Mastering Data Privacy, Social Media, & Cyber Law
|
|
|
- Horace Hicks
- 10 years ago
- Views:
Transcription
1 Mastering Data Privacy, Social Media, & Cyber Law October 22, 2014 Data Breach Notification and Cybersecurity Developments in 2014 Melissa J. Krasnow, Dorsey & Whitney LLP, and Certified Information Privacy Professional/US This presentation was created by Dorsey & Whitney LLP, 50 South Sixth Street, Suite 1500, Minneapolis, MN This presentation is intended for general information purposes only and should not be construed as legal advice or legal opinions on any specific facts or circumstances. An attorney-client relationship is not created or continued by sending and/or receiving this presentation. Members of Dorsey & Whitney will be pleased to provide further information regarding the matters discussed in this presentation. 1
2 State breach notification laws 47 states, plus the District of Columbia, Guam, Puerto Rico and Virgin Islands, have breach notification laws (Alabama, New Mexico, and South Dakota do not have these laws) These laws require notification of a breach to affected individuals These laws cover breaches involving personal information in electronic format 2
3 2014 state breach notification law developments 18 state laws, plus Puerto Rico law, also require notification of a breach to a state attorney general or regulator in addition to the affected individuals 7 state laws cover breaches involving personal information in both electronic and paper formats California and Florida laws define personal information as covering online account information New Kentucky breach notification law 3
4 California breach notification law amendment effective January 1, 2015 Where a person or business was the source of a breach, the person or business providing breach notification must offer to provide appropriate identity theft prevention and mitigation services, if any, at no cost to an affected individual for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed his or her first name or first initial and last name, together with any of the following data elements, where the name or the data elements are not encrypted: SSN Driver's license number or California identification card number 4
5 Breach notification in federal and foreign laws and provisions in contracts and policies Federal HIPAA / HITECH Act breach notification for covered entities and business associates regarding protected health information Laws in other countries (e.g., Canada) Provisions in contracts and policies 5
6 Cybersecurity laws and guidance and provisions in contracts and policies State security procedures laws: Massachusetts and certain other states (e.g., California) Issued in February 2014: Federal: National Institute of Standards and Technology critical infrastructure cybersecurity framework California cybersecurity guidance Provisions in contracts and policies 6
7 Cyber liability insurance Main coverages in a traditional cyber liability insurance policy include: Security and privacy liability insurance that responds to third party liability Event management insurance that responds by paying costs for breach notification, public relations and other services to assist in managing a covered privacy or network security incident Cyber extortion insurance that pays to settle network securityrelated extortion demands made against the insured Network business interruption insurance that responds to an insured s loss of income and operating expenses when business operations are interrupted or suspended due to a failure of network security 7
8 Enforcement, litigation and other consequences Federal Trade Commission Department of Health and Human Services State attorneys general (e.g., California and Massachusetts) Foreign regulators Litigation Other consequences 8
