Interesting People mailing list archives

Privacy policies, HIPAA, international law, and the rest


From: David Farber <dave () farber net>
Date: Mon, 25 Feb 2008 10:10:15 -0500



Begin forwarded message:

From: "Jonathan Ezor" <jezor () tourolaw edu>
Date: February 25, 2008 10:00:04 AM EST
To: <dave () farber net>
Subject: Privacy policies, HIPAA, international law, and the rest
Reply-To: <jezor () tourolaw edu>

The ongoing discussion about privacy policies, HIPAA and different
countries' laws and rules has been very interesting, and I thank you all. I
wanted to add a few additional thoughts to the mix:

1)      From my work as an attorney, I can tell you that a very large
percentage of businesses not only don't read their own privacy policies, but
are unaware that they are almost all inaccurate.  Not only that, but
inaccurate policies by themselves can lead to liability, even if there is no
other law being broken.  The primary culprit is the very nice-sounding
statement that the site owner will not share personal information with third
parties.  Really?  Web hosts are 3rd parties; so are ISPs, credit card
processors, delivery services, backup sites, non-employees....the list goes
on and on.  When I work with clients on privacy policies, I start with a
detailed questionnaire to figure out exactly how they are collecting, using
and sharing information, and *then* write the policy to match.

2)      The FTC's very interesting enforcement page (at
<http://www.ftc.gov/privacy/privacyinitiatives/promises_enf.html>) is full of cases where companies' failure to follow their own policies lead to fines and other legal problems. Note too that the FTC is beginning to focus on failures to *secure* customer data, even absent specific legal obligations
to do so, as a general consumer protection matter.

3)      The issues with regard to international "travel" of data, even
health-related data, are not new. In my classes and seminars on privacy and data protection, I frequently point to David Lazarus' article from October 2003 about how UCSF medical data ended up in the hands of a transcription worker in Pakistan, who threatened to release them on the Internet if she
weren't paid the $100 her subcontractor employer owed her:

<http://www.sfgate.com/cgi-bin/article.cgi?file=/c/a/2003/10/22/MNGCO2FN8G1 .
DTL>

4)      Beyond general laws, individual industries may have their own rules.
As a lawyer, I have an obligation to keep my clients' information
confidential, and risk losing my license and/or being sued for malpractice and worse if I fail to do so. Technology has made it entirely too easy for
attorneys to violate that rule, whether by losing a Blackberry or
mis-addressing an e-mail, as happened recently to a few attorneys:
<http://www.forbes.com/feeds/ap/2008/02/19/ap4671287.html>
<http://www.portfolio.com/news-markets/top-5/2008/02/05/Eli-Lilly-E-Mail-to-
New-York-Times>

{Jonathan}
-------------------
Prof. Jonathan I. Ezor
Assistant Professor of Law and Technology
Director, Institute for Business, Law and Technology (IBLT)
Touro Law Center
225 Eastview Drive, Central Islip, NY  11722
Direct: 631-761-7119  Fax: 516-977-3001
e-mail: jezor () tourolaw edu



-------------------------------------------
Archives: http://www.listbox.com/member/archive/247/=now
RSS Feed: http://www.listbox.com/member/archive/rss/247/
Powered by Listbox: http://www.listbox.com


Current thread: