Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'privacy law'


Smart Grid Privacy: Possible Privacy Standards To Address Concerns

Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by...

15 Smart Grid Privacy Concerns + Other Smart Grid Thoughts

I've had about half a dozen folks ask me how things are going with the work I'm doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the...

HIPAA And Surveillance In Hospitals

Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......

CEs and BAs: Be HIPAA/HITECH Compliant Or Pay A Hefty Penalty

The HHS released HITECH Act Enforcement Interim Final Rule today......

Smart Grid Privacy: Laws and Implications

I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......

CORRECTION: Massachusetts Data Protection Law Takes Effect May 1, 2009

A big thank you to Brandon Dunlap and Brett Myers for catching an error I made in my January 1 post......

New Data Protection Laws Go Into Effect Today

Happy New Year! Several news laws go into effect today. Here are just a few of them......

Federal Reserve Releases Examination Procedures For Red Flags Rule Compliance

If you must comply with the Red Flags Rule, which is a rule that falls under the umbrella of the Fair and Accurate Credit Transactions Act (FACTA), which most organizations in the U.S. who process payments from their customers must...

PII Encryption Required by New Massachusetts and Nevada Laws

There is a growing trend in laws that require personally identifiable information (PII) to be encrypted. Encryption in past laws have been directed to be considered based upon risk, but now they are more explicitly required in some laws....

Useful Data Protection (Privacy) Law Sites

This morning I took a little time to update my long listing of world-wide data protection (privacy) laws. Here are some of them you may find helpful:...

A New Privacy/Security Breach Notice Law Soon In The Land Down Under?

Another country appears to be on the verge of passing a privacy breach notice law......

More On Überveillance And Privacy

I recently blogged about "6 "Scary Stuff" Privacy Terms IT, Info Sec and Privacy Folks Should Know." I was very pleasantly surprised to hear from Dr. Michael G. Michael and his wife Dr. Katina Michael a couple of days ago...

Judge Rules University Policy & FERPA Allow Student PII To Be Released

Here's a case I found interesting...the U.S. District Court for the Eastern District of Tennessee ruled on October 24th that providing a group of record company plaintiffs with student personally identifiable information (PII) does not violate the U.S. Family Educational...

Insider Threat Lessons: Posting Threats And Personnel PII On The Internet Establishes Federal Jurisdiction

Here's another insider threat example to know and to discuss with your legal counsel and HR folks. It highlights the need for information security and privacy policies, shows how information security and privacy must work with multiple areas on an...

Do Something To Change Information Security, Privacy and Compliance...Contact Congress!

I, along with a very large number of other bloggers, writers and instructors, often pick apart data protection and privacy laws and regulations, and point out how certain portions of them are infeasible for most organizations to implement, and talk...

New Nevada Law Explicitly Requires Organizations to Encrypt PII Sent Through Networks

To date there have been several laws that direct organizations in certain industries to consider using encryption as one way to protect data based upon the organization's considered risks, and laws that make encryption a factor in decisions regarding breach...

Information Security Awareness in Europe...The Issues Are the Same Worldwide

on 8/22/2007 a very interesting and useful report was released by the European Network and Information Security Agency (ENISA), "Information security awareness initiatives: Current practice and the measurement of success."...

EU Data Protection Directive 95/46/EC: Member Countries

Multi-national organizations doing business in Europe must know and understand not only their obligations to protect personally identifiable information (PII) under the European Union (EU) Data Protection Directive 95/45/EC, but they must also know and understand the data protection laws...

Privacy Act: FTC Proposes Allowing Disclosure of PII Records to Third Parties To Assist Data Breach Response Within Gov't Agencies

On March 29 the FTC published a proposed new routine use, (72 Fed. Reg. 14814, 3/29/07), that would allow FTC records governed by the Privacy Act to be disclosed to "appropriate" persons and entities when reasonably necessary to respond and...

Legislation Passed to Strengthen Bush's Privacy and Civil Liberties Oversight Board

On February 15 the Senate Homeland Security and Governmental Affairs Committee approved legislation with provisions to strengthen President Bush's Privacy and Civil Liberties Oversight Board. The provisions were part of a bill, the "Improving America's Security Act of 2007" (S....

U.S. Privacy Related Bills Introduced February 15 & 16

Before the U.S. House adjourned Febuary 16 and the Senate adjourned February 17 for a week-long recess, they submitted some bills with privacy impacts....

Privacy: How to handle individual access requests in the UK in compliance with the Data Protection Act

In many countries, such as in all 25 of the European Union states and within Canada, just to name a few, individuals have the legal right to request from organizations a verification of whether or not the organization has information...

Privacy Law: Leahy & Specter File Personal Data Privacy Act of 2007 Bill

On Tuesday, February 6, U.S. Sen. Patrick Leahy, D-Vt., and Sen. Arlen Specter, R-Pa., filed legislation,the Personal Data Privacy Act of 2007, that would, among other things, require organizations to notify consumers of security breaches as well as mandate the...

Privacy Breach: Bank in UK Sends Personal Data of 75,000 Customers to 1 Customer Requesting Her Own Statement

The Halifax Bank of Scotland sent the complete account information for 75,000 of their customers to one customer who had requested a copy of her own statement....

Identity Theft: More Info On Fallout From The TJX Breach

The Akron Beacon Journal reported February 5 more impacts of the massive TJX breach that occurred late in 2006 that may have impacted over 40 million individuals according to the Wall Street Journal....

HIPAA: Congressional and GAO Reports Say HHS Needs To Make Changes To Protect Patient Privacy

According to a congressional testimony report posted February 1, "Private Health Records: Privacy Implications of the Federal Government's Health Information Technology Initiative," the Department of Health and Human Services (HHS) needs to do more to address privacy and security concerns...

PCI DSS and GLBA Compliance & Privacy Breach: Lawsuits Filed Against TJX

Let's look at the events that have occurred with the recent TJX computer hack and resulting privacy breach and identity thefts:...

CAN-SPAM Violation: TJ Web Productions Must Pay $465,000 Fine And Perform Additional Actions for 5 Years

Yesterday the U.S. FTC and Department of Justice jointly announced a $465,000 penalty against TJ Web Productions for violating the CAN-SPAM Act....

Puget Sound Energy Ordered to Pay $995,000 For Selling Customer Personal Information

Puget Sound Energy, Washington state's largest electricity and natural gas utility, with over 1 million customers in 11 western Washington counties, was ordered to pay a total of $995,000 in fines for selling their customer information to marketing companies over...

Routine Personal Information Posting in the U.S. State Government Agencies

NBC news ran a story about how many state government agencies post sensitive personally identifiable information (PII) on their websites. In this case an Ohio county court "routinely posted traffic tickets and other public records on its Web site."...

What IT Leaders Need to Know About Using Production Data for Testing

There are many issues involved with using live production data, particularly real personally identifiable information (PII), for test and demo purposes.  For many years it has been the norm within organizations to use copies of production data for testing during...

Demystifying Privacy Laws: What You Need to Know to Protect Your Business

We are undergoing a data protection renaissance.  New laws have considerably expanded corporate obligations regarding security and privacy for information in all forms.  A significant obligation of the laws is applicable to basically all organizations; the duty to provide reasonable...

Site Tags

Site tags used on this blog: