identity theft

Showing posts with label identity theft. Show all posts
Showing posts with label identity theft. Show all posts

Breach notification law debate continues in the US

Today's Los Angeles Times is running a lengthy article on the debate over federal legislative responses to security breach violations involving personal information. On on hand are organizations like EPIC and Consumers Union, which do not want the federal law to override stronger state laws and want to keep the threshold for notification low. On the other hand are banks and information brokers who want the federal law to preempt state laws and to only require notification if there is a "significant risk of fraud" using the compromised information. Othwise, it is argued, consumers will begin to ignore the flurry of notices they'll likely receive.

The article is also interesting because it sheds additional light on a study released this fall that suggested there is a low risk of fraud when information is compromised. I noted the study in this blog (The Canadian Privacy Law Blog: Study on data breach fallout), and noted that there was nothing in the original about its methodologies. The LA Times articles suggests it was flawed and may not actually measure anything particularly useful:

Data Brokers Press for U.S. Law - Los Angeles Times:

"It's an area of policy in which legislation is driven by hysteria," Cate said. "There's just very little theft of data going on that is actually being used to commit identity theft."

Another study was announced this month by San Diego-based ID Analytics Inc., which described its findings in House testimony, to senators on two relevant committees and to the media. That generated news stories with such headlines as "ID Theft Fears Overblown, Study Says" and "Good News on ID Theft."

The firm earns money by helping banks figure out whether credit card applications might be fraudulent, and banks are among the institutions most actively opposed to new notification requirements.

The company said it studied four major losses of personal information, which it didn't identify or explicitly claim were representative, and found that less than one person in 1,000 was victimized by fraud as a result.

But ID Analytics looked only for what it called signs of "organized misuse" — for example, if a criminal gave himself away by using the same contact telephone number for two people whose information had been obtained in the same breach. In an interview, ID Analytics Vice President Mike Cook said he didn't know what proportion of fraud would leave that sort of fingerprint.

He also acknowledged that to be detected by the study, a criminal needed to seek credit or make a purchase from a client of ID Analytics — largely unnamed banks and cellular phone companies.

"If someone steals identities and created checks, passed bad checks at a supermarket, we probably wouldn't catch that," Cook said.

Identity theft of hospital patients and the recently deceased

The Red Tape Chronicles from MSNBC.com recently ran an article on identity theft that is connected to hospital stays and what patients can do to protect themselves. The article itself is interesting, but there are dozens of comments that are equally iluminating:

Hospital ID theft: How to protect yourself - The Red Tape Chronicles - MSNBC.com

Stories of nurses, patients, and visitors stealing identities from the sick can be ripped from the headlines across America, like the story of a nurse in a Philadelphia hospital who gave terminally ill patients' identities to a crime ring. They drained the patients' accounts and obtained $10 million in fraudulent mortgages using the stolen personal information.

"They’re like vultures. You wonder how people can be so horrible," said Mari Frank, an ID theft victim lawyer and author of two books on the subject. "They think, 'Who cares, he's going to die anyway.' "

It's hard to imagine, particularly if you trust your doctor and your hospital. But do you trust the patient across the hallway? And all his visitors? The grim reality is, identity theft is a peril for hospital patients, another concern sick and dying people, and their families, must put on their checklists.

Fortunately, there are some things you can do to protect the privacy of people you love while they’re recovering in the hospital....


Thanks to Privacy Digest for the link.

Incident: Personal information of Iowa State University donors and employees hacked

Manitoba opposition politicians introduce security breach notification bill

The opposition Conservatives in Manitoba have introduced a bill in the provincial legislature to be substantially similar to PIPEDA and to be the first general application statute to provide for security breach notification. The CBC article on the bill (CBC Manitoba - Proposed law forces companies to report information leaks) quotes Brian Bowman, Manitoba's leading privacy lawyer, who himself has been a victim of identity theft.

