<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Tue, 25 Aug 2026 23:58:00 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Tue, 25 Aug 2026 23:58:00 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[OCR Reminds Covered Entities to Choose Friends Carefully]]></title>
<description><![CDATA[
 
 
 
 
     <font face="Arial"> <i><b>Lack of Technical Controls Leads to Two Settlements with OCR for $4.8M.</b></i> <br><br>On May 8, 2014, the Office of Civil Rights (OCR) announced a settlement with New York and Presbyterian Hospital (NYP) and Columbia University (CU) involving allegation of violations of the HIPAA Privacy and Security Rules. Under the Resolution Agreements, NYP will pay $3 million and CU will pay $1.5 million to settle the investigations.<br></font><br><table style="text-align: left; margin-left: auto; margin-right: auto;" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i> </b></font><font color="#FFFFFF">This settlement is a good reminder that covered entities, business associates, and subcontractors must choose their partners carefully. As more organizations implement data sharing agreements, form strategic healthcare IT partnerships (e.g., those involving big data, analytics, etc.), and otherwise store their data with vendors, data breach issues are inevitable. Healthcare providers and vendors must carefully review their agreements to ensure that each party bears the appropriate amount of risk. Provisions related to indemnification, limitation of liability, damages caps, and insurance requirements should be reviewed with special attention.</font></font></font><br></td></tr></tbody></table><br><font face="Arial">NYP and CU are separate covered entities, but have an affiliation - generally called New York Presbyterian Hospital/Columbia University Medical Center - where CU faculty members serve as attending physicians at NYP.&nbsp; Under this arrangement, "NYP and CU operate a shared data network and a shared network firewall that is administered by employees of both entities. The shared network links to NYP patient information systems containing ePHI."[1]<br><br>NYP and CU filed a joint breach report in September 27, 2010 (<b>yes, 2010</b> - compare that to the 2014 settlement date!) following notification that the information of 6,800 patients, including patient status, vital signs, medications, and laboratory results, was available online. Specifically, according to the OCR Press Release:<br></font><blockquote><font face="Arial">The investigation revealed that the breach was caused when a physician employed by CU who developed applications for both NYP and CU attempted to deactivate a personally-owned computer server on the network containing NYP patient ePHI.&nbsp; Because of a lack of technical safeguards, deactivation of the server resulted in ePHI being accessible on internet search engines.&nbsp; <b>The entities learned of the breach after receiving a complaint by an individual who found the ePHI of the individual's deceased partner, a former patient of NYP, on the internet</b>.</font></blockquote><font face="Arial">OCR notified each of the entities on November 5, 2010 that it would launching an investigation. According to the Resolution Agreement with each of the entities, the OCR found the following conduct problematic:<br><br></font><table style="border: 1px solid #000000;" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><div align="left"><font face="Arial">a. NYP impermissibly disclosed the ePHI of 6,800 patients to Google and other Internet search engines when a computer server that had access to NYP ePHI information systems was errantly reconfigured.</font><br><br><font face="Arial">b. NYP failed to conduct an accurate and thorough risk analysis that incorporates all IT equipment, applications, and data systems utilizing ePHI.</font><br><br><font face="Arial">c. NYP failed to implement processes for assessing and monitoring all IT equipment, applications, and data systems that were linked to NYP patient databases prior to the breach incident, and failed to implement security measures sufficient to reduce the risks and vulnerabilities to its ePHI to a reasonable and appropriate level.</font><br><br><font face="Arial">d. NYP failed to implement appropriate policies and procedures for authorizing access to its NYP patient data bases, <u>and it failed to comply with its own policies on information access management</u>.<font size="2">[2] (emphasis added)<br><br></font></font><div align="left"><font face="Arial"><font color="#993399"><b>NYP settlement: $3 million</b></font>.<br></font></div></div><font face="Arial"></font></td><td align="left" valign="top"> <font face="Arial">a. CU failed to conduct an accurate, and thorough risk analysis that incorporates all IT equipment, applications and data systems utilizing ePHI, including the server accessing NYP-ePHI.<br><br>b. CU failed to implement processes for assessing and monitoring IT equipment, applications and data systems that were linked to NYP patient data bases prior to the breach incident and failed to implement security measures sufficient to reduce the risks of inappropriate disclosure to an acceptable level.<font size="2">[3]<br><br></font></font><font face="Arial"><font color="#993399"><b>CU settlement: $1.5 million</b></font>.</font></td></tr></tbody></table><font face="Arial"><br></font><font face="Arial"><font face="Arial">As is the usual course, each Resolution Agreement includes a Corrective Action Plan. Each of the parties must take the following steps:</font></font><br><font face="Arial"><font face="Arial"><br></font></font><table style="border: 1px solid #000000;" border="0" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><font face="Arial"><b>Modify Existing Risk Analysis Process.</b><br>. . . NYP shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems, and applications controlled, administered or owned by NYP, its workforce members, and affiliated staff that contains, stores, transmits or receives NYP ePHI. NYP shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . . <br><br><b>Develop and Implement a Risk Management Plan</b>.<br>Within ninety (90) calendar days of the completion of the Risk Analysis . . . , NYP shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . . <br><br><b><br>Review and Revise Policies and Procedures on Information Access Management. </b><br>. . . NYP shall review, and to the extent necessary, revise its internal policies and procedures for authorizing access to NYP ePHI. The revised policies and procedures shall include a specific process to be followed by workforce members and affiliated staff for requesting authorization to access NYP ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. NYP shall forward its policies and procedures for authorizing access to all NYP ePHI to HHS for its review . . . <br><b><br><br>Implement Process for Evaluating Environmental and Operational Changes.</b><br>. . . NYP shall develop a process to evaluate any environmental or operational changes that affect the security of NYP ePHI.<br><br><b>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . NYP shall review, and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download, or transmit NYP ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilize NYP ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. NYP shall forward its policies and procedures to HHS for its review . . .<br><br><b>Develop an Enhanced Privacy and Security Awareness Training Program.</b><br>1. . . NYP shall augment its existing mandatory Health Information Privacy and Security Awareness Training Program (for workforce members and affiliated staff that have access to protected health information including ePHI, to train on the necessity and existence of prohibitions on the purchase, use or administration of computer equipment that accesses NYP ePHI, except under the explicit management of NYP IT personnel ("the Training Program"). As before, the Training Program shall also include general instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and NYP health information security policies and procedures, and shall also include training on new policies and procedures, if any, developed as required by . . . this CAP.<br><br>2. Under the Training Program, NYP shall provide training to all workforce members and affiliated staff as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member or affiliated staff that commences working for NYP, or that are given access to ePHI, after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment or affiliation with NYP.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date training was received. NYP shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. NYP shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments.</font><br></td><td align="left" valign="top"><b> </b><font face="Arial"><b>Conduct a thorough Risk Analysis.</b><br>. . . CU shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems and applications controlled, administered or owned by CU, its workforce members that contains, stores, transmits or receives CU ePHI. CU shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . .<br><br><b><br>Develop and Implement a Risk Management Plan.</b><br>Within ninety (90) calendar days of completion of the Risk Analysis . . . , CU shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . .<br><br><b>Review and Revise Policies and Procedures on Information Access Management.</b><br>. . . CU shall review and to the extent necessary revise its internal policies and procedures for authorizing access to CU ePHI. The revised policies and procedures shall include a process to be followed by workforce members for requesting authorization to access CU ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. CU shall forward its policies and procedures for authorizing access to all CU ePHI to HHS for its review . . . <br><br><br><b>Compliance with Evaluation Standard.</b><br>. . . CU shall develop a process to evaluate any environmental or operational changes that affect the security of CU ePHI. <br><br><b><br>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . CU shall review and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download or transmit CU ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilized CU ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. CU shall forward its policies and procedures to HHS for its review . . . <br><br><b>Develop a Privacy and Security Awareness Training Program.</b><br>1. . . . CU shall develop a mandatory Health Information Privacy and Security Awareness Training Program (the Training Program) for workforce members that have access to protected health information including ePHI. The Training Program shall include instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and CU health information security policies and procedures, and shall particularly include training on the policies and procedures developed as required by . . .&nbsp; this CAP.<br><br>2. Under the Training Program, CU shall provide training to all workforce members as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member that commence working for CU after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment with CU.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date train ing was received. CU shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. CU shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments. </font><br></td></tr></tbody></table><font face="Arial"><br>For a chart summary of the OCR fines as well as other HIPAA related litigation, please see<a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html"> </a></font><font face="Arial"><a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html">https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html</a>. <br><br><font size="2">---------------------<br>[1] Press Release, Office of Civil Rights (May 8, 2014), <i>available at</i> <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html</a>.<br><br>[2] <a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and </a></font></font><font face="Arial"><font size="2"><a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf"><font face="Arial">New York and Presbyterian Hospital</font></a><font face="Arial"> (agr. undated, press release from May 8, 2014).</font><br><br>[3] <a href="https://melniklegal.com/av/2014_OCR-columbia-university-resolution-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and Columbia University</a> (agr. undated, press release from May 8, 2014).<br></font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">---------------------<br></font></font></font></font><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Posted by: Tatiana Melnik on May 8, 2014</font></font><br></font></font></font> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1399561833_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1399561833_Data-Breach.html</guid>
<pubDate>Thu, 08 May 2014 11:10:33 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Interest in Cyber Security of Financial Services Firms Continues to Increase]]></title>
<description><![CDATA[
 
 
 
  
  
  
  
  
     <table align="left" border="0"><tbody><tr><td align="left" valign="top"><font face="Arial"><font face="Arial">As news of data breaches continue to mount, federal and state regulators are becoming increasingly interested in the steps companies are taking to secure the information entrusted to them by consumers as well as other companies. This year we have seen an increased focus on the financial services sector, which suffered large losses in the wake of the data breach at Target. This was then followed by data breaches at Neiman Marcus, Michaels, PF Changs, among many many others.</font></font></td><td align="left" valign="top"><font face="Arial"> </font><font face="Arial"><img src="https://melniklegal.com/images/1407508517.jpg"></font><br></td></tr></tbody></table><div align="left"><br><font face="Arial">Some of the recent examples include:</font><br><ul><li><div><font face="Arial"><b>FFIEC</b> - The Federal Financial Institutions Examination Council has launched a pilot program to assess the cyber security preparedness of 500 community banks. This announcement coincides with the launching of a web page on <font color="#009900"><b>June 24, 2014</b></font> on cyber security, which is meant to serve as "a central repository for current and future FFIEC-related materials on cyber security."
  As the FFIEC explains, "Regulators are particularly focusing on risk 
 management and oversight, threat intelligence and collaboration, 
 cyber security controls, service provider and vendor risk management, and
  cyber incident management and resilience."<font size="2">[1]</font></font></div></li></ul><ul><li><div><font face="Arial"><b>New York Department of Financial Services</b> - In <font color="#009900"><b>May 2014</b></font>, the New York Department of Financial Services (NYDFS) issued a "Report on Cyber Security in the Banking Sector." 
