Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Thursday, August 15, 2013

Photocopier Hard Drives Cause Breach Yielding $1.2 Million HIPAA Settlement


On August 14, 2013, the Office of Civil Rights for the U.S. Department of Health and Human Services ("HHS OCR") announced a $1.2 million settlement with Affinity Health Plan for violations of the privacy and security rules under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). According to the HHS OCR press release, the violation arose when Affinity disposed of photocopiers with built-in hard drives which still contained images of patient records that had been photocopied on the devices:

Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act. The HITECH Breach Notification Rule requires HIPAA-covered entities to notify HHS of a breach of unsecured protected health information. Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity. CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.

Afinity estimated that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives. In addition, the investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents.
The Affinity resolution agreement may be downloaded here.

Beyond the substantial size and number of individuals' records involved in this case, it is notable that the breach in question was from a device not typically thought of as prone to privacy problems: a photocopier with an internal hard drive. Most users don't consider the built-in storage in printers and photocopiers, but these devices can and do retain previously printed and scanned information. The FTC and NIST offer useful information for organizations on improving security and privacy of digital printers and copiers.

Wednesday, December 12, 2012

Peter Fleischer, Other Google Execs Still May Face Jail in Italy Privacy Case

AP Image of trial court via KLEWTV.com
 In the latest installment in a case that highlights both the legal risks and absurdity of the cross-border nature of the Internet, the Milanese prosecutor in the case against Peter Fleischer and two other Google executives has asked an appeals court to uphold the six-month jail sentences they received in a criminal privacy case. The case arose out of a 2006 posting to Google Video by Italian teenagers of a short video of a learning-disabled classmate. Although none of the executives had any involvement with the posting or its prompt removal by Google Video after notification, they were still charged (along with another colleague, later acquitted) of violations of Italian privacy law. Fleischer, who was then Google's chief privacy counsel in Europe, was arrested when he traveled from his Paris office to Italy to give a lecture in January 2009. After the case came to trial, Fleischer and two of his colleagues (including Google's chief legal officer, David Drummond) were convicted in February 2010 and given six month sentences, automatically suspended under Italian law. The case was then appealed, leading to the latest development.

Fleischer, in a recent blog entry about the appeal, describes both the facts and the illogical nature of the case against him, given that he and his colleagues had nothing to do with the incident:

Under European law, hosting platforms that do not create content, such as Google Video, YouTube, Bebo, Facebook, and even university bulletin boards, are not legally responsible for the content that others upload onto these sites. But in this instance, a public prosecutor in Milan decided to charge us with criminal defamation and a failure to comply with the Italian privacy code.  None of us, however, had anything to do with this video. We did not appear in it, film it, upload it or review it. None of us knew the people involved or were even aware of the video's existence until after it was removed.
 This case, similar in many ways to the action in Germany against Compuserve's Felix Somm in 1996, serves as a stark reminder that those associated with companies doing business online may find themselves facing personal liability or even prosecution based on the laws of other countries, even when the individuals had no connection with the activity in question, and even when the activity was fully legal under the laws of the jurisdiction in which the company is based. While it is impossible to research and be certain of compliance with every relevant law in every possible country with access to the Internet, those who work for high-profile businesses, especially companies whose activities may potentially violate particular nations' cultural norms, should at the least be aware of these risks when considering business or personal travel to other regions. Companies, for their part, must include these risks in their overall assessments when choosing to do business online.

Friday, November 30, 2012

Risk Highlight: Syrian Government Turns Off Internet

In the latest salvo between the Syrian government and opposition forces, the government has reportedly used its control over Syria's telecommunications infrastructure to completely cut off the nation's Internet access. (The shut off can be seen in Renesys' Internet traffic graph for Syria, showing the complete cessation of all globally reachable Syrian networks between 10:20 and 10:30 UTC on November 29th:

Renesys Internet Traffic Graph for Syria

In response, other nations and companies have stepped in to try to provide at least limited connectivity to Syrians. Google has reactivated its Speak2Tweet service, although the limited telephone service in Syria may reduce its usefulness, and the U.S. State Department announced that it had previously provided 2,000 communications kits, with computers, telephones and cameras, that are "designed to be independent from and able to circumvent the Syrian domestic network precisely for the reason of keeping them safe, keeping them secure from regime tampering, regime listening, regime interruption."

Beyond the clear local and geopolitical aspects, this latest governmental cutoff of Internet access, as with the outages caused by recent storms in the United States, highlights that the telecommunications infrastructure on which businesses depend is largely out of their control. Effective risk management, involving backup systems, contracts, insurance and other means, must take that reality (and its potential implications) into account.