<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compensation Solutions Blog &#187; Identity Theft</title>
	<atom:link href="http://blog.csihro.com/index.php/tag/identity-theft/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.csihro.com</link>
	<description>Human Resources Outsourcing (HRO - PEO - ASO - Payroll - Agency)</description>
	<lastBuildDate>Thu, 17 May 2012 18:05:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Red Flags Rule Scheduled to Take Effect June 1, 2010</title>
		<link>http://blog.csihro.com/index.php/2010/05/26/red-flags-rule-scheduled-to-take-effect-june-1-2010/</link>
		<comments>http://blog.csihro.com/index.php/2010/05/26/red-flags-rule-scheduled-to-take-effect-june-1-2010/#comments</comments>
		<pubDate>Wed, 26 May 2010 14:05:23 +0000</pubDate>
		<dc:creator>Teresa DeSousa</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Red Flags Rule]]></category>

		<guid isPermaLink="false">http://blog.csihro.com/?p=310</guid>
		<description><![CDATA[After several delays, the Red Flags Rule is scheduled to take effect on June 1, 2010.  This rule, enforced by the Federal Trade Commission (FTC), requires businesses and organizations to develop and implement a written Identity Theft Prevention Program designed to detect signs, or “red flags” of identity theft in their daily operations, take steps [...]]]></description>
			<content:encoded><![CDATA[<p>After several delays, the <strong>Red Flags Rule</strong> is scheduled to take effect on June 1, 2010.  This rule, enforced by the Federal Trade Commission (FTC