9 Some steps companies are taking to prepare Preparing, revising and testing incident response plans Tabletop Exercise (TTX) A TTX is intended to generate discussion of various issues regarding a hypothetical, simulated emergency. TTXs can be used to enhance general awareness, validate plans and procedures, rehearse concepts, and/or assess the types of systems needed to guide the prevention of, protection from, mitigation of, response to, and recovery from a defined incident. Generally, TTXs are aimed at facilitating conceptual understanding, identifying strengths and areas for improvement, and/or achieving changes in perceptions. Source: Homeland Security Exercise and Evaluation Program (HSEEP) (April 2013) 9
10 Some steps companies are taking to prepare (continued) Preparing and revising company policies and programs, including training Procuring security and data breach services Considering or reviewing cyber liability insurance 10
11 Resources Data breach California Privacy Laws Change: Identity Theft Prevention and Mitigation Services Changes in State Breach Notification Laws California s Breach Notification Law Expands to Include Online Account Information Verizon 2014 Data Breach Investigations Report Cybersecurity Cybersecurity White Paper 11
12 Resources (continued) Cybersecurity (continued) Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation ms%20compliance%20with%20the%20massachusetts%20% %29.pdf Guidance for Managing Cybersecurity Risks National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity Cybersecurity in the Golden State Boards of Directors, Corporate Governance and Cyber-Risks: Sharpening the Focus National Association of Corporate Directors 2014 Cyber-Risk Oversight Handbook 12
13 Questions & Answers Melissa J. Krasnow
Mastering Data Privacy, Protection, & Forensics Law
Mastering Data Privacy, Protection, & Forensics Law April 15, 2015 Data Breach Notification and Cybersecurity Developments in 2015 Melissa J. Krasnow, Dorsey & Whitney LLP, and Certified Information Privacy
The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide
The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide Practising Law Institute January 9, 2012 Melissa J. Krasnow, Partner, Dorsey & Whitney LLP, and Certified Information Privacy Professional
Updates within Network Security and Privacy Risk Management
Updates within Network Security and Privacy Risk Management RIMS Minneapolis Meeting Melissa Krasnow, Partner, Dorsey & Whitney LLP (Minneapolis, MN) Mario Paez, Midwest Practice Leader for Tech., Privacy,
Auditing your institution's cybersecurity incident/breach response plan. Baker Tilly Virchow Krause, LLP
Auditing your institution's cybersecurity incident/breach response plan Objectives > Provide an overview of incident/breach response plans and their intended benefits > Describe regulatory/legal requirements
Disaster Design: How to Develop and Conduct an Effective Tabletop Exercise
Community College Risk Management Consortium July 23 24, 2015 Disaster Design: How to Develop and Conduct an Effective Tabletop Exercise JEFF COPELAND JULY 2015 Disaster by Design How to develop and conduct
Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation
View the online version at http://us.practicallaw.com/7-523-1520 Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation MELISSA J. KRASNOW, DORSEY & WHITNEY LLP
Data Security 101. Christopher M. Brubaker. A Lawyer s Guide to Ethical Issues in the Digital Age. [email protected]
Data Security 101 A Lawyer s Guide to Ethical Issues in the Digital Age Christopher M. Brubaker [email protected] November 4-5, 2015 Pennsylvania Bar Institute 21 st Annual Business Lawyers Institute
Chex Systems, Inc. does not currently charge a fee to place, lift or remove a freeze; however, we reserve the right to apply the following fees:
Chex Systems, Inc. does not currently charge a fee to place, lift or remove a freeze; however, we reserve the right to apply the following fees: Security Freeze Table AA, AP and AE Military addresses*
Health Care Data Breach Discovery Strategies for Immediate Response
Health Care Data Breach Discovery Strategies for Immediate Response March 27, 2014 Pillsbury Winthrop Shaw Pittman LLP Faculty Gerry Hinkley Partner Pillsbury Winthrop Shaw Pittman LLP Sarah Flanagan Partner
Data Privacy & Security: Essential Questions Every Business Must Ask
