Showing posts with label medical identity theft. Show all posts
Showing posts with label medical identity theft. Show all posts

Thursday, March 20, 2008

HealthNow New York Shows How to Mishandle a Data Loss

Healthow a healthcare claims provider in upstate New York has earned a spot on our office identity theft "Wall of Shame" this month for totally blowing how to handle a data loss then offering a service they will do next to nothing and the high cost will ultimately be passed on to their employers or members directly.

Last week the Buffalo, New York claims provider sent letters to 40,000 members alerting them to a possible loss of personal information. An employee downloaded patient information and then apparently lost the laptop. Apparently this happened many months ago and they first “spent an exorbitant amount of time” to try and locate the laptop, which they still believe is in the company’s building.

This company is responsible for keeping track of medical and health records of thousands and they want people to believe that they are just sitting on a laptop they cannot find. Maybe when they clean their room it will turn up. What are they, a 10 year old? It does not give me much confidence and points to pure lack of control on their part.

Then they make a second attempt at pacification by stating they are not even sure what information it contained. Teenagers deploy keyloggers, governors get their text messages exposed, malware can track every click of a mouse, and parents can track and view everything a child does on a computer for $39, but a healthcare organization of this magnitude has not a clue what their employee downloads from their database.

The employee is now a former employee but apparently they are still in contact with him. Another vote of confidence.

And the final nail in the coffin is this statement: “With all of the factors and orchestrating credit monitoring, we do believe our response time has been reasonable. Reasonable? For who? Around 4 months has passed and any chance of giving the people a heads up to potential fraud is all but vanished.

If you read between the lines....the laptop has sensitive information on it, they know it, that is why they looked for it for months. Better to not have to be exposed. The former employee who left for another job, fired within a week of the loss or theft. That laptop with sensitive information is long gone, they know it. Now, backed into a corner and options have run out, time to air the dirty laundry.

And to throw out a useless bone, free credit monitoring for a year. When you get alerted by the agency that someone tried to open an account in your name, you'll sleep better knowing a stranger definitely has your personal information and is trying to use it. Credit monitoring will alert you right away that a thief has opened up and used $10,000 of credit in your name. That way you can start the mop up and recovery process.

But wait, the thief may not be done with your information. They will use it for draining existing bank accounts, or for a criminal arrest and then the patient or victim get s warrants issued against them for not appearing in court. It will be useful when medical services are provided to the thief, or prescriptions are obtained then sold illegally on the street. It is handy for a disability claim , or sell to an illegal immigrant to get a job. So much for the monitoring bone, won't help with any of this.

There are pro-active ways to defend yourself against many of these pitfalls, but knowing about them in a timely manner is key.

Thursday, January 31, 2008

Identity Theft “Prevention” Defined Accurately

Everybody that talks about prevention uses the word in a different way. It is about perspective. Here is an example:

Think about how you would feel if this scenario happened: Your bank called and said “someone infiltrated your savings account and they have been making withdrawals regularly for the last three months. Your account has been drained of $25,000 but due to our diligence we stopped it and you still have $15,000 left. We have effectively prevented the thief from draining your account. We thought you’d like to know we mitigated your loss.”

Was there any prevention here? Absolutely! Are you going to be happy about it? I doubt it. People are paying big money for a false sense of the word “prevention”. They are really paying for and getting “mitigation”.

Now let’s compare the words “prevention” and “mitigation”:

pre·ven·tion [ pri vénshən ] (plural pre·ven·tions)

action that stops something from happening: an action or actions taken to stop somebody from doing something or to stop something from happening

  • the prevention of crime

mit·i·gate [ mítti gàyt ] (past and past participle mit·i·gat·ed, present participle mit·i·gat·ing, 3rd person present singular mit·i·gates)

  • to mitigate a loss

lessen something: to make something less harsh, severe

When put in the context of identity theft: Everyone uses the word prevention when they are referring to credit freeze, fraud monitoring and credit reports, and credit monitoring, data scouring etc.

Now let’s look at it from the context of the consumer: Prevention would be keeping my information completely secure and preventing it from being stolen in the first place.

Real prevention is thwarting the theft of your personal information. Securing your name so nobody uses it for anything. That is what ID theft “prevention” truly is.

If I rely on a credit report, a fraud alert or a credit freeze to stop something from happening, that means that SOMEONE ALREADY HAS OBTAINED MY PERSONAL INFORMATION ! A CRIME HAS ALREADY OCURRED! Now that does not sound like identity theft prevention at all, it most definitely is mitigation. Sure it may have plugged a small hole but in the grand scheme of the information that thief still has, it is like putting a bandage on a bullet wound.

So how can credit freeze, fraud monitoring and credit reports, and credit monitoring qualify as prevention? Well, they stopped something from happening, and that has some limited value, but now who has this information and where are they going with it next? Keep in mind if they have gone to the effort to steal your info, they are going to use it. A car thief does not steal a car and drive around in it until it runs out of gas. They are going to use the stolen device until it no longer meets their needs. The same with your identity, it could be used next for medical services, prescriptions, getting arrested, forging a check, and so on.

An ID theft recovery company stated under the guise of “prevention” that they look for changes in your existing accounts and they look for new accounts and transactions in your name. By doing this, they can detect someone's attempt to steal your identity before it gets too far and before any damage has been done. Sorry people, but if any of this is detected, the damage has been done. SOMEONE HAS ALREADY STOLEN YOUR IDENTITY! THEY HAVE YOUR PERSONAL INFORMAION AND ARE PUTTING IT TO USE! This should not be sugar coated as identity theft “prevention”. The prevention ship has sailed, it is now time to mitigate.

You will still have to wonder when or where they may use it next. And you still may have work to do, to get everything closed down, changed, modified etc. and you may never be completely sure you’ve plugged the gaps because how do you know your personal information has not been passed around or sold on the black market?

So how much is “mitigation” really worth? It is up to you, but most will pay much more for “prevention”.

True identity theft “PREVENTION” is about stopping the crime from occurring, and that starts with preventing and keeping your information out of the hands of the thieves to start with. True prevention is up to you! True prevention starts with you doing the right things with your personal information.

Don’t confuse paying for mitigation services and expect prevention. You may not end up being happy with the results.

Monday, August 20, 2007

Apple Online Lawsuit Brings to Light Another Threat of Identity Theft

A recent lawsuit alleges Apple Store is not in compliance with Fair Credit Reporting Act, thereby making it easier for identity thieves to gather more personal information on consumers.

All businesses need to heed this as an example of things to come and protect their clients' personal information in any way that they can after a class action lawsuit, case number 07-22040, was brought against Apple Store online last week in Florida Federal Court alleging that the stores violated the Fair Credit Reporting Act (FCRA). The FCRA is a federal law designed to help ensure that consumer reporting agencies act fairly, impartially, and with respect for the consumer's right to privacy when preparing consumer reports on individuals.

In 2003, an amendment was added that states, "No person that accepts credit cards or debit cards for the transaction of businesses shall print more than the last five digits of the card number or the expiration date upon any receipt provided to the card holder at the point of sale or transaction."

It was this amendment that Apple Store online was violating. Apple Store was apparently printing credit card expiration dates on the receipts, in addition to the other personal information. Companies were given a three-year grace period to comply with the law and the cost is so miniscule to make the change that most have made the change well in advance of the deadline. Apple Store, as of last week, was still not in compliance.

Identity thieves are getting smarter and smarter. Consumers must stay one step ahead and protect themselves from the financial devastation of identity theft. Consumers expect businesses to uphold the law and do what they can to protect personal information they acquire.

While no proof of a specific identity theft has stemmed from Apple Store's non-compliance, it is a recipe for disaster that reminds consumers to take every precaution when making an online purchase or any purchase with a credit card. The federal government has made efforts to protect citizens from identity theft but consumers must be on the offense and take matters into their own hands.

Place yourself in a situation to protect your personal information from theft and learn to practice fire prevention versus firefighting.

Monday, August 13, 2007

Credit Freeze Not the Only Solution to Identity Theft Prevention

Many people who live in states that allow you to freeze your credit are recognizing the benefits of such actions. But a lot are stopping there and not doing any more feeling they have covered the bases and have done what they can to protect themselves.

Governor Deval Patrick from Massachusetts recently signed into law comprehensive identity theft prevention legislation. This new law will require Massachusetts state residents be notified immediately if their personal information has been lost or stolen via security breaches with businesses and government agencies.

As a part of the legislation, the law also states that consumers have the right to freeze their credit reports to prevent new accounts from being fraudulently opened and also puts into effect strict standards for businesses when disposing of personal information.

The portion of the law that puts into place the standards for disposing of personal information is a step in the right direction to identity theft prevention. But allowing a consumer to freeze their credit report does not prevent the theft.

Personal information can already be in the hands of the wrong people. When personal information, such as social security numbers, drivers' license numbers or bank account information is used for widespread fraud, an emotional and potentially expensive mess is left for the victim to clean up.

Of the millions of victims of identity theft last year, many of them had crimes committed against them that had nothing to do with a credit card or loan. This would not be picked up by on credit report which is the focal point of a credit freeze. The black market is booming for individuals' names and IDs for thieves to sell and the buyers will use them for many different types of identity theft. That could include medical treatments, prescriptions, arrests, and theft of existing or open accounts.

One major solution to the problem is for people to practice self defense when it comes to their personal information. Society has become so accustomed to keeping droves of information available we are leaving it laying around us everywhere. The identity thieves are everywhere picking it up.

When it comes to your identity you need to think in terms of fire prevention and not firefighting.

Thursday, June 7, 2007

Identity Theft with Obsolete Computers

We are coming to a point in time when many people are replacing their computers with a new faster and sleeker versions that will do just about everything they need to keep up with the multi-media world we now live in.

Judging by the age of the internet going mainstream, it will likely be your 3rd replacement with the last two really being used with much of your personal information embedded somewhere on the hard drive. Ten years ago you thought nothing of donating it to a school, or giving it to another family member or even the local Salvation Army.

If you still think that way today about disposing of that old PC, don’t! Yes you want to do the right thing, help out, be conscious of the environment, or any other good reason you may come up with for not just discarding it. But before you take that step, think about identity theft first. Your personal information from the last few years is somewhere on that hard drive. Sure you deleted it, formatted it, cleaned it, but to a persistent thief, they can dig up anything with a little effort, and they do.

Thieves pick them up on auction sites, at garage sales, in used shops, flea markets, all loaded with personal information.

There are software products in the market ranging from $30-$60 that guarantee you that they will wipe that hard drive clean to department of defense standards. I am not denying the validity of these nor endorsing them, but there are other surefire alternatives.


1)Remove the hard drive before giving the PC to anyone, a replacement will cost very little to the recipient verses buying a new PC.

2)Replace the hard drive and designate that PC as a “kids only” PC, let them download all the spyware and viruses while they fileshare using P2P networks. The keylogger they pick up will find nothing good on Disney.com.

3)Replace the hard drive yourself then donate it or give it away.

4)Recycle the entire PC, but remove the hard drive first. Call your local waste management office to find out how, many designate special days for these items.

5)Keep the PC forever and never let it leave the house (some are sentimental about everything)


So what do you do with that old hard drive that you removed? Just pick your weapon of choice and destroy it. Toss it on the grill for a half hour, smash it with a baseball bat, drill a half dozen holes in it, place it in your tool box and use it when you can’t find that hammer.

All this may seem extreme and time consuming, but the hassle of identity theft is much worse.

Friday, May 18, 2007

Medical Identity Theft Can be a Killer

Financial identity theft is in the news all over. It is an epidemic in this country and is showing no real signs of letting up any time soon.

But medical identity theft and how it can impact someone is not a common topic and gets under reported by the media.

Medical identity theft occurs when someone steals your identity for any medical service ranging from prescriptions to full blown surgery.

While the number of victims for this crime is estimated to be low on a yearly basis in the range of 400,000 to 800,000 (compared to the 8-10 million financial thefts) the financial impact is much greater and the impact to personal lives can be deadly.

The theft can occur from an individual to the office staff member or by an actual practitioner. A doctor or psychiatrist may create an unfounded diagnosis in order to inflate bills and steal from your insurance. So how does this affect someone? Try getting a job if an employer does a medical background check on you and finds in your record you are diagnosed as psychotic and suffer from delusions when you really don’t. And then try getting something like that changed. Sure, the keepers of that information are going to let a psychotic person change their record! That can damage you for life! It makes financial identity theft look like a prank.

Someone could get medical treatment in your name for a serious heart condition and then you apply for life insurance. The letter will read “ We are sorry but we cannot offer life insurance to a 38 year old male who has had 3 massive coronaries and bypass surgery.”

The ramifications on a personal life can be horrific. And then try getting it changed. It is not a simple as sending a protest letter to the 3 credit agencies and telling them there is an error.

Can it get worse? Absolutely! You go to the hospital for a major medical issue and find out your health insurance has been maxed out and you are not covered for a treatment that you need. Are you going to jump out of that hospital bed and straighten out the error then come back to get the treatment in a month or two?

The killer issue is if you go in for surgery and someone has received treatment in your name prior to you but your records now reflect the identity thief, including things like blood type, medications and may not reflect your current medications. You receive the wrong blood type, a drug that interacts, or the wrong dose of anesthesia , all that will kill you in a heartbeat.

So now you need to start looking at your medical records before you receive treatment to be sure your true records are reflected.

More on this soon