Improper disposition of medical records appears to be an international problem. The Saskatchewan Information and Privacy Officer recently issued regulatory guidance to health care providers on complying with the province’s health data protection law. The guidance is being sent to all health regulatory bodies and health care organization privacy boards in Saskatchewan to remind them
April 2011
OCR Conducting HIPAA Enforcement Training for State Attorneys General
The HITECH Act authorizes a state attorney general to bring a civil action for an injunction or damages in situations where the attorney general “has reason to believe that an interest of one or more of the residents of that State has been or is threatened or adversely affected” by a HIPAA violation. The HHS…
Congressman Calls for FTC Investigation of Apple’s Privacy Practices
CNET reports that Rep. Jay Inslee (D-WA) is calling on the FTC to investigate Apple’s privacy practices, particularly with respect to location-based services. In a letter to FTC Chairman John Leibowitz, Inslee expressed concern about users’ lack of awareness of “location-aware technology.” He writes: “Citizens expect to be able to know the extent to which…
New Privacy and Data Security Events Spur New EU Investigations
Smartphone Location Data
Last week two UK-based researchers revealed that Apple iPhones record location-based data in an unencrypted file stored on each phone. The information, gleaned from WiFi routers and cellular towers within the phone’s signal range, has been collected without the knowledge of the phones’ owners, and would allow Apple to track each phone’s…
California “Do Not Track” Bill Would Prohibit Selling, Sharing Data
Just when the conversation about privacy legislation had shifted to the bills recently introduced by Sen. John Kerry and Rep. Cliff Stearns, California State Senator Alan Lowenthal has recaptured the headlines by amending his “Do Not Track” bill (S.B. 761) to include a sweeping prohibition against selling, sharing or transferring consumer information. Lowenthal’s bill would require the…
DOT issues final rule on passenger rights
Yesterday the Department of Transportation issued its final rule on “Enhancing Airline Passenger Protections.” The proposed rule had been published in December 2009 and received over 2,000 comments. One of the most controversial aspects of the original proposed rule was a requirement that airlines must provide all their fare and product information to Global Distribution Systems…
California DNT Hearing Scheduled For May 3
As we have previously posted, California State Senator Alan Lowenthal has introduced do-not-track legislation with the support of Consumer Watchdog and other public advocacy groups. Most recently, the California Senate Judiciary Committee has scheduled a May 3, 2011 hearing on the bill. SB 761 directs the California attorney general to adopt regulations requiring companies that collect online…
For Now, RockYou Court Finds Standing Based on PII Disclosure
By Eric Bosset
Judge Phyllis Hamilton of the U.S. District Court for the Northern District of California recently permitted a lawsuit arising out of a major data security breach suffered by social-media application developer RockYou to survive a motion to dismiss in part, based on the theory that plaintiff had stated a “generalized injury” sufficient to maintain Article III standing—at least at the…
The Article 29 Working Party and Breach Notification in the EU
The Article 29 Working Party recently released an opinion on data breach notification in the EU. The opinion addresses two main issues:
- Experience to date with the existing breach notification rules in the ePrivacy Directive.
The breach notification obligation imposed by article 4.3-5 of the ePrivacy Directive (2002/58/EC) only applies to providers of electronic communications…
Obama Administration Unveils Identity Ecosystem Vision
On Friday, the Obama Administration unveiled the final draft of its ambitious National Strategy for Trusted Identities in Cyberspace (NSTIC), which seeks to develop new and more secure systems for identity authentication online, creating new “Identity Ecosystem.” Secretary of Commerce Gary Locke as well as other officials unveiled the NSTIC (pronounced “en-stick”), which is signed…