March 2010
S M T W T F S
« Feb    
 123456
78910111213
14151617181920
21222324252627
28293031  

Legal Disclaimer

Your use of this Blog does not create an attorney-client relationship. Your e-mail or comments do not create an attorney-client relationship. We have no duty to keep confidential the information that is submitted to this blog. This blog is not a substitute for, nor does it constitute legal advice. Only an attorney who knows the details of your particular situation and is properly licensed in the applicable state (or states) is able to appropriately and properly address any legal issues you may have.

Blog Categories

HHS announced proposed rulemaking to modify the HIPAA privacy rule to comply with Section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008 (GINA)

On October 7, 2009 HHS announced proposed rulemaking to modify the HIPAA privacy rule to comply with Section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008 (GINA) regarding the privacy and confidentiality of genetic information. Generally, the HIPAA Privacy Rule establishes national standards to protect individuals’ medical records and other personal health information and applies to health plans, health care clearinghouses, and those health care providers that conduct certain health care transactions electronically. The HIPAA Privacy Rule requires a covered entity (and beginning next year Business Associates) to implement reasonable and appropriate administrative, technical and physical safeguards to protect the privacy of personal health information (PHI). The HIPAA privacy rule more generally sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization. The Rule also gives patients rights over their health information, including rights to examine and obtain a copy of their health records, and to request [...]

Updated -- Summary of 50 State Security Breach Notification Laws

Attached is an updated summary of the major provisions of each state law that have enacted security breach statutes. In the event of a security breach, you should consult legal counsel to ascertain the appropriate method of notification and other requirements. To date — forty-five states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information. States with no security breach laws include: Alabama, Kentucky, Mississippi, New Mexico, and South Dakota. Arkansas, California, Minnesota, and Texas now include health information within the scope of their respective security breach statutes by including health information within the definition of personal information. Eight states take an acquisition based approach when defining whether notice should be given, while the remaining states take a more pragmatic risk assessment of the likelihood of harm as controlling whether notice should be sent to consumers. [...]

Evaluating Secutiy Incidents — Security Incident DOs and DON’Ts

Security Incidents can be accidental incursions or deliberate attempts to break into systems and can be benign to malicious in purpose or consequence, each incident requires a careful response at a level commensurate with its potential impact to the security of individuals and your organization as a whole however few organizations have an appropriate security incident policy. The fundamental components of a security incident response plan include the following — [...]

Interim Final Rule on Breach Notification for HIPAA Covered Entities and Business Associates Released by HHS (Effective September 23, 2009) & FTC Releases Final Guidance on PHR Security Breach Notification Requirements

Regulations requiring health care providers, health plans, and other entities covered by the Health Insurance Portability and Accountability Act (HIPAA) to notify individuals when personal health information is breached were issued August 19th, 2009, by the U.S. Department of Health and Human Services (HHS). These “breach notification” regulations implement provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 [...]

HHS Tranfers Enforcement of the HIPAA Security Rule to OCR (Office of Civil Rights)

It appears HHS has taken this critique to heart. HHS recently released notice of an important shift in the internal responsibility/delegation of authority for the monitoring and enforcement of the HIPAA Security Rule (and all additional health IT-related security responsibilities, under ARRA). Previously responsibility for administering (interpretation, education, guidance, FAQs, etc), monitoring and enforcing the HIPAA Security Rule was a CMS responsibility (specifically, the CMS Office of E-Standards and Services or CMS/OESS). The administration, monitoring and enforcement of the HIPAA Privacy Rule fell under the Office for Civil Rights [...]

New York Pivacy and Security Laws Intended to Protect Personal Identifiable Information (PII)

Below I briefly review New York’s security breach and other relevant privacy/security law provisions which are sometimes not addressed in a corporation’s privacy and security policies (but should be). I have also reference and review New York’s Guidance on business best privacy and security practices. There are three basic areas of inquiry: privacy law pertaining to the protection of confidential information that requires specific actions with respect to specific identifiers (e.g. SSN, DL Number, etc.); obligations of an employer’s to the employer’s employees that include affirmative privacy obligations; and New York’s version of a security breach notification laws currently found in 45 states. New York Consumer Protection Board (“CPB”) is New York’s key agency responsible for protecting the residents of New York by “publicizing unscrupulous and questionable business practices; conducting investigations and hearings; researching issues; developing legislation and creating consumer education programs and materials.” The CPB has released guidance (New York’s Business Guide to Privacy) that provides an excellent summary of New York State privacy and security laws. Most actions brought under the discussed statutes must be brought by the State Attorney General. HIPAA and other Federal Laws (including the new HITECH Act) I have discussed in other blog [...]

Fingerprinting (Writeprinting) Text Using Stylistic Features Can Be Used To Accurately Identify the Authorship of Anonymous Emails, Blog Entries and IRC Chat Sessions

Going to Court to force an ISP to disclose the identity raises many issues including First Amendment issues. For example,

On June 13, 2007, the New Jersey Township of Manalapan filed a malpractice suit against its former attorney Stuart Moskovitz, alleging misconduct regarding the Township’s purchase of polluted land in 2005. The decision to file suit was met by a lively debate in the regional press and among localbloggers. One blogger who was particularly critical of the Township, of this and other decisions, was Blogspot blogger “datruthsquad”

(http://www.eff.org/cases/manalapan-v-moskovitz).

Long story short the Township lost, a copy of EFF’s motion squash is available here motiontoquashmpa-signed; and the Court order squashing the subpoena is available here order-122107. However, there may exist an alternative method for “unmasking” anonymous bloggers, cyber-stalkers, etc. using public information. Everyone has a unique writeprint (basically a written fingerprint that can be used to identify him or her). This technique s has traditionally been used to identify the true author of a text (e.g. a book) where authorship is disputed or unknown. Forensics linguistics has been used to provide evidence in trademark disputes cases, identifying the author of anonymous texts (such as threat or harassment letters), and identifying cases of plagiarism. The identification process relies on the analysis of an individual’s particular patterns of language use (vocabulary, collocations, pronunciation, spelling, grammar, etc.). The term “idiolect” is defined as the speech patterns of a specific person (a dialect, unique in pronunciation, grammar, and vocabulary to a single person). Stylistic features can be used to create a fingerprint of an individual’s writing style (a linguistic fingerprint is called a “writeprint”). A writeprint is composed of features that represent an author’s writing style, which are consistent across all of an individual’s writings. For a gentle introduction, see Digital fingerprints: tiny behavioral differences can reveal your identity, by Julie Rehmeyer in the January 13, 2007 issue of Science News (Westlaw cite 2007 WLNR [...]

Credit Monitoring Services May Not Be Required But Put the Plaintiff in a Difficult Position When Trying to Prove Damages

A number of Plaintiffs have brought actions following notification that their sensitive financial information had been disclosed during a security incident. Approximately 45 states including the District of Columbia now require that a party be informed when his/her sensitive information has been released, however, this exposure of someone’s identity even when coupled with the cost to guard against identity theft, generally does not constitute a compensable injury to state a claim for negligence or for breach of [...]

FTC Grants “Three-Month Delay of Enforcement of ‘Red Flags Rule’ Requiring Creditors and Financial Institutions to Adopt Identity Theft Prevention Programs”

The FTC announced today that the enforcement date for the Red Flag Rules is being extended until August 1, 2009 (instead of May 1, 2009). The press release is at http://www.ftc.gov/opa/2009/04/redflagsrule.shtm.
April 30th, 2009 — “The Federal Trade Commission will delay enforcement of the new “Red Flags Rule” until August 1, 2009, to give creditors and financial institutions more time to develop and implement written identity theft prevention programs. For entities that have a low risk of identity theft, such as businesses that know their customers personally, the Commission will soon release a template to help them comply with the [...]

American Recovery and Reinvestment Act: Overview of Modifications to the HIPAA Privacy and Security Regulations

Stimulus Update – HIPAA

This alert provides a brief overview of privacy and security provisions included within “The American Recovery and Reinvestment Act of 2009” (H.R.1, S.1) (the “Stimulus”).  The Stimulus also includes funding for health information technology (“HIT”) and funding for comparative effectiveness research.  These provisions will be the subject of future alerts.  Future [...]

Improve the web with Nofollow Reciprocity.