<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Thu, 13 Aug 2026 02:39:02 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Thu, 13 Aug 2026 02:39:02 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[Hospital Settles with OCR for $ 218,400 Over Cloud-Based File Sharing]]></title>
<description><![CDATA[
 
 
 
 <div align="left"><font face="Arial">Covered entities, business associates and subcontractors using cloud-based file sharing offerings such as Dropbox, Box.com, and the various other similar solutions should note the most recent settlement announcement from the Office of Civil Rights (OCR). On July 10, 2015, OCR announced a settlement with St. Elizabeth’s Medical Center (Medical Center) for $ 218,400 involving allegations of violations of the HIPAA Security Rule stemming from two reported incidents, the first of which was brought to the OCR’s attention through a third-party complaint.</font><br></div><div align="left"><font face="Arial"><br></font></div><style>
  .linkcolorchange A:link {color: #edad27; text-decoration: 
 underline}.linkcolorchange A:visited {color: #edad27; text-decoration: 
 underline}  .linkcolorchange A:active {text-decoration: underline}  
 .linkcolorchange A:hover {text-decoration: underline; color: #edad27;} 
 </style><table style="text-align: left; margin-left: auto; 
 margin-right: auto;" class="linkcolorchange" align="left" border="0"><tbody><tr><td style="border: 1px solid 
 #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few 
 preliminary comments....</i> </b></font><font color="#FFFFFF" face="Arial">This settlement reminds organizations that they need to follow the flow of PHI in their environment and to pay attention to where their workforce members are storing PHI. It is possible with today's technology to log the software installed on corporate computers and, further, to prohibit certain software from being installed. Similarly, usb ports and cd/dvr drives can be disabled.<br><br>What is striking about this settlement is the specificity of the OCR settlement, where OCR has not only expressly required the Medical Center to interview workforce members, but also dictated the <b><i>types </i></b>of workforce members that must be interviewed.<br></font></font></font></td></tr></tbody></table><div align="left"><font face="Arial"><br>St. Elizabeth’s Medical Center is a tertiary-care hospital based in Brighton, Massachusetts. The OCR Settlement stems from two separate incidents:<br></font><blockquote><font face="Arial"><u><b>(1) &nbsp; 2012 Incident</b></u> – This incident involved the Medical Center using an online file-sharing solution to store protected health information (PHI) of at 498 individuals “without having analyzed the risks associated with such a practice.”<font size="2">[1]</font> This incident was brought to OCR’s attention through a third-party complaint received by OCR on November 16, 2012. OCR initiated its investigation on February 14, 2014 and found that the Medical Center “failed to timely identify and respond to the known security incident, mitigate the harmful effects of the security incident, and document the security incident and its outcome.”<font size="2">[2] </font><br><br><u><b>(2) &nbsp; 2014 Incident</b></u> – This incident involved “a breach of unsecured ePHI stored on a former [Medical Center’s] workforce member’s personal laptop and USB flash drive, affecting 595 individuals” that the Medical Center self-reported to the OCR on August 25, 2014. OCR initiated this second investigation on November 17, 2014.<font size="2">[3]</font><font size="2"></font><br></font></blockquote><font face="Arial">While the two incidents were two years apart, strikingly, the Settlement Agreement does encompass both incidents.<font size="2">[4]</font><br><br>According to the Resolution Agreement, the OCR found the following conduct problematic:<br></font><ul><li><font face="Arial">Medical Center <font color="#333399"><b>disclosed the PHI </b></font>of at least 1,093 individuals.</font></li><li><font face="Arial">Medical Center <font color="#339999"><b>failed to implement sufficient security measures regarding the transmission of and storage of ePHI</b></font> to reduce risks and vulnerabilities to a reasonable and appropriate level. </font></li><li><font face="Arial">Medical Center <font color="#009900"><b>failed to timely identify and respond to a known security incident, mitigate the harmful effects of the security incident, and document the security incident and its outcome</b></font>.</font></li></ul><font face="Arial">Similar to past Resolution Agreements, the Medical Center and OCR entered into a Corrective Action Plan, requiring the Medical Center to take a number of steps to address the HIPAA Rule deficiencies. What appears to be different between this agreement and past agreements, however, is the relative amount of detail required by OCR, including setting froth relatively detailed requirements for the Self-Assessment. Specifically, the Corrective Action Plan requires the Medical Center to:<br></font><font face="Arial"><br></font></div><table style="border: 1px solid #000000;" align="left" border="0" cellpadding="5" cellspacing="5"><tbody><tr><td align="left" valign="top"><font face="Arial"><b>Conduct and Report a Self-Assessment</b><br>Within one hundred twenty (120) calendar days of the Effective Date, [Medical Center] . . . shall conduct an assessment … of [Medical Center’s] workforce members’ <u><i><b>familiarity and compliance with [Medical Center] policies and procedures</b></i></u> that address the following: </font><br><blockquote><font face="Arial"><b>a.