The relevant sections of Bill 207 read:

The Personal Information Protection and Identity Theft Prevention Act:

"Notice if control of information lost

34(2) An organization must, as soon as reasonably practicable and in the prescribed manner, notify an individual if personal information about the individual that is in its custody or under its control is stolen, lost or accessed in an unauthorized manner.

Exception re law enforcement agency investigation

34(3) The requirement to notify an individual under subsection (2) does not apply where

(a) the organization is instructed to refrain from doing so by a law
enforcement agency that is investigating the theft, loss or unauthorized
accessing of the personal information; or

(b) the organization is satisfied that it is not reasonably possible for the
personal information to be used unlawfully.



Right of action

34(4) An individual may commence an action in a court of competent jurisdiction against an organization for damages arising from its failure to

(a) protect personal information that is in its custody or under its control;
or

(b) provide an individual notice under subsection (2), if it was not
reasonable for the organization to have been satisfied that the personal
information that was stolen, lost or accessed in an unauthorized manner would
not be used unlawfully.



Other rights not affected

34(5) The right of action under this section is in addition to any other right of action or remedy available at law. But where the court deems it just, damages awarded in an action under this section may be taken into account in assessing damages in any other proceeding arising out of the failure of the organization to protect personal information in its custody or under its control.

Retention of information

35 Notwithstanding that a consent has been withdrawn or varied under section 9, an organization may for legal or business purposes retain personal information as long as is reasonable."

Meth addicts' other habit: Online theft

USA Today is running a lengthy article on the intersection between methamphetamine addiction and identity theft. The article, Meth addicts' other habit: Online theft, chonicles investigations that began in Edomonton and Calgary, Alberta and forcefully brought this connection to the attention of Canadian law enforcement.

Intersection of crimes

... What's happening in Edmonton is happening to one degree or another in communities across the USA and Canada — anywhere meth addicts are engaging in identity theft and can get on the Internet, say police, federal law enforcement officials and Internet security experts.

Internet Relay Chat channels, private areas on the Internet where real-time text messaging takes place, are rife with communications between organized cybercrime groups and meth users and traffickers discussing how they can assist each other. "It's big time," says San Diego-based security consultant Lance James, who monitors IRC channels.

Such collaboration seems almost preordained. "This hits at the intersection of two of the more complex law enforcement investigations: computer crimes and drug crimes," says Howard Schmidt, CEO of R&H Security Consulting and former White House cyber-security adviser.

Identity theft has fast become the crime of preference among meth users for three reasons: It is non-violent, criminal penalties for first-time offenders are light — usually a few days or weeks in jail — and the use of computers and the Internet offers crooks anonymity and speed with which to work. Meth is a cheap, highly addictive street derivative of amphetamine pills; it turns users into automatons willing to take on risky, street-level crime.

Meanwhile, global cybercrime groups control e-mail phishing attacks, keystroke-stealing Trojan horse programs and insider database thefts that swell the pool of stolen personal and financial information. They also have ready access to hijacked online-banking accounts. But converting assets in compromised accounts into cash is never easy. That's where the meth users come in.

Sophisticated meth theft rings, like the one in Edmonton, control local bank accounts — and underlings who are willing to extract ill-gotten funds from such accounts. The two men at the seedy motel were helping outside crime groups link up with local accounts under their control when a tipster guided police to them in December 2004....


The article is worth the read.

Incident: Tape containing records of 2 million mortgagors lost

Another missing tape incident. No evidence of fraud, but notable nevertheless:

ABN AMRO data lost:

"Homeowners should monitor credit reports

December 17, 2005

If you have a home mortgage through LaSalle Bank or the former Standard Federal Bank, look out for a letter from your lender warning you about a missing computer tape -- a tape that includes your Social Security number and payment history.

Friday, ABN AMRO Mortgage Group, a subsidiary of LaSalle Bank Corp., announced that a computer tape containing data for about 2 million mortgage customers had been lost.

About 320,000 homeowners in Michigan would have been included on that tape.

