Thursday, June 16, 2005

Insurance access trumps privacy: court

I have not read the judge's decision in this case, but I am not surprised by the conclusion. Apparently, according to the Canadian Broadcasting Corporation, a judge of the Supreme Court of Nova Scotia has concluded that a defendant in a personal injury lawsuit has a right to review the complete medical records of the plaintiff for the last five years to review for pre-existing injuries.

This appears consistent with previous judgements, such as the decision of the Ontario courts in Ferenczy v. MCI Medical Clinic (see: PIPEDA and Canadian Privacy Law: PIPEDA and Video Surveillance: Guidance from the Ontario Courts).

CBC Newfoundland and Labrador - Insurance access trumps privacy: court:

"ST. JOHN'S - The Supreme Court of Newfoundland and Labrador has ruled an insurance company's right to access personal information may override an individual's right to privacy.

Mount Pearl resident Roseanne O'Dea applied to the court to restrict an insurance company from obtaining her medical records.

O'Dea had been in a collision with a taxi in 2003.

The Insurance Corporation of Newfoundland, which is representing the taxi company, said it wanted to review her medical and pharmacy records for the past decade before it proceeded with any compensation.

O'Dea refused, calling the request an unacceptable breach of her privacy.

Justice Robert Hall ruled there are occasions when an insurance company's access to records should be limited.

However, Hall ruled that O'Dea's privacy must give way to the right of the company to access all potentially relevant information.

Hall said pre-existing medical conditions could be relevant to O'Dea's claim.

Don Forgeron, Atlantic vice-president of the Insurance Bureau of Canada, welcomed Thursday's ruling.

In the past, he said, courts have determined rights of access on a case-by-case basis.

'In the course of settling a claim, there needs to be appropriate medical information put forward to assess the extent of the injuries,' Forgeron said.

'We would look to the courts, as they have done in the past, to apply the appropriate tests to determine whether or not the information being requested is relevant to the proceedings.'"

Adding Privacy to the Constitution

This is a new one ... amid all the calls for legislation to protect personal information in the United States, a commentator in Business Week Online is calling for an amendment to the US Constitution to protect consumer privacy: Adding Privacy to the Constitution.

Wednesday, June 15, 2005

Irish cabinet working group to consider privacy law

According to the Irish Times, that country's cabinet is studying privacy laws to rein in the press: Irish Times Article - Working group to consider privacy law.

Congress Must Deal With ID Theft

Not surprisingly, Wired thinks that the US government should step in to address identity theft. The suggestions seem to be picking up traction, if you listen to other commentators in the media recently:

Wired News: Congress Must Deal With ID Theft
  • Require businesses to secure data and levy fines against those who don't.
  • Require companies to encrypt all sensitive customer data.
  • Keep the plan simple and provide authority and funds to the FTC to ensure legislation is enforced.
  • Keep Social Security numbers for Social Security.
  • Force credit agencies to scrutinize credit-card applications and verify the identity of credit-card applicants.
  • Extend fraud alerts beyond 90 days.
  • Allow individuals to freeze their credit records so that no one can access the records without the individuals' approval.
  • Require opt-in rather than opt-out permission before companies can share or sell data.
  • Require companies to notify consumers of any privacy breaches, without preventing states from enacting even tougher local laws.

Data leaks stunt e-commerce, survey suggests

MSNBC is reporting on a survey that suggests the recent publicity about privacy breaches is starting to affect consumer attitudes:

Data leaks stunt e-commerce, survey suggests - Consumer Security - MSNBC.com:

"Nearly half of all Americans avoid shopping on the Internet because they are worried their personal information will be stolen, according to a survey released Wednesday by an industry group. The survey also found nearly all Americans think identity theft and spyware are serious problems, but only 28 percent think the government is doing enough to address the issues. About 70 percent said new laws are necessary to protect consumer privacy...."

Lower overseas rates of identity theft could guide U.S. lawmakers

New York Newsday is running an article by AP Business writers Brian Bergstein and Matt Moore, suggesting that the United States may be able to learn a thing or two from other countries when it comes to protecting privacy and reducing the incidence of identity theft. It considers the privacy and credit environment of the UK, other European countries, Japan and Canada. Worth reading: New York City: Lower overseas rates of identity theft could guide U.S. lawmakers

New findings from the Federal Privacy Commissioner

The Commissioner's Office has just released three new "findings" under the Personal Information Protection and Electronic Documents Act. In short, they are:

Commissioner's Findings - Privacy Commissioner of Canada

Tuesday, June 14, 2005

Privacy Officers: Security Types Need Convincing

People often confuse privacy and security. Security is a part of privacy. (Security is also an important part of protecting other corporate assets.) Some may that privacy is the latest buzzword for applying security to personal information. It's more than that.

In IT Management, Ray Everett-Church writes about how to explain privacy to security-types, and particularly the need to have a privacy officer.

Privacy Officers: Security Types Need Convincing:

"I've spent much of the last six or seven years promoting the importance of privacy officers. Much to my dismay, over the course of the years, some of the greatest skepticism I've met has come from security professionals.

Much of the skepticism boils down to some basic misconceptions about the relationship between privacy and security, and fears that privacy officers are just going to be competing for the same organizational ''turf''. But as I have sat with security professionals to explain why the role of the privacy officer is complimentary, but fundamentally different, the concerns and misconceptions are easily dispelled.