 The Report notes that, "Although large-scale denial-of-services attacks 
 against major financial institutions generate the most headlines, 
 community and regional banks, credit unions, money transmitters, and 
 third-party service providers (such as credit card and payment 
 processors) have experienced attempted breaches in recent years."<font size="2">[3]</font> After conducting a preliminary survey of 154 financial services institutions in 2013, the Department now "plans to expand its IT examination procedures to focus more fully on cyber security." These "revised
  examination procedures will include additional questions in the areas 
 of IT management and governance, incident response and event management,
  access controls, network security, vendor management, and disaster 
 recovery." Those providing services to these entities should also expect to see more questions regarding cyber security now that regulators are becoming more interested in vendor practices.</font><br></div></li></ul><ul><li><font face="Arial"><b>SEC</b> - Cyber security has been a focal point at the Securities and Exchange Commission for a few years. But, the SEC's Office of Compliance Inspections and Examinations announced in a Risk Alert on <font color="#009900"><b>April 15, 2014</b></font> that it is undertaking cyber security examinations of more than 50 registered broker-dealers and registered investment advisers.</font><font face="Arial"><font face="Arial"><font size="2">[2]</font></font> The OCIE will be focusing on the entity’s cyber security governance, identification and assessment of cyber security risks, protection of networks and information, risks associated with remote customer access and funds transfer requests, risks associated with vendors and other third parties, detection of unauthorized activity, and experiences with certain cyber security threats.</font><br></li></ul></div><div align="left"><br><font face="Arial"><font face="Arial"><font size="2">---------------------------------------</font></font></font><br><font face="Arial"><font size="2">[1] Press Release, FFEIC, FFIEC Launches Cybersecurity Web Page, Promotes Awareness of Cybersecurity Activities, June 24, 2014, <a href="https://www.ffiec.gov/press/pr062414.htm">https://www.ffiec.gov/press/pr062414.htm</a>.</font></font><br><br><font face="Arial"><font size="2">[2] SEC, National Exam Program Risk Alert, Vol. IV, Iss. 2 (April 15, 2014), <a href="https://www.sec.gov/ocie/announcement/Cybersecurity+Risk+Alert++%2526+Appendix+-+4.15.14.pdf">https://www.sec.gov/ocie/announcement/Cybersecurity+Risk+Alert++%2526+Appendix+-+4.15.14.pdf</a></font></font>.<br><br><font face="Arial" size="2">[3] NY State Department of Financial Services, </font><font face="Arial" size="2"><font face="Arial">Report on Cyber Security in the Banking Sector (May 2014),</font> <a href="https://www.dfs.ny.gov/about/press2014/pr140505_cyber_security.pdf">https://www.dfs.ny.gov/about/press2014/pr140505_cyber_security.pdf</a></font>.<br><font face="Arial"><font size="2">---------------------------------------</font></font><br><br><font face="Arial"><font size="2">Posted by Tatiana Melnik on August 8, 2014</font></font><br></div>
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1407508168_Financial-Services.html</link>
<guid>http://melniklegal.com/weblog/1407508168_Financial-Services.html</guid>
<pubDate>Fri, 08 Aug 2014 10:29:28 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Telemedicine is Coming to Florida (Slowly but Surely)]]></title>
<description><![CDATA[
 
 
 
 
   <div align="left"><font face="Arial"><i><b>The Florida Boards of Medicine and Osteopathic Medicine are Moving Closer to Proposing a Rule on Standards for Telemedicine Practice. </b></i><br><br>In a joint meeting of the Florida Boards of Medicine and Osteopathic Medicine on November 14, 2013, the Telemedicine Subcommittee moved closer to proposing a rule aimed at setting the standards for telemedicine practice in Florida.</font><br><br><font face="Arial">The Telemedicine Subcommittee was established during the August 2013 Board of Medicine meeting to address Florida's growing telemedicine field. The Subcommittee is comprised of six Board of Medicine members and three Board of Osteopathic Medicine members.<a href="#one">[1]</a> </font><br><br><font face="Arial">The current telemedicine rule for each of the Florida Board of Medicine and Osteopathic Medicine is limited to Internet prescribing.<a href="#two">[2]</a> But, as Dr. Orr, the Chair of the Telemedicine Subcommittee, explained during the first meeting on September 9, 2013, the Subcommittee's goal is to examine current uses of telemedicine and to amend the Board's rules to address the use of telemedicine <a href="#three">[3]</a> in a more comprehensive manner.</font><br><br><font face="Arial">The Subcommittee has proposed to define telemedicine as "the practice of medicine by a licensed Florida physician or physician assistant where patient care, treatment, or services are provided through the use of medical information exchanged from one site to another via electronic communications. Telemedicine shall not include the provision of health care services only through an audio only telephone, email messages, text messages, facsimile transmission, U.S. Mail or other parcel service, or any combination thereof." <a href="#four">[4]</a></font><br><br><font face="Arial">Additionally, "[t]he standard of care, as defined in s. 456.50(1)(e), F.S., shall remain the same regardless of whether a Florida licensed physician or physician assistant provides health care services in person or by telemedicine." <a href="#five">[5]</a></font><br><br><font face="Arial">Some members of the public expressed concern during the November 14 meeting that the proposed rule did not provide adequate clarity that use of telemedicine would be subject to compliance with HIPAA and other data privacy and security requirements similar to in-person patient encounters.&nbsp; But, the subcommittee expressed concerns regarding including an express reference to HIPAA because of Florida's requirements with respect to incorporating other statutes and regulations. That is, under Florida law, a Board may incorporate only the current version of a federal regulation or statute. So, when that regulation or statute changes, the Board must convene to incorporate the new version. This may be problematic if a particular regulation or statute is routine modified. </font><br><br><font face="Arial">However, the Subcommittee agreed that language should be added to clarify obligations with respect to patient confidentiality and proposed language that, "[t]he practice of medicine by telemedicine does not alter any obligation of the physician or the physician assistant regarding patient confidentiality or recordkeeping."</font><br><br><font face="Arial">One issue that was raised, but not yet addressed, is whether Florida will permit out of state doctors to treat Florida patients via telemedicine. That is, several other states do have limited telemedicine licenses.&nbsp; Texas, for example, provides that:</font><br><blockquote><font face="Arial">(a) For a person to be eligible for an out-of-state telemedicine license to practice medicine across state lines under the Medical Practice Act, §151.056, and §163.1 of this title (relating to Definitions), the person must: <br>&nbsp; (1) be 21 years of age or older; <br>&nbsp; (2) be actively licensed to practice medicine in another state which is recognized by the board for purposes of licensure, and not the recipient of a previous disciplinary action by any other state or jurisdiction; <br>&nbsp; (3) not be the subject of a pending investigation by a state medical board or another state or federal agency; <br>&nbsp; (4) be currently certified by a member board of the American Board of Medical Specialties or Bureau of Osteopathic Specialists, or by the American Board of Oral and Maxillofacial Surgery, obtained by passing, within the ten years prior to date of applying for licensure, a monitored:&nbsp; (A) specialty certification examination; (B) maintenance of certification examination; or (C) continuous certification examination; <br>&nbsp; (5) have passed the Texas Medical Jurisprudence Examination; <br>&nbsp; (6) complete a board-approved application for an out-of-state telemedicine license for the practice of medicine across state lines and submit the requisite initial fee; and <br>&nbsp; (7) not be determined ineligible for licensure under subsection (b) of this section.