Data Privacy & Security: Essential Questions Every Business Must Ask Presented by: Riddell Williams P.S. Riddell Williams P.S. May 6, 2015 #4841-4703-9779 Innocent? 2 Overview 3 basic questions every business
Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation
View the online version at http://us.practicallaw.com/7-523-1520 Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation Melissa J. Krasnow, Dorsey & Whitney LLP
Introduction to Data Security Breach Preparedness with Model Data Security Breach Preparedness Guide
Introduction to Data Security Breach Preparedness with Model Data Security Breach Preparedness Guide by Christopher Wolf Directors, Privacy and Information Management Practice Hogan Lovells US LLP [email protected]
Homeland Insurance Company of New York Homeland Insurance Company of Delaware (Stock companies owned by the OneBeacon Insurance Group)
Homeland Insurance Company of New York Homeland Insurance Company of Delaware (Stock companies owned by the OneBeacon Insurance Group) NETWORK SECURITY AND PRIVACY LIABILITY RENEWAL APPLICATION PORTIONS
Data Breach and Cybersecurity: What Happens If You or Your Vendor Is Hacked
Data Breach and Cybersecurity: What Happens If You or Your Vendor Is Hacked Linda Vincent, R.N., P.I., CITRMS Vincent & Associates Founder The Identity Advocate San Pedro, California The opinions expressed
Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation
Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation Melissa J. Krasnow, Dorsey & Whitney LLP A Note discussing written information security programs (WISPs)
2014 INCOME EARNED BY STATE INFORMATION
BY STATE INFORMATION This information is being provided to assist in your 2014 tax preparations. The information is also mailed to applicable Columbia fund non-corporate shareholders with their year-end
SECTION 109 HOST STATE LOAN-TO-DEPOSIT RATIOS. The Board of Governors of the Federal Reserve System (Board), the Federal Deposit
SECTION 109 HOST STATE LOAN-TO-DEPOSIT RATIOS The Board of Governors of the Federal Reserve System (Board), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency
SECTION 109 HOST STATE LOAN-TO-DEPOSIT RATIOS. or branches outside of its home state primarily for the purpose of deposit production.
SECTION 109 HOST STATE LOAN-TO-DEPOSIT RATIOS The Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency (the agencies)
United States Department of Justice Executive Office for United States Trustees. Public Report:
United States Department of Justice Executive Office for United States Trustees Public Report: Debtor Audits by the United States Trustee Program Fiscal Year 2014 (As required by Section 603(a)(2)(D) of
The Obama Administration and Community Health Centers
The Obama Administration and Community Health Centers Community health centers are a critical source of health care for millions of Americans particularly those in underserved communities. Thanks primarily
Data Breach Response Basic Principles Under U.S. State and Federal Law. ABA Litigation Section Core Knowledge January 2015 1
Data Breach Response Basic Principles Under U.S. State and Federal Law ABA Litigation Section Core Knowledge January 2015 1 I. Introduction Data breaches have become an unfortunate reality for many of
12/4/2013. Regulatory Updates. Eric M. Wright, CPA, CITP. Schneider Downs & Co., Inc. December 5, 2013
Regulatory Updates Eric M. Wright, CPA, CITP Schneider Downs & Co., Inc. December 5, 2013 Eric M. Wright, CPA, CITP Eric has been involved with Information Technology with Schneider Downs since 1983. He
Exhibit 57A. Approved Attorney Fees and Title Expenses
Exhibit 57A Approved Attorney Fees and Title Expenses Written pre-approval from Freddie Mac is required before incurring any expense in excess of any of the below amounts. See Sections 71.19 and 71.24
THE HARTFORD ASSET MANAGEMENT CHOICE sm POLICY NETWORK
THE HARTFORD ASSET MANAGEMENT CHOICE sm POLICY NETWORK SECURITY AND THEFT OF DATA COVERAGE APPLICATION Name of Insurance Company to which application is made NOTICE: THIS POLICY PROVIDES CLAIMS MADE COVERAGE.
Intercountry Adoptions Finalized Abroad
State Statutes Series Current Through July 2005 Adoptions Finalized Abroad adoptions may be finalized abroad or domestically. Most State statutes give full effect and recognition to intercountry adoptions
(In effect as of January 1, 2004*) TABLE 5a. MEDICAL BENEFITS PROVIDED BY WORKERS' COMPENSATION STATUTES FECA LHWCA
(In effect as of January 1, 2004*) TABLE 5a. MEDICAL BENEFITS PROVIDED BY WORKERS' COMPENSATION STATUTES Full Medical Benefits** Alabama Indiana Nebraska South Carolina Alaska Iowa Nevada South Dakota
Network Security & Privacy Landscape
Network Security & Privacy Landscape Presented By: Greg Garijanian Senior Underwriter Professional Liability 1 Agenda Network Security Overview -Latest Threats - Exposure Trends - Regulations Case Studies
Real Progress in Food Code Adoption
Real Progress in Food Code Adoption The Association of Food and Drug Officials (AFDO), under contract to the Food and Drug Administration, is gathering data on the progress of FDA Food Code adoptions by
NOTICE OF PROTECTION PROVIDED BY [STATE] LIFE AND HEALTH INSURANCE GUARANTY ASSOCIATION
NOTICE OF PROTECTION PROVIDED BY This notice provides a brief summary of the [STATE] Life and Health Insurance Guaranty Association (the Association) and the protection it provides for policyholders. This
Managing Cyber Threats Risk Management & Insurance Solutions. Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal
Managing Cyber Threats Risk Management & Insurance Solutions Presented by: Douglas R. Jones, CPCU, ARM Senior Vice President & Principal Overview Recent Trends and Loss Exposures Risk Management Strategies
Data Breach Reporting: Summary of Governing Bodies with Reporting Requirements in the United States
Data Breach Reporting: Summary of Governing Bodies with Reporting Requirements in the United States Introduction When it comes to Personally Identifiable Information (PII), privacy laws and regulations
Cyber Insurance Presentation
Cyber Insurance Presentation Presentation Outline Introduction General overview of Insurance About us Cyber loss statistics Cyber Insurance product coverage Loss examples Q & A About Us A- Rated reinsurance
Best practices and insight to protect your firm today against tomorrow s cybersecurity breach
Best practices and insight to protect your firm today against tomorrow s cybersecurity breach July 8, 2015 Baker Tilly Virchow Krause, LLP Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently
Prepared by : Michael R. Fowlkes CBP / Fraudulent Document Officer San Ysidro Port of Entry 720 E. San Ysidro Blvd. San Ysidro, CA 92173 (619)
Prepared by : Michael R. Fowlkes CBP / Fraudulent Document Officer San Ysidro Port of Entry 720 E. San Ysidro Blvd. San Ysidro, CA 92173 (619) 662-7342 Social Security Facts: The Social Security act was
Protecting Personal Information: The Massachusetts Data Security Regulation (201 CMR 17.00)
Protecting Personal Information: The Massachusetts Data Security Regulation (201 CMR 17.00) May 15, 2009 LLP US Information Security Framework Historically industry-specific HIPAA Fair Credit Reporting
Privacy Rights Clearing House
10/13/15 Cybersecurity in Education What you face as educational organizations How to Identify, Monitor and Protect Presented by Jamie Gershon Sr. Vice President Education Practice Group 1 Privacy Rights
Cyber Insurance: How to Investigate the Right Coverage for Your Company
6-11-2015 Cyber Insurance: How to Investigate the Right Coverage for Your Company Presented by: Faith M. Heikkila, Ph.D., CISM, CIPM, CIPP-US, ABCP Greenleaf Trust Chief Information Security Officer (CISO)
Brief. The BakerHostetler Data Security Incident Response Report 2015
Brief The BakerHostetler Data Security Incident Response Report 2015 The rate of disclosures of security incidents in 2015 continues at a pace that caused many to call 2013 and then 2014 the year of the
Application for Automatic Extension of Time To File U.S. Individual Income Tax Return
Form 4868 Department of the Treasury Internal Revenue Service (99) Application for Automatic Extension of Time To File U.S. Individual Income Tax Return Information about Form 4868 and its instructions
New Privacy Laws Impacting the Health Care Work Place
New Privacy Laws Impacting the Health Care Work Place Presented by Thomas E. Jeffry, Jr., Esq. Arent Fox LLP Washington, DC New York, NY Los Angeles, CA November 12 & 19, 2009 Overview 1. Overview of California
Data Security Breach Notice Letter
View the online version at http://us.practicallaw.com/3-501-7348 Data Security Breach Notice Letter DANA B. ROSENFELD & ALYSA ZELTZER HUTNIK, KELLEY DRYE & WARREN LLP A letter from a company to individuals
Full Medical Benefits**
(In effect as of January 1, 2006*) TABLE 5a. MEDICAL BENEFITS PROVIDED BY WORKERS' COMPENSATION STATUTES Full Medical Benefits** Alabama Indiana Nebraska South Carolina Alaska Iowa Nevada South Dakota
RETAIL INSTALLMENT CREDIT AGREEMENT
RETAIL INSTALLMENT CREDIT AGREEMENT In this Agreement, the words you and your refer to any person who signs this Agreement, has requested and is issued a Tiffany & Co. credit card, or is authorized to
Model Regulation Service January 2006 DISCLOSURE FOR SMALL FACE AMOUNT LIFE INSURANCE POLICIES MODEL ACT
Table of Contents Section 1. Section 2. Section 3. Section 4. Section 5. Section 6. Section 1. Model Regulation Service January 2006 Purpose Definition Exemptions Disclosure Requirements Insurer Duties
Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015
Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Katherine M. Layman Cozen O Connor 1900 Market Street Philadelphia, PA 19103 (215) 665-2746
Cloud Computing: A Primer on Legal Issues, Including Privacy and Data Security Concerns. Privacy and Information Management Practice / Washington, DC
Cloud Computing: A Primer on Legal Issues, Including Privacy and Data Security Concerns Privacy and Information Management Practice / Washington, DC Disclaimer THIS PRESENTATION IS TO ASSIST IN A GENERAL
CYBER SECURITY SPECIALREPORT
CYBER SECURITY SPECIALREPORT 32 The RMA Journal February 2015 Copyright 2015 by RMA INSURANCE IS AN IMPORTANT TOOL IN CYBER RISK MITIGATION Shutterstock, Inc. The time to prepare for a potential cyber
Cloudy With a Chance Of Risk Management
Proudly presents Cloudy With a Chance Of Risk Management Toby Merrill, ACE USA John Mullen, Nelson Levine de Luca & Hamilton Shawn Melito, Immersion Ltd. Michael Trendler, ACE INA Canada What is Cloud
A/B MAC Jurisdiction 1 Original Medicare Claims Processor
A/B MAC Jurisdiction 1 Jurisdiction 1 - American Samoa, California, Guam, Hawaii, Nevada and Northern Mariana Islands Total Number of Fee-For-Service Beneficiaries: 3,141,183 (as of Total Number of Beneficiaries
Cyber/Information Security Insurance. Pros / Cons and Facts to Consider
1 Cyber/Information Security Insurance Pros / Cons and Facts to Consider 2 Presenters Calvin Rhodes, Georgia Chief Information Officer Ron Baldwin, Montana Chief Information Officer Ted Kobus, Partner
OPT Extension Application Process 11/22/2010
OPT Extension Application Process 11/22/2010 Step One: Request an I-20 recommending OPT Extension from Designated School Officer (DSO) (Pi-Shin [email protected] or Bill [email protected] or Jessie [email protected])
Understanding the Business Risk
AAPA Cybersecurity Seminar Andaz Savannah Hotel March 11, 2015 10:30 am Noon Understanding the Business Risk Presenter: Joshua Gold, Esq. (212) 278-1886 [email protected] Disclaimer The views expressed
Data Breach and Senior Living Communities May 29, 2015
Data Breach and Senior Living Communities May 29, 2015 Todays Objectives: 1. Discuss Current Data Breach Trends & Issues 2. Understanding Why The Senior Living Industry May Be A Target 3. Data Breach Costs
Send the Form 8821, with a COPY of your Application to the IRS at the Following address:
STATE OF CALIFORNIA DEPARTMENT OF INDUSTRIAL RELATIONS Division of Labor Standards Enforcement Licensing & Registration Unit 455 Golden Gate Avenue, 9 th Floor San Francisco, CA 94102 Tel: (415) 703-4848
HIPAA BUSINESS ASSOCIATE AGREEMENT
HIPAA BUSINESS ASSOCIATE AGREEMENT THIS HIPAA BUSINESS ASSOCIATE AGREEMENT ( BAA ) is entered into effective the day of, 20 ( Effective Date ), by and between the Regents of the University of Michigan,
Conducting due diligence and managing cybersecurity in medical technology investments
Conducting due diligence and managing cybersecurity in medical technology investments 2015 McDermott Will & Emery LLP. McDermott operates its practice through separate legal entities in each of the countries
APR 11 2014 Marilyn Tavenner Administrator Centers for Medicare & Medicaid Services
DEPARTMENT OF HEALTH AND HUMAN SERVICES OFFICE OF INSPECTOR GENERAL TO: WASHINGTON, DC 20201 APR 11 2014 Marilyn Tavenner Administrator Centers for Medicare & Medicaid Services Leon Rodriguez Director
Five Rivers Medical Center, Inc. 2801 Medical Center Drive Pocahontas, AR 72455. Notification of Security Breach Policy
Five Rivers Medical Center, Inc. 2801 Medical Center Drive Pocahontas, AR 72455 Notification of Security Breach Policy Purpose: This policy has been adopted for the purpose of complying with the Health
Who May Adopt, Be Adopted, or Place a Child for Adoption?
State Statutes Series Current Through February 2006 Who May Adopt, Be Adopted, or Place a Child for Adoption? In order for an adoption to take place, a person available to be adopted must be placed in
Schedule B DS1 & DS3 Service
Schedule B DS1 & DS3 Service SCHEDULE B Private Line Data Services DS1 & DS3 Service... 2 DS-1 Local Access Channel... 2 DS-1 Local Access Channel, New Jersey... 2 DS-1 Local Access Channel, Out-of-State...
SAMPLES OF ACCEPTABLE DOCUMENTS FOR AUTHORIZATION TO WORK VERIFICATION
SAMPLES OF ACCEPTABLE DOCUMENTS FOR AUTHORIZATION TO WORK VERIFICATION ATTACHMENT 2 Below are representative images of some of the documents that are acceptable for establishing an individual s authorization
LLC Member/Manager Disclosure Question by: Cathy Beaudoin. Jurisdiction. Date: 01 March 2011. LLC Member/Manager Disclosure 2011 March 01
Topic: LLC Member/Manager Disclosure Question by: Cathy Beaudoin : Maine Date: 01 March 2011 Manitoba Corporations Canada Alabama Alaska Arizona Arkansas California Our statement of information (aka annual
FINRA Publishes its 2015 Report on Cybersecurity Practices
Securities Litigation & Enforcement Client Service Group and Data Privacy & Security Team To: Our Clients and Friends February 12, 2015 FINRA Publishes its 2015 Report on Cybersecurity Practices On February
Comparison of US State and Federal Security Breach Notification Laws. Current through August 26, 2015
Comparison of US State and Federal Security Breach Notification Laws Current through August 26, 2015 Alaska...2 Arizona...6 Arkansas...9 California...11 Colorado...19 Connecticut...21 Delaware...26 District
Cyber Risks Management. Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor
Cyber Risks Management Nikos Georgopoulos, MBA, cyrm Cyber Risks Advisor 1 Contents Corporate Assets Data Breach Costs Time from Earliest Evidence of Compromise to Discovery of Compromise The Data Protection
VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium
1 VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 2 Agenda Introduction Vendor Management what is? Available Guidance Vendor Management
DATA SECURITY AND COMMERCIAL CONTRACTS
DATA SECURITY AND COMMERCIAL CONTRACTS An update on the changing US laws relating to data security and how to address this critical area of change and risk in your commercial contracts http://delvacca.acc.com
