EU-U.S. Agreement on Law Enforcement Data; European Data Protection Supervisor Criticizes Privacy Shield; House Members Criticize FCC Privacy Proposal; NHTSA Targets Automotive Cybersecurity; Yahoo Releases National Security Letters; CareFirst Data Breach Lawsuit Dismissed; FDA Guidance on Data Protection in Investigations

EU and U.S. sign Umbrella Agreement on Law Enforcement Data

On June 2, 2016, Vera Jourová, European Commissioner for Justice and Consumer Protection, Dutch minister Ard van der Steur and U.S. Attorney General Loretta E. Lynch signed the “Umbrella Agreement”, a deal between the U.S. and the EU “on the protection of personal information relating to the prevention, investigation, detection and prosecution of criminal offenses”. The agreement aims at enhancing the cooperation of the EU and the U.S. in criminal enforcement (including terrorism), while at the same time protecting personal data of European citizens, when transferred from the EU to the U.S. for criminal investigations.

The text of the agreement, which was negotiated over a long period due in part to a Court of Justice of the EU (ECJ) finding that European citizens lacked adequate rights of redress, includes provisions on purpose limitation, information security, data retention, rights of data subjects, breach notifications and onward transfers. A “fact sheet”-FAQ is available on the Commission’s website. Before the agreement can be finally concluded, the European Parliament will still need to give its consent.

European Data Protection Supervisor criticizes “EU-U.S. Privacy Shield”

On May 30, the European Data Protection Supervisor (EDPS), Giovanni Buttarelli, issued an opinion on the draft “EU-U.S. Privacy Shield (“Privacy Shield”), which is in line with the criticism previously raised by the Article 29 Working Party and the European Parliament.

Continue Reading Privacy & Cybersecurity Weekly News Update- Week of May 30, 2016

Data Breach Liability Requires Actual Misuse; More U.S.-EU Data Transfer Uncertainty; Airline App Exempt from State Privacy Law; Pending Cyber Bill Would Create Consortium; Encryption-Related Deceptive Advertising Settlement; PayPal Fined for Deceptive Trade Practices

The Spokeo effect: data breach claims require actual examples of information misuse

Last week, a federal court dismissed claims alleging harm from a hospital data breach, on the grounds that the plaintiff failed to allege more than the mere threat of injury.  In Khan v. Children’s National Health System, No. 8:15-cv-2125 (D. Md.), the plaintiff alleged that phishing attacks compromised hospital employees’ email accounts containing patient information, including social security numbers, addresses, dates of birth, and other private healthcare information.  The court held that the plaintiff lacked standing and could not proceed in federal court because the plaintiff failed to allege either specific instances of misuse from the particular breach at issue or “a clear indication that the data breach was for the purpose of using the plaintiffs’ personal data to engage in identity fraud.”

The court’s reasoning also demonstrates the favorable impact that this month’s Supreme Court decision in Spokeo v. Robbins may have for defendants in data breach actions.  The Khan opinion explained that mere violation of a statute does not necessarily create the “concrete harm,” such as actual misuse of information, required by Spokeo.  Although it remains to be seen what the Ninth Circuit does with Spokeo on remand and how Spokeo will impact future cases, it seems likely that federal courts will continue to be inclined to disfavor claims where the harm alleged is the “diminished value” of personal information, a general loss of privacy, or simply a technical statutory violation.

Continue Reading Privacy & Cybersecurity Weekly News Update- Week of May 23, 2016

The Panama Papers Leak – An overview on histories’ biggest data leak; Article 29 Working Party about to release opinion on EU-U.S. Privacy Shield; EU: GDPR and PCJ DPD about to be approved next week – final consolidated text published by Council; US: New HIPAA Audit Protocol Released as a Guidance Tool for phase two of Compliance Audits; U.S. Sneak News: Defend Trade Secrets Act, NPRM and Sony Settlement Approval. EU: GDPR, PCJ DPD and PNR Directive adoped by Parliament; U.S.: House Judiciary Committee approves E-Mail Privacy Act; Senate to require airlines to report cyberattacks; FTC issues online tool identifying applicable law for health apps; Global: Turkey releases first comprehensive Data Protection law; Connected cars found vulnerable for cyberattacks; Data Breaches May Waive Attorney-Client Privilege?; Encryption Continues to Dominate Privacy Headlines; Hospital Settles with HHS for $ 2.2 Million in HIPAA Action; Southern District of New York Adds Ransomware Conspirator to Hacking Case; European and Canadian Data Protection Authorities Investigate IoT Devices; Norway Requires Data Breach Notification for Individuals

The Panama Papers Leak – An overview on histories’ biggest data leak

On April 3, 2016, reports revealed that a set of 11.5 million confidential documents (“the Panama Papers”), providing detailed information about more than 200,000 offshore companies connected to Panamanian legal service provider Mossack Fonseca, had been made available to German Daily Newspaper Süddeutsche Zeitung by an anonymous source in 2015.

The documents, which form part of the biggest data leak in history, reveal aspects on (potential) exploitations of offshore tax regimes and other illegal purposes, such as fraud or drug trafficking. Among the people concerned are not only big companies, but also twelve national leaders among 143 politicians, celebrities, government officials or other law firms. The Süddeutsche Zeitung, given the scope of the leak, involved the International Consortium of Investigative Journalists (ICIJ) and about 400 other journalists in 76 different countries to investigate and analyze the documents. ICIJ has promised to publish a full list of companies involved in early May 2016.

Mossack Fonseca, the leaked firm, defended its commercial conduct, stating that itself would always comply with applicable laws and carry out thorough due diligence on its clients. However, the leak will have a huge impact on the offshore business, as the biggest selling point of this business, secrecy, has been massively cracked.

Continue Reading Privacy & Cybersecurity News Update- 3 Week Summary

Following an April 11 ruling by the Fourth Circuit in Travelers Indemnity Company of America v. Portal Healthcare Solutions, LLC, Travelers must defend its policyholder, Portal Healthcare, in a class action lawsuit concerning a security breach.  For years, courts have wrestled with whether traditional commercial general liability (CGL) policies provide coverage in event of a data breach.  The results have been mixed.  This most recent decision highlights the uncertainty that remains over whether traditional insurance policies cover cyber liabilities and, if so, under what circumstances and to what extent.  This case appears to have been driven by specific policy language and the facts of the cyber incident, particularly the conduct of the policyholder, but highlights the increasing prevalence of cyber insurance issues.

Travelers had issued two CGL policies to Portal Healthcare, a medical records company.  In April 2013, a class action was filed in New York state court alleging that, as a result of Portal Healthcare’s failure to properly protect its server, confidential medical records for patients at a New York hospital were accessible on the Internet to unauthorized individuals.  The class action complaint  asserts counts for alleged negligence, breach of warranty, breach of contract, and also seeks injunctive relief against Portal Healthcare, the hospital, and others. 

In July 2013, Travelers filed the coverage action at issue here in the U.S. District Court for the Eastern District of Virginia.  Travelers sought a declaration that it was not obligated under its CGL policies to defend or indemnify Portal Healthcare against the underlying class action lawsuit.  Specifically, Travelers argued that it was entitled to declaratory judgment because the underlying class action does not allege “personal injury,” “publication of material,” “advertising injury” or “website injury,” as defined in the Travelers policies.

Continue Reading Fourth Circuit Affirms Carrier’s Duty to Defend Against Security Breach Claims Under Traditional Insurance Policy

FCC Adopts a NPRM for Privacy Proposal; FTC Chairwoman Wants IoT Threat Addressed; Consumer Reports Hit with Privacy Class Action; DOJ Accesses Shooter’s Phone and Drops Apple Suit

FCC Adopts a NPRM for Privacy Proposal

On Thursday, March 31 in a 3-2 party-line vote, the FCC advanced a Notice of Proposed Rulemaking (NPRM) for broadband privacy. The proposed rules would restrict ISP’s use of basic consumer data and require consumer consent for certain types of data collection.  Although ISPs under the rule could still collect basic consumer data to market communications- related services to subscribers, ISPs would have to allow users to opt-out of that data collection.  On the other hand, ISPs would have to allow used to opt-in to the use and sharing of other types of data, such as browsing history and physical location.  Under the proposed rules, providers are also required to share how data is used or shared with consumers.  Some have criticized the proposed rules, arguing that they have the potential to create an uneven enforcement regime as companies have the potential to face varied FCC and FTC standards.

FTC Chairwoman Wants IoT Threat Addressed

On Thursday, March 31, FTC Chairwoman Edith Ramirez urged manufacturers of Internet of Things (IoT) devices to “design devices that take into consideration unexpected uses of their IoT data, and the potential for misuse.” In a speech at the American Bar Association’s conference on IoT in Washington, DC, Chairwoman Ramirez outlined a series of steps that she recommends manufacturers take as they develop new IoT technology.  Drawing on common privacy practices, Chairwoman Ramirez advised manufacturers to provide consumers with clear notice of data collection practices and to allow consumers to opt in or out of particular data collection practices.  She also encouraged manufacturers to build security into devices from the outset and keep track of issues through a device’s life cycle.   The FTC plans to hold a series of workshops this fall to look at a series of issues arising from new technology, such as smart televisions and UAVs.

Continue Reading Privacy & Cybersecurity Weekly News Update

OCR Launches Next Round of HIPAA Audits; French Privacy Office Levies € 100,000 Fine on Google; SEC Reaches $18 Million Settlement for Alleged Hacker-Trader Conspiracy; FTC and Canadian Regulator Execute Anti-Spam MOU; FTC Commissioner Announces She Will Step Down

OCR Launches Next Round of HIPAA Audits

Last Monday, following much anticipation, the Department of Health and Human Services OCR announced Phase 2 of its audit program to measure compliance with the patient privacy provisions of HIPAA. This audit follows OCR’s pilot audit of 115 Covered Entities and will likely examine 200 additional Covered Entities. For more information about what entities can expect, read Elliot Golding’s March 23 post.

French Privacy Office Levies € 100,000 Fine on Google

The French data protection authority (CNIL), one of the most active privacy regulators in Europe, fined Google € 100,000 for “failure to comply with the obligation to respect the rights of individuals to erase data” under the European “right to be forgotten.”  In May 2014, the European Court of Justice ruled that the compilation of Google search result links were “data processing,” and, as such, search engines should remove links at the request of data subjects.  The CNIL faulted Google for only removing links from searches that originated from EU IP address and not delisting all “Google Search” extensions.

SEC Reaches $18 Million Settlement for Alleged Hacker-Trader Conspiracy

The SEC secured settlements, totaling almost $18 million, with seven defendants accused of participating in a scheme to trade on hacked newswire information. These seven defendants are part of a larger alleged scheme of 32 defendants who, over five years, hacked newswires to obtain earnings announcements before they were released and then distributed and traded on those stolen statements. The government has also brought a parallel criminal action against some of the 32 defendants in the District of New Jersey and has stayed a massive civil suit based on the same hacking scheme.  The $18 million in recent SEC settlements come on the heels of a $4.2 million SEC settlement with Concorde Bermuda Ltd., also accused of taking part in the scheme.

Continue Reading Privacy & Cybersecurity Weekly News Update

On March 2, 2016, the National Association of Insurance Commissioners (NAIC) Cybersecurity Task Force proposed a new model law intended to “establish the exclusive standards for data security and investigation and notification of a breach of data security” in the insurance industry.

The model law requires licensed insurers and producers to:

  1. Develop, implement and maintain an information security program to ensure confidentiality of personal information, and protect against anticipated threats to and unauthorized access of such information.
  2. Provide for board of directors oversight of the information security program (if applicable) and annual reporting to the board of directors regarding the data security program.
  3. Include provisions in all third-party service provider contracts regarding (a) third-party safeguards, (b) post-breach notification, (c) post-loss indemnification, (d) cyber-security audits, and (e) representations and warranties regarding compliance.
  4. Provide certain information to consumers regarding the types of personal information collected and stored, and the applicable privacy policy.
  5. Investigate a suspected data breach and take steps to restore the security and confidentiality of compromised systems.
  6. Provide notice of a data breach to (a) the appropriate Federal and state law enforcement agency, (b) the insurance commissioner, (c) consumers, and (4) consumer reporting agencies.
  7. Implement protections for consumers after a data breach as prescribed by the commissioner but not less than twelve months of identity theft protection for affected consumers paid for by the insurer/producer.