The homeowners could have gotten an ABN AMRO mortgage through LaSalle Bank branches, the former Standard Federal Bank, outside mortgage brokers or ABN AMRO's own Mortgage.com.

Thomas M. Goldstein, chairman and chief executive officer of ABN AMRO Mortgage Group in Chicago, said the lender deeply regrets the mix-up but has seen no signs of identity theft or misuse of the information at this point....


Update: The Canadian Privacy Law Blog: Update: Tape containing information on 2M mortgage customers found.

Meth users and identity theft go together like rats and garbage

Evidence linking methamphetamine addiction and identity theft is getting more compelling all the time. The San Jose Mercury News is running an AP story on the connection between the two, particularly focusing on California.

AP Wire | 12/17/2005 | Meth users turning to identity theft to pay for their habit:

RIVERSIDE, Calif. - Stealing mail. Digging through trash. Days spent in front of a computer trying to unlock financial information.

All to score methamphetamine.Authorities are discovering that more and more desperate users of the drug are turning to identity theft to pay for their habit, creating a criminal nexus costing Americans millions of dollars.

The trend is sweeping the West and spreading to other parts of the country, with one hub of activity in the garages and trailer parks of Riverside and San Bernardino counties on the fringe of suburban Los Angeles.

The region was the site of a third of California's nearly 500 meth lab busts in 2004 and is home to the second-highest number of identity theft victims in the nation.

'It's been said the two crimes go together like rats and garbage,' said Jack Lucky, a Riverside County prosecutor who nearly became a victim of identity theft himself before his personal information was found at a meth lab.'It's a pervasive problem,' he said...



Drug addiction and crime have always been linked as addicts are in need of quick cash to fuel their habits. Muggings and burglaries have generally had a strong connection with drug abuse. As addicts move to ID theft and similar forms of fraud, the amount of money they are able to get is greater and the risk of violence is much lower. Some might even say that this is a good thing.

Korea Solves the Identity Theft Problem

Rob Hyndman is pointing to Schneier on Security: Korea Solves the Identity Theft Problem. Apparently, Korea is about to pass a law placing full responsibility for losses on the banks for identity theft and online financial fraud, even if the bank is only partially responsible. This will provide the incentive to put in place fraud-blocking measures.

The next questions are: (i) will it work? and (ii) will it only be a Korean phenomenon?

Greater risk of fraud if personal data is stolen in smaller batches

According to Finance Tech, a recent study suggests that individuals are at greater risk of indentity theft and other fraud if their personal information is compromised in smaller batches. Much of the focus of media attention has been on large breaches, but fraudsters would have to work overtime for years to exploit all that data. See: Small Data Breaches Pose Big Identity Theft Risks.

Poorly designed online interfaces make identity theft simple

Risks Digest is a good source of information on all sorts of risks -- including privacy risks. Recently, Marty Lyons posted the following about a particular experience he had renewing this AAA membership.

The Risks Digest Volume 24: Issue 11:

"I recently had to renew my membership with the American Automobile
Association (the equivalent to the CAA in Canada, or the RAC in the UK). In
the past there was no web interface, but AAA has now moved online. To sign
up for an account, I needed to supply a membership number (printed on your
plastic member card), and my name (also printed on the card), along with an
email address, and a chosen account name. A few seconds later, I was logged
in, and was able to check my account info, including mailing address, and
type of credit card used for membership.

There was no verification of identity at all during account establishment.
At a minimum, mandating that a user-entered postal code match the AAA
database prior to creating the account would have afforded some protection.

So with a AAA member number and name, someone is well on their way to
identity theft -- the rest of your wallet not required. Since many places
take AAA cards to provide discounted services (hotels, car repair,
restaurants, movie theatres, etc.) you can imagine the RISK. I've sent a
letter to the organization letting them know their web registration needs to
be redesigned."


I am not sure someone can steal your identity using your AAA membership, but interfaces like this attached to something more sensitive may lead to big problems.

