Saturday, December 10, 2005

Poorly designed online interfaces make identity theft simple

Risks Digest is a good source of information on all sorts of risks -- including privacy risks. Recently, a contributor posted about a particular experience he had renewing this AAA membership: The Risks Digest Volume 24: Issue 11.

I am not sure someone can steal your identity using your AAA membership, but interfaces like this attached to something more sensitive may lead to big problems.

2019-06-28: Updated to remove the name of the Risks contributor and the content of his contribution, at his request.

Ontario Information and Privacy Commissioner responds to "Plan B" concerns

A letter to the editor in today's Toronto Star:

TheStar.com - No problem with giving Plan B info:

Letter, Dec. 9.

In his letter, Tim Lu stated that I recommended pharmacists not ask any questions when dispensing Plan B. Allow me to offer the following correction. I refer him to the Ontario College of Pharmacists notice of Dec. 8, 2005, which states the following: 'the Privacy Commissioner stressed that pharmacists should continue to provide information to patients who request this drug, to gather information and to educate and counsel patients. Pharmacists should ask questions of patients if necessary in the course of providing this service but should not record personal health information in a manner which identifies individual patients.'

My office did not recommend that pharmacists not communicate relevant information to women to ensure the safe and effective use of Plan B. Indeed, I noted that pharmacists provide very important services and guidance. However, in order to protect the privacy of Ontarians, as I am mandated to do under the Personal Health Information Protection Act, I must ensure that identifiable personal health information is only collected when it is necessary and that no more personal health information is collected than is necessary. With this in mind, my office together with the Ontario College of Pharmacists and the Ontario Association of Pharmacists is working expeditiously to develop new guidelines to assist pharmacists when dispensing Plan B.

Again, let me be clear. I have no problem with a pharmacist imparting information on Plan B to patients. My concerns lie with the unnecessary collection and recording of personally identifiable, sensitive health information.

Ann Cavoukian, Ontario Information and Privacy Commissioner, Toronto

Friday, December 09, 2005

Canadian Law Blogs List

A bit off the usual topic, but I have to give a plug for Steve Matthews' list of Canadian law blogs. Check it out: Vancouver Law Librarian Blog: Canadian Law Blogs List.

Also, a belated happy blogiversary to Steve's Vancouver Law Librarian Blog.

West Vancouver to require landlords to inspect tenants' apartments

I don't think this will pass a constitutional challenge ... on both jurisdictional and freedom from unreasonable search and seizure grounds.

My cousin lives in West Vancouver, BC. He just received a notice from his landlord saying that his apartment would be inspected every three months. Apparently The District of West Vancouver Controlled Substance Nuisance Bylaw No. 4417 requires landlords to enter into and inspect the premises of their tenants, supposedly looking for marijuana grow-ops. Granted, grow-ops are a problem in BC but this is the first municipal bylaw (that I know of) that purports to allow a landlord to enter into someone's rented space without any suspicion to check up on them for what are essentially law enforcement purposes. My cousin's a little miffed at this.

More on dispensing "Plan B"

In response to the debate over the dispensing of "Plan B" by pharmacies, a pharmacist has written to the Toronto Star that the controvertial form has already saved one customer of his from taking the drug inappropriately. Perhaps the conclusion to be drawn is that pharmacists should ask the customer if she would like detailed instructions on its proper use? See: TheStar.com - Make `Plan B' form voluntary

Beyond the Patchwork of Privacy Regulations

Kristina Lovejoy at Newsfactor is calling for omnibus privacy legislation for the US. What's interesting is that what she proposes looks a lot like the CSA Model Code that's built into PIPEDA:

NewsFactor Network - Enterprise - Beyond the Patchwork of Privacy Regulations:

...Because terms like privacy, confidentiality, and security often create confusion, the label 'information protection' was coined to encompass the range of mechanisms that guide collection, use, and disclosure of information. An information-protection regulation is one that enforces the right of privacy by dictating, among other things, requirements for maintaining the confidentiality, integrity, and availability of protected data.

