of South
Carolina warned employees earlier this month that a breach of
computers at its Sumter campus exposed the personal information of
31,000 faculty, staff, retirees and students system-wide.
USC officials, like those at Midlands Tech, said there is no evidence
that anyone’s personal information was used improperly.
Gavin said no student information was compromised in the Midlands Tech
breach, which occurred at the college’s Airport campus.
In an e-mail dated Feb. 18, Crystal Rookard, human resource director
and legal counsel at Midlands Tech, told employees: “We take this
situation very seriously and recognize our responsibility to maintain
your confidence in our ability to protect confidential information.”
A painter who was working near the human resources office where the
flash drive was located has been questioned by law enforcement, Gavin
said, adding he does not know if or when charges might be filed.
“We don’t know how it got blank,” Gavin said of the flash drive. “We
don’t think it was blank to begin with.”
Rookard told employees, “The individual responsible for removing the
flash drive has indicated that the flash drive was not accessed or
viewed at any point.”
In addition to the internal review of security procedures, Gavin said
Midlands Tech is offering employees free credit monitoring. “To date,
nobody’s reported anything out of the ordinary on their credit.”
drive containing some of their personal information was taken from a
human resources office at the college.
The flash drive, since returned — without the personal data it
previously held — could compromise the personal information of some of
the college’s 500 employees. But Midlands Tech spokesman Todd Gavin
said no problems have been reported by employees so far.
“There’s no reason to believe that anybody’s information was
compromised,” Gavin said. “The college is already working on an
internal audit of its security to make sure this doesn’t happen
again.”
The security breach at Midlands Tech is the second acknowledged by an
area college or university in the last week. The University of South
Carolina warned employees earlier this month that a breach of
computers at its Sumter campus exposed the personal information of
31,000 faculty, staff, retirees and students system-wide.
USC officials, like those at Midlands Tech, said there is no evidence
that anyone’s personal information was used improperly.
Gavin said no student information was compromised in the Midlands Tech
breach, which occurred at the college’s Airport campus.
In an e-mail dated Feb. 18, Crystal Rookard, human resource director
and legal counsel at Midlands Tech, told employees: “We take this
situation very seriously and recognize our responsibility to maintain
your confidence in our ability to protect confidential information.”
A painter who was working near the human resources office where the
flash drive was located has been questioned by law enforcement, Gavin
said, adding he does not know if or when charges might be filed.
“We don’t know how it got blank,” Gavin said of the flash drive. “We
don’t think it was blank to begin with.”
Rookard told employees, “The individual responsible for removing the
flash drive has indicated that the flash drive was not accessed or
viewed at any point.”
In addition to the internal review of security procedures, Gavin said
Midlands Tech is offering employees free credit monitoring. “To date,
nobody’s reported anything out of the ordinary on their credit.”
WikiLeaks cables are America's worst security breach, says John McCain
THE leaking of secret cables to the WikiLeaks website run by
Australian Julian Assange was the most damaging breach of US security
ever, senior American political figure Senator John McCain says.
Security issues featured in talks between Prime Minister Julia Gillard
and the former Republican presidential candidate and ranking member on
the US Senate's armed services committee during her visit to
Washington.
The US Government is considering its legal options in relation to Mr
Assange, which could include a treason charge, and the alleged
instigators of the leaking of 250,000 diplomatic cables.
Intelligence analyst Private First Class Bradley Manning is being held
in the Marine Corps brig in Quantico, Virginia, pending his appearance
on a raft of charges over the alleged leaking of the Government files
to WikiLeaks a year ago.
Senator McCain said after the meeting with the Prime Minister the
WikiLeaks issue had serious implications for all aspects of global
security.
"It is the greatest, most damaging security breach in the history of
this country," he said.
What was most concerning were the revelations of people in places such
as Iraq and Afghanistan who were cooperating with intelligence
services, he said.
"It literally puts their lives in danger," Senator McCain said.
He said those responsible for giving Private Manning access to such
high-security documents also needed to be brought to account.
"He couldn't have done all of that by himself," he said.
Asked whether Australia would help in any future extradition of Mr
Assange, the Prime Minister said she would not speculate.
"The only legal matter affecting Mr Assange are matters stemming out
of proceedings in Sweden," she said, referring to the sex charge
against the internet whistleblower.
"At every stage Mr Assange has received consular assistance, just as
any other Australian would receive." Mr Assange is appealing against
his extradition to Sweden.