<br></font></blockquote><font face="Arial">Texas Administrative Code, 22-9-172(C) Rule §172.12.</font><br><br><font face="Arial">The Subcommittee advised that it would research the licensure issue and further discuss it at a later meeting.</font><br><br><font face="Arial">The Subcommittee made clear that it was eager to move quickly on developing telemedicine rule.</font><br><br><font face="Arial">Nonetheless, for now, reimbursement for telemedicine (or telehealth) services in Florida remains an issue because it is limited to a very narrow set of circumstances under the Medicaid program and no state law requires reimbursement by private insurers. </font><br><br><u><font face="Arial" size="2"><br>References and Resources</font></u><br><br><font face="Arial" size="2"><a name="one">[1]</a> Florida Board of Medicine, <a href="https://melniklegal.com/av/2013_Fl_Board_Medicine_Updates_on_Telemedicine_09252013.pdf">Newsletter: Updates on Telemedicine</a>, Sept. 25, 2013. (PDF)</font><font size="2"><br><br><font face="Arial"><a name="two">[2]</a><a> For Florida Board of Medicine, <i>see</i> Rule 64B8-9.014. <i>Standards for Telemedicine Prescribing Practice</i>. For Florida Board of Osteopathic Medicine, <i>see </i>Rule 64B15-14.008 <i>Standards for Telemedicine Practice</i>.</a></font><a><br><br><font face="Arial"></font></a><font face="Arial"><a name="three">[3]</a> Florida Board of Medicine, <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Minutes/September2013/09092013_TeleMed_Minutes.pdf">Joint Meeting of the Florida Boards of Medicine &amp; Osteopathic</a></font><br><font face="Arial"><a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Minutes/September2013/09092013_TeleMed_Minutes.pdf">Medicine Telemedicine Subcommittee Meeting Report</a>, Sept. 9, 2013 (opening comments by Dr. Orr). (PDF)</font><br><br><font face="Arial"><a name="four">[4]</a> For a full record of the materials, see the <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/November2013/11142013_TelemedicineSubcommittee_AgendaBook.pdf">Public Book for the Nov. 14, 2013 Telemedicine Subcommittee Meeting</a>. (PDF). The Rules as proposed are <a href="https://melniklegal.com/av/2013_Pages_from_11142013_Telemed_PublicBook.pdf">Rule 64B8-9.0141 (Medicine) and Rule 64B15-14.0081 (Osteopathic Medicine) and are available here</a>. <i>See also</i> <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/September2013/09092013_Telemed_PublicBook.pdf">Telemedicine Subcommittee, Public Book</a>, Sept. 9, 2013 for the full materials and <a href="https://melniklegal.com/av/2013_Pages_from_09092013_Telemed_PublicBook.pdf">click here for the rules as proposed on Sept. 9</a>. (PDF)</font><br><br><font face="Arial"><a name="five">[5]</a> <a href="https://ww10.doh.state.fl.us/pub/medicine/Agenda_Info/Public_Information/Public_Books/November2013/11142013_TelemedicineSubcommittee_AgendaBook.pdf">Telemedicine Subcommittee, Public Book</a>, Nov. 14, 2013. (PDF)</font></font><br><br><br><br><br><br><font face="Arial"> </font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1384531131_Telemedicine.html</link>
<guid>http://melniklegal.com/weblog/1384531131_Telemedicine.html</guid>
<pubDate>Fri, 15 Nov 2013 10:58:51 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[FCC: The Newest Regulator to Throw its Hat into the Data Privacy and Security Ring]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div align="left"><font face="Arial">It's a sure sign that the tide on privacy and security enforcement has turned when the Federal Communications Commission (FCC), not one known to take enforcement actions in the data privacy and security space, fines two telecoms for $10 million dollars. On Friday, October 24, 2014, the FCC issued a Notice of Apparent Liability for Forfeiture (Notice) against TerraCom, Inc. and YourTel America, Inc., levying, in a 3-2 vote, a fine against the two companies for failing to protect the "proprietary information" of low income Americans.<font size="2">[1]</font></font><br></div><br></div><table style="text-align: left; margin-left: auto; margin-right: auto;" align="left" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A brief summary and comparison to other enforcement actions and settlement agreements....</i> </b></font><font color="#FFFFFF">The facts and circumstances in the action against TerraCom and YourTel read very similar to enforcement actions from the Federal Trade Commission, where it frequently relies on statements made in privacy policies. Here, we have two telecoms that used a third-party vendor to provide a significant amount of services, including the storage of sensitive data. The companies advertised on their websites and privacy policies that they safeguarded consumer information, but in fact, "failed to employ reasonable practices to safeguard this information as they represented, expressly or by implication, in their privacy policies." Importantly, the FCC looks to what the companies represented and noted that they were looking at the express language or "by implication." That is, it appears that the FCC, like the FTC, will look more broadly at what the materials meant to convey. <br><br>Further, the FCC found the use of passwords and encryption important noting that, "the Companies' choice to store, or its vendor's choice to store, files containing the PI of customers in a publicly accessible folder on the Internet, without password protection or encryption, is the practical equivalent of having provided no security at all." But, then the FCC went further, stating that "given the state of technology, we believe the lack of encryption clearly evidences the unjust and unreasonable nature of the Companies' data security practices." This speaks directly to the approach taken by the Office of Civil Rights in its settlement agreements with covered entities that have failed to encrypt laptops that were subsequently lost.<br><br>Finally, the FCC found it troubling that the Companies failed to notify all potential victims. This speaks directly to that basis of several enforcement actions brought by State's Attorneys' General, including, for example, the Attorney General of Indiana and the Attorney General of Massachusetts.<br><br>Moving forward, this enforcement action may signal an important turn in the discussion of the regulatory framework of the Internet of Things, where the FCC is sure to be a strong player.<br></font></font></font></td></tr></tbody></table><div align="left"><br><font face="Arial"><br></font><div align="left"><font face="Arial">The issue was brought to light when, in 2013, a reporter from the Scripps Howard News Service discovered that the companies were storing the information in an unsecured manner and, over the period of several days, Scripps' reporters accessed 128,066 documents. When the news service brought the issue to the attention of the two companies, the companies sent a cease and desist letter to Scripps calling the reporters "hackers".<font size="2">[2]</font>&nbsp; The companies notified the FCC Enforcement Bureau on May 7, 2013 regarding the incident "claim[ing] that the Companies were victims of a security breach."