Semper Fidelis is the U.S. Marines’ motto – “always faithful.” Perhaps an ironic twist of phrase in the context of its recent and preventable data breach. Let’s recap. The Marine Forces Reserve recently announced that personal information of over 21,000 Marines, sailors, and civilians were “compromised.” The PI included social security numbers, bank account and routing numbers, card information, name, address and other contact information. In other words, PI which is a treasure trove for identity thieves. Some of the PI may have been redacted in part. How did this breach occur? The culprit was an e-mail incorrectly sent with an unencrypted attachment. The email was sent out by the Defense Travel System which manages travel itineraries and expense reimbursement. Obviously sensitive location information is also in play. Probably not a big thing for a travelling salesperson, but highly problematic for defense sector travel.
U.S. v. Microsoft: Is Your Data and Privacy at Risk?
On February 27, 2018, the Supreme Court heard arguments in United States v. Microsoft Corp., a case that will decide whether a digital communications provider has to comply with a U.S. search warrant for user data that is stored outside of the U.S. U.S. v. Microsoft could have major consequences for digital privacy and international data sharing, especially for the cloud-computing industry.
What to Know About ED’s New Stance On Data Breach Reporting
It’s no longer optional for colleges and universities to report data breaches to the U.S. Department of Education — yet the agency has not clearly defined its expectations. Here’s what institutions should be aware of.
Hurdles the Internet of Things Must Clear for Manufacturers and Providers
The influence of the Internet of Things (IoT) will undoubtedly be transformational with a total potential economic impact estimated to be $3.9 trillion to $11.1 trillion a year by 2025. In the race into the IoT marketplace, there are both known and unknown legal hurdles that will affect those who offer of goods and services during the proliferation of the Internet of Things.
Forget Me, Forget Me Not: What’s New (Nouveau, Nuevo, Neu…) EU?
St. Louis was named after Louis IX (born in 1214!), hosted a World Fair (technically, the 1904 Louisiana Purchase Exposition), the fleur-de-lis is ubiquitous, and we love soccer and football, although we have neither major league football nor soccer teams (St. Louis FC, our USL minor league soccer team, has a crest which features, you guessed it, a fleur-de-lis). However, St. Louis is known as the “Gateway to the West” – directionally away from Europe. Every once in a while, St. Louisans, like the rest of America, need to heed to what is going on over the pond, particularly when it comes to privacy and data security developments. Below is a brief update on a few foreign issues to begin the New Year.
HIPAA New Year!
It’s time for year-behind-us reminisces and year-before-us prognostications and, for those of us with nothing better to do during the last few days of 2017 and first few days of 2018, attention turns to HIPAA enforcement. So what happened and what can we look forward to? If past is prologue, expect the sound of silence as there was nominal Office for Civil Rights (OCR) activity in 2017 and, with the one noisy exception, no actions to cause your ears to burn.
More or Less Than the Plaintiff Bargained For: Two Recent Appellate Courts Thwart Privacy Claims Based On The Contract
In 2016, the U.S. Supreme Court in Spokeo, Inc. v. Robins, provided a potentially powerful Article III standing defense under F.R.Civ.P. 12(b)(1) seemingly applicable to a variety of privacy claims, including FCRA, FACTA, TCPA, and FDCPA statutory damage claims. The Court noted for a plaintiff to establish standing to sue in federal court, she must establish an “injury in fact” consisting of an invasion of a legally protected interest, which is both particularized and concrete.
Spokeo dealt with the “concrete” portion. To be concrete, an injury must be real but may also be intangible. Congress’ intent in creating a right is instructive, but not sufficient. Allegations of a bare procedural violation likely would not suffice to maintain standing. Some injuries create harm, others do not. Thanks for that.
Ready or Not, It’s Coming: Preparing for the GDPR
Europe’s data protection rules will undergo their biggest change in two decades when the new General Data Protection Regulation (“GDPR”) goes into effect on May 25, 2018. The GDPR replaces the current Data Protection Directive and imposes uniform data security requirements on all EU members. While the GDPR is “an evolution, not a revolution” for data protection, there are several significant changes for which companies should be prepared.
Top 3 HIPAA Lessons Learned from Hurricane Season
With a few more weeks left in the hurricane season, it may be a good time to review HIPAA Privacy Rule protocols in emergency situations.
Don’t Make “Uber” Promises You Can’t Keep
The advice we always give to clients regarding privacy policies is: “say what you do and do what you say.” It seems simple, but simplicity can be deceiving. Companies want to reassure consumers that their personal data is safe and secure; however, in today’s world, no one can make fail-safe representations of security. Uber’s recent settlement with the FTC illustrates this problem.