Australian Julian Assange was the most damaging breach of US security
ever, senior American political figure Senator John McCain says.
Security issues featured in talks between Prime Minister Julia Gillard
and the former Republican presidential candidate and ranking member on
the US Senate's armed services committee during her visit to
Washington.
The US Government is considering its legal options in relation to Mr
Assange, which could include a treason charge, and the alleged
instigators of the leaking of 250,000 diplomatic cables.
Intelligence analyst Private First Class Bradley Manning is being held
in the Marine Corps brig in Quantico, Virginia, pending his appearance
on a raft of charges over the alleged leaking of the Government files
to WikiLeaks a year ago.
Senator McCain said after the meeting with the Prime Minister the
WikiLeaks issue had serious implications for all aspects of global
security.
"It is the greatest, most damaging security breach in the history of
this country," he said.
What was most concerning were the revelations of people in places such
as Iraq and Afghanistan who were cooperating with intelligence
services, he said.
"It literally puts their lives in danger," Senator McCain said.
He said those responsible for giving Private Manning access to such
high-security documents also needed to be brought to account.
"He couldn't have done all of that by himself," he said.
Asked whether Australia would help in any future extradition of Mr
Assange, the Prime Minister said she would not speculate.
"The only legal matter affecting Mr Assange are matters stemming out
of proceedings in Sweden," she said, referring to the sex charge
against the internet whistleblower.
"At every stage Mr Assange has received consular assistance, just as
any other Australian would receive." Mr Assange is appealing against
his extradition to Sweden.
Corporate data breach average cost hits $7.2 million
Corporate data breach average cost hits $7.2 million
March 8, 2011 by admin
Filed under Commentaries and Analyses
The cost of a data breach went up to $7.2 million last year up from
$6.8 million in 2009 with the average cost per compromised record in
2010 reaching $214, up 5% from 2009.
The Ponemon Institute.s annual study of data loss costs this year
looked at 51 organizations who agreed to discuss the impact of losing
anywhere between 4,000 to 105,000 customer records. The private-sector
firms participating in the Ponemon Institute.s .2010 Annual Study:
U.S. Cost of a Data Breach. hail from across various industries,
including financial services, retail, pharmaceutical technology and
transportation.
March 8, 2011 by admin
Filed under Commentaries and Analyses
The cost of a data breach went up to $7.2 million last year up from
$6.8 million in 2009 with the average cost per compromised record in
2010 reaching $214, up 5% from 2009.
The Ponemon Institute.s annual study of data loss costs this year
looked at 51 organizations who agreed to discuss the impact of losing
anywhere between 4,000 to 105,000 customer records. The private-sector
firms participating in the Ponemon Institute.s .2010 Annual Study:
U.S. Cost of a Data Breach. hail from across various industries,
including financial services, retail, pharmaceutical technology and
transportation.
Fringe: ISTEP breach may lead to 80, 000 test scores thrown out
The Indiana Department of Education has reason to believe security was
breached during this week's ISTEP testing.
That means tens of thousands of scores may have to be thrown away.
The DEA says an essay question for the test was leaked.
Officials think a test coordinator copied the question and shared it
with others. One eventually posted it on a Facebook page connected
with a teachers group.
The question apparently asked students their opinion on school vouchers.
The test results of about 80,000 8th graders may have to be invalidated.
breached during this week's ISTEP testing.
That means tens of thousands of scores may have to be thrown away.
The DEA says an essay question for the test was leaked.
Officials think a test coordinator copied the question and shared it
with others. One eventually posted it on a Facebook page connected
with a teachers group.
The question apparently asked students their opinion on school vouchers.
The test results of about 80,000 8th graders may have to be invalidated.
Friday, February 25, 2011
Report details health care reform theft
As the nation moves toward growing use of electronic medical records,
data vulnerability becomes increasingly evident.
A new report released on Wednesday by Kaufman, Rossin & Co., showed
4.9 million patients had their personal health information compromised
as a result of 166 data breaches that occurred during the first year
of the Health Information Technology for Economic and Clinical Health
(HITECH) Act
The act was signed into law in February 2009 to promote the adoption
and meaningful use of health information technology. It also provides
for more stringent fines for privacy breaches.
Of the breaches in the study, laptops were the greatest source, being
involved in 43 cases and affecting more than 1.5 million individuals.