</b> transmitting ePHI using unauthorized networks; </font><br><font face="Arial"><br><b>b.</b> storing ePHI on unauthorized information systems, including unsecured networks and devices; </font><br><font face="Arial"><br><b>c.</b> removal of ePHI from Medical Center; </font><br><font face="Arial"><br><b>d.</b> prohibition on sharing accounts and passwords for ePHI access or storage; </font><br><font face="Arial"><br><b>e.</b> encryption of portable devices that access or store ePHI; and </font><br><font face="Arial"><br><b>f.</b> security incident reporting related to ePHI. </font><br></blockquote><font face="Arial">[The] Self-Assessment will include, but not be limited to: <br></font><blockquote><font face="Arial"><b>a.</b> Unannounced site visits to five [Medical Center] departments, including the Cardiology Department (the “Covered Departments”) to assess implementation of the policies and procedures [described in this Settlement Agreement]; </font><br><font face="Arial"><br><b>b.</b> Interviews with a total of fifteen (15) randomly selected [Medical Center] workforce members who have access to ePHI, thirteen (13) of whom shall be from the Covered Departments—including at least one intern, resident, or fellow, and the remaining two (2) of whom shall be interns, residents, or fellows working in Hematology/Oncology; and </font><br><font face="Arial"><br><b>c.</b> Inspection of at least three (3) portable devices at each of the Covered Departments that can access ePHI, including one (1) laptop, one (1) other portable device, such as a tablet or smartphone, and one (1) portable storage media, such as a USB flash drive, randomly selected to ensure that such devices satisfy all applicable requirements of the policies and procedures [described in this Settlement Agreement].</font><br></blockquote><font face="Arial">[The Medical Center must produce a written report within] one hundred fifty (150) calendar days of the Effective Date [and provide the report to HHS.] The Self-Assessment Report shall include, but not be limited to: <br></font><blockquote><font face="Arial"><b>a.</b> Dates and locations of unannounced site visits; </font><br><font face="Arial"><br><b>b.</b> Job titles and duties of workforce members interviewed; </font><br><font face="Arial"><br><b>c.</b> Summaries of results of interviews; </font><br><font face="Arial"><br><b>d.</b> Summaries of inspections of workstations and other devices containing ePHI; and </font><br><font face="Arial"><br><b>e. </b>Identification of any material compliance issues with the policies described [described in this Settlement Agreement], and recommendations for improving these policies and procedures, oversight and supervision, or training.</font><br></blockquote><font face="Arial"><b><br>Revision and Distribution of Policies and Procedures<br></b>[If the Self-Assessment reveals that the Medical Center must revise its policies and procedures, then the Medical Center will] draft the appropriate revisions for review by HHS. If the Self-Assessment indicates that [Medical Center] workforce members are unfamiliar with or not substantially complying with [Medical Center’s] policies and procedures[, such as those involving the use of unauthorized networks, removal of PHI from the Medical Center, encryption, security incident reporting and others identified in the Settlement&nbsp; Agreement, then the Medical Center will] develop an oversight mechanism reasonably tailored to ensure that all Medical Center workforce members follow such policies and procedures, and that ePHI is only used and disclosed as provided for by such policies and procedures. <br><br>[The Medical Center must provide the revised policies and procedures as well as the oversight mechanism to HHS for review and approval.] Within thirty (30) calendar days after receiving HHS’ final approval of any revisions to the policies and procedures [the Medical Center will] implement and distribute the policies and procedures to all appropriate workforce members.<b><br><br><br>Train Workforce Members</b><br>[If the Self-Assessment reveals that the Medical Center must revise its training materials, then the Medical Center will] draft the appropriate revisions for review by HHS. [Upon final approval by HHS, the Medical Center will] distribute a security reminder reflecting the content of such training and describing any revised policies and procedures to all [Medical Center] workforce members who have access to ePHI. [Medical Center] shall incorporate the revised training into its next annual refresher training for all applicable Medical Center workforce members [and] provide such training to new members of the workforce who have access to ePHI within sixty (60) calendar days of the workforce members beginning their service. Each individual who is required to attend training shall certify, in writing or in electronic form, that the individual has received the required training. The training certification shall specify the date training was completed. A sign-in sheet shall suffice to meet this requirement. All course materials shall be retained [for the six (6) year document retention period].<font size="2">[5]</font><br></font></td></tr></tbody></table><div align="left"><font face="Arial"><br>For a chart summary 
 of the OCR fines as well as other HIPAA related litigation, please 
 see<a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html">
  </a><a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html">https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html</a>.
  <br><br><font size="2">---------------------</font><br></font><div><font face="Arial"><font size="2">[1] Press Release, HHS Office of Civil Rights, HIPAA Settlement Highlights Importance of Safeguards When Using Internet Applications, July 10, 2015, <i>available at</i> <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/SEMC/bulletin.pdf">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/SEMC/bulletin.pdf</a>.</font><font size="2"><font size="2"></font></font></font><br><br><font face="Arial"><font size="2">[2] <i>Id</i>.</font></font><br><br><font face="Arial"><font size="2">[3] Resolution Agreement between HHS Office of Civil Rights and St. Elizabeth’s Medical Center (July 8, 2015), <i>available at</i> <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/SEMC/ra.pdf">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/SEMC/ra.pdf</a>.</font></font><br><br><font face="Arial"><font size="2">[4] <i>Id</i>. at I.1.2 (In describing the so-called “Covered Conduct,” OCR identifies a total of 1,093 patients, meaning that it was adding the patients from both the 2012 and 2014 incidents).</font></font><br><br><font face="Arial"><font size="2">[5] <i>Id</i>. at V.</font></font><br></div><font face="Arial"><font size="2"><font size="2">---------------------</font></font><br><br><font size="2"><font size="2"><font size="2">Posted by: 
 Tatiana Melnik on July 23, 2015</font></font></font></font><font face="Arial"><font size="2"><font size="2"><font size="2"></font></font></font><br></font> 
 </div>   
 
 
   
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1437673811_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1437673811_Data-Breach.html</guid>
<pubDate>Thu, 23 Jul 2015 13:50:11 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[IBM and the EEOC Experiment with BYOD]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div align="left"><font face="Arial">Many companies are moving to a BYOD system. And the move is understandable given anticipated employee efficiency and productivity increases as well as cost savings for employers. On the other hand, companies also need to be aware of the problems that can arise when moving to a BYOD environment, including employee push back and increased security concerns.</font><br><br><font face="Arial"><u><b>BYOD Can Garner Cost Savings - A BYOD Case Study</b></u></font><br><br><font face="Arial">In 2012, the U.S. Equal Employment Opportunity Commission (EEOC) undertook a BYOD pilot, during which the EEOC was able to significantly reduce the information technology budget for BlackBerry mobile devices. The EEOC explained,</font><br><blockquote><font face="Arial">Last year [2011], the EEOC was paying $800,000 for its Government issued BlackBerry devices. Subsequently, the EEOC’s FY2012 IT budget was cut from $17.6 million to $15 million, nearly a 15% reduction. The EEOC’s Chief Information Officer, Kimberly Hancher, significantly reduced contractor services, eliminated some software maintenance, and slashed the agency’s budget for mobile devices -- leaving only $400,000 allocated for Fiscal Year 2012. . . . [As a result of several cost saving measures discussed below,] FY 2012 costs were reduced by roughly $240,000[.]<br></font></blockquote></div><div><div align="left"><font face="Arial">Importantly, before implementing changes, the EEOC evaluated use of existing devices. Specifically, the EEOC found that,</font><br><blockquote><font face="Arial">75% of our users never made phone calls from their BlackBerrys … Email is the killer app. They either used the phone on their desk or they used their personal cell phone to make calls because it’s just easier. We also found there were a number of zero-use devices. People have them parked in their desk drawer, and the only time they use it is when they travel.</font><br></blockquote></div><div align="left"><font face="Arial">After evaluating the existing environment, the EEOC was able to form a plan to implement several cost saving measures, including pressing their "wireless carrier, a GSA Networx contract provider, to help cut costs or risk losing the EEOC’s BlackBerry business." The EEOC also eliminated zero-use devices and moved the remaining BlackBerry devices to a bundled rate plan with shared minutes. </font><br></div><div align="left"><br><font face="Arial">But, moving to a BYOD environment can also be problematic. While employees desire to use their own devices, they may also push back on a company's efforts to monitor and track the devices. Moreover, as IBM learned in its implementation, employees must be trained on best practices to protect their devices and avoid security pitfalls.</font><br><br><font face="Arial"><b><u>IBM Experiments with BYOD</u></b></font><br><br><font face="Arial">IBM is a sophisticated technology company whose storied history of innovation dates back to 1880. IBM holds more patents than any other U.S. based IT company and has lead the list of top patent recipients for 19 consecutive years. Yet, when IBM adopted a BYOD policy in 2010, similar to other companies, it too encountered technology challenges</font><br><br><font face="Arial">In an interview with the MIT Technology Review in 2012, Jeanette Horan, IBM's Chief Technology Officer, reported that her IT department was bogged down with security issues brought about by employees using certain apps (e.g., Dropbox), forwarding internal e-mail to public e-mail services, and creating open Wi-Fi hotspots with their mobile devices.</font><br><br><font face="Arial">According to the MIT Technology Review, Horan's team "surveyed several hundred employees using mobile devices, [and found that] many were 'blissfully unaware' of what popular apps could be security risks." In general, her team "found a tremendous lack of awareness as to what constitutes a risk."</font><br><br><div align="left"><font face="Arial">Given the lack of awareness among IBM employees of security risks associated with mobile apps and time spent addressing these concerns, "[t]he trend toward employee-owned devices isn’t saving IBM any money . . . Instead, [Horan] says, it has created new challenges for her department of 5,000 people, because employees’ devices are full of software that IBM doesn’t control."</font><br><br><font face="Arial"><u><b>BYOD Is Not For Everyone</b></u></font><br><br><font face="Arial">It is important for companies to recognize that a bring your own device approach is not appropriate for every company. True, IBM, the EEOC, and many other organizations have managed to make BYOD work for them. But, that does not mean that this approach is the best approach for every organization. As is clear from IBM's experience, companies may not see an immediate cost savings from moving to a BYOD environment. On the other hand, companies could realize immediate cost savings by eliminating zero-use devices as did the EEOC.</font><br></div></div><div align="left"><br><br><font face="Arial"><u><b>Resources and Supporting Materials</b></u></font><br><ul><li><font face="Arial">White House Digital Government - Bring Your Own Device - A Toolkit to Support Federal Agencies Implementing Bring Your Own Device (BYOD) Programs (August 23, 2012)</font></li><ul><li><font face="Arial">Includes three BYOD Case Studies:</font></li><ul><li><font face="Arial">Alcohol and Tobacco Tax and Trade Bureau (TTB) Virtual Desktop Implementation</font></li><li><font face="Arial">U.S. Equal Employment Opportunity Commission (EEOC) BYOD Pilot</font></li><li><font face="Arial">State of Delaware BYOD Program</font></li></ul><li><font face="Arial">Includes Sample Policies</font></li><ul><li><font face="Arial">Sample #1: Policy and Guidelines for Government-Provided Mobile Device Usage</font></li><li><font face="Arial">Sample #2: Bring Your Own Device – Policy and Rules of Behavior</font></li><li><font face="Arial">Sample #3: Mobile Information Technology Device Policy</font></li><li><font face="Arial">Sample #4: Wireless Communication Reimbursement Program</font></li><li><font face="Arial">Sample #5: Portable Wireless Network Access Device Policy</font></li><li><font face="Arial"><i><b>**Disclaimer - inclusion does not constitute endorsement or approval.</b></i><br></font></li></ul><li><div><font face="Arial"><a href="https://www.whitehouse.gov/digitalgov/bring-your-own-device">https://www.whitehouse.gov/digitalgov/bring-your-own-device</a>&nbsp; or&nbsp; <a href="https://melniklegal.com/av/2012_BYOD_Case_Studies_White_House.pdf">PDF copy</a></font></div></li></ul></ul><ul><li><div><font face="Arial">Brian Bergstein, <a href="https://www.technologyreview.com/news/427790/ibm-faces-the-perils-of-bring-your-own-device/"><i>IBM Faces the Perils of "Bring Your Own Device":</i></a> <i>After letting its employees use their own phones and tablets for work, the company confronted a flood of insecure apps from the open Web</i>, MIT Technology Review (May 21, 2012).</font></div></li></ul><ul><li><font face="Arial">IBM Press Release, <i><a href="https://www-03.ibm.com/press/us/en/pressrelease/36463.wss">IBM Breaks U.S. Patent Record; Tops Patent List for 19th Consecutive Year</a>: IBM inventors received more than 6,000 patents in 2011</i>. Jan 11. 2012. <br></font></li></ul></div><font face="Arial"><br></font></div></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1381716709_BYOD.html</link>
<guid>http://melniklegal.com/weblog/1381716709_BYOD.html</guid>
<pubDate>Sun, 13 Oct 2013 22:11:49 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Family Stumped by Fired Live-In Nanny Who Won't Leave]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial"><i><b>The Importance of Running Background Checks. </b></i><br><br>Employers generally recognize that there is a need to run background checks on prospective employees. But, sometimes after an interview or because of a time crunch, this simple detail is overlooked. A story reported by ABC News out of California on June 26, 2014 on a nanny who refuses to work and leave the premises serves as a good reminder of the need to run comprehensive background checks on prospective employees.<font size="2">[1] </font>As reported by Sarah Figalora,&nbsp;</font><blockquote><font face="Arial">A California family is stumped about what to do with a live-in nanny they say refuses to work, refuses to be fired and refuses to leave. <br><br>In fact, Marcella Bracamonte claims that the nanny, Diane Stretton, has threatened to sue the family for wrongful firing and elder abuse. . . .<br><br>&nbsp;Bracamonte called the police, but the cops declined to do anything, saying it was a civil matter. Lt. John Moore of the Upland Police Department confirmed to ABC News that there is no immediate action that can be taken against Stretton, saying "generally, once somebody has established residency, you have to go through a formal eviction process.”<br><br>Bracamonte soon realized that this was not Stretton’s first time with legal matters. Stretton reportedly has been involved in 36 lawsuits, landing herself on California’s Vexatious Litigant Lists for repeatedly abusing the legal system. <br></font></blockquote><font face="Arial">While the experience of the Bracamonte family is certainly unusual, it serves as a good example of the need to run thorough background checks on employees and to double check references. Employees do misbehave and are often the cause of data breaches and other security lapses</font><font face="Arial">. See for example, <font size="3"><b><a href="https://melniklegal.com/programs/weblog.cgi?showpage=1396887751_Identity-Theft">Former Employee of a Florida Medical Center Pleads Guilty to Identity Theft</a>. <br><br></b></font></font><div align="left"><font face="Arial"><font size="3">Aside from issues related to identity theft, employees with access to company funds have also been prosecuted for embezzlement.&nbsp;<b> </b>For example, in the dental space, it is often stated that three out of five dental practices are being embezzled from. Further, in a 2012 Ponemon Institute report, the organization found that "</font></font><font face="Arial"><font size="3">[o]n average, it takes 87 days to first recognize that insider fraud has 
 occurred and more than three months (105 days) to get at the root cause 
