Is HIPAA meaningful? For a long time, the answer to that question was arguably no. The date for compliance with the privacy rules was April 14, 2003, and the date for compliance with the security rule was two years later (the HIPAA Wikipedia entry has a good summary of this history). Nevertheless, it wasn't until 2007 that the first HIPAA audit took place (see here), and the lack of enforcement led many to believe that HIPAA was basically toothless (see, e.g., here).
Now though, that may be changing. One of the notable features of the HITECH act was that it gave state attorneys general the right to file suit on behalf of state residents who have been harmed by a HIPAA violation (the text of the act can be found here). Since then, the attorney general of Connecticut has taken advantage of that new authority, and filed suit against Health Net Connecticut, Inc. for HIPAA violations (among other things). The press release is here, and the complaint can be found here. Does this herald a new era of aggressive HIPAA enforcement? I tend to think not. The HITECH act limits the amount of damages recoverable by attorneys general to $25,000 per calendar year for violations of any individual requirement or prohibition, so HIPAA enforcement isn't going to be a panacea for states which already have limited enforcement budgets. On the other hand, there has already been one suit, and if an attorney general is already thinking about bringing an action (e.g., under some applicable state law), the extra HIPAA recovery could make the difference in whether a suit is brought. Either way though, with the Connecticut attorney general's action, the era of absent HIPAA enforcement is officially closed.
Showing posts with label state enforcement. Show all posts
Showing posts with label state enforcement. Show all posts
Sunday, March 7, 2010
Monday, December 31, 2007
2008 Privacy Roundup
Privacy International has released its 2007 International Privacy Rankings. Sadly, the United States ranks last in terms of statutory protections and privacy enforcement of all the countries in the democratic world. Among the points noted about U.S. privacy protection were that state data breach notification laws had proven useful in identifying security faults, but that Congress had approved presidential spying program, and is considering retroactive immunity for telecoms (something I wrote about here, and will almost certainly write more on in the future). One thing I'd like to point out in this is that the problems the report identified (e.g., presidential spying) are coming from the Federal Government, while the bright spots in privacy protection (e.g., data breach notification laws) are implemented at the state level. To my mind, this provides further evidence that we should be cautious in pushing for a federal data breach notification laws, given that they could preempt the state laws which are already in place and have proven to be effective.
(via BoingBoing)
(via BoingBoing)
Tuesday, December 18, 2007
New North Carolina Privacy Protection Law
North Carolina has a new law protecting individual privacy. The law adds to North Carolina's existing identity theft protection act by making it a violation of the act for any person to
So what's behind these consumer friendly features of the North Carolina law? I think there are two forces at work. The first is an individual named Glenn Hagele (web site here), who lobbied for this specific law to help address a specific fact pattern - where an individual's personal information was made available on the Internet as a reprisal for that individual's public statements. Without Glenn's work on the law, there is simply no reason to think it would exist. The second force I see is more systemic. Identity theft is still a significant concern for consumers (e.g., this article from the AARP describing identity theft concerns of older Americans) and with a seemingly endless stream of high profile incidents taking place, legislators are probably feeling pressure to do something about it. While data breach notification acts revealed that there is a problem with personal information being revealed, the repeated failures of consumers in court have shown that current law doesn't really give individuals the tools they need to protect themselves. Laws like that in North Carolina, which explicitly give consumers a right to sue for statutory damages, could be a step that more legislatures will take in the future to remedy that situation.
knowingly broadcast or publish to the public on radio, television, cable television, in a writing of any kind, or on the Internet, the personal information of another with actual knowledge that the person whose personal information is disclosed has previously objected to any such disclosure.Looking at its text, the North Carolina law seems to have been written to actually be enforced by aggrieved individuals. Indeed, the North Carolina law explicitly states that it can be enforced by individuals, rather than limiting the right to bring suit under the law to the state attorney general. Also, the North Carolina law includes a statutory damages provision, which addresses difficulties that individuals have had showing actual damage in previous data exposure cases. See, e.g., here and here.
So what's behind these consumer friendly features of the North Carolina law? I think there are two forces at work. The first is an individual named Glenn Hagele (web site here), who lobbied for this specific law to help address a specific fact pattern - where an individual's personal information was made available on the Internet as a reprisal for that individual's public statements. Without Glenn's work on the law, there is simply no reason to think it would exist. The second force I see is more systemic. Identity theft is still a significant concern for consumers (e.g., this article from the AARP describing identity theft concerns of older Americans) and with a seemingly endless stream of high profile incidents taking place, legislators are probably feeling pressure to do something about it. While data breach notification acts revealed that there is a problem with personal information being revealed, the repeated failures of consumers in court have shown that current law doesn't really give individuals the tools they need to protect themselves. Laws like that in North Carolina, which explicitly give consumers a right to sue for statutory damages, could be a step that more legislatures will take in the future to remedy that situation.
Labels:
North Carolina,
state enforcement,
state legislation
Monday, December 10, 2007
Children's Online Privacy Protection Act Enforcement in Texas
As described in this article from Computer World, the Texas attorney general has sued two web sites for violations of the Children's Online Privacy Protection Act (COPPA). According to the article, the two sites collected personal information from children under the age of 13 without obtaining sufficient verification of parental consent, and without giving the children the opportunity to review or pull back the data.
There are two things I find particularly interesting about the article. First, this article is another demonstration (to me) that law enforcement in Texas is taking its responsibilities regarding individual privacy relatively seriously. As described previously here, this year the Texas attorney general has repeatedly brought suit based on violations of privacy law, for example, for improper disposal of customer records. Thus, the actions by the Texas attorney general show what can be done if state law enforcement is willing to take an active role. The second thing I found interesting about the article was it stated that this enforcement by the Texas attorney general was the first to be brought under COPPA. COPPA was passed in 1998. To me, that shows just how far we have to go in terms of actually enforcing even the (relatively minimial) privacy protections that the law does provide.
There are two things I find particularly interesting about the article. First, this article is another demonstration (to me) that law enforcement in Texas is taking its responsibilities regarding individual privacy relatively seriously. As described previously here, this year the Texas attorney general has repeatedly brought suit based on violations of privacy law, for example, for improper disposal of customer records. Thus, the actions by the Texas attorney general show what can be done if state law enforcement is willing to take an active role. The second thing I found interesting about the article was it stated that this enforcement by the Texas attorney general was the first to be brought under COPPA. COPPA was passed in 1998. To me, that shows just how far we have to go in terms of actually enforcing even the (relatively minimial) privacy protections that the law does provide.
Subscribe to:
Posts (Atom)