Monday, April 11, 2005

Aeroplan rapped over data security

Aeroplan is once again in the privacy hot-seat, according to this article from the Globe and Mail. This time, it is for inadequate security that allowed an Aeroplan member's boss to review and modify his account information. The article has some pretty strong words from Heather Black, the Assistant Privacy Commissioner of Canada:

The Globe and Mail: Aeroplan rapped over data security:

"By PAUL WALDIE

Monday, April 11, 2005 Page B1

The Office of the Privacy Commissioner has sharply criticized security at Air Canada's popular Aeroplan frequent-flyer program and told the airline to better protect members' account information.

"On the whole, there was a clear lack of diligence on the part of Air Canada with respect to its handling and protection of customer personal information," Heather Black, assistant privacy commissioner, said in a recent ruling involving a Vancouver businessman whose Aeroplan account was accessed, and changed, by his former boss.

While noting the airline has taken some steps to tighten security, she said key data is still too easily available. "If someone with access to an account number calls the system, he or she [is able to access] the account holder's name, the number of miles recently credited to the account, and the account balance."

"This information is not password protected. I remain concerned about the accessibility to the information that is still on the system."

Aeroplan has six million members and has reward program partnerships with retailers such as Future Shop Ltd., Imperial Oil Ltd.'s Esso gasoline chain and Bell Canada's phone services.

Michele Meier, an Aeroplan spokeswoman, said the company has already acted on recommendations made during the investigation, "We're in the process of evaluating whether any further measures will be taken or will be necessary," she said.

The case dates back to March 14, 2002, when the businessman, Danny Yehia, received a duplicate copy of his previous Aeroplan statement.

When he contacted Aeroplan for an explanation of why he was sent the additional statement, he was told that someone had requested the information and changed the e-mail address on his account.

At the time, Mr. Yehia was involved in a lawsuit with his former boss, Joel Berman, a Vancouver glass designer. Mr. Berman alleged Mr. Yehia and his partner had taken company secrets when they left his glass business months earlier. Part of the lawsuit centred around a trip Mr. Yehia took to Australia allegedly to meet a rival glass company.

Mr. Berman admitted to the privacy officer that he obtained detailed information about Mr. Yehia's account from Aeroplan's computerized telephone information system and through an Air Canada agent. "Air Canada states that he could do this because there was no personal identification number required," Ms. Black said in her decision.

She said Mr. Berman did not misrepresent himself or pretend to be Mr. Yehia. In fact, he provided the agent with his name in order to pay a processing fee to change the account.

The lawsuit was eventually dropped, but Mr. Yehia complained about Aeroplan's actions to the privacy commissioner.

In her decision, released last week, Ms. Black said she was "disturbed by Air Canada's lack of co-operation with respect to [Mr. Yehia's] complaint."

She also said the agent who changed the account had not been properly trained in privacy issues and "it did not appear to concern her that she was not speaking to the account holder." The agent "did not even seem to be aware of the importance of maintaining the confidentiality of personal information."

She added that, given the number of people who have access to Aeroplan members' numbers, such as employers, travel agents, and Aeroplan workers, "I do not believe that having account information readily available, without any protection on it, constituted an adequate safeguard."

Ms. Meier said Aeroplan regrets "this unfortunate incident," and noted that it has restricted the information on the automated phone service. It has also updated privacy procedures and introduced more training for staff.

But Ms. Black questioned whether the changes go far enough. She said the automated system still provides access to account holders' names, the number of miles recently credited to the account and the account balance.

"Many individuals have credit cards that are partnered with Aeroplan. Anyone with access to the Aeroplan account number could potentially know from the number of miles credited to the account how much money was charged against the account holders' credit card in a month."

She recommended password controls should be placed on all account information that is accessible though the automated system.

Mr. Yehia said Aeroplan should be doing much more to protect information.

"You'd think that after [the Sept. 11, 2001 terrorist attacks] security would be an important issue," he said.