Continue Reading NAIC Announces Insurance Data Security Model Law

US Changes Stance on Wassenaar Arrangement Hacking Amendment; FCC Proposes Privacy Rules for Internet Providers; New Jersey Supreme Court Unanimously Approves Roving Wiretaps; FTC Commissioner Opposes Encryption Backdoor Legislation

US Changes Stance on Wassenaar Arrangement Hacking Amendment

Last week, the U.S. executive branch announced that it will change its stance on the 2013 amendment to the Wassenaar Arrangement that closely regulates the international export of cyber hacking and surveillance technology.  This is a big win for the private sector.  Indeed, industry has long been critical of this amendment to the Wassenaar Arrangement, a multilateral export control regime with 41 participating states, because of its potential to chill and stifle innovation in the cybersecurity.  The controversy over this rule has highlighted the difficulty of applying export controls, which are usually restricted to physical items, to the virtual world.   Now, the U.S. faces the daunting task of convincing the 40 other countries on the Arrangement to agree with its new position before the controversial amendment can be formally changed.

FCC Proposes Privacy Rules for Internet Providers

After much anticipation, on March 10 the FCC unveiled its proposed broadband privacy rules, which will be voted on by the full commission at its March 31 open meeting.  According to the fact sheet published alongside the rules, the FCC sought to emphasize customer choice, transparency, and security. Generally, the proposed requirements parallel requirements of other consumer privacy efforts, such as the proposed SPY CAR Act, where lawmakers have sought to require industry to better inform consumers about the use and collection of their data.

Among other things, the proposed rules would oblige providers to obtain customer consent via an “opt-in” to use customer data outside of marketing for “communications-related services.”  The proposed rules also require ISPs to take “reasonable steps” to safeguard customer information.   Those reasonable steps include, “at a minimum,” adopting risk management practices, instituting personnel training practices, adopting strong consumer authentication requirements, identifying senior management responsible for data security, and taking responsibility for the use and protection of customer information when shared with third parties.  Providers must also notify consumers, the Commission, the FBI, and the Secret Service in the event of some breaches.

Continue Reading Privacy & Cybersecurity Weekly News Update

EU-US Privacy Shield Principles Released; No Insurance Coverage for Data Breach, New York Court Holds; CFPB Levies First Data Security Fine; New York Court Sides with Apple in 4th Amendment War; “I confirm that I am over 13 years old” Checkbox Ruled Not an Effective Age-Screener

EU-US Privacy Shield Principles Released

After years of negotiations that intensified after the U.S.-EU Safe Harbor program was invalidated late last year, the U.S. Department of Commerce (DOC) and the European Commission (EC) reached an agreement to replace Safe Harbor, called the EU-U.S. Privacy Shield. On February 29, the DOC formally published this agreement.  The EC also published the draft adequacy decision for the new framework.  This formal agreement largely tracks the priorities discussed in a press release issued earlier in February and will allow companies to plan for lawful data transmissions across the Atlantic. For more information about the differences between the previous framework (U.S.-EU Safe Harbor) and the new one, please join us on March 9 at Crowell & Moring in Washington, D.C. for a seminar on the EU-U.S. Privacy Shield and the forthcoming EU Data Protection Regulation (GDPR).

No Insurance Coverage for Data Breach, New York Court Holds

The New York Appellate Court for the Third Division upheld the trial court’s decision to deny insurance coverage for RVST Holdings (RVST), which operate fast food restaurants in the New York area. Trustco Bank, in another action, filed suit against RVST for failing to secure their customers’ credit card information after third parties obtained the credit card numbers from RVST’s network and made fraudulent charges.  RVST, in turn, filed suit against Main Street Assurance Company, its business insurance provider, seeking coverage.  This coverage was denied.

Continue Reading Privacy & Cybersecurity Weekly News Update

In a recent Law360 publication, C&M attorneys Rachel Raphael and Ellen Farrell discuss how directors and officers (D&O) insurance coverage applies when a company experiences a data breach.  As they explain, D&O policies may provide some coverage when a company’s directors and officers are sued after a cyber incident, but there are often policy exclusions