<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Identity Theft and Data Breach News &#124; ID Experts Corporate Blog &#187; id experts</title>
	<atom:link href="http://blog.idexpertscorp.com/tag/id-experts/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.idexpertscorp.com</link>
	<description>ID Experts Corporate Blog</description>
	<lastBuildDate>Wed, 21 Jul 2010 15:34:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>HITECH Data Breach Risk Assessment  Webinar</title>
		<link>http://blog.idexpertscorp.com/2010/05/hitech-risk-assessment-overview-webinar/</link>
		<comments>http://blog.idexpertscorp.com/2010/05/hitech-risk-assessment-overview-webinar/#comments</comments>
		<pubDate>Mon, 17 May 2010 23:36:31 +0000</pubDate>
		<dc:creator>Doug Pollack</dc:creator>
				<category><![CDATA[Breach Notification]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[Medical Identity Theft]]></category>
		<category><![CDATA[data breach notification]]></category>
		<category><![CDATA[data breach risk assessment]]></category>
		<category><![CDATA[hhs hitech rules]]></category>
		<category><![CDATA[id experts]]></category>
		<category><![CDATA[kirk nahra]]></category>
		<category><![CDATA[rick kam]]></category>
		<category><![CDATA[wiley rein]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=319</guid>
		<description><![CDATA[Healthcare organizations that fall under the definition of HIPAA covered entities should be very aware of their obligations under the data breach provisions of the HITECH Act. The reason being that there are now very substantial penalties for disregarding the security and privacy regulations, for lax detection of data breach incidents and for failing to [...]]]></description>
			<content:encoded><![CDATA[<p>Healthcare organizations that fall under the definition of HIPAA covered entities should be very aware of their obligations under the data breach provisions of the HITECH Act. The reason being that there are now very substantial penalties for disregarding the security and privacy regulations, for lax detection of data breach incidents and for failing to notify affected individuals of an incident within a specified period of time.</p>
<p>One of the keys to meeting the notification requirement is completing and documenting a data breach incident &#8220;risk assessment&#8221; for each and every incident that is detected. The &#8220;rules&#8221; for carrying out this mandated assessment are specified by the department of Health and Human Services (HHS) in their rulemaking. This webinar will assist information security, compliance and privacy officers and professionals at hospitals, health insurers, and other covered entities in understanding what they need to do and how to go about doing it, when faced with a potential data breach incident.</p>
<p>A description of the webinar follows.</p>
<p>The HITECH Act requires HIPAA-covered entities to carry out a careful risk assessment, including an evaluation of potential harm, for every potential data breach incident. This risk assessment will assist organizations in deciding whether they are obligated to then notify affected individuals, the Department of Health and Human Services (HHS) and the media about data breach incidents.</p>
<p>Kirk Nahra, CIPP, a partner at the premier healthcare law firm Wiley Rein LLP, and Rick Kam, president and founder of ID Experts, will review and discuss the HHS rules for completing these mandated data breach incident risk assessments in order to ensure compliance and utilize evolving best practices.</p>
<p>Learn about considerations for HIPAA-covered entities in carrying out mandated HITECH data security breach incident risk assessments. To enroll to attend the webinar, <a href="https://www2.gotomeeting.com/register/666004955" target="_blank">click here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2010/05/hitech-risk-assessment-overview-webinar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High Unemployment Increases Cybercrime</title>
		<link>http://blog.idexpertscorp.com/2010/04/high-unemployment-increases-cybercrime/</link>
		<comments>http://blog.idexpertscorp.com/2010/04/high-unemployment-increases-cybercrime/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 22:59:43 +0000</pubDate>
		<dc:creator>Doug Pollack</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[id experts]]></category>
		<category><![CDATA[unemployment]]></category>
		<category><![CDATA[verizon business]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=309</guid>
		<description><![CDATA[In the past, a significant percentage of data breach incidents have been attributed to carelessness.  The lost laptop is one of the most common data breach causes, especially given how few use encryption technology and how common it is for employees to have access of private data.
With the economic meltdown of 2009, and the subsequently [...]]]></description>
			<content:encoded><![CDATA[<p>In the past, a significant percentage of data breach incidents have been attributed to carelessness.  The lost laptop is one of the most common data breach causes, especially given how few use encryption technology and how common it is for employees to have access of private data.</p>
<p>With the economic meltdown of 2009, and the subsequently high unemployment rates,  there is now emerging a growing trend of data breaches caused by disaffected or displaced employees.</p>
<p>Recently noted by San Francisco Chronicle writer Alejandro Martínez-Cabrera in his article titled &#8220;<a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2010/04/07/BUDB1CQ2E8.DTL" target="_blank">How some ex-employees turn to cybercrime</a>&#8220;:</p>
<p>&#8220;Corporations across all  industries have  been dealing with  a steadily growing number of  internal data breaches since the financial meltdown. A Verizon data loss report noted that individuals with insider  knowledge of organizations accounted for 20 percent of all breaches last  year, and that number has been increasing  as economic malaises drag  on, said Chris Novak, managing principal of Verizon Business&#8217; Global  Investigative Response Team.&#8221;</p>
<p>&#8220;Stolen data can range from employees&#8217; health care records or clients&#8217;  credit card numbers to merger and acquisition plans, confidential  agreements or valuable source code, said Rick Kam, president and  co-founder of data breach prevention firm ID Experts.</p>
<p>Thieves can easily sell the information to cyber-criminal rings or  use it as a bargaining chip to get a job with their former employer&#8217;s  competitors. According to the Ponemon Institute study, 67 percent of  respondents said they would use &#8220;their former company&#8217;s confidential,  sensitive or proprietary information to leverage a new job.&#8221;</p>
<p>&#8216;The issue of identity theft is all about opportunity,&#8217; Kam said. &#8216;And our first instinct is to protect ourselves.&#8217;</p>
<p>In one case handled by Kam&#8217;s company six months ago, a disgruntled  man  went as far as trying to extort his former employer, a large health  care provider, by threatening to release thousands of sensitive patient  records that would have triggered an avalanche of lawsuits.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2010/04/high-unemployment-increases-cybercrime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Ready for HITECH?</title>
		<link>http://blog.idexpertscorp.com/2009/11/208/</link>
		<comments>http://blog.idexpertscorp.com/2009/11/208/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 18:51:42 +0000</pubDate>
		<dc:creator>Doug Pollack</dc:creator>
				<category><![CDATA[Breach Notification]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[arra]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[covered entities]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[data breach notification]]></category>
		<category><![CDATA[himss]]></category>
		<category><![CDATA[himss analytics]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[id experts]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=208</guid>
		<description><![CDATA[HIMSS Analytics this past week released a study titled &#8220;Evaluating HITECH’s Impact on Healthcare Privacy and Security&#8221; that looks at healthcare providers and their business associates, relative to their awareness of the HITECH Act&#8217;s data breach provisions, as well as their experience with data breach incidents and concerns about preparedness and compliance with HITECH Act [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-207" title="ha_logo" src="http://blog.idexpertscorp.com/wp-content/uploads/2009/11/ha_logo.gif" alt="ha_logo" width="250" height="73" />HIMSS Analytics this past week released a study titled &#8220;<a href="http://www.idexpertscorp.com/breach/download/?altid=b_himms_download&amp;cid=prhimss1117 " target="_blank">Evaluating HITECH’s Impact on Healthcare Privacy and Security</a>&#8221; that looks at healthcare providers and their business associates, relative to their awareness of the HITECH Act&#8217;s data breach provisions, as well as their experience with data breach incidents and concerns about preparedness and compliance with HITECH Act provisions.</p>
<p>This study, co-sponsored by <a href="http://www.idexpertscorp.com">ID Experts</a>, the leader in identity breach protection, exposes some significant concerns.  It concludes that healthcare business associates, those organizations that provide services such as billing, credit bureaus, benefits management, legal services, claims processing, insurance brokers, data processing firms, pharmacy chains, accounting firms, temporary office personnel, and offshore transcription, are &#8220;unprepared for data breach&#8221;.</p>
<p>Further it notes that  <em>&#8220;68 Percent of Provider Respondents Indicated that the HITECH Act’s Expanded Breach Notification Requirements will Result in More Discovery and Reporting of Incidents&#8221;.</em></p>
<p>This implies that healthcare organization are experiencing data breach incidents that in the past have either gone unrecognized or unreported. And that the new law is likely to &#8220;expose&#8221; more incidents because of the compliance requirements and the potentially large penalties for non-compliance.It also notes that a lack of preparedness and concern on the part of healthcare providers&#8217; business associates creates a very significant risk to the privacy of their patients.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2009/11/208/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Santa Fe Group Announces ID Crime Victims&#8217; Bill of Rights</title>
		<link>http://blog.idexpertscorp.com/2009/02/santa-fe-group-announces-id-crime-victims-bill-of-rights/</link>
		<comments>http://blog.idexpertscorp.com/2009/02/santa-fe-group-announces-id-crime-victims-bill-of-rights/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 17:17:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Credit Bureaus]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Fair Credit Reporting Act]]></category>
		<category><![CDATA[Gramm-Leach-Bliley Act]]></category>
		<category><![CDATA[ID Restoration]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[SEC]]></category>
		<category><![CDATA[fact act]]></category>
		<category><![CDATA[id experts]]></category>
		<category><![CDATA[id theft]]></category>
		<category><![CDATA[identity crime]]></category>
		<category><![CDATA[santa fe group]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=103</guid>
		<description><![CDATA[by Doug Pollack
The Santa Fe Group, an industry consortium, announced today an identity crime victims&#8217; bill of rights that proposes the rights that should be provided to all individuals and recommending an approach to legislation for adopting this bill of rights.
&#8220;The five basic rights address the need for legislation that enables individual victims of identity [...]]]></description>
			<content:encoded><![CDATA[<p>by Doug Pollack</p>
<p>The <a href="http://www.santa-fe-group.com/" target="_blank">Santa Fe Group</a>, an industry consortium, announced today an identity crime victims&#8217; bill of rights that proposes the rights that should be provided to all individuals and recommending an approach to legislation for adopting this bill of rights.</p>
<p>&#8220;The five basic rights address the need for legislation that enables individual victims of identity theft to access and correct personally identifiable information (PII) records. The Bill of Rights white paper, titled <strong>Victims&#8217; Rights: Fighting Identity Crime on the Front Lines, </strong>is now available at <a href="http://santa-fe-group.com/whitepapers/register.php" target="_blank">http://santa-fe-group.com/whitepapers/register.php</a>.&#8221;</p>
<p>The Identity Crime Victims Bill of Rights advocates improved protection and support for victims and includes:</p>
<ul>
<li>Assessment of the nature and extent of the crime that removes the procedural &#8216;Catch-22s&#8217; when validating identity</li>
<li>Full restoration of victims&#8217; identities to pre-theft status, including the ability to expunge records</li>
<li>Freedom from harassment from collection agencies, law enforcement and others</li>
<li>Prosecution of offenders and accountability for businesses that fail to reasonably secure personal information</li>
<li>Restitution that includes repayment for financial losses and expenses</li>
</ul>
<p>&#8220;The white paper effort was led by the Identity Management Working Group of The Santa Fe Group Vendor Council chaired by <strong>Rick Kam</strong>, President of ID Experts (<a href="http://www.idexpertscorp.com/" target="_blank">www.idexpertscorp.com</a>).</p>
<p>&#8216;Despite new additions to the Fair and Accurate Credit Transaction Act of 2003 (FACT), such as free credit reports and the ability to place fraud alerts after identity theft, victims are still subject to inconsistent and unfair treatment from state and federal agencies, law enforcement and businesses,&#8217; said <strong>Rick Kam</strong>, President of Portland-based ID Experts, a leader in data breach prevention and remediation. &#8216;We created the Bill of Rights to empower victims by granting them the same rights as victims of other crimes.&#8217;&#8221;</p>
<p>The Santa Fe Group, ID Experts and other members of the Vendor Council will be holding meetings in Washington, DC later this spring in order to drum up support for this concept and related legislation.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2009/02/santa-fe-group-announces-id-crime-victims-bill-of-rights/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Millions Affected by Small Fraudulent Charges Nationwide</title>
		<link>http://blog.idexpertscorp.com/2009/01/millions-affected-by-small-fraudulent-charges-nationwide/</link>
		<comments>http://blog.idexpertscorp.com/2009/01/millions-affected-by-small-fraudulent-charges-nationwide/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 18:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Adele Services]]></category>
		<category><![CDATA[credit card fraud]]></category>
		<category><![CDATA[fraudulent charge]]></category>
		<category><![CDATA[id experts]]></category>
		<category><![CDATA[Melville]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=96</guid>
		<description><![CDATA[Internet complaint boards have been busy and credit card fraud departments are scratching their heads. Thousands of customers across the country are reporting small (about 25 cents to 1 dollar) charges mysteriously appearing on their monthly statements. The Boston Globe carried the story here. 
The charge shows up on statements as coming from “Adele Services” [...]]]></description>
			<content:encoded><![CDATA[<p><span style="Calibri;">Internet complaint boards have been busy and credit card fraud departments are scratching their heads. Thousands of customers across the country are reporting small (about 25 cents to 1 dollar) charges mysteriously appearing on their monthly statements. The Boston Globe carried the story <a title="The Boston Globe" href="http://www.boston.com/business/personalfinance/articles/2009/01/11/mysterious_credit_card_charge_may_have_hit_millions_of_users/">here</a>. </span></p>
<p class="MsoNormal" style="0in 0in 10pt;"><span style="Calibri;">The charge shows up on statements as coming from “Adele Services” in Melville, N.Y. Of course, there is no business by that name in Melville, or anywhere in New York. According to The Boston Globe, “<em>Two theories of what is going on have advanced on message boards and among consumer advocates: Someone is trying to find out whether an illegally obtained credit card number will work before making a bigger charge, or they&#8217;re trying to rip off tiny amounts from tons of people.</em>”</span></p>
<p class="MsoNormal" style="0in 0in 10pt;"><span style="Calibri;">So far, most reports indicate that no larger charges have appeared yet. However, the Better Business Bureau estimates the number of victims to be in the millions. It has not yet been determined how the card numbers became compromised. It has been mostly successful since most people are likely to overlook or ignore a small charge. As former Massachusetts assistant attorney general Edgar Dworsky, told The Boston Globe, &#8220;<em>It&#8217;s easier to steal $1 from a million people than $1 million from one person</em>.”</span></p>
<p><span style="AR-SA;">This is a great reminder of why it is important to examine your monthly statements closely, and to always question charges you do not recognize no matter how small. If you let it slide, that is exactly what they are hoping for. If you have one of these charges, call your financial institution and notify them of the disputed charge. Then file a complaint with the FTC (<a href="http://www.ftc.gov/">www.ftc.gov</a>) and the FBI’s Internet Crime Complaint Center (<a href="http://www.ic3.gov/">www.ic3.gov</a>). It is important to lodge a complaint, even if the charge is small, as a large number of similar complaints can launch a federal investigation.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2009/01/millions-affected-by-small-fraudulent-charges-nationwide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Ponemon Study &#8212; data breaches from the consumer&#8217;s perspective</title>
		<link>http://blog.idexpertscorp.com/2008/04/new-ponemon-study-data-breaches-from-the-consumers-perspective/</link>
		<comments>http://blog.idexpertscorp.com/2008/04/new-ponemon-study-data-breaches-from-the-consumers-perspective/#comments</comments>
		<pubDate>Tue, 15 Apr 2008 23:50:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[data breach notification]]></category>
		<category><![CDATA[id experts]]></category>
		<category><![CDATA[ponemon institute]]></category>

		<guid isPermaLink="false">http://blog.idexpertscorp.com/?p=61</guid>
		<description><![CDATA[by Doug Pollack
The Ponemon Institute today released a new study, sponsored by ID Experts, titled &#8220;Consumers Report Card on Data Breach Notification&#8220;.  They describe the rationale and importance of this study as follows:
&#8220;It is well established that identity theft has become a very serious issue for Americans. But how well are organizations responding to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.idexpertscorp.com/wp-content/uploads/2008/04/ponemon.gif"><img class="alignleft size-medium wp-image-62" title="ponemon" src="http://blog.idexpertscorp.com/wp-content/uploads/2008/04/ponemon-300x47.gif" alt="" width="300" height="47" /></a>by Doug Pollack</p>
<p>The <a title="Ponemon Institute" href="http://www.ponemon.org/" target="_blank">Ponemon Institute</a> today released a new study, sponsored by <a href="http://www.idexpertscorp.com/breach/">ID Experts</a>, titled &#8220;<a href="http://www.idexpertscorp.com/breach/ponemon-study/" target="_blank">Consumers Report Card on Data Breach Notification</a>&#8220;.  They describe the rationale and importance of this study as follows:</p>
<p>&#8220;It is well established that identity theft has become a very serious issue for Americans. But how well are organizations responding to consumers&#8217; worries when their personal information is lost as the result of a data breach? We decided to conduct this study to find out if consumers who received notification about a data breach involving their personal information were satisfied with the organizations&#8217; response and transparency. In other words, if the consumers had the ability to issue a report card on the current status of data breach notification would it be A for excellent or F for failing?&#8221;</p>
<p>The report provides a wealth of useful information to companies in order to effectively plan for a data breach response effort. Given an earlier Ponemon study estimate that around two-thirds of the $197 per person average cost of a data breach is in lost business and reputation,  this report can assist companies in evaluating how elements of their data  breach response effort can influence their customer retention rates and thereby attempt to reduce this very critical component of the cost equation.</p>
<p>Dr. Larry Ponemon states that:</p>
<p>&#8220;Data breach notifications are a failure if individuals do not have a clear understanding of their level of risk, available support, and the steps they need to take to respond to the loss of theft of their personal information. Our research strongly suggests that legal compliance is the primary goal of many companies&#8217; notification efforts. This approach does not serve the best interests of consumers and contributes to a breakdown of trust that can impact a company monetarily as a result of increase in customer defection.&#8221;</p>
<p>To <a href="http://www.idexpertscorp.com/breach/">download a copy of this study</a>, visit the ID Experts website and click on the New Ponemon Study link.</p>
<div>
<hr size="1" /><!--[endif]--></p>
<div id="ftn1">
<p class="MsoFootnoteText"><a name="_ftn1" href="#_ftnref1"></a><span style="font-size: 9pt; font-family: Arial;"> </span></p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.idexpertscorp.com/2008/04/new-ponemon-study-data-breaches-from-the-consumers-perspective/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