</font><font face="Arial"><font face="Arial"><font size="2">[3]</font></font> The FCC alleges that the companies exposed the proprietary information of more than 300,000 consumers.</font><br><br><font face="Arial">As the opening paragraph of the Introduction explains:</font><br><blockquote><font face="Arial">Today, we take action against two companies that collected names, addresses, Social Security numbers, driver's licenses, and other proprietary information (PI) belonging to low-income Americans and stored them on unprotected Internet servers that anyone in the world could access with a search engine and basic manipulation. The companies stored such consumer PI in two publicly accessible folders on the Internet without password protection or encryption. By not employing appropriate or even reasonable&nbsp;&nbsp;&nbsp; security measures, the companies exposed their customers to an unacceptable risk of identity theft and other serious consumer harms.</font><font face="Arial"><font face="Arial"><font size="2">[4]</font></font></font></blockquote></div><font face="Arial">The FCC found that the companies violated Sections 201(b) and 222(a) of the Communications Act of 1934 as well as FCC Rules when they:<br></font><blockquote><font face="Arial">(i) failed to properly protect the confidentiality of consumers' PI they collected from applicants for the Companies' wireless and wired Lifeline telephone services; </font><br><br><font face="Arial">(ii) failed to employ reasonable data security practices to protect consumers' PI; </font><br><br><font face="Arial">(iii) engaged in deceptive and misleading practices by representing to consumers in the Companies' privacy policies that they employed appropriate technologies to protect consumers' PI when, in fact, they had not; and</font><br><br><font face="Arial">(iv) engaged in unjust and unreasonable practices by not fully informing consumers that their PI had been compromised by third-party access.</font><br> </blockquote><div align="left"><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial">Both companies provide subsidized telephone services to low income Americans under the Lifeline program. While the companies "have common shareholders, share key management employees, and are joint owners of a third company, BrightStar Global Solutions, LLC (BrightStar), [they] are separate corporate entities headquartered in Oklahoma and Missouri."</font><font face="Arial"><font face="Arial"><font face="Arial"><font size="2">[5]</font></font></font>&nbsp; In providing the services, Brightstar retained a third party vendor, CallCenters India, Inc., d/b/a Vcare Corporation (Vcare), to provide certain hosted services, including the call center, back office support, billing, software, and data storage for customer application files.</font><font face="Arial"><font face="Arial"><font face="Arial"><font face="Arial"><font size="2">[6]</font></font></font></font>&nbsp; According to the FCC Notice, Vcare stored customer files in "in clear, readable text and in electronic format accessible via the Internet."</font><font face="Arial"><font face="Arial"><font face="Arial"><font face="Arial"><font size="2">[7]</font></font></font></font>&nbsp; These files contained all the information that customers needed to apply for the Lifeline program including, for example, "their name and address, date of birth, Social Security Number, . . . driver's license or state ID card . . .&nbsp; annual statement of government benefits; the prior year's state, federal or Tribal tax return; paycheck stubs; Social Security benefit statements; Veterans Administration benefit statements; retirement or pension information; Unemployment or Workers' Compensation benefit statements; Federal or Tribal notice letters of participation in General Assistance; divorce decrees or child support awards; or other official documents establishing the applicant's income level."<br><br></font><font face="Arial">As describe above, an investigative reporter discovered that the telecoms were storing information in an unsecured manner. When the news service notified the telecoms regarding their security hole, the companies called the reporters working for the news service hackers and then proceeded notify the FCC regarding the security incident.</font><br></td><td align="left" valign="top"><font face="Arial"> </font><font face="Arial"><img src="https://melniklegal.com/images/telephone.jpg"></font><br></td></tr></tbody></table><font face="Arial"></font><font face="Arial"><br>In its action, the FCC explains, TerraCom and YourTel "apparently willfully and repeatedly" violated their duties under Section 222(a) of the Communications Act of 1934, which requires carriers "to protect the confidentiality of proprietary information of, and relating to . . . customers."<font size="2">[8]</font>&nbsp; The FCC further notes that, "[t]he Commission has made clear that section 222(a) requires carriers to take every reasonable precaution to protect the confidentiality of proprietary or personal customer information and that it was committing to taking resolute enforcement action to ensure that the goals of section 222 are achieved."<font size="2">[9]</font>&nbsp; While declining to adopt the NIST definition of personally identifiable information, the Commission found it instructive in formulating its definition of proprietary information and read the definition of proprietary information broadly:</font><br><div align="left"><blockquote><font face="Arial">In the context of Lifeline service at issue here, "proprietary information" includes all documentation submitted by a consumer or collected by an ETC to determine a consumer's eligibility for Lifeline service, as well as all personally identifiable information contained therein. Specifically, information such as a consumer's (i) first and last name; (ii) home or other physical address; (iii) email address or other online contact information, such as an instant messaging screen name that reveals an individual's email address; (iv) telephone number; (v) Social Security Number, tax identification number, passport number, driver's license number, or any other government-issued identification number that is unique to an individual; (vi) account numbers, credit card numbers, and any information combined that would allow access to the consumer's accounts; (vii) Uniform Resource Locator ("URL") or Internet Protocol ("IP") address or host name that identifies an individual; or (viii) any combination of the above, constitutes "proprietary information" protected by Section 222(a).<font size="2">[10]</font></font></blockquote></div></div><div align="left"><font face="Arial">This broad reading is consistent with the approach taken by the Health Insurance Portability and Accountability Act (HIPAA) in its definition of protected health information as well as the definitions of personally identifiable information adopted by more recent state data breach laws, such as the Florida Information Protection Act of 2014.</font><br><br><font face="Arial">Interestingly, in assessing consumer expectations, like the Federal Trade Commission, the FCC also looked at the promises the telecoms made in their privacy policies, noting specifically that:</font><br><blockquote><font face="Arial">The Companies' privacy policies assure those persons submitting"[c]ustomer specific information" through their website that they will protect that information and, in fact, inform such applicants that"[b]y providing us with your information, you acknowledge that you have read this privacy policy, understand it, agree to its terms and consent to the transfer of such information outside your resident jurisdiction.<font size="2">[11]</font></font></blockquote><font face="Arial">Therefore, the telecoms set certain expectations in the minds of their consumers that they failed to meet.