In general, a strong information-protection plan would require the following:

1. Establishing ownership and accountability within the organization for confidentiality, integrity, and availability.

2. Identifying the reasons for obtaining private information from an end user and making those reasons available.

3. Establishing mechanisms for gaining consent of the end user before collecting private information.

4. Limiting collection of private information only to that information you need for business purposes.

5. Limiting use and disclosure only for the purposes for which you have gained consent, and limiting retention of information to a period specified by law or by user consent.

6. Ensuring that information collected is accurate.

7. Implementing administrative, technical, and physical controls around information to ensure its confidentiality, integrity, and availability.

8. Creating a culture of openness so that if the confidentiality, integrity, or availability of the information is breached in a significant way, the user is notified.

9. Providing the end user with documented escalation policy and process.

In the U.S., information-protection mandates have generally had impact only in certain market segments, such as the Health Insurance Portability and Accountability Act (HIPAA) in healthcare industry and the Gramm-Leach-Bliley Act (GLBA) in the banking sector.

Will there be increased pressure to regulate other industries? Yes. Will there be impetus for creating an Omnibus Information Protection regulation? Definitely.

Thursday, December 08, 2005

Study on data breach fallout

This may be the first news about ID theft in a little while. A San Diego company, ID Analytics, has done a computerized study of the effects of four of the highest profile data breaches of the last year or so. They found that of those whose information was leaked, only 0.098% were used in connection with fraud. I don't know anything about the company and its methodologies, but I expect some cynics may think that the timing on this is too coincidental as the conclusion to be drawn from the study is that there is little need to notify individuals if their information is compromised. See: SignOnSanDiego.com > News > Technology -- Good news on ID theft.

UWO pension and the USA Patriot Act

According to an item on the Western News, the University of Western Ontario is entering into an arrangement to have a US-based company administer the faculty pension. That has made at least one person unhappy that Canadian faculty info will be within the reach of the USA Patriot Act.

Communications and Public Affairs

Senator member Mike Carroll wants written assurance faculty pension information will never be turned over to secret U.S.intelligence courts. But he isn't holding his breath.

So why be concerned if you're not a terrorist?

...

The statement seems to be saying that they might well transmit our pension data across international boundaries - and this of course would in itself bring such data within reach of the Patriot Act

Ok, but so what? No terrorists here, right? Why worry? Actually, for several reasons. U.S. FIS courts operate in secrecy with little or no oversight (it's a crime to reveal an action of this court and a felony not to comply with an order to turn over records). As any number of academic bodies in the U.S. (including a number of academic Senates just a tad more activist than ours) have suggested, the wide-ranging authority granted under the Patriot Act poses a threat to civil liberties and creates a climate of fear that undermines academic freedom. In addition, the combination of such wide ranging-power with strict secrecy means that mistakes affecting ordinary (and innocent) people are easy to make and hard to correct (think Ted Kennedy and the "no fly" list).

U.S. academics have no choice at the moment. They are subject to the Patriot Act. But it seems to me entirely inappropriate that the Western Administration should so casually enter into an institutional arrangement that likely puts our personal data within reach of U.S. courts acting under the authority of that Act. At Senate tomorrow, I will be asking the Administration to seek explicit written assurances from Buck Consultants Canada that they will not be shipping our data across international boundaries and would not comply with a FIS court order to turn over data.

Simple. questions that should have straightforward answers. Anyone want to bet we'll ever see those answers? I personally think it unlikely, unless of course someone in SLB decides it might improve our grade on the Globe and Mail scorecard.

Alberta Commissioner authorizes an organization under PIPA to disregard an access request.

The Information and Privacy Commissioner of Alberta, Frank Work, has authorized a company to ignore access requests as being vexatious. PIPA allows the Commissioner to authorize a company to ignore such requests. In this case, the individual had been involved in fifteen years of litigation with Manulife (the applicant). The company said it had no other information on the individual that had not already been handed over as part of the discovery process. The report of the Commissioner is availble here: http://www.gov.ab.ca/acn/200512/19181.pdf.

Incident: Misuse of personal information by store clerks looking for bonuses

WCPO in Cincinatti is reporting that two employees of Fashion Bug have been charged with six counts of "identity fraud" after they applied for credit cards in the names of customers. Apparently they had no intention to use the credit cards, but rather received incentives for the number of people they signed up. Interesting. See: Fashion Bug Employees Charged With ID Theft.