All of the breaches occurred between Sept. 21, 2009 and Sept. 21 2010,
the first year when breach incidents were publicly reported to the
Secretary of the Department of Health and Human Services
“There are so many various ways for data to be breached in this day
and age and many businesses are not properly prepared or are
completely unaware of just how vulnerable this information is,” said
Jorge Rey, the study’s co-author and director of information security
and compliance with Kaufman, Rossin. “The HITECH Act is changing the
way PHI must be protected and those companies that are not serious
about protecting their patients’ information find themselves facing
serious reputation, legal and financial repercussions.”
Among other findings:
Theft was the primary cause of a data breach, occurring 58 percent of
the time; loss and other were tied in second at 14 percent.
20 percent of the breaches occurred at a business associates.
Theft affected the highest number of individuals: 3.12 million
32 percent of breaches were reported within the first three months
The report notes that data breaches come in various forms, from
hacking to medical information that is mailed to the wrong address,
though the later is responsible for a very small amount of the
breaches.
The report sites some examples of theft such as:
An impostor posing as a representative of a legitimate vendor stole
several barrels of purged x-ray films, which contained the health care
information of approximately 1,300 patients.
A laptop computer was stolen from a hospital employee’s vehicle that
contained the health care information of 943 patients
A binder with printed protected health information was stolen from an
employee’s vehicle and contained the information of up to 1,272
patients.
The report goes on to recommend that health care organizations review
their security policies, encrypt new and existing laptops and perform
detailed annual risk assessments, among other things.
data vulnerability becomes increasingly evident.
A new report released on Wednesday by Kaufman, Rossin & Co., showed
4.9 million patients had their personal health information compromised
as a result of 166 data breaches that occurred during the first year
of the Health Information Technology for Economic and Clinical Health
(HITECH) Act
The act was signed into law in February 2009 to promote the adoption
and meaningful use of health information technology. It also provides
for more stringent fines for privacy breaches.
Of the breaches in the study, laptops were the greatest source, being
involved in 43 cases and affecting more than 1.5 million individuals.
All of the breaches occurred between Sept. 21, 2009 and Sept. 21 2010,
the first year when breach incidents were publicly reported to the
Secretary of the Department of Health and Human Services
“There are so many various ways for data to be breached in this day
and age and many businesses are not properly prepared or are
completely unaware of just how vulnerable this information is,” said
Jorge Rey, the study’s co-author and director of information security
and compliance with Kaufman, Rossin. “The HITECH Act is changing the
way PHI must be protected and those companies that are not serious
about protecting their patients’ information find themselves facing
serious reputation, legal and financial repercussions.”
Among other findings:
Theft was the primary cause of a data breach, occurring 58 percent of
the time; loss and other were tied in second at 14 percent.
20 percent of the breaches occurred at a business associates.
Theft affected the highest number of individuals: 3.12 million
32 percent of breaches were reported within the first three months
The report notes that data breaches come in various forms, from
hacking to medical information that is mailed to the wrong address,
though the later is responsible for a very small amount of the
breaches.
The report sites some examples of theft such as:
An impostor posing as a representative of a legitimate vendor stole
several barrels of purged x-ray films, which contained the health care
information of approximately 1,300 patients.
A laptop computer was stolen from a hospital employee’s vehicle that
contained the health care information of 943 patients
A binder with printed protected health information was stolen from an
employee’s vehicle and contained the information of up to 1,272
patients.
The report goes on to recommend that health care organizations review
their security policies, encrypt new and existing laptops and perform
detailed annual risk assessments, among other things.
HHS Imposes a $4.3 Million Civil Money Penalty for Violations of the HIPAA Privacy Rule
HHS imposes a $4.3 million civil money penalty for violations of the
HIPAA Privacy Rule
Action marks first civil money penalty issued by HHS for HIPAA Privacy
Rule violations
The U.S. Department of Health and Human Services’ (HHS) Office for
Civil Rights (OCR) has issued a Notice of Final Determination finding
that Cignet Health of Prince George’s County, Md., (Cignet) violated
the Privacy Rule of the Health Insurance Portability and
Accountability Act of 1996 (HIPAA). HHS has imposed a civil money
penalty (CMP) of $4.3 million for the violations, representing the
first CMP issued by the Department for a covered entity’s violations
of the HIPAA Privacy Rule.
The CMP is based on the violation categories and increased penalty
amounts authorized by Section 13410(d) of the Health Information
Technology for Economic and Clinical Health (HITECH) Act.
