Printer Friendly
The Free Library
14,800,168 articles and books
Member login
User name  
Password 
 
Join us Forgot password?

Federal And State Privacy Laws - Compliance Deadlines Fast Approaching.


The number and complexity of federal and state privacy laws continue to increase. These laws affect a broad range of public and private companies, including U.S. companies as well as foreign companies that conduct business in the United States. Any company that possesses personal information relating to U.S. employees, customers, shareholders or others likely is subject to privacy laws. For purposes of the privacy laws, personal information typically includes names together with information like social security numbers, financial account information or driver's license numbers. Protected health information is covered by the federal Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health (HITECH) Act. A number of new privacy law compliance deadlines are fast approaching. Failure to comply with privacy laws could trigger U.S. regulator and State Attorney General action as well as monetary penalties. In some cases, there also could be private lawsuits. Below is a brief summary of upcoming privacy law compliance deadlines.

November 1, 2009 - Federal Trade Commission Written Identity Theft Prevention Program A company that regularly extends, renews or continues credit, including accepting deferred payments for goods and services, may need to comply with the Federal Trade Commission's "Red Flags" Rule. Examples of these companies include utility companies, telecommunications companies, finance companies, mortgage brokers, real estate agents, health care providers, lawyers, accountants, other professionals, automobile dealers, retailers that offer financing or collect or process credit applications for third party lenders and third party debt collectors that regularly renegotiate the terms of a debt. This Rule requires that a written identity theft prevention program be in place.

January 1, 2010 - Nevada Requirements for Encryption A company (except for a telecommunications provider) doing business in Nevada that deals with personal information must comply with specific encryption requirements if it does not accept a payment card (a credit card or similar card) in connection with a sale of goods or services. This law also requires that a company that does accept payment cards in connection with a sale of goods or services comply with the current version of the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is an industry security standard developed by the PCI Security Standards Council (including American Express, Discover, JCB, MasterCard and Visa) for the protection of customer account data.

February 17, 2010 - Federal HITECH Act Requirements Under the federal HITECH Act, health plans, health care providers and health care clearinghouses (i.e., covered entities), among other things, must review and update their business associate agreements, as well as their privacy and security policies and procedures, regarding (i) marketing, (ii) sale of protected health information, (iii) minimum necessary standards, (iv) accounting of disclosures and (v) restrictions on disclosure of services paid out-of-pocket. Business associates (those who perform functions on behalf of, or provide services to, covered entities that involve the use of protected health information) will be directly regulated under the HIPAA privacy and security rules, and must comply for the first time with those rules, including, among other things, a requirement to perform security risk assessments and develop security policies and procedures to address HIPAA security standards.

March 1, 2010 (Subject to a Revised Version of This Regulation) - Massachusetts Comprehensive Written Information Security Program A company that owns or licenses personal information regarding Massachusetts residents must have a comprehensive written information security program with encryption requirements in place. In addition, third-party service providers - by contract - must implement and maintain appropriate security measures for personal information. A company that complies with HIPAA requirements or the Gramm-Leach-Bliley Act also must comply with this regulation. On September 22, 2009, a public hearing on this regulation was held. The Massachusetts Office of Consumer Affairs and Business Regulation expects to issue a revised version of this regulation in the coming weeks. We Can Help The upcoming compliance deadlines just hint at the many applicable privacy laws that present traps for the unwary. Implementing policies and procedures is not only advisable, but often times required under applicable privacy laws. From data breach notification procedures to record retention policies to social media policies, we can help you navigate the ever-changing landscape of privacy laws.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Ms Melissa Krasnow

Dorsey & Whitney LLP

50 South Sixth Street

Suite 1500

Minneapolis

MN 55402 1498

UNITED STATES

Tel: 6123402600

Fax: 6123402868

E-mail: marketing@dorsey.com

URL: www.dorsey.com

Click Here for related articles

(c) Mondaq Ltd, 2009 - Tel. +44 (0)20 8544 8300 - http://www.mondaq.com

COPYRIGHT 2009 Mondaq Ltd.
No portion of this article can be reproduced without the express written permission from the copyright holder.
Copyright 2009 Gale, Cengage Learning. All rights reserved.

 Reader Opinion

Title:

Comment:



 

Article Details
Printer friendly Cite/link Email Feedback
Publication:Mondaq Business Briefing
Geographic Code:1USA
Date:Oct 23, 2009
Words:768
Previous Article:Dillon Eustace Opens Office In New York.(Brief article)
Next Article:Fifth Circuit Decision Threatens A Tsunami Of Climate Change Tort Cases While The Defense Bar Awaits A Circuit Split.(Murphy Oil USA Inc. into...
Topics:



Related Articles
Summary of Selected Internet & E-Commerce Issues for Franchisors and Franchisees.(business)
Personal Information: Key Federal Privacy Laws Do Not Require Information Resellers to Safeguard All Sensitive Data.
Massachusetts delays effective date of new data security regulation.
Privacy And Security Alert: Breaking News--Massachusetts Extends Deadline To Comply With Data Security Standards To May 1, 2009.
Put the 'i' in IT compliance: a holistic, program-based approach can address security and privacy requirements.(Network Security)
Federalization in information privacy law.
Audio conference tackles HIPAA concerns.(Conference news)
How to prepare for HIPAA: Some dos and don'ts.
Congress still racing to meet looming privacy law deadline.
Congress is likely to enact federal legislation that will pre-empt state confide.

Terms of use | Copyright © 2010 Farlex, Inc. | Feedback | For webmasters | Submit articles