When asked if he is still an Aeroplan member, he laughed and replied: "I am. Because where I travel, I don't really have much choice."

Presently, passwords are required to view and modify account information. Also, phone agents are requiring more proof of identity before assisting Aeroplan members.

Sunday, April 10, 2005

Texas Considering Security Breach Notification Law

PrivacySpot is reporting that the state of Texas is considering a privacy breach notification law, similar to the law already in place in California:

One Million Dollars: Texas Considering Security Breach Notification Law | PrivacySpot.com - Privacy Law and Data Protection:

"...The law would require a person 'that owns or licenses computerized data that includes identifying information of a resident of this state' to notify the resident of any computer security breach if the resident's unencrypted identifying information was, or was reasonably believed to have been, obtained by an unauthorized person.

Notification would be required within a reasonable time after the data controller discovered the security breach, taking into consideration any law enforcement agency requests to delay the notification and any measures necessary to determine the scope of the breach or restore the reasonable integrity of the data system. A data controller that has notification procedures built in to its data security policy could use those notification procedures so long as they were not inconsistent with the timing requirements of the law...."

Identity complex: Data brokers' files are extensive, as are their destinations

Today's Palm Beach Post is running a feature article on the data broker industry. There's not too much to learn here for those who follow the industry, but it's a good introduction for newcomers.

Identity complex: Data brokers' files are extensive, as are their destinations:

"... The personal information these firms have collected on virtually every American is staggering.

ChoicePoint has 19 billion documents; LexisNexis and its Boca business, Seisint, have 33 billion records. InfoUSA Inc. -- targeting companies with consumer and business data -- runs a database containing information on 250 million consumers and 14 million businesses. Another company, Acxiom Corp., says its consumer database covers 95 percent of U.S. households.

These records encompass more than just Social Security and driver license numbers. They include telephone numbers, birth and death records, personal addresses, vehicle ownership, criminal records, marriage and divorce records, liens and judgments, mortgages, property taxes individuals paid, personal bankruptcies and professional and business licenses. They include demographic data, consumer purchasing behavior and lifestyle interests...."

Saturday, April 09, 2005

Incident: Bank employee uses access to personal information in attempt to drain funds from an account

The Bourse de Montreal has disciplined a representative of National Bank Financial Inc. for using access to personal information to impersonate the holder of an inactive account to obtain the funds held in that account. The findings of the Bourse include that the subject of the investigation used a fake drivers' license in the name of the account holder with a fake address to cash the cheque.

The press release is below:

Canada NewsWire Group:

"MONTREAL, April 6 /CNW Telbec/ - On November 13, 2003, following an investigation made by the Investigation Department of the Regulatory Division, Bourse de Montréal Inc. (the Bourse) filed a complaint against Paul Robert, a person approved by the Bourse.

Following a hearing, the Disciplinary Committee of the Bourse (the Committee) issued a decision imposing to Paul Robert a fine of $25,000 and requiring that he refunds the total costs and expenses, including professional fees, paid or incurred by the Bourse for an amount of $8,096. In addition, Paul Robert has been permanently prohibited to be approved in any capacity for an approved participant of the Bourse.

The Disciplinary Committee concluded that during the period from August 12, 2002 to November 9, 2002 Paul Robert contravened article 4101 of the Rules of the Bourse.

Subparagraph a) ii) of article 4101 of the Rules of the Bourse prohibits any act, conduct, practice or proceeding unbecoming an approved person, inconsistent with just and equitable principles or detrimental to the reputation of the Bourse or to the interests or welfare of the public or of the Bourse.

During the above-mentioned period, Paul Robert, while being registered as a representative and officer for National Bank Financial Inc. (NBF), used its position as a compliance analyst responsible for the daily monitoring of clients accounts to gain illicit access to personal information relating to inactive accounts and more particularly on an account that had been inactive for a few years and whose holder could not be traced. Pending the eventual transfer of its assets, as required by law, to the Curateur public du Québec, this account, which had a cash balance of $16,190.98, was under the responsibility of National Bank Correspondent Network (NBCN), a subsidiary of FBN.