</font><br><br><font face="Arial">Further, the FCC found that TerraCom and YourTel violated Section 201(b) of the Communications Act of 1934, because their "failure to protect and secure the PI of their customers . . . constitute[d] an unjust and unreasonable practice."<font size="2">[12]</font></font><br><br><font face="Arial"><i><b>Unreasonable Data Privacy and Security Practices</b></i></font><br><br><font face="Arial">According the FCC, the "evidence shows that the Companies' security measures lacked even the most basic features to protect consumers' PI."<font size="2">[13]</font>&nbsp; The FCC noted the following practices as being unreasonable:</font><br><ul><li><font face="Arial">Storing the information in plain text thereby enabling it to be read by search engines - "the PI hosted by Vcare on its server was widely available on public websites online through a simple Google search," at least two applications were cached by the Google search engine, and these applications remained cached until the FCC contacted Google to have them removed<font size="2">.[14]</font></font> </li></ul><ul><li><font face="Arial">Failing to properly secure the server directories storing the PI and using applicant names in the URLs - </font></li></ul><ul><ul><li><font face="Arial">"The Companies knew or should have known that the use of random URLs without more (e.g., encryption) to protect applicant records provided inadequate security and left the documents vulnerable to exposure via search engines-which operate by visiting websites, indexing all or much of the content available on them, and then delivering links to the indexed results to anyone that queries the engine."<font size="2">[15]</font></font></li></ul></ul><ul><ul><li><font face="Arial">"[T]he Companies' URL naming convention for one of the folders containing PI that was stored on Vcare's server also exposed the names of the applicants or customers directly in the URL, further demonstrating the lack of security of the records."<font size="2">[16]</font></font></li></ul></ul><ul><li><font face="Arial">Failing to use encryption - "We do not hold here that encryption without more would satisfy a carrier's duty under Section 201(b); however, given the state of technology, we believe the lack of encryption clearly evidences the unjust and unreasonable nature of the Companies' data security practices.<font size="2">"[17]</font></font> </li></ul><font face="Arial"><i><b>Failing to Notify Consumers</b></i></font><br><br><font face="Arial">The FCC also found it troubling that the companies only notified 35,129 consumers of the potentially 300,000+ that were impacted. The telecoms argued that they followed the state data breach laws for each of the individual states, but the FCC found the "failure to notify all affected consumers of the breach unjust and unreasonable because it left consumers ignorant about the risks of identity theft problems that may occur due in whole or part to the breach-a problem made even more troubling in light of the Companies' admission that they do not know the extent or breadth of the breach."<font size="2">[18]</font></font><br></div><br><br><font face="Arial">-------------------------------------------</font><br><font face="Arial"><font size="2">[1] FCC, In the Matter of TerraCom, Inc. and YourTel America, Inc., File No.:EB-TCD-13-00009175, FRNs:0010103745 and 0020097572 (Oct. 24, 2014), <a href="https://transition.fcc.gov/Daily_Releases/Daily_Business/2014/db1027/FCC-14-173A1.pdf">https://transition.fcc.gov/Daily_Releases/Daily_Business/2014/db1027/FCC-14-173A1.pdf</a>.</font></font><br><br><font size="2"><font face="Arial">[2] <i>Id</i>. at para 6-7.<br><br>[3] </font></font><font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 8.</font></font><br><br>[4]</font></font> <font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 1 (emphasis added).</font></font></font></font><br><br><font size="2"><font face="Arial">[5]</font></font> <font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 3.</font></font></font></font><br><br>[6]</font></font> <font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 5.</font></font></font></font></font></font><br><br>[7] <i>Id</i>.<br></font></font><br><font size="2"><font face="Arial"><font size="2"><font face="Arial">[8] </font></font></font></font><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 13.</font></font></font></font></font></font><br><br>[9] <i>Id</i>. (internal quotations and citations omitted.)<br></font></font><br><font size="2"><font face="Arial">[10] </font></font></font></font><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><i>Id</i>. at para 19.</font></font></font></font></font></font></font></font></font></font><br><br>[11] <i>Id</i>. at para. 25. See also the discussion starting in para. 36.<br><br>[12] <i>Id</i>. at para. 31.<br><br></font></font></font></font><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial">[13] </font></font></font></font><i>Id</i>. at para. 29.<br><br>[14] <i>Id</i>.<br><br>[15] <i>Id</i>.<br><br>[16] <i>Id</i>. at para. 33.<br><br>[17] <i>Id</i>. at para. 32.<br></font></font></font></font><br><font size="2"><font face="Arial"><font size="2"><font face="Arial">[18] <i>Id</i>. at para. 39.<br></font></font></font></font><font face="Arial"><font face="Arial">-------------------------------------------</font></font><br><br><br><font face="Arial"><font size="2">Posted by Tatiana Melnik on October 27, 2014.</font></font><br></div><font face="Arial"> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1414465469_FCC.html</link>
<guid>http://melniklegal.com/weblog/1414465469_FCC.html</guid>
<pubDate>Mon, 27 Oct 2014 23:04:29 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[FTC Targets a Medical Biller, Settles with Accretive Health for Privacy Violations]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial">Accretive Health, Inc., a company providing medical billing and revenue management services to hospitals throughout the US. </font><font face="Arial"><font face="Arial">Accretive </font>"has agreed to settle Federal Trade Commission charges that its inadequate data security measures unfairly exposed sensitive consumer information to the risk of theft or misuse." This settlement follows a settlement between Accretive and the Minnesota Attorney General for HIPAA violations.<br></font><br><div><font face="Arial"><a href="#take">[Jump to Take-a-Ways]</a></font><br></div><br><table style="border: 0px solid red;"><tbody><tr><td><table border="0"><tbody><tr style="font-family: Arial;" align="center"><td><font size="3"><font size="2"></font></font><table style="text-align: left; margin-left: auto; margin-right: auto;" border="0"><tbody><tr><td valign="top"><font size="3"><u><i><b><font size="3">Minnesota </font>Action</b></i></u><br><br>The </font><font size="3"><font face="Arial">Accretive </font>saga started in July 2011, when "an Accretive employee left an unencrypted laptop containing sensitive information on 23,500 Minnesota patients of two Minnesota hospital systems . . . in a rental car after 10 p.m." and the laptop was stolen. [1] (See my brief discussion of this case in the </font><font size="3"><font size="3">October issue of Nephrology News &amp; Issues back in 2012 - "<a href="https://melniklegal.com/av/2012_Nephrology_News_HIPAA_Breach_Dialysis_Providers_pt2.pdf"><i>HIPAA: Privacy, Security &amp; the Consequences of a Breach for Dialysis Providers - Part 2: Recommendations to Minimize Exposure to Data Breach-Related Liabilities</i></a>" <font size="2">(PDF)</font>.) (According to the FTC Press Release, while there were 23,500 patients, the laptop contained 20 million pieces of information.)