Red cross employee implicated in ID theft of blood donors

Even if the organization is 100% benevolent and trustworthy, you still need to be concerned about the employees. Case in point: three (former -- hopefully!) employees the Red Cross have been indicted for stealing the identities of 40 blood donors, using information collected during corporate blood drives:

Three indicted in identity theft scheme victimizing blood donors:

"A Red Cross employee and two other people were accused Friday of stealing the identities of about 40 blood donors and using the information to obtain about $268,000 in cash and merchandise.... "

Cornell University outlines security and privacy incident response plans

In response to a new New York law that requires notification of security and privacy breaches, Cornell University has issued the following media release outlining their plans for compliance:

Cornell complies with new state law on notification about stolen data:

By Bill Steele

If someone hacks into a Cornell University computer and pulls out personal and private information about members of the Cornell community, the people whose data has been compromised will be notified promptly, according to Cornell Information Technologies and the University Counsel's office.

Although the exact procedures have not been worked out, notification would be by ordinary mail, according to Norma Schwab, associate university counsel. E-mail notification, she said, is not legally adequate and might be unreliable, especially in an age when users are bombarded with "phishing" messages with subject lines like "your account has been compromised."

The notification plan is being developed by an ad hoc group called the Data Incident Response Team, which includes members from the Office of Information Technologies, the Office of University Counsel, Cornell Police and the University Audit Office. The group meets periodically to consider data security policy and comes together whenever there is a concern that sensitive data may have been accessed.

The action is in response to a New York state law, the Information Security Breach and Notification Act, passed in August and going into effect Dec. 8. The law requires any business -- including nonprofits -- that maintains personal and private data to provide notification when its systems are invaded and there is a reasonable belief that personal information might have been revealed. The kinds of data involved include Social Security and driver's license numbers and credit card information, and the notification requirement is intended to help consumers fend off possible identity theft.

"It made sense that we should let people know that we are complying with the new law," said Steve Schuster, director of information security. Schuster said he plans to take advantage of the opportunity to make Cornell staff more aware of their responsibilities to protect sensitive data.

"We're still in a state where our data resides in a lot of different areas," he explained. "We all have to take responsibility for it." In other words, sensitive information is not all on one university mainframe, but may also be on ordinary desktop computers in various departments. Schuster plans to require that all new staff members receive a policy and practices briefing -- a short version of the Travelers of the Electronic Highway course required for new students -- before they are issued net IDs. He hopes eventually to set up some sort of annual review of security procedures for all staff. For nontechnical staff, security measures include using strong passwords, protecting those passwords from disclosure and physically securing the computer.

University policies on security are being updated. The venerable Responsible Use of Electronic Communications policy is being expanded as Responsible Use of Information Technology Resources, and it will incorporate policies on data management and security. Data will be broken into three categories: regulated information for which state and federal laws require security, such as Social Security numbers and grades; "Cornell confidential" information, such as salaries and performance reviews; and public data. Security should be tailored to the level of confidentiality of the data. "It will be necessary for departments to inventory where these data reside in their systems," Schuster said.

Despite having very talented people around, higher education institutions are not immune to security breaks, Schuster pointed out. "In the first six months of 2005 there were 72 media-worthy computer compromises in the United States," he reported, "and slightly over half of them were in higher ed. We deal with break-ins here all the time, but we have a really good process in place."

The New York law, patterned on one passed about two years ago in California, was inspired by several incidents in which large corporate databases were compromised. In the most widely publicized case, ChoicePoint, a credential-verifying firm, allowed criminals to obtain personal data on some 140,000 people. At least 15 states have passed similar laws, and legislation is pending at the federal level.


"Trust is fundamental. Distrust has a devastating impact on profitability."

At a recent conference in Toronto, reported on by IT Business, Ontario's outspoken Information and Privacy Commissioner, Anne Cavoukian, had some strong words about how companies respond to privacy incidents.


IT Business : EDGE:

With identity theft being the fastest growing form of fraud -- Equifax in Canada reported between 1,400 and 1,800 identity theft-related complaints per month -- companies can no longer say it’s just an external threat that can be remedied by a firewall, for example. The Privacy Commissioner of Ontario, Ann Cavoukian, who also spoke at Tuesday’s event, said businesses need to think of privacy as a business issue rather than an IT-related one. Cavoukian cited several U.S.-based studies that show customers said identity theft-related incidents affected their purchasing decisions.

“If I were a business I would make privacy work for me,” said Cavoukian. “Trust is fundamental. Distrust has a devastating impact on profitability.”

To illustrate her point, Cavoukian mentioned the CIBC faxing fiasco as an example of how not to handle a privacy breach. The U.S. case involved a West Virginia scrapyard owner who had been receiving faxes containing confidential data from CIBC for three years. In April, the Privacy Commissioner of Canada ruled the bank was in violation of PIPEDA principles. CIBC responded to the Commissioner’s findings by creating a national database to track privacy issues and establishing a national privacy office, among other initiatives.

“I’m outraged by CIBC’s response to the faxing fiasco,” said Cavoukian, adding the incident will make it into business studies as an example of how not to handle such a situation. “Everything is in your management of a crisis and your immediate reaction.”

Ontario government switches to damage control

After the recent incident that saw personal information of 27,000 Ontarians disclosed (see: Another privacy breach to round out the week, et seq), the government of Ontario has switched to damage control mode. Interestingly, the Chairman of Ontario's Management Board says there is no threat of identity theft or fraud from the incident:

Government insists no threat of identity theft after release of personal data:

"TORONTO -- There's no serious threat of identity theft after the government mistakenly sent out 27,000 provincial cheques with the wrong names and social insurance numbers attached, Management Board Chairman Gerry Phillips insisted Monday.

''We know exactly who got the name of the next person,'' Phillips told the legislature. ''I think that frankly eliminates any possibility of theft or fraud in this case.''...."

Shifting the risk and imposing statutory damages in identity theft cases

Kevin Drum, in Washington Monthly, has an interesting proposal for shifting the risk of identity theft from consumers (and the victims) to the credit granting establishment. Just as congress pushed the risk of credit card fraud onto the industry through the Truth in Lending Act, forcing the industry to be creative in fighting fraud, the same should be done with loss of customer information and fraudulently-obtained credit:

"You Own You " by Kevin Drum:

...The same method should be used for identity theft. There's no need to create mountains of regulations, which are uniformly despised by the credit industry. Instead, simply make the industry itself—and any institution that handles personal data—liable for the losses in both time and money currently borne by consumers. The responsible parties will do the rest themselves.

How would this work? Congress could assign specific minimum values—statutory damages—for each of the acts associated with identity theft. Extending credit without conducting adequate background checks, or issuing a faulty credit report thanks to undiscovered theft of identity, might be worth $10,000 per incident. Losing someone's personal information in the first place might be worth less—perhaps around $1,000—since only a small percentage of cases of information loss ultimately lead to a full-fledged theft of identity.

The establishment of statutory damages would allow consumers to bring personal or class-action lawsuits for any of these transgressions. (Currently, such suits are difficult to win because breaches of privacy are extremely hard to value—some courts even flirt with the notion that privacy has no value at all.) And consumers would not need to show that those responsible for the theft acted negligently. When your money is stolen from a bank, the bank is liable no matter how diligently it tried to protect it. That's why banks take care of your deposits. If the credit industry and other data-handlers knew that the legal system would hold them responsible for extending credit to impostors, issuing inaccurate credit reports, or losing data, you can bet they'd figure out better ways to stop those things from happening.

The beauty of this solution is that by giving the credit industry a financial stake in solving the problem, it uses market-based self-interest rather than top-down federal mandates. Instead of relying on a regulatory agency to levy fines—or not levy them, depending on the administration—it gives companies an incentive to change their behavior. Under this plan, credit agencies would no longer charge consumers for “credit protection” services. Rather, they would beg consumers to make use of them, free of charge and with maximum ease of access. Credit issuers and other businesses that offer credit would quickly stop opening up new accounts without adequate background checks. And companies that handle personal data would finally get serious about implementing effective safeguards....


Thanks to Overlawyered for the link.

Don't be liable for identity theft

[A slightly edited version of the article below was just published in the December 2005 edition of Business Voice.]

Don't be liable for identity theft


Identity theft, we are told, is one of the fastest growing crimes in North America, claiming thousands of new victims every year. This crime most often involves using the personal information of unsuspecting victims to obtain goods and services, including credit, in the names of those victims. How the fraudsters obtain personal information varies and, unfortunately, their ingenuity apparently knows no bounds. Identity theft is obviously a problem for its victims but it also presents significant legal risk to businesses.

Every business in Atlantic Canada that handles customer information is subject to the Personal Information Protection and Electronic Document Act (“PIPEDA”). Among its many requirements, PIPEDA requires every business to implement safeguards to protect personal information against inappropriate use and disclosure. The form of safeguards depends upon the sensitivity of the information. If the misuse of the information could lead to fraud or identity theft, the safeguards must be appropriately robust.

Unfortunately businesses are often the weak link in the data protection chain, jeopardizing their customers and their own business reputations. In the first half of this year, the media reported on a series of incidents that resulted in the disclosure or theft of personal information of almost two million Americans. We are not immune here in Canada: Some may recall the attention given to the accidental faxing of the personal information of thousands of bank customers to a junkyard in the United States. More shocking was the discovery made by police in Alberta this past winter: piles of extremely sensitive information, including credit reports, on senior provincial public servants were found in a methamphetamine lab. Further investigations showed that drug addicts are being hired by identity thieves to steal personal information by a number of means, including “dumpster diving” in the trash receptacles and recycling bins of businesses. It would be foolish to assume that this does not occur in Atlantic Canada.

Businesses that do not adequately lock up personal information can find themselves legally and financially liable to the victims of identity theft and other forms of fraud. In April of this year, a number of identity theft victims in Michigan successfully sued a trade union because information of its members to be misused. The high profile misdirected faxes incidents spawned a class-action lawsuit in Ontario, alleging that the bank involved should have to pay compensation for the increased risk of identity theft, plus the actual cost of more vigilant credit monitoring. These lawsuits relate to inappropriate safeguards, but it will not be long before individuals whose identities are stolen will seek recourse against credit grantors and others who offered facilities to the impostors, arguing they did not do enough to verify the identity of the person seeking credit. These plaintiffs will be seeking damages related to the costs of repairing their credit and, perhaps, opportunities they have lost due to an unfavourable credit rating. PIPEDA, to which all Atlantic Canadian businesses are subject, allows individuals to seek damages in the Federal Court for any harm they might have suffered, including any embarrassment that might have been caused by a leak of personal information.

So what does all this mean to businesses? Anybody in possession of personal information that would be useful to commit identity theft or the disclosure of which might be embarrassing to the individual has an obligation to protect that information against all risks. This obligation is already set out in PIPEDA and the common law will likely also impose a duty of care where the risk of identity theft is foreseeable. (In the current climate, it would be difficult to argue that identity theft is not foreseeable.)

Business owners also need to be very careful to supervise employees. Significant portions of fraud committed can be traced to dishonest employees who misuse the information they have access to or even participate in activities such as “card skimming”, where information is taken from credit cards and debit cards. All employers need to be aware that the courts will generally hold them legally and financially responsible for the misdeeds of their employees.

Credit grantors in particular have to be even more vigilant in establishing the identities of those to whom they extend credit. This will not only protect against credit losses, but will reduce the likelihood that your company will be the subject of privacy complaints and litigation. In this effort, privacy laws unfortunately pull businesses in two different directions. On one hand, credit grantors should clearly establish the identity of an applicant. On the other hand, the law says that they can only collect information that is reasonably necessary in the circumstances. To satisfy both, businesses need to establish reasonable policies and practices on how identity will be confirmed and how that information will be subsequently used. Doing so simply makes business sense in this legal climate.