“Ensuring that Americans’ health information privacy is protected is
vital to our health care system and a priority of this Administration.
The U.S. Department of Health and Human Services is serious about
enforcing individual rights guaranteed by the HIPAA Privacy Rule,”
said HHS Secretary Kathleen Sebelius.
In a Notice of Proposed Determination issued Oct. 20, 2010, OCR found
that Cignet violated 41 patients’ rights by denying them access to
their medical records when requested between September 2008 and
October 2009. These patients individually filed complaints with OCR,
initiating investigations of each complaint. The HIPAA Privacy Rule
requires that a covered entity provide a patient with a copy of their
medical records within 30 (and no later than 60) days of the patient’s
request. The CMP for these violations is $1.3 million.
During the investigations, Cignet refused to respond to OCR’s demands
to produce the records. Additionally, Cignet failed to cooperate with
OCR’s investigations of the complaints and produce the records in
response to OCR’s subpoena. OCR filed a petition to enforce its
subpoena in United States District Court and obtained a default
judgment against Cignet on March 30, 2010. On April 7, 2010, Cignet
produced the medical records to OCR, but otherwise made no efforts to
resolve the complaints through informal means.
OCR also found that Cignet failed to cooperate with OCR’s
investigations on a continuing daily basis from March 17, 2009, to
April 7, 2010, and that the failure to cooperate was due to Cignet’s
willful neglect to comply with the Privacy Rule. Covered entities are
required under law to cooperate with the Department’s investigations.
The CMP for these violations is $3 million.
“Covered entities and business associates must uphold their
responsibility to provide patients with access to their medical
records, and adhere closely to all of HIPAA’s requirements,” said OCR
Director Georgina Verdugo. “The U.S. Department of Health and Human
Services will continue to investigate and take action against those
organizations that knowingly disregard their obligations under these
rules.”
HIPAA Privacy Rule
Action marks first civil money penalty issued by HHS for HIPAA Privacy
Rule violations
The U.S. Department of Health and Human Services’ (HHS) Office for
Civil Rights (OCR) has issued a Notice of Final Determination finding
that Cignet Health of Prince George’s County, Md., (Cignet) violated
the Privacy Rule of the Health Insurance Portability and
Accountability Act of 1996 (HIPAA). HHS has imposed a civil money
penalty (CMP) of $4.3 million for the violations, representing the
first CMP issued by the Department for a covered entity’s violations
of the HIPAA Privacy Rule.
The CMP is based on the violation categories and increased penalty
amounts authorized by Section 13410(d) of the Health Information
Technology for Economic and Clinical Health (HITECH) Act.
“Ensuring that Americans’ health information privacy is protected is
vital to our health care system and a priority of this Administration.
The U.S. Department of Health and Human Services is serious about
enforcing individual rights guaranteed by the HIPAA Privacy Rule,”
said HHS Secretary Kathleen Sebelius.
In a Notice of Proposed Determination issued Oct. 20, 2010, OCR found
that Cignet violated 41 patients’ rights by denying them access to
their medical records when requested between September 2008 and
October 2009. These patients individually filed complaints with OCR,
initiating investigations of each complaint. The HIPAA Privacy Rule
requires that a covered entity provide a patient with a copy of their
medical records within 30 (and no later than 60) days of the patient’s
request. The CMP for these violations is $1.3 million.
During the investigations, Cignet refused to respond to OCR’s demands
to produce the records. Additionally, Cignet failed to cooperate with
OCR’s investigations of the complaints and produce the records in
response to OCR’s subpoena. OCR filed a petition to enforce its
subpoena in United States District Court and obtained a default
judgment against Cignet on March 30, 2010. On April 7, 2010, Cignet
produced the medical records to OCR, but otherwise made no efforts to
resolve the complaints through informal means.
OCR also found that Cignet failed to cooperate with OCR’s
investigations on a continuing daily basis from March 17, 2009, to
April 7, 2010, and that the failure to cooperate was due to Cignet’s
willful neglect to comply with the Privacy Rule. Covered entities are
required under law to cooperate with the Department’s investigations.
The CMP for these violations is $3 million.
“Covered entities and business associates must uphold their
responsibility to provide patients with access to their medical
records, and adhere closely to all of HIPAA’s requirements,” said OCR
Director Georgina Verdugo. “The U.S. Department of Health and Human
Services will continue to investigate and take action against those
organizations that knowingly disregard their obligations under these
rules.”
Subscribe to:
Posts (Atom)