Paul Robert impersonated the holder of the account and manoeuvred to fraudulently misappropriate the funds. Using illicitly obtained personal information on the holder of the inactive account, Paul Robert communicated by phone with NBCN customers' services falsely presenting himself as being the holder of the account and attempted to misappropriate a part of the balance, that is $4,000. Thereafter, always under false representations, he asked NBCN to close the account and attempted to claim the total balance of the account.

He succeeded to have NBCN issue two cheques to the order of the account and to forward them to a false address. However, he was unable to take possession of these cheques as he expected to. After further actions, he succeeded in having a third cheque issued and being able to take possession of it.

Once the cheque in his possession, Paul Robert presented himself to a cashiering services provider with a false driver's licence identifying him as being the beneficiary of the cheque and indicating a false address that he had given to NBCN. The provider's employee, suspecting some irregularity, called the police who came to arrest Paul Robert and imprisoned him. Later on, he was charged with fraud attempt and use of forgery.

Paul Robert was dismissed by NBF shortly after having been charged.

In its analysis, the Committee considered the amount involved, the fact that the fraudulent acts of Paul Robert were among the most serious that exist for an approved person and that his acts and deeds were planned and carried on over a period of many months thus showing a very clear determination to carry his project to completion. There was even a gradation of the fraudulent maneuvers as he initially attempted to misappropriate $4,000 and later on the total balance of the account. He even used the services of an accomplice to obtain false identification documents in order to complete the misappropriation of the funds under the custody of NBCN. The Committee also considered that Paul Robert position as a compliance analyst with NBF as an aggravating factor. While in such position Paul Robert should have acted as a guardian of the compliance with legality and with the justice and fairness principles governing the securities industry, he rather took advantage from his position to abuse the trust of his employer and of the public.

The Committee also tempered its analysis by taking into account the fact that Paul Robert had finally not succeeded to misappropriate the account holder funds and that, as a consequence, neither the account holder nor his assigns had incurred a loss. The Committee also took into account the absence of disciplinary history for Paul Robert, the fact that he had been dismissed by his employer and that the reasons for his dismissal would follow him for a significant part of his career and, finally, that he had cooperated with his former employer and with the personnel of the Bourse all along the disciplinary process.

Paul Robert is not currently employed in the securities industry.

Based on the facts and circumstances disclosed during the investigation, the Regulatory Division of the Bourse determined that there was no cause for initiating disciplinary complaints against NBF.

To access the full text version of the Committee, please refer to the following link: http://www.m-x.ca/f_publications_fr/050215_decision_disciplinaire_02_fr.pdf (available in French only).

For further information: Jean-Charles Robillard, Communications, (514) 871-3551, or by e-mail at ????????@m-x.ca."

Incident: Break and enter at Windsor Ontario medical lab exposes patient information

A medical lab in Windsor, Ontario was broken into on January 1, 2005 and the thieves made off with a computer containing personal health information. The lab only issued a notice this week after they incorrectly assumed they needed the OK from the Information and Privacy Commissioner of Ontario. (In fact, the new Ontario Personal Health Information Protection Act requires that such disclosures be reported to affected patients.) The lab says they informed the IPC right away, a fact that the IPC's office disputes.

From Canada.com:

Fort St. John - canada.com network:

"Patients kept in dark over theft of lab files: Information taken during break and enter in Windsor

Doug Schmidt
Windsor Star

April 9, 2005

Ontario's Ministry of Health wants to know why it took more than three months for a Windsor medical lab to begin reporting the theft of personal and medical information to affected patients and their doctors.

"Eventually, the ministry would want some kind of justification for the delay," ministry spokesman John Leatherby said. "Those who are affected need to be in the know."

