Interesting People mailing list archives
Privacy policies, HIPAA, international law, and the rest
From: David Farber <dave () farber net>
Date: Mon, 25 Feb 2008 10:10:15 -0500
Begin forwarded message: From: "Jonathan Ezor" <jezor () tourolaw edu> Date: February 25, 2008 10:00:04 AM EST To: <dave () farber net> Subject: Privacy policies, HIPAA, international law, and the rest Reply-To: <jezor () tourolaw edu> The ongoing discussion about privacy policies, HIPAA and differentcountries' laws and rules has been very interesting, and I thank you all. I
wanted to add a few additional thoughts to the mix: 1) From my work as an attorney, I can tell you that a very largepercentage of businesses not only don't read their own privacy policies, but
are unaware that they are almost all inaccurate. Not only that, butinaccurate policies by themselves can lead to liability, even if there is no
other law being broken. The primary culprit is the very nice-soundingstatement that the site owner will not share personal information with third
parties. Really? Web hosts are 3rd parties; so are ISPs, credit cardprocessors, delivery services, backup sites, non-employees....the list goes
on and on. When I work with clients on privacy policies, I start with adetailed questionnaire to figure out exactly how they are collecting, using
and sharing information, and *then* write the policy to match. 2) The FTC's very interesting enforcement page (at<http://www.ftc.gov/privacy/privacyinitiatives/promises_enf.html>) is full of cases where companies' failure to follow their own policies lead to fines and other legal problems. Note too that the FTC is beginning to focus on failures to *secure* customer data, even absent specific legal obligations
to do so, as a general consumer protection matter. 3) The issues with regard to international "travel" of data, evenhealth-related data, are not new. In my classes and seminars on privacy and data protection, I frequently point to David Lazarus' article from October 2003 about how UCSF medical data ended up in the hands of a transcription worker in Pakistan, who threatened to release them on the Internet if she
weren't paid the $100 her subcontractor employer owed her:<http://www.sfgate.com/cgi-bin/article.cgi?file=/c/a/2003/10/22/MNGCO2FN8G1 .
DTL> 4) Beyond general laws, individual industries may have their own rules. As a lawyer, I have an obligation to keep my clients' informationconfidential, and risk losing my license and/or being sued for malpractice and worse if I fail to do so. Technology has made it entirely too easy for
attorneys to violate that rule, whether by losing a Blackberry or mis-addressing an e-mail, as happened recently to a few attorneys: <http://www.forbes.com/feeds/ap/2008/02/19/ap4671287.html> <http://www.portfolio.com/news-markets/top-5/2008/02/05/Eli-Lilly-E-Mail-to- New-York-Times> {Jonathan} ------------------- Prof. Jonathan I. Ezor Assistant Professor of Law and Technology Director, Institute for Business, Law and Technology (IBLT) Touro Law Center 225 Eastview Drive, Central Islip, NY 11722 Direct: 631-761-7119 Fax: 516-977-3001 e-mail: jezor () tourolaw edu ------------------------------------------- Archives: http://www.listbox.com/member/archive/247/=now RSS Feed: http://www.listbox.com/member/archive/rss/247/ Powered by Listbox: http://www.listbox.com
Current thread:
- Privacy policies, HIPAA, international law, and the rest David Farber (Feb 25)
