Save Online law articles on social network:
Showing posts with label law enforcement. Show all posts
Showing posts with label law enforcement. Show all posts

Article: B.C. responds to U.S. Patriot Act with privacy plan

The Vancouver Province is reporting that the BC government will be responding to concerns about the impact of the PATRIOT Act on BC by introducing legislation:

The Province: B.C. responds to U.S. Patriot Act with privacy plan:

"VICTORIA -- The B.C. government is moving to introduce tough new privacy protection laws in response to the USA Patriot Act.

Attorney General Geoff Plant and Management Services Minister Joyce Murray outlined the plan Friday to B.C.'s Information and Privacy Commissioner.

Murray says the government is taking every step to have the strongest privacy legislation in Canada.

He says the laws would make sure no sensitive personal information will be sent to the U.S. on either a temporary or permanent basis.

It limits the application of the Act by ensuring that American affiliates and B.C. service providers do not have access to information supplied by a public body.

Plant calls the move a 'made-in-B.C.' solution and hopes other provinces will follow.

The U.S. government introduced the Patriot Act after the 9/11 terrorist attacks to give more power to law agencies like the FBI. "


I'll post more info as I find it. In the meantime, you can check out information about the BC Privacy Commissioner's consultations on this matter at his website:http://www.oipcbc.org/sector_public/usa_patriot_act/patriot_act.htm.

Read more from this post in Online law articles »

Campaign in BC to prevent outsourcing of medical info management to US company

The BC Freedom of Information and Privacy Association has a report about a campaign launched to prevent the BC government from ousourcing the management of the BC Medical Services Plan to an American company. The fear is that once the info is in the hands of an American firm, it will be within easy reach of the FBI and others, thanks to the USA PATRIOT Act.

'Right to Privacy Campaign' launched to protect individuals' privacy by stopping Maximus deal:

A diverse and growing group of rights, health, union and other organizations has launched a province-wide campaign to demand that the BC government drop its proposed deal with the Maximus corporation because of the privacy implications of the USA PATRIOT Act.

The Right to Privacy Campaign (RPC) believes that contracting out the administrative functions of BC's Medical Services Plan and PharmaCare to the American corporation Maximus Inc. will place British Columbians' confidential health and related information within easy reach of the FBI and, through the FBI, the entire array of American government agencies.

The primary goal of the RPC is to ensure that there is 'no contracting out by the Government of BC of information or information management, such as MSP or PharmaCare, to any company subject to foreign laws that violate the privacy rights of Canadians, like the USA PATRIOT Act'...."


Unfortunately, the website of the Right to Privacy Campaign seems to be down, which I expect would have much more info.

Read more from this post in Online law articles »

BC privacy watchdog seeks US government, FBI input in Patriot Act

The British Columbia Privacy Commissioner has released a statementthat he will begin an inquiry into the impact of the US Patriot Act on the privacy of British Columbians. Specifically, he is concerned that US federal authorities will have access to personal information of British Columbians if a US company is used as the outsourced service provider for various public services.

Here are links to articles from Google News:


Pending inquiry, government should halt its plan to give private ...
BCGEU, Canada - 11 hours ago
The provincial government should immediately halt plans that would put private information on every British Columbians into the hands of US firms, pending a ...

BC privacy watchdog seeks US government, FBI input in Patriot Act ...
Canada East, Canada - 14 hours ago
VICTORIA (CP) - The FBI and US Attorney General John Ashcroft are being asked to contribute to a British Columbia study of the US Patriot Act. ...

Patriot Act probe begins
CBC British Columbia, Canada - 14 hours ago
VICTORIA - BC's Privacy Commissioner has launched a review of the impact of the US Patriot Act on government plans to contract out the Medical Services Plan to ...

BC privacy czar to study US Patriot Act
CTV, Canada - 12 hours ago
VICTORIA — The FBI and US Attorney General John Ashcroft are being asked to contribute to a British Columbia study of the US Patriot Act. ...


Read more from this post in Online law articles »

Incident: Computer System at U.C. San Diego Hacked

From today's Yahoo News:


Yahoo! News - Computer System at U.C. San Diego Hacked:

"Computer System at U.C. San Diego Hacked

Fri May 7,11:55 PM ETAdd U.S. National - AP to My Yahoo!


SAN DIEGO - Hackers broke into the computer system of the University of California, San Diego, compromising confidential information on about 380,000 students, teachers, employees, alumni and applicants.

Investigators urged those affected to guard against identity theft.

Hackers infiltrated four computers that stored Social Security (news - web sites) and driver's license numbers in the university's business and financial services department. Investigators are unaware of any illegal use of the data.

University officials discovered the security breach April 16 after noticing a spike in traffic on the network.

In December, more than 178,000 San Diego State University students, alumni and employees had personal information exposed by hackers who broke into a university computer server. The FBI (news - web sites) and campus police investigation found computers used for the hacking were on the East Coast.

Last month, the San Diego Supercomputer Center, which is on the UCSD campus, was infiltrated by a hacker, although officials said no critical information was lost. "


Read more from this post in Online law articles »

File-swapping litigation raises important privacy issues

Up until recently, Canadians have been free of the sort of litigation that the American recording industry has inflicted on "file sharers" in the U.S. As many know, the first movements toward similar litigation has recently been noticed in Canada (See the Globe & Mail's article, Canadian Recording Industry hopes to inspire fear over file swapping). Some of the more recent media attention has focussed on the attempt by CRIA to discover the identities of individuals whom they have targetted:



London Free Press: Business Section - Copyright suit raises concerns

David Canton, Freelance writer 2004-03-06 03:22:53



A legal action that could potentially affect anyone who has downloaded music on the Internet was recently initiated in Canada. The plaintiffs in this civil suit are some of the biggest music record labels, represented by the Canadian Recording Industry Association (CRIA).

...

CRIA intends to go after "egregious" or high-volume file-sharers that make massive quantities of music available for free.

The defendants in these proceedings are unknown for the moment. CRIA is requesting a court order that could change that. If granted, it would require Internet service providers (ISP) to produce names and addresses of the alleged perpetrators.

Electronic Frontier Canada and the Canadian Internet Policy and Public Interest Clinic have both been allowed by the court to intervene in this matter to argue the legal issues surrounding privacy, due process, and copyright law.

CRIA has tracked computers trading in copyrighted songs using their Internet protocol (IP) addresses through the use of surveillance technology. CRIA needs to match those IP addresses with subscriber information to identify the defendants.

Five ISPs have been targeted by CRIA for the disclosure of personal information that would lead to the identification of subscribers using the Web to upload music. The court ordered an adjournment until March 12 so the parties can cross-examine each other's affidavit documents to determine the technical and legal issues in dispute.

Downloading involves taking information from another computer. Uploading is transferring data from one's own computer to another. It is generally accepted that the Copyright Act allows music downloading so long as it is for personal use. Uploading is not so clear. These issues have not yet been decided in courts.

...

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an ISP is not permitted to disclose a subscriber's personal information without the person's knowledge and consent. One exception is a court order.

There are many issues to be considered, such as whether civil actions should be held to a higher threshold before privacy is violated than in criminal cases, and whether uploading music as done by the peer-to-peer networks is actually copyright infringement.

There is also concern about the accuracy of the information being sought. Dynamic IP addresses can be reassigned to different customers on a continual basis, making it difficult to determine which individuals upload music files.

The worry is that ISPs could be compelled to provide private information that wrongly identifies someone. One of the ISPs maintains it can not accurately match the IP addresses with alleged file-sharers.

Copyright © The London Free Press 2001,2002,2003



One concern that I have, right off the bat, is that the ISPs probably collect way too much information in the first place and probably should put in place a rigorous retention policy that would delete their logs pretty darn quick. If they don't have the information desired by CRIA, they don't have to worry about it. It is not the job of the ISPs to collect and stockpile evidence for the recording industry (or any other organization). In fact, under PIPEDA they should probably not retain it:

Principle 5 -- Limiting Use, Disclosure, and Retention



Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes.




The information being requested by CRIA is probably from routine logging of network activity and connections. I know of some providers who (despite advice to the contrary) keep these logs indefinitely for security and audit purposes. In most cases, this is not made known to the customers. I know that my ISP does not mention this sort of information collection in its Privacy Policy, even though the Openness Principle requires making this sort of collection known. My cellphone company doesn't say anything about signalling information, which I am sure is logged and can be traced to me.


According to what I've heard, the US PATRIOT Act allows the Department of Homeland Security to request information about borrowers from public libraries. The logical response from many librarians is to make sure they don't collect information that would be useful to the FBI. From the San Francisco Public Library:


The Library does not maintain a history of what a borrower has previously checked out once books and materials are returned on time.


In short, if you don't want to fight over disclosing it to anyone, don't collect it and, if you do, don't retain it!




Read more from this post in Online law articles »

Article: Privacy officials fear U.S. law's reach: FBI could gain access to personal information about Canadians, government warned

The Victoria Times Colonist and the Vancouver Sun are reporting about fears that the US PATRIOT Act might require companies to hand over Canadian data to the FBI:



Privacy officials fear U.S. law's reach: FBI could gain access to personal information about Canadians, government warned




Judith Lavoie

Victoria Times Colonist




Thursday, March 04, 2004

Provincial information and privacy offices across the country are scrambling to find ways of stopping the FBI gaining access to sensitive personal information about Canadians under a controversial new American law.

"This has the potential for being the biggest privacy issue we have ever dealt with," said Mary Carlson, director of policy and compliance for the B.C. Information and Privacy Commissioner's Office.

"It is the first we had heard of the long arm of the FBI coming across the border."

At issue is the U.S. Patriot Act, brought in after the 9-11 terrorist attacks, which allows the FBI to order organizations to turn over information. A "gag provision" then prohibits the organizations from telling anyone that the data has been released.

Legal opinions given to the B.C. Government and Service Employees' Union -- which has filed a lawsuit in an effort to stop privatization of the Medical Services Plan -- say Canadian subsidiaries of U.S. companies would be subject to the Act. Any corporation that has access to documents wanted by the FBI, even if the company does not have a legal right to those documents, could be ordered to turn them over.

That would mean the FBI could demand health and social service information about all British Columbians.

Governments are increasingly outsourcing work, often to companies with U.S. connections, but no one had figured in the far-reaching powers of the Patriot Act, said Carlson.

"If this is true, our data would be exposed in ways we have never imagined before," she said.

Carlson contacted the federal information and privacy commissioner and provincial offices and found the Patriot Act was not on their radar screens.

All the offices are now looking at the potentially serious implications, Carlson said. "We are working feverishly here trying to work out what we can do."

The two companies shortlisted to take over MSP and PharmaCare administration services are both American-based. IBM is American with a wholly-owned Canadian subsidiary and Maximus is based in Virginia.

Other recent government outsourcing includes a large chunk of BC Hydro's business services, which went to a Canadian subsidiary of Accenture, a company with its head office in Bermuda and main business office in the U.S., and government debt collection which went to a Canadian subsidiary of multi-national Electronic Data Systems.

Health Services Minister Colin Hansen said previously that the American government could not pass a law that applies to data owned by B.C. and which never leaves B.C. But, under the Patriot Act, that is in doubt.

Management Services Minister Joyce Murray, whose portfolio includes information and privacy, met with Commissioner David Loukidelis Wednesday to discuss the problem.

"We are now working in collaboration with the Attorney-General's office and Health Services to seek extra professional advice," she said.

A lawyer specializing in American law and privacy of information will look at implications of the Patriot Act and the government will work actively with other provinces and the federal government on the issue, Murray said.

"Whatever the advice is, the bottom line is that we're totally committed to ensuring that the privacy of information is protected for British Columbians," she said.

Any contracts with private companies must enshrine the absolute protection of privacy and those contracts will be monitored, she said.

Murray said she can understand why no one had picked up the importance of the U.S. law, as there have been no challenges or court cases around it.

But BCGEU president George Heyman said Hansen and Premier Gordon Campbell had obviously not done their homework in the rush to privatize and contract out.

"We could figure it out and they have a whole phalanx of lawyers and staff. I would think they could figure out the risk. It's more likely that they don't care," he said.

Read more from this post in Online law articles »

US Health Privacy Law leads to conviction of ID theft and fraud

The first conviction under HIPAA, the United States Health Insurance Portability and Accountability Act, has taken place in Seattle. The US Attorney's office has released the following press release, describing the guilty plea related to the theft of a cancer patient's personal information for ID theft purposes. Interestingly, he wasn't charged under traditional identity theft laws, but only for "wrongful disclosure of individually identifiable
health information for economic gain.".



http://www.usdoj.gov/usao/waw/press_room/2004/aug/gibson.htm

August
19, 2004


 


SEATTLE
MAN PLEADS GUILTY IN FIRST EVER CONVICTION FOR HIPAA RULES VIOLATION


 



RICHARD W. GIBSON, age 42, of SeaTac, Washington pleaded guilty today
in federal court in Seattle to wrongful disclosure of individually identifiable
health information for economic gain. This is the first criminal conviction
in the United States under the health information privacy provisions
of the Health Insurance Portability and Accountability Act (HIPAA) which
became effective in April, 2003. Those provisions made it illegal to
wrongfully disclose personally identifiable health information.

As set forth in the Plea Agreement
(also view Information),
GIBSON admitted that he obtained a cancer patient's name, date of birth
and social security number while GIBSON was employed at the Seattle
Cancer Care Alliance, and that he disclosed that information to get
four credit cards in the patient's name. GIBSON also admitted that he
used several of those cards to rack up more than $9,000 in debt in the
patient's name. GIBSON admitted he used the cards to purchase various
items, including video games, home improvement supplies, apparel, jewelry,
porcelain figurines, groceries and gasoline for his personal use. GIBSON
was fired shortly after the identity theft was discovered.


The Government and GIBSON agreed as part of the Plea
Agreement,
that GIBSON should be sentenced to a term of 10 to 16
months. Under these terms, the Court could order that the term be served
either wholly in federal prison, or in a combination of federal prison
and either home confinement or community confinement. GIBSON has also
agreed to pay restitution to the credit card companies, and to the patient
for expenses he incurred as a result of GIBSON's use of his identity.


At a hearing scheduled for November 5, 2004, U.S. District Court Judge
Ricardo S. Martinez will determine whether to accept the Plea Agreement,
and if accepted, will determine GIBSON's sentence within the 10-16 month
range set forth in the Plea Agreement and the length of any supervised
release following his prison term. If the Court rejects the Plea Agreement
and the agreed upon sentence, GIBSON will have an opportunity to withdraw
his guilty plea.


"Too many Americans have experienced identity theft and the nightmare
of dealing with bills they never incurred. To be a vulnerable cancer
patient, fighting for your life, and having to cope with identity theft
is just unconscionable," stated United States Attorney John McKay.
"This case should serve as a reminder that misuse of patient information
may result in criminal prosecution."


The case was investigated by the Federal Bureau of Investigation (FBI)
and is being prosecuted by Assistant United States Attorney Susan Loitz.
For further information please contact Emily Langlie, Public Affairs
Officer for the United States Attorney's Office at (206) 553-4110.




Thanks to Symtym and GruntDoc for leading me to this release.

Read more from this post in Online law articles »
Info recommended by: Webpages of law and Law articles

© Online law articles: law enforcement