<br><br></font>The laptop contained sensitive patient information, including the </font><font size="3"><font size="3">patient’s name, address, date of birth, and Social Security number, as well as </font>highly sensitive patient information, including "a checklist to denote whether the patient has 22 different chronic medical conditions and, if so, the condition of the patient [including] three mental health conditions (depression, bipolar disorder and schizophrenia) [and] HIV." [2]<br><br>The Minnesota State Attorney General was particularly concerned about&nbsp;</font><font size="3"><font size="3">Accretive's involvement in the revenue cycle, its "aggressive" debt collection practices, and lack of disclosure to patients. As the AG described: "Accretive has told Wall Street investors that its revenue cycle operations contract starts 'when a patient registers for future service or arrives at a hospital or clinic for an unscheduled visit' and ends when 'the hospital has collected all the appropriate revenue from all possible sources.' Through these contracts, Accretive controls the revenue functions of the hospitals, including front office (patient access), middle office (billing), and back office (collections) functions. It reports to Wall Street investors that it carries out these functions using 'data mining,' 'consumer behavior modeling,' and 'propensity to pay' algorithms."</font></font><font size="3"><font size="3"><br></font></font><br><font face="Arial" size="3"><font size="3">The AG filed suit in the United States District Court in Minnesota, alleging that Accretive violated state and federal health privacy laws, state debt collection laws, and state consumer protection laws. The AG sought "It seeks an order requiring Accretive to fully disclose to [Minnesota] patients: (1) what information it has...; (2) what information it has lost...; (3) where and to whom it has sent information about [the] patients; [and] (4) the purposes for which it amasses and uses information about Minnesota patients."<br></font></font></td><td style="border: 1px solid #edad27; padding:3px;" bgcolor="#001c31" valign="top" width="300px"><font color="#FFFFFF" size="3"><u><b>A Few Highlights<br></b></u></font><font color="#FFFFFF"><br><font size="3">- The matter came to light in 2011 when an unencrypted laptop containing detailed patient data was stolen out of an employee's car.</font><i></i><br><br>- As a result of this incident, Accretive was investigated by both the Minnesota Attorney General and the Federal Trade Commission.<br><br>- During the investigation, several practices came to light, including Accretive's lack of HIPAA compliance and its aggressive healthcare debt collection practices.<br><br>- The Minnesota AG brought an action pursuant to the HIPAA enforcement authority granted to AGs by the HITECH Act. Accretive is a business associate of a covered entity and, per the HITECH Act, direct enforcement against business associates is permitted.<br><br>- The Minnesota AG settled with Accretive in 2012. The settlement required Accretive to cease operations in Minnesota and banned the company from doing business in Minnesota for at least 2 years.<br><br>- The FTC brought an action based on Section 5 of the FTC Act, alleging that, Accretive Health created unnecessary risks of unauthorized access or theft of personal information.<br><br>- The FTC's action tracks the requirements of HIPAA, and sets forth additional requirements with respect to Accretive's subcontractors.<br><br>- The OCR is unlikely to take any action against Accretive.</font></td></tr></tbody></table></td></tr></tbody></table></td></tr></tbody></table><div><br><font face="Arial" size="3"><font size="3"><font face="Arial" size="3"><font size="3">The lawsuit also asked "Accretive to disclose whether it has sent health data about Minnesota patients to its so-called 'Shared Services Blended Shore Center of Excellence' in New Delhi, India."<br><br></font></font>Unlike previous State AGs that sought to take action against those who lost patient data, the Minnesota AG relied, at least in part, on the authority grated to state AGs by the HITECH Act to take enforcement action against covered entities and business associates that violated the HIPAA Privacy and Security Rules. [3] This case was also the first example of an enforcement action against a business associate.</font></font><br><br><font face="Arial" size="3"><font size="3">The case came to end in July 2013, when Accretive settled wit the </font></font><font face="Arial" size="3"><font size="3"><font size="3">Minnesota </font>AG. Compared to the settlements often entered into by the HHS Office of Civil Rights, the Minnesota AG settlement was relatively harsh. Under the settlement, Accretive agreed to "cease all operations in Minnesota within ... 90 days, or by November 1, 2012.&nbsp; The company [was] then be subject to an outright ban on operating in Minnesota for two years, after which, for the next four years, it can only reenter the State if the Attorney General agrees to a Consent Order regarding its business practices in the State." [4]</font></font><br><br><div><u><i><b><font face="Arial">The FTC Action</font></b></i></u><br><font face="Arial"><br></font><div><font face="Arial">The FTC Action against Accretive stems from the same incident: the loss of the unencrypted laptop.<br></font></div><font face="Arial"><br>The FTC brought an action on its enforcement authority under the Section 5 of the FTC Act, prohibits "unfair or deceptive acts or practices in or affecting commerce." [5] In the Complaint, the FTC alleged the following violations:<br></font><blockquote><font face="Arial">Until at least July 2011, Accretive failed to provide reasonable and appropriate security for consumers' personal information it collected and maintained by engaging in a number of practices that, taken together, unreasonably and unnecessarily exposed consumers' personal data to unauthorized access. Among other things, Accretive Health <i>created unnecessary risks of unauthorized access or theft of personal information by</i>:<br></font><blockquote><font face="Arial"><b>a. </b>Transporting laptops containing personal information in a manner that made them vulnerable to theft or other misappropriation; <br><br><b>b. </b>Failing to adequately restrict access to, or copying of, personal information based on an employee's need tor information; <br><br><b>c.</b> Failing to ensure that employees removed information from their computers for which they no longer had a business need; and <br><br><b>d.</b> Using consumers' personal information in training sessions with employees and failing to ensure that the information was removed from employees' computers following the training. [6]</font></blockquote></blockquote><font face="Arial">The behaviors that the FTC identifies as creating "unnecessary risks of unauthorized access or theft" generally align with the types of behaviors that the Office of Civil Rights finds problematic.