Indeed, many security executives quickly realize that privacy officers get to deal with many of the murkier, subjective, and often politically-charged issues that many security officers try to avoid being drawn into -- such as marketing strategies or legal and regulatory compliance.

But let's not miss the bigger point here.

Assuming Congress could fix the law so it would require the auditing of privacy practices, instead of the day-to-day work of the privacy officer, this is something that should be encouraged. A critical element of the Federal Trade Commission's enforcement actions in the realm of privacy has been the requirement that companies bring in outside auditors to oversee their privacy fixes and ongoing practices.

If this panel believes you should only audit after a problem is discovered, then they don't appear to have a good grasp on the reality of today's privacy methodology in use at the most enlightened organizations the world over.

The methodology is pretty simple... I ought to know. I helped develop it. The four elements of a coherent privacy program are:

  • Know your current privacy-related practices;
  • Articulate those practices in a privacy policy;
  • Implement those practices through training and oversight, and
  • Audit those practices, from within and without, to ensure compliance.

All of this may be for naught, however.

According to reports, Rep. Tom Davis (R-Va.), chairman of the U.S. House of Representatives Government Reform Committee, is pushing legislation that would repeal the appropriations language that mandated the CPO appointments. But if the Davis proposal does not become law by year's end, the ranks of America's CPO population will grow by a few dozen, and somebody will finally be accountable for privacy practices at federal agencies.

And know knows... maybe by then some government committee will have grasped what these new CPOs are supposed to be doing!"

At least in Canada's legal environment, the status quo may not be acceptable. I would therefore suggest that a coherent privacy program has the following elements:

  1. Know your current personal information management practices: where it comes from, where it is kept, how it is used and to whom it is disclosed;
  2. Benchmark your current personal information management practices against a recognized standard, such as the Canadian Standards Association Model Code for the Protection of Personal Information;
  3. Modify your practices to accord with the standard (collect only what you need, use and disclose it only in the ways you've articlated, secure the information)
  4. Articulate your new practices in an easy to understand privacy statement and document them in an operational policy;
  5. Train all staff to implement your new practices; and
  6. Audit your practices.

The Rising Threat from Bad Data

I have previously pointed to items addressing the issue of data quality and data aggregators, but this piece from Baseline Magazine shows a real human side of the potential consequences of bad data:

The Rising Threat from Bad Data:

"Steven Calderon had a clean record, a clean conscience and no reason to think that his new employer's routine background check would cause any problem at all. Then the sheriff showed up at the office and took him to jail on warrants for child molestation and rape.

A nightmare? Sure, but Calderon figured it was a mistake that could be cleared up pretty quickly. He'd reported the theft of his Social Security number and birth certificate in 1993, so it was obvious that the bad guy was whoever had stolen Calderon's identity.

A week later he was still in jail, a victim of bad information from data broker ChoicePoint -- and of the blind belief held by his employer, the police and everyone else involved that he was more likely to be lying than the data was...."

Inicdent: Ottawa medical info trashed and then dumped in driveway

It's bad enough that sensitive medical information was being thrown out instead of being shredded, but someone dropped the bag of "trash" on a Manotick man's driveway. But it gets worse ... this is the second time.

The Ottawa Sun is reporting in incident involving the medical waste and health information originating from Gamma-Dynacare in a suburb of Ottawa.

Ottawa Sun Online: NEWS - Patient info in trash: "Homeowner finds medical waste, including personal data, in his driveway for second time

A MANOTICK homeowner was shocked last week to find used medical supplies and private health information in a garbage bag dumped in his driveway.

Anthony Heembrock opened the bag Thursday to find out who'd dumped garbage on Rideau Bend Cres. for a second week in a row.

He says he found medical debris, including bloodied gauze and lab test forms with patients' names, addresses, phone and OHIP numbers.

"What if my animals or my kids got into this stuff?" Heembrock said. "What about patients' confidentiality?"

He's worried that kids and pets are at risk from handling medical waste and patients from identity theft or fraud if the information fell into the wrong hands.

Heembrock said the forms listed the Gamma-Dynacare Medical Laboratories, which shares a building with the Manotick Medical Centre. Gamma-Dynacare didn't return calls yesterday.

Dr. Ann Fillingham, a physician at the health centre, says the public was never at risk from the bag of garbage but how it disappeared is under investigation, she said.

The medical items Heembrock found, including urine specimen bottles, had never been used, she said. The bag did contain cotton balls that are taped to patients' arms after blood tests because patients throw them in the trash.

The clinic has secure disposal of needles and blood products and shreds all sensitive patient information, Fillingham said.

LOCKED AT ALL TIMES

She said the records found were requisition forms from the lab, not medical centre patient records.

Someone must have grabbed the garbage in the few minutes between when it's collected from the building and put in a locked dumpster, Fillingham said. It's now locked up at all times.

"How the garbage got to where it got twice doesn't make sense," Fillingham said. "Something is going on. We're not letting it happen again."

Having health information turn up in the garbage could violate new health privacy legislation, said Bob Spence, spokesman for the province's information and privacy commissioner.

The Personal Health Information Protection Act requires health care workers to store, share and discard private information securely.

"Anyone who works in health would be encouraged to destroy health information rather than throwing it out in the trash," said Spence. "Once we obtain more information, we will be launching a privacy investigation into this."..."