 of the fraud [and that according] to 73 percent of respondents, an employee’s malfeasance has caused financial loss and possibly brand damage."<font size="2">[2] </font>With the costs of data breach notification and remediation increasing, these are pretty frightening statistics that all business owners should take to heart (particularly those where employees have misused information </font>to commit identity theft).</font><br></div><font face="Arial"><br><font size="3">While running background checks is important, they must also be done in accordance with both federal and state legal requirements. </font><font size="3">It is important to remember that any background check must be job-related and consistent with business necessity.</font><font size="3">The Federal Trade Commission and the Equal Employment Opportunity Commission (EEOC) have been particularly active in this space recently, because of their concerns that employers are using criminal background checks to exclude applicants. As the EEOC and the FTC have clarified:</font><br></font><blockquote><font face="Arial" size="3">Except for certain restrictions related to medical and genetic information (see below), <b>it's not illegal for an employer to ask questions about an applicant's or employee's background, or to require a background check</b>.</font><font face="Arial"><br><br>However, any time you use an applicant's or employee's background information to make an employment decision, regardless of how you got the information, you must comply with federal laws that protect applicants and employees from discrimination. That includes discrimination based on race, color, national origin, sex, or religion; disability; genetic information (including family medical history); and age (40 or older). These laws are enforced by the Equal Employment Opportunity Commission (EEOC).<br><br>In addition, when you run background checks through a company in the business of compiling background information, you must comply with the Fair Credit Reporting Act (FCRA). The Federal Trade Commission (FTC) enforces the FCRA.<font size="2">[3]</font><br></font></blockquote><font face="Arial">Aside from federal laws, many states also have laws addressing pre-employment background screening. In Florida, for example, <a href="https://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Display_Statute&amp;URL=0400-0499/0435/0435ContentsIndex.html">Chapter 435 of the Florida Statutes</a> addresses employment screening. Some states also have laws addressing whether <a href="https://melniklegal.com/states_regulate_social_media.html">social media information may be used as part of pre-employment screening</a>.<br><br><b><br><font size="3">A Few Outside Resources:</font></b><br></font><ul><li><font face="Arial" size="3">Privacy Rights Clearinghouse - Employment Background Checks: A Jobseeker's Guide -&nbsp; <a href="https://www.privacyrights.org/employment-background-checks-jobseekers-guide">https://www.privacyrights.org/employment-background-checks-jobseekers-guide</a></font></li></ul><ul><li><font face="Arial" size="3">FTC - Consumer Information: Employee Background Checks - <a href="https://www.consumer.ftc.gov/media/video-0026-employee-background-checks">https://www.consumer.ftc.gov/media/video-0026-employee-background-checks</a></font></li></ul><ul><li><font face="Arial" size="3">EEOC</font></li><ul><li><font face="Arial">Background Checks - What Employers Need to Know -&nbsp; <a href="https://www.eeoc.gov/eeoc/publications/background_checks_employers.cfm">https://www.eeoc.gov/eeoc/publications/background_checks_employers.cfm</a></font></li><li><font face="Arial">Pre-Employment Inquiries and Arrest &amp; Conviction - https://www.eeoc.gov/laws/practices/inquiries_arrest_conviction.cfm.<br></font></li></ul></ul><div align="left"><font face="Arial">-----------------------------</font><br><font face="Arial"><font size="2">[1] Sarah Figalora, Family Stumped by Fired Live-In Nanny Who Won't Leave, ABC News, Good Morning America, June 26, 2014, <a href="https://abcnews.go.com/US/family-stumped-fired-live-nanny-leave/story?id=24316229">https://abcnews.go.com/US/family-stumped-fired-live-nanny-leave/story?id=24316229</a>.</font></font><br><br><font face="Arial"><font size="2">[2] Press Release, Ponemon Institute, <i>Ponemon Survey Indicates the Growing Threat of Insider Fraud Not a Top Security Priority for Organizations, Proves a Costly Mistake</i> (Feb. 28, 2013), <i>available at</i> <a href="https://www.ponemon.org/news-2/49">https://www.ponemon.org/news-2/49</a>.</font></font><br><br><font face="Arial"><font size="2">[3] EEOC, Background Checks - What Employers Need to Know, A joint publication of the Equal Employment Opportunity Commission and the Federal Trade Commission, <a href="https://www.eeoc.gov/eeoc/publications/background_checks_employers.cfm">https://www.eeoc.gov/eeoc/publications/background_checks_employers.cfm</a> (last visited June 29, 2014).</font></font><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">---------------------</font></font></font></font></font></font><br><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Posted by: Tatiana Melnik on June 29, 2014</font></font></font></font></font></font></font></font></div></div><font face="Arial"> </font>   
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1404071750_Employment.html</link>
<guid>http://melniklegal.com/weblog/1404071750_Employment.html</guid>
<pubDate>Sun, 29 Jun 2014 15:55:50 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[When Looking at Security, Consider Every Device]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial"><i>Internet of Things to Complicate Compliance.<br><br></i>When evaluating security, organizations must evaluate every device that is connected to the Internet, whether directly or through the company's network. This includes everything from radiology software systems, to VPNs, to video conferencing equipment, to printers and faxes. The more devices that are connected, the more difficult this process becomes. </font><font face="Arial"><font face="Arial">The move to the Internet of Things is sure to exacerbate this problem as organizations have that many more devices to monitor and control. Healthcare providers should take steps to prepare now by enrolling their devices into device management programs, taking stock of devices that are owned by the company or owned by employees but used for company purposes (<i>e.g.</i>, smartphones, tablets, etc.), and implementing processes to receive and address security incident warnings from those outside of an organization, who may not be business associates.<br></font><br>In February 2014, the SANS Institute, with support from Norse, published a report summarizing findings from a year-long analysis of cybersecurity threats in the healthcare industry. The amount of data collected was specific to the healthcare industry:<br></font><blockquote><font face="Arial">During the sample period [(September 2012 and October 2013)], the Norse threat intelligence infrastructure—a global network</font> <font face="Arial">of sensors and honeypots that process and analyze over 100 terabytes of traffic daily—</font><font face="Arial">gathered data. The intelligence data collected for this sample included:</font><br><ul><li><font face="Arial">49,917 unique malicious events</font></li><li><font face="Arial">723 unique malicious source IP addresses</font></li><li><font face="Arial">375 U.S.-based compromised health care-related organizations<font size="2"> [1]</font><br></font></li></ul></blockquote><font face="Arial">The organizations that were compromised varied in size and financial resources:</font><font face="Arial"><br></font><blockquote><font face="Arial">About a third of the organizations represent small providers, while the rest represented</font> <font face="Arial">clearinghouses, health plans, pharmaceutical companies and other types of medical organizations. Some of these providers were also quite large, with renowned research</font> <font face="Arial">centers and teaching hospitals among the sources sending out the malicious packets. <font size="2">[2]</font><br></font></blockquote><font face="Arial">Interestingly, while most of the largest data breaches reported to the HHS Office of Civil Rights to date involved business associates, SANS found that a large percentage of the malicious IP traffic emanated from healthcare providers, with covered entities accounting for 78.6% of the compromised organizations:</font><br><blockquote><ul><li><font face="Arial">Health care providers—72.0% of malicious traffic</font></li><li><font face="Arial">Health care business associates—9.9% of malicious traffic</font></li><li><font face="Arial">Health plans—6.1% of malicious traffic</font></li><li><font face="Arial">Health care clearinghouses—0.5% of malicious traffic</font></li><li><font face="Arial">Pharmaceutical—2.9% of malicious traffic</font></li><li><font face="Arial">Other related health care entities—8.5% of malicious traffic</font><font face="Arial"><font face="Arial" size="2"> [3]</font> </font></li></ul></blockquote><font face="Arial">Most strikingly, SANS noted:<br></font><blockquote><font face="Arial">Many of the organizations were compromised and, therefore, out of compliance for</font><br><font face="Arial">months, and some for the duration of the study—<font color="#0070c0"><b>meaning they never detected their compromises or outbound malicious communications, <u><i>nor did they acknowledge warnings from the Norse response team</i></u></b></font>.</font><font face="Arial"><font size="2">[4]</font></font></blockquote><font face="Arial">Whi<font face="Arial">le it seems surprising that </font>any organization would ignore a direct notice of an on-going security compromise, particularly an organization trusted with sensitive healthcare data, it is not unheard of (<i>see e.g.</i>, the pending FTC case against LabMD, which was allegedly brought to the FTC by a security firm, and the FTC settlement with HTC America, where the FTC alleged that HTC ignored vulnerability reports from security experts<font size="2"> [5]</font>). But, as we continue to see data breaches in the healthcare space as well as healthcare providers becoming the victims of cyberattacks</font><font face="Arial"><font face="Arial">—</font>such as the attacks against each of </font><font face="Arial">Anthem Inc. and Premera Blue Cross</font><font face="Arial"><font face="Arial"><font face="Arial">—healthcare providers will need to implement stronger policies and procedures to ensure that security warnings are not ignored.<br><br>These monitoring programs must include all systems and devices on the organizations' infrastructure. In its analysis, SANS evaluated the types of systems and devices emanating malicious traffic and found a wide variety of systems and edge devices. <i>See </i>Figure 1 below<font size="2">[6]</font>. Many of these devices</font></font></font><font face="Arial"><font face="Arial"><font face="Arial"><font face="Arial"><font face="Arial"><font face="Arial">—</font></font></font>particularly network-connected edge devices such as printers, faxes, web cameras, and video conferencing systems are often overlooked as the source of security vulnerabilities, despite being recognized as potential entry points for hackers and cybercriminals.<font size="2">[7]</font><br><br></font></font></font><div align="center"><font face="Arial"><font face="Arial"><font face="Arial"><img src="https://melniklegal.com/images/SANS_healthcare_malicious_traffic.jpg"></font></font></font><br></div><font face="Arial"><font face="Arial"><font face="Arial"><br>Specifically:<br></font></font></font><div><ul><li><font face="Arial"><b><u>Connected medical endpoints</u></b>. The findings of this study indicate that 7 percent of traffic was coming from radiology imaging software, another 7 percent of malicious traffic originated from video conferencing systems, and another 3 percent came from digital video systems that are most likely used for consults and remote procedures. . . . <br></font></li></ul><ul><li><font face="Arial"><u><b>Internet-facing personal health data</b></u>. The study shows 8 percent of malicious<br>traffic was emitted through a web-based call center website, backed by a VoIP PBX,<br>in use by a medical supply company. Also we found indications of a compromised<br></font><div><font face="Arial">personal health record (PHR) system. . . .</font></div></li></ul><ul><li><div><font face="Arial"><u><b>Security systems and edge devices</b></u>. In this study, most of the malicious traffic passed through or was transmitted from VPN applications and devices (33 percent), whereas 16 percent was sent by firewalls, 7 percent was sent from routers and 3 percent was sent from enterprise network controllers (ENCs). This indicates that the security devices and applications themselves were either compromised, which is a common tactic among malware families, or that these “protection” systems are not detecting malicious traffic coming from the network endpoints inside the protected perimeter—inside the firewall or behind the VPN concentrator. . . . <font size="2">[8]</font></font><br></div></li></ul></div><font face="Arial">When evaluating security, organizations must take a broad look at their environment and consider any network-connected device a potential source of a security vulnerability.</font><br><br><br><font face="Arial"><font face="Arial"><font size="2">-------------------------------------</font></font></font><font face="Arial"><font face="Arial"><br></font></font><div align="left"><font face="Arial"><font face="Arial"><font size="2">[1] Barbara Filkins, <a href="https://www.sans.org/reading-room/whitepapers/analyst/health-care-cyberthreat-report-widespread-compromises-detected-compliance-nightmare-horizon-34735">Health Care Cyberthreat Report: Widespread Compromises Detected, Compliance Nightmare on Horizon</a>, SANS Institute Whitepaper, 3, Feb. 2014.</font></font></font><br><br><font face="Arial"><font size="2">[2] Id. <br><br>[3] Id.<br><br>[4] Id.</font></font><br><br><font face="Arial"><font size="2">[5] LabMD Inc. v. Tiversa Holding Corp. et al., Case No. 2:15-cv-00092, U.S. District Court for the Western District of Pennsylvania (Jan. 21, 2015); Press Release, Federal Trade Commission, H<i>TC America Settles FTC Charges It Failed to Secure Millions of Mobile Devices Shipped to Consumers: Company Required to Patch Vulnerabilities on Smartphones and Tablets</i>, Feb. 22, 2013, <a href="https://www.ftc.gov/news-events/press-releases/2013/02/htc-america-settles-ftc-charges-it-failed-secure-millions-mobile">https://www.ftc.gov/news-events/press-releases/2013/02/htc-america-settles-ftc-charges-it-failed-secure-millions-mobile</a>.</font></font><br><br><font face="Arial"><font size="2">[6] </font><font face="Arial"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font face="Arial"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Filkins, <i>supra </i>note 1, at 8.</font></font></font></font></font></font></font></font></font></font></font></font></font></font><br></div><font face="Arial"><font face="Arial"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font face="Arial"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2"><br>[7] Nicole Perlroth, <i>Cameras May Open Up the Board Room to Hackers</i>, NYTimes.com, Jan. 22, 2013, <a href="https://www.nytimes.com/2012/01/23/technology/flaws-in-videoconferencing-systems-put-boardrooms-at-risk.html">https://www.nytimes.com/2012/01/23/technology/flaws-in-videoconferencing-systems-put-boardrooms-at-risk.html</a><br><br>[8] Filkins, <i>supra </i>note 1, at 7.<br><br><div><font face="Arial"><font size="2">-------------------------------------</font></font></div><br><div><font face="Arial"><font size="2">Posted by Tatiana Melnik on March 28, 2015<br></font></font></div></font></font></font></font></font></font></font></font></font></font></font></font></font></font></div><font face="Arial"><font size="2"><font face="Arial"><font size="2"> </font></font></font></font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1427590149_Security.html</link>
<guid>http://melniklegal.com/weblog/1427590149_Security.html</guid>
<pubDate>Sat, 28 Mar 2015 20:49:09 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Dentist Sued Over the Marketing Practices of Its Independent Contractor]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial"><i><b>Companies Must be Careful in Hiring Marketing Firms</b></i></font><br><br><font face="Arial">A Florida dentist is currently in litigation over the actions of the subcontractor of his subcontractor. Briefly, the dentist hired an individual to help him market his dental practice. That individual then hired a third-party marketing firm located in Romania to </font><font face="Arial"><font face="Arial">send 10,000 fax ads to phone numbers within a specific zip code. The plaintiff, a golf course, filed a class action lawsuit based on violations of the </font></font><font face="Arial"><font face="Arial"><font face="Arial">Telephone Consumer Protection Act, which permits consumers to sue and receive statutory damages for certain unsolicited telemarketing efforts.</font></font></font><br><br></div><table style="text-align: left; margin-left: auto; margin-right: auto;" align="left" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i> </b></font><font color="#FFFFFF">Companies must be careful when engaging third parties to undertake marketing efforts on their behalf. In the past several years, there has been a hot bed of litigation surrounding the TCPA, particularly since certain regulatory changes in October 2013, which removed the "established business relationship" exemption and put in place a requirement of prior express written consent for certain types of marketing efforts (e.g., text messages). The current case provides a great example that the chain of responsibility can be quite long. This is similar to what providers see in the context of HIPAA, where, generally, covered entities remain ultimately responsible. When engaging marketing firms, consider engaging only parties who are experienced, understand the regulatory landscape, and carry their own insurance. Be sure to ask for a copy of the certificate of insurance and double check that the type of insurance is appropriate for the services being offered.