Friday, Medical Laboratories of Windsor Ltd. (MLW) issued a news release reporting a computer containing patients' names, addresses, health card numbers and health information was stolen from its 1428 Ouellette Ave. office Jan. 1.

Windsor police have been investigating the theft but report no success.

"As soon as we discovered the theft, we contacted authorities," company spokeswoman Jennifer Yee said.

As required by law, the company notified Ontario's Office of the Information and Privacy Commissioner, but spokesman Bob Spence said Friday it wasn't until early March -- two months after the B&E -- that it was made aware of the theft. He said the privacy commissioner has also launched an investigation into the theft.

According to police, one or more suspects broke into the front door of the Ouellette Avenue office building that night and then smashed through MLW's medical office door on the third floor, leaving with a computer, flat-screen television, a computer monitor and petty cash.

The missing computer was used to collect and transmit ECG information from patient tests to family physicians and cardiologists, Yee said.

She said she "wouldn't want to speculate" on the number of patients affected by the theft, but added more than 100 doctors in the Windsor-Essex area were sent letters Thursday advising them of the theft.

"We sincerely regret this situation," Yee said.

Staff Sgt. Ed McNorton said Windsor police believe the suspects targeted the computer for its hardware value and not the personal and private medical information it contained.

Nevertheless, said the ministry's Leatherby: "Those individuals who have had their personal information stolen -- they should be next to the first persons to be advised."

Asked why MLW, which has operated locally the past 43 years, waited three months to alert doctors, patients and the public to the possible theft of personal data, Yee said it was only Thursday that the company received the required approval from the privacy commissioner's office.

NOT NEEDED

But commissioner spokesman Spence told The Star Friday there is no need for such approval.

"We do not tell organizations not to advise people -- or announce to the public -- that information may have been lost," he said.

Though there are four other MLW offices across the county, Yee said, only the ECG test results and patient information of those attending the Ouellette Avenue office were affected.

The private company said it launched its own internal investigation and is also working with the Ontario Ministry of Health and Long-Term Care on the case.

"We have ... taken a number of steps to ensure MLW's security and data protection measures meet or exceed current health industry standards," company president Dr. George Yee said in Friday's news release.

The Health Ministry will wait until the conclusion of the police investigation before launching a probe into the reporting delay, Leatherby said.

Any patients requiring additional information are asked to call MLW at 258-1991."

States initiatives on the privacy law front

Today's Washington Post, via Yahoo! News, is running a story on the various state legislative initiatives related to protecting personal information:

Yahoo! News - States Scramble To Protect Data:

"Legislatures in more than two dozen states are considering ways to give consumers more control over personal information that is collected and sold by private firms, but many of the proposals are drawing fire from financial services companies...."

ChoicePoint scandal driving tougher global privacy standards

From today's Palm Beach Post:

ChoicePoint scandal driving tougher global privacy standards:

"WASHINGTON - U.S. corporations are sending more personal data for processing overseas in a 'race to the bottom' for lower costs. But a consumer-driven 'race to the top' for tougher privacy standards should help protect that information, one expert said Friday.

The trend toward stricter rules has gotten a big boost from the ChoicePoint scandal, Privacy Times editor Evan Hendricks said Friday....

Hendricks discussed the case's impact at a seminar, "Offshoring and Privacy: Consumer Data in the Global Economy," sponsored by the Brookings Institution, a research group.

"In the long run, I'm optimistic" about improving privacy because the ChoicePoint scandal has so dramatically underscored the risks of failing to protect consumers, he said. The company, which sells data including Social Security numbers, property records, bank accounts and criminal histories, has been hit by dozens of lawsuits as its stock has dropped.

In recent years, a growing number of U.S. companies have been using the Internet to send financial and other personal information to contractors operating in India, the Philippines and other countries where wages are lower.

One of the speakers defending the practice was Kiran Karnik, president of the National Association of Software and Services Companies, which promotes India as a trusted outsourcing destination.

Karnik said it's natural for people to question the wisdom of sending sensitive data far away, especially across borders. People in the industry "very much understand" that people often distrust foreigners, and "deep down" don't want them seeing personal data, he said.