While legal liability may appear remote to many businesses, a single incident can destroy your business reputation that you have worked years to develop. Surveys have shown that customers are increasingly concerned about their personal information and are making buying decisions based upon what businesses they trust. If word gets out that your business is not doing what is necessary to protect customer information, it can be shunned by consumers with dramatic effect on your bottom line.

Tips for Protecting Information


  • Only collect the minimum amount of information that is necessary for carrying on your business. The more information you have, the greater the likelihood of loss and the consequences such as fraud.

  • Information that is no longer required must be securely disposed of. This involves shredding all paper that contains personal information and making sure that all hard-drives of surplus computers are completely wiped clean of data.

  • Carefully screen all employees who will have access to personal information.

  • Carefully restrict employee access to personal information, on a need-to-know basis.

  • Carefully vet all service providers, such as cleaning companies and data processors, and require them to sign non-disclosure agreements and indemnities in case they misuse personal information or allow its disclosure.

Identity theft and fraud in the healthcare context

Jeff, at HIPAA Blog points to an article on ID theft and fraud in the healthcare context put out by the American Health Information Managment Association. He introduces it thusly:

HIPAA Blog

More on identity theft: Here's an article from AHIMA that supports my constant cry that the big risk of improper use/disclosure of PHI isn't about the 'H' but about the 'P'. Unless you're a professional athlete, nobody cares about your knee surgery. But they do care about your name, address and social security number. There's money in that information.


From the into to the article:

Identity Theft and Fraud-The Impact on HIM Operations (Journal of AHIMA):

Identity theft and fraud are the fastest growing crimes today. Healthcare organizations are particularly vulnerable to identity theft due to the wealth of patient personal, demographic, and financial information that is collected, transmitted, and maintained in the course of operations. Healthcare employees with legitimate access to protected health information (PHI) may gather information for later misuse. Credit cards and identification may be stolen while patients are being treated in healthcare facilities. Individuals posing as investigators may contact patients or providers asking for information that allows them to impersonate the patient or provider.

NJ to Enjoy Strong Identity Theft Protections

Chris Hoofnagle at EPIC West reports on new anti-ID theft legislation in New Jersey that is said to be among the strongest in the US: EPIC West: Electronic Privacy Information Center West Coast Office: NJ to Enjoy Strong Identity Theft Protections.

His post also links to a convenient table of US credit freeze and security notification legislation maintained by US PIRG: State Breach and Freeze Laws.

Hawai'i puts anti-ID theft law on the books

According to Identity Theft Spy, Hawai'i has joined the growing list of states with laws designed to prevent identity theft and to require notification of consumers for certain security breaches: Identity Theft Spy: Hawaii implements anti-identity theft laws.

Canadian polling on ID theft

The Canadian Press is reporting on a handful of statistics related to identity theft in Canada, compiled by Phone Busters:

IDiots? Bank warns against identity theft miscues:

TORONTO (CP) - More than 9,000 people in Canada have had their identities stolen this year, and a new poll indicates 77 per cent of Canadians worry about identity theft but only 10 per cent feel they know what to do about it.

Identity theft occurs when criminals steal and use personal information, such as a social insurance number and date of birth, to assume a person's identity and make purchases or open credit card accounts and other debt lines in the assumed name.

According to PhoneBusters, the central agency that collects information on identity theft in Canada, there were 9,034 victims of identity theft reported in the first 10 months of this year, with losses totalling $7.2 million.

The early-November poll for the Canadian subsidiary of U.S.-based Capital One Financial Corp. found 45 per cent of the 2,002 adults surveyed do not monitor their credit reports on a regular basis for errors or suspicious items.

The Ipsos Reid survey, which claims a margin of error of 2.2 percentage points, 'reveals that consumers should be more cognizant of some simple practices that could help protect against identity theft,' says Capital One Bank....