The Office of the National Coordinator for Health Information Technology (ONC) is proposing to conduct a nationwide survey regarding consumer attitudes toward the privacy and security aspects of electronic health records (EHR) and electronic health information exchange, according to a notice in last Thursday’s Federal Register.
ONC’s plan is to use computer-assisted telephone interviews
November 2011
NIST Releases Draft Roadmap for the U.S. Government’s Implementation of Cloud Technology
Last week, the U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) released for public comment a draft roadmap for implementing cloud computing technology across U.S. government agencies. The roadmap is intended to foster adoption of cloud computing by federal agencies, reduce uncertainty surrounding cloud computing by improving the information available to policymakers, and…
Privacy and Security Requirements for Handling Government Records Under Scrutiny
Government agencies maintain large quantities of information about individuals, covering everything from physical description to the person’s family life, property, political activity, employment history, criminal records, and health condition. In a light of a recent finding that reports of information-security incidents at federal agencies have increased more than 650 percent over the past five years,…
Congress Continues to Ponder Data Security Legislation
Sen. John Rockefeller (D-WV), chair of the Senate Commerce Committee, is still working to reach consensus on the data security bill that he and Sen. Mark Pryor (D-AR) introduced in June. A scheduled markup was canceled in September, and the committee decided not to consider the bill at yesterday’s executive session. Nonetheless, a spokesman for…
PCI Council Opens Feedback Period for PCI-DSS and PA-DSS Versions 2.0
On Tuesday, the Payment Card Industry Security Standards Council announced that it was opening the formal feedback period for versions 2.0 of the Payment Card Industry Data Security Standard (“PCI-DSS”) and Payment Application Data Security Standard (“PA-DSS”), which were issued in October 2010 and will become effective exclusively when versions 1.2.1 are officially retired on…
CFPB Supervision and Examination Manual Provides Procedures for Examining Compliance with Financial Privacy Laws
In mid-October 2011, the Consumer Financial Protection Bureau (CFPB) released version 1.0 of its Supervision and Examination Manual. Pursuant to Dodd-Frank, the CFPB has primary examination authority for compliance with federal consumer financial laws over banks having $10 billion or more in assets and their affiliates, such as banks’ service providers, as well as…
Senator Rockefeller Requests Information Regarding Visa and Mastercard Data Collection Practices and Proposals
On October 27, 2011, Senator John D. Rockefeller, chairman of the Senate Commerce, Science, and Transportation Committee, sent letters to Visa and Mastercard requesting information regarding the companies’ data collection and aggregation practices and proposals. An October 25, 2011, Wall Street Journal article outlined various initiatives from the two companies pertaining to online behavioral advertising.
Senator…
California AG Files Suit Regarding Plastic “Biodegradable” and “Recyclable” Claims
Last week, the California Attorney General brought its first suit under California’s environmental marketing law, which restricts the labeling of plastic food or beverage containers as “biodegradable.” The Attorney General claims that a plastics company’s statements that its microbial additive results in the “first truly biodegradable and recyclable” plastic bottle and that the bottle will break down…
The Swedish DPA Issues Guidelines on the Provision and Use of Cloud Services
Recently, the Swedish Data Protection Authority (“DPA”) published a review of the use of cloud services, informed by the practices of three Swedish municipalities’ use of services from leading cloud providers. Based on the study, the DPA has published guidelines (currently only available in Swedish) that clarify the requirements of Swedish data protection law with…