Entries from Realtime Community | IT Compliance tagged with 'privacy law'
Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by...
Posted by Rebecca Herold on November 28, 2009 6:42 PM
I've had about half a dozen folks ask me how things are going with the work I'm doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the...
Posted by Rebecca Herold on November 9, 2009 5:12 PM
Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......
Posted by Rebecca Herold on November 5, 2009 8:29 PM
The HHS released HITECH Act Enforcement Interim Final Rule today......
Posted by Rebecca Herold on October 29, 2009 8:05 PM
I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......
Posted by Rebecca Herold on October 21, 2009 12:07 PM
A big thank you to Brandon Dunlap and Brett Myers for catching an error I made in my January 1 post......
Posted by Rebecca Herold on January 3, 2009 9:25 PM
Happy New Year! Several news laws go into effect today. Here are just a few of them......
Posted by Rebecca Herold on January 1, 2009 2:55 PM
If you must comply with the Red Flags Rule, which is a rule that falls under the umbrella of the Fair and Accurate Credit Transactions Act (FACTA), which most organizations in the U.S. who process payments from their customers must...
Posted by Rebecca Herold on October 17, 2008 12:03 PM
There is a growing trend in laws that require personally identifiable information (PII) to be encrypted. Encryption in past laws have been directed to be considered based upon risk, but now they are more explicitly required in some laws....
Posted by Rebecca Herold on September 29, 2008 8:58 AM
This morning I took a little time to update my long listing of world-wide data protection (privacy) laws. Here are some of them you may find helpful:...
Posted by Rebecca Herold on March 19, 2008 10:40 AM
Another country appears to be on the verge of passing a privacy breach notice law......
Posted by Rebecca Herold on February 1, 2008 9:04 AM
I recently blogged about "6 "Scary Stuff" Privacy Terms IT, Info Sec and Privacy Folks Should Know." I was very pleasantly surprised to hear from Dr. Michael G. Michael and his wife Dr. Katina Michael a couple of days ago...
Posted by Rebecca Herold on January 3, 2008 10:50 AM
Here's a case I found interesting...the U.S. District Court for the Eastern District of Tennessee ruled on October 24th that providing a group of record company plaintiffs with student personally identifiable information (PII) does not violate the U.S. Family Educational...
Posted by Rebecca Herold on November 6, 2007 8:49 PM
Here's another insider threat example to know and to discuss with your legal counsel and HR folks. It highlights the need for information security and privacy policies, shows how information security and privacy must work with multiple areas on an...
Posted by Rebecca Herold on November 5, 2007 2:30 AM
I, along with a very large number of other bloggers, writers and instructors, often pick apart data protection and privacy laws and regulations, and point out how certain portions of them are infeasible for most organizations to implement, and talk...
Posted by Rebecca Herold on November 4, 2007 8:54 AM
To date there have been several laws that direct organizations in certain industries to consider using encryption as one way to protect data based upon the organization's considered risks, and laws that make encryption a factor in decisions regarding breach...
Posted by Rebecca Herold on October 9, 2007 7:37 PM
on 8/22/2007 a very interesting and useful report was released by the European Network and Information Security Agency (ENISA), "Information security awareness initiatives: Current practice and the measurement of success."...
Posted by Rebecca Herold on August 24, 2007 1:29 PM
Multi-national organizations doing business in Europe must know and understand not only their obligations to protect personally identifiable information (PII) under the European Union (EU) Data Protection Directive 95/45/EC, but they must also know and understand the data protection laws...
Posted by Rebecca Herold on August 22, 2007 11:31 AM
On March 29 the FTC published a proposed new routine use, (72 Fed. Reg. 14814, 3/29/07), that would allow FTC records governed by the Privacy Act to be disclosed to "appropriate" persons and entities when reasonably necessary to respond and...
Posted by Rebecca Herold on April 3, 2007 12:10 PM
On February 15 the Senate Homeland Security and Governmental Affairs Committee approved legislation with provisions to strengthen President Bush's Privacy and Civil Liberties Oversight Board. The provisions were part of a bill, the "Improving America's Security Act of 2007" (S....
Posted by Rebecca Herold on February 27, 2007 12:30 AM
Before the U.S. House adjourned Febuary 16 and the Senate adjourned February 17 for a week-long recess, they submitted some bills with privacy impacts....
Posted by Rebecca Herold on February 26, 2007 12:30 AM
In many countries, such as in all 25 of the European Union states and within Canada, just to name a few, individuals have the legal right to request from organizations a verification of whether or not the organization has information...
Posted by Rebecca Herold on February 16, 2007 3:32 PM
On Tuesday, February 6, U.S. Sen. Patrick Leahy, D-Vt., and Sen. Arlen Specter, R-Pa., filed legislation,the Personal Data Privacy Act of 2007, that would, among other things, require organizations to notify consumers of security breaches as well as mandate the...
Posted by Rebecca Herold on February 8, 2007 12:30 AM
The Halifax Bank of Scotland sent the complete account information for 75,000 of their customers to one customer who had requested a copy of her own statement....
Posted by Rebecca Herold on February 7, 2007 12:30 AM
The Akron Beacon Journal reported February 5 more impacts of the massive TJX breach that occurred late in 2006 that may have impacted over 40 million individuals according to the Wall Street Journal....
Posted by Rebecca Herold on February 7, 2007 12:15 AM
According to a congressional testimony report posted February 1, "Private Health Records: Privacy Implications of the Federal Government's Health Information Technology Initiative," the Department of Health and Human Services (HHS) needs to do more to address privacy and security concerns...
Posted by Rebecca Herold on February 5, 2007 10:28 AM
Let's look at the events that have occurred with the recent TJX computer hack and resulting privacy breach and identity thefts:...
Posted by Rebecca Herold on February 4, 2007 10:01 PM
Yesterday the U.S. FTC and Department of Justice jointly announced a $465,000 penalty against TJ Web Productions for violating the CAN-SPAM Act....
Posted by Rebecca Herold on January 31, 2007 2:49 PM
Puget Sound Energy, Washington state's largest electricity and natural gas utility, with over 1 million customers in 11 western Washington counties, was ordered to pay a total of $995,000 in fines for selling their customer information to marketing companies over...
Posted by Rebecca Herold on January 30, 2007 10:25 AM
NBC news ran a story about how many state government agencies post sensitive personally identifiable information (PII) on their websites. In this case an Ohio county court "routinely posted traffic tickets and other public records on its Web site."...
Posted by Rebecca Herold on January 29, 2007 9:25 PM
There are many issues involved with using live production data, particularly real personally identifiable information (PII), for test and demo purposes. For many years it has been the norm within organizations to use copies of production data for testing during...
Posted by Rebecca Herold on July 14, 2006 2:53 PM
We are undergoing a data protection renaissance. New laws have considerably expanded corporate obligations regarding security and privacy for information in all forms. A significant obligation of the laws is applicable to basically all organizations; the duty to provide reasonable...
Posted by Rebecca Herold on June 30, 2006 1:17 PM
Site tags used on this blog: