As reported by CBC, B.C. Pension Corporation announced a data breach involving pension plan records after discovering a box containing microfiche could not be found following a recent office move. The box contained personal information (names, social insurance numbers and dates of birth) on approximately 8,000 pension plan participants. The company employed those participants
destruction
Is it really deleted?
A significant percentage of “recycled” computers were found to still contain personal information, according to a study conducted by the National Association for Information Destruction (NAID). As reported in e-Place Solutions, the NAID-ANZ Secondhand Hard Drive Study, found that “15 of 52 hard drives randomly purchased contained highly confidential personal information.”…
New Tennessee Law Requires Destruction of Certain PHI Following Medical Malpractice Litigation
New Tennessee law requires destruction of certain PHI following medical malpractice litigation…
Continue Reading New Tennessee Law Requires Destruction of Certain PHI Following Medical Malpractice Litigation
The Consumer Fraud and Abuse Act — Does It Apply To An Employee’s Personal Computer?
Many employers often question what recourse is available when faced with the destruction or alteration of company data by former employees. This question is made more complicated when employees use their own personal computer for work. In addressing this issue, the U.S. District Court for the Northern District of Illinois, Eastern division held that an employee’s …
The Commercial Privacy Bill of Rights Act
Two Senators who clearly did not let the potential government work stoppage affect them, formally introduced the Commercial Privacy Bill of Rights Act of 2011 on April 12. In a bipartisan effort, Senators John Kerry (D-Mass.) and John McCain (R-Arizona) introduced the legislation which sets forth privacy rules governing businesses that collect, use, or share…
Data Security, Destruction and Encryption Leads the Way for States in 2010
Less than one month into 2010 the trend to address data security, destruction, and encryption has continued among state lawmakers. Specifically, Florida, Michigan, Kentucky, Kansas, Pennsylvania, and New York all have introduced, reintroduced, or amended legislation of this kind.
- The Florida and Michigan laws would amend personal data destruction rules for companies.
- The New York law would mandate data security and encryption measures.
- The Kentucky bill would require government agencies to protect all personal data under the Gramm-Leach-Bliley Act.
- The Michigan bill includes a state version of the Federal Trade Commission’s Red Flags Rule and would require creditors in the state to implement programs aimed at spotting “red flags” of possible identity theft and put in place mitigation measures. Michigan is also considering a number of other measures.
- The Kansas law would require state agencies to engage in periodic network security reviews.
- The Pennsylvania bill would require public agencies to notify state residents of a breach of their personal information within seven days of the discovery of the breach.
While 5 states remain without data breach notice bills (Alabama, Kentucky, Mississippi, New Mexico, and South Dakota), Congress is considering legislation, the Data Accountability and Trust Act (DATA) (H.R. 2221), that would preempt all state notification laws and instead establish a national breach notice standard.
As we have previously mentioned, we anticipate data privacy and security legislation and case law to be at the forefront of legal issues in 2010. Employers should begin by reading the Data Security Primer and consider implementing comprehensive data security policies and procedures that would allow them to comply with the various state laws that may impact their business. …
Continue Reading Data Security, Destruction and Encryption Leads the Way for States in 2010
Do You Know How to Take Out the Trash?
Joining the growing number of states which have enacted laws regulating the destruction of records to prevent possible identity theft, the Rhode Island Legislature passed H. 5092 on October 29, 2009. The bill requires businesses and government agencies to completely destroy records containing personal information, or render the personal information unusable, before disposing of records whether …