<br><br><b>Excerpts from the FTC Consent Order</b><br><br>In the Consent Order, the FTC sets forth a number of requires Accretive must undertake:</font><br><blockquote><font face="Arial">[E]stablish and implement, and thereafter maintain, or continue to maintain a comprehensive information security program reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. Such program ...shall contain administrative, technical, and physical safeguards appropriate to respondent's size and complexity, the nature and scope of respondent's activities, and the sensitivity of the personal infonnation collected from or about consumers, including:<br></font><blockquote><font face="Arial">(1) The designation of an employee or employees to coordinate and be accountable for the information security program</font>;<br><br><font face="Arial">(2) The identification of material internal and external risks to the security, confidentiality and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and the assessment of the sufficiency of any safeguards in place to control the risks. At a minimum, this risk assessment should include consideration of the risks in each relevant area of operations, including but not limited to: (a) employee training and management; (b) information systems, including network and software design, information processing, storage, transmission, and disposal; and (c) prevention, detection, and response to attacks, intrusions, and other system failures;<br><br>(3) The design and implementation of reasonable safeguards to control the risks identified through risk assessment and regular testing and monitoring of the effectiveness of the safeguards' key controls, systems, and procedures;<br><br>(4) The development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from respondent, and requiring service providers by contract to implement and maintain appropriate safeguards; and<br><br></font><div><font face="Arial">(5) The evaluation and adjustment of the information security program in light of the results of the testing and monitoring required by [this Order], any material changes to operations or business arrangements, or any other circumstances that Defendant knows or has reason to know may have material impact on the effectiveness of the information security program. [7]</font><br></div></blockquote></blockquote><div><font face="Arial">The FTC's consent order mirrors some of the HIPAA requirements, including, for example, undertaking a risk assessment, develop appropriate measures to address issues identified in the risk assessment, and designate a responsible individual. But, this Order also imposes additional requirements with respect to subcontractors that are beyond what is required by HIPAA, in that the Order requires for the "development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from" Accretive. Under HIPAA business associates are only required to obtain "reasonable assurances" in the form of a written agreement. As such, the FTC's language seems to suggest a requirement of more than a written agreement.</font><br></div><font face="Arial"><br>Like other FTC orders, this one too is in effect for a period of 20 years.<br><br><u><i><b>Where is the Office of Civil Rights?</b></i></u><br><br>The Office of Civil Rights (OCR) is unlikely to take any action against Accretive as a result of the data breach. P</font><font face="Arial">art of the reason that the HITECH Act specifically extended enforcement authority over business associates was to overcome</font><font face="Arial"> an interpretation released by the Department of Justice many years ago that HHS lacked direct enforcement authority over business associates.<br><br>Leon Rodriguez, the Director of OCR, has previously stated that the OCR will not be taking enforcement actions against business associates until after HHS releases the revised HIPAA Rules (revised pursuant to HITECH) and the Rules come into effect. The HIPAA Omnibus Rule was not released until January 2013 and the compliance period came into effect in September 2013. But, the Accretive breach happened in July 2011. This may explain why the FTC Order tracks HIPAA so closely.<br><br></font><div><font face="Arial"><b><font face="Arial"><a name="take">Take-a-Ways</a></font></b></font><br></div></div></div><div><br><div><font face="Arial"><font face="Arial">There are a number of legal take-a-ways from the FTC's latest action.</font></font><br></div><div><ul><li><font face="Arial">The FTC Consent Order requirements may track HIPAA requirements, including undertaking a risk assessment.</font></li></ul><ul><li><font face="Arial">The FTC appears to be requiring Accretive to undertake some sort of vetting process of subcontractors to ensure that they are "</font><font face="Arial">capable of appropriately safeguarding personal information they receive from" Accretive, in addition to entering into business associate agreements.<br></font></li></ul><ul><li><font face="Arial">In some respects, it would have been better for Accretive if it was OCR that brought an action because OCR's resolution agreements are generally for about 5 years. But, the FTC's agreement is for 20 years.<br></font></li></ul></div><div><font face="Arial">Similar to the recent action by<a href="https://melniklegal.com/programs/weblog.cgi?showpage=1388165329_HIPAA"> OCR against Adult &amp; Pediatric Dermatology, P.C., a dermatology practice delivering services in Massachusetts and New Hampshire</a>, this is another breach that could have been avoided with the use of encryption on portable devices, including laptops.&nbsp; </font><br></div></div><font face="Arial"><br>-----------------<font face="Arial" size="2"><br>[1] Press Release</font><font face="Arial" size="2">, Minnesota Attorney General, Attorney General Swanson Sues Accretive Health for Patient Privacy Violations: Debt Collector Lost Laptop Containing Sensitive Data on 23,500 Minnesota Patients, <a href="https://www.ag.state.mn.us/consumer/pressrelease/120119accretivehealth.asp">https://www.ag.state.mn.us/consumer/pressrelease/120119accretivehealth.asp</a> (last visited Jan. 2, 2014). <br><br>[2] Id.<br><br>[3] </font><font face="Arial" size="2"><font face="Arial" size="2"><a href="https://melniklegal.com/av/2012_accretive_health_minn_ag_complaint.pdf">Complaint, State of Minnesota by its Attorney General Lori Swanson v. Accretive Health, Inc.</a>, Civil File No. ___ (D. Minn. Jan. 19, 2012) ("Count 1: Violations of HIPAA. Accretive is business associate of both Fairview and North Memorial as defined in HIPAA. <i>See, e.g.</i>, 45 C.F.R. § 160.103. Because HITECH Section 13401 (42U.S.C. § 17931) provides that 45 C.F.R. §§ 164.308, .310, .312 and .316 apply to a business associate of a covered entity in the same manner as they would to a covered entity, Accretive is thus subject to the security provisions contained within HIPAA as well as applicable civil and criminal penalties.")</font><br><br>[4] </font><font face="Arial" size="2"><font face="Arial" size="2"><font face="Arial" size="2">Press Release</font><font face="Arial" size="2">, Minnesota Attorney General, Attorney General Swanson Says Accretive Will Cease Operations in the State of Minnesota Under Settlement of Federal Lawsuit, Cannot Reenter Minnesota For Six Years Without Attorney General’s Agreement, <a href="https://www.ag.state.mn.us/consumer/pressrelease/07312012accretiveceaseoperations.asp">https://www.ag.state.mn.us/consumer/pressrelease/07312012accretiveceaseoperations.asp</a> (last visited Jan. 2, 2014).<br><br></font></font>[5] <i>In the Matter of Accretive Health, Inc.</i>, FTC Complaint, Docket No. ___ (File. no. 122 3077) (Dec. 31, 2013), <i>available at </i><a href="https://www.ftc.gov/enforcement/cases-and-proceedings/cases/122-3077/accretive-health-inc">https://www.ftc.gov/enforcement/cases-and-proceedings/cases/122-3077/accretive-health-inc</a>.<br><br>[6] Id. at para. 6<br><br>[7] </font></font><font face="Arial"><font face="Arial" size="2"><font face="Arial"><font face="Arial" size="2"><i>In the Matter of Accretive Health, Inc.</i>, FTC Order, Docket No. ___ (File. no. 122 3077) (Dec. 31, 2013), <i>available at </i><a href="https://www.ftc.gov/enforcement/cases-and-proceedings/cases/122-3077/accretive-health-inc">https://www.ftc.gov/enforcement/cases-and-proceedings/cases/122-3077/accretive-health-inc</a>.<br><br></font></font>FTC's Press Release - <a href="https://www.ftc.gov/news-events/press-releases/2013/12/accretive-health-settles-ftc-charges-it-failed-adequately-protect">https://www.ftc.gov/news-events/press-releases/2013/12/accretive-health-settles-ftc-charges-it-failed-adequately-protect</a>. <br></font></font></div><div align="left"><font face="Arial"><font face="Arial"> </font>&nbsp; </font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1388685990_Privacy.html</link>
<guid>http://melniklegal.com/weblog/1388685990_Privacy.html</guid>
<pubDate>Thu, 02 Jan 2014 13:06:30 EST</pubDate>
</item>
			
			
</channel>
</rss>