But he said U.S. companies require their contractors to follow the same laws as if they were based in America.

In addition, he said, India is revising its domestic privacy laws to satisfy concerns of its European and U.S. customers. Karnik's group and the Information Technology Association of America held a conference in New Delhi in October on this topic.

The same pressures are likely to lead to even tougher rules in the future. Hendricks said that in a global economy, European companies will want to be able to do business with contractors in the United States, India and other countries."

Friday, April 08, 2005

Incident: Mississippi joins list of colleges leaking data as names and SSNs are posted online

For quite some time, a list of names, frats and social security numbers has been publicly available on a University of Mississippi web server. Only after notified by MSNBC did the university take it down:

Mississippi joins list of colleges leaking data - Spam, Scams & Viruses - MSNBC.com:

"Ray was just surfing the Internet looking for information on an old friend. Instead, he found a gold mine for identity thieves -- a Web site full of documents listing hundreds of student names and Social Security Numbers. It was posted right on the University of Mississippi's Web site, there for anyone to see.

'I was just looking up an old college friend when I stumbled on this page,' said Ray, who requested his last name be withheld. 'I know this isn't something I should be able to see.'

There were about 20 documents listing fraternity and sorority members. Some had as few as five entries. The list of Phi Mu members included 189 names and Social Security Numbers. In all, about 700 students were listed in the documents.

After a call from MSNBC.com, the university shut down access to the Web page Wednesday. Jeff Alford, assistant vice chancellor for university relations, said the files had likely been exposed on the Internet since 2003...."

Thanks to PrivacySpot.com for the link.

Update:

Leak of UM data 'mistake' - The Clarion-Ledger:

"Students' info accidentally posted on server

The Associated Press

OXFORD - University of Mississippi officials say there was no malicious intent by a former staff member who backed up student information onto a document that could have made the data available to anyone over the Internet.

Jeff Alford, assistant vice president for university relations, said Friday that the names and Social Security numbers of about 300 students have been taken off the school's Web server.

Alford said MSNBC contacted the university on Wednesday after it broadcast a report that a man used the Internet to look up a college friend...."

Safire: Goodbye to Privacy

This Sunday's New York Times Review of Books contains (or will contain) a review by William Safire of "No Place to Hide" and "Chatter: Dispatches From the Secret World of Global Eavesdropping". It clearly discloses Safire's take on the privacy issue and gives a good review of both titles, firmly within the context of current events.

The New York Times > Books > Sunday Book Review > Goodbye to Privacy:

"... In the past five years, what most of us only recently thought of as ''nobody's business'' has become the big business of everybody's business. Perhaps you are one of the 30 million Americans who pay for what you think is an unlisted telephone number to protect your privacy. But when you order an item using an 800 number, your own number may become fair game for any retailer who subscribes to one of the booming corporate data-collection services. In turn, those services may be -- and some have been -- penetrated by identity thieves.

The computer's ability to collect an infinity of data about individuals -- tracking every movement and purchase, assembling facts and traits in a personal dossier, forgetting nothing -- was in place before 9/11. But among the unremarked casualties of that day was a value that Americans once treasured: personal privacy.

The first civil-liberty fire wall to fall was the one within government that separated the domestic security powers of the F.B.I. from the more intrusive foreign surveillance powers of the C.I.A. The 9/11 commission successfully mobilized public opinion to put dot-connection first and privacy protection last. But the second fire wall crumbled with far less public notice or approval: that was the separation between law enforcement recordkeeping and commercial market research. Almost overnight, the law's suspect list married the corporations' prospect list...."

Hughes Luce on Online Marketing Privacy Issues

Anthony Cerminaro's Deal Attorney blogis pointing to a very good and useful compendium on online privacy issues prepared by Hughes Luce. I'm planning to keep it handy as I have to deal with privacy issues with an American aspect on a regular basis.