<br></font></font></font></td></tr></tbody></table><div align="left"><br><font face="Arial">Companies often hold the mistaken belief that they cannot be held legally responsible for the actions of their independent contractors. Often, based on contract terms, they can be held directly responsible. For example, many commercial contracts may include a clause similar to:</font><br><blockquote><font face="Arial">USE OF SUBCONTRACTORS. Company may engage subcontractors to perform services under this Agreement.&nbsp; </font><font face="Arial">Company </font><font face="Arial">understands and agrees that the management of any subcontractor is the sole responsibility of </font><font face="Arial"><font face="Arial">Company </font>to the same extent as if </font><font face="Arial"><font face="Arial">Company </font>had not subcontracted such performance and that a subcontractor's non-performance </font><font face="Arial">shall not relieve </font><font face="Arial"><font face="Arial">Company </font>of any obligations or performance required under this Agreement.<br></font></blockquote><font face="Arial">Similarly, companies may be held responsible for the actions of their vendors under federal and state laws.</font><br><br><font face="Arial">One such law is the Telephone Consumer Protection Act (TCPA) (47 U.S.C. § 227), which permits consumers to sue and receive damages for receiving unsolicited telemarketing calls, faxes, pre-recorded calls, auto-dialed calls, or text messages without their prior written authorization. The TCPA has been a hotbed of litigation, particularly class action litigation, because it provides for either actual damages or statutory damages ranging from $500.00 to $1,500.00 per unsolicited call/message.</font><br><br><font face="Arial">The TCPA has become an issue for one Florida dentist. In February 2012, </font><font face="Arial"><font face="Arial"><font face="Arial">Palm Beach Golf Center-Boca filed a class action against </font></font>Dr. </font><font face="Arial"><font face="Arial"><font face="Arial">John G. Sarris </font></font></font><font face="Arial"><font face="Arial"><font face="Arial">for allegedly </font></font>sending unsolicited faxes. But, the faxes were not sent directly by Dr. Sarris, but by an independent contractor of an independent contractor. That is, Dr. Sarris engaged an individual named Roberts, an independent contractor, to market his dental practice. This contractor then engaged another entity called Business to Business Solutions ("B2B"), which sold facsimile advertising services in the US on behalf of a Romanian company called Macaw, to send 10,000 fax ads to phone numbers within a specific zip code. The Plaintiff purportedly received one of these fax advertisements.</font><br><br><font face="Arial">On October 22, 2013, the United States District Court for the Southern District of Florida granted summary judgment in favor of Dr. Sarris. The court rejected the plaintiff's direct liability claim, ruling that the golf center could establish liability, if at all, only on the basis of vicarious liability. The court further held that Dr. Sarris </font><font face="Arial"><font face="Arial">could not be held vicariously liable for purported violations of the TCPA. The court's decision was based, in part, on a 2013 FCC decision, <i>In re Joint Petition filed by Dish Network</i>, 28 FCC Rcd. 6574 (2013) (addressed availability of direct and vicarious liability for unlawful telemarketing calls under the TCPA), where the FCC ruled "</font>that the seller generally is not directly liable for unlawful telemarketing calls initiated by third-party telemarketers on the seller’s behalf." [1]</font><br><br><font face="Arial">The Plaintiff appealed the decision to the </font><font face="Arial"><font face="Arial">Eleventh Circuit and on July 7, 2014, the Court sought comments from the FCC asking the FCC's position </font></font><font face="Arial"><font face="Arial">"on whether the [TCPA] and its accompanying regulations allow a plaintiff to recover damages from a defendant who sent no facsimile to the plaintiff, but whose independent contractor did." </font></font><font face="Arial"><font face="Arial">In a letter brief filed Thursday, July 17, 2014, the FCC answered in an affirmative yes. The FCC specifically addressed its decision in the <i>Dish Network</i> case, explaining:</font></font><br><blockquote><font face="Arial"><font face="Arial">The DISH Network ruling did not address or alter the treatment of facsimile transmissions under the TCPA or the Commission’s implementing regulations. Under the terms of the statute and regulations, the recipient of an unsolicited facsimile advertisement may recover damages from a defendant that does not itself transmit the offending facsimile, if the defendant has hired an independent contractor to transmit facsimiles advertising the defendant’s goods or services. Such liability does not depend upon the application of federal common law vicarious liability principles.</font></font></blockquote><font face="Arial">According to the court's docket, the Eleventh Circuit has scheduled to hear oral arguments on the appeal on July 30, 2014. </font><br><br><font face="Arial">The case is <b><i>Palm Beach Golf Center-Boca, Inc. v. John G. Sarris, D.D.S., P.A. et al</i></b>., 9:12-cv-80178-KMW (S.D. Fla.), app. docket 13-14013. <a href="https://melniklegal.com/av/2012_PalmBeachGolfCenter-BocavSarris-complaint.pdf">Complaint is available here</a>.</font><br><br><font face="Arial">-------------------------------------------</font><br><font face="Arial"><font size="2">[1] <a href="https://melniklegal.com/av/2014_FCC_letter_in_Sarris_TCPA_case_11th_circuit.pdf">FCC Brief in Response to <i>Palm Beach Golf Center-Boca, Inc. v. Sarris, No. 13-14013</i>, July 17, 2014</a>. </font></font><br><font face="Arial"><font face="Arial">-------------------------------------------</font></font><br><br><br><font face="Arial"><font size="2">Posted by Tatiana Melnik on July 22, 2014</font></font><br><br><br><br></div><font face="Arial"> </font>   
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1406032985_Marketing.html</link>
<guid>http://melniklegal.com/weblog/1406032985_Marketing.html</guid>
<pubDate>Tue, 22 Jul 2014 08:43:05 EST</pubDate>
</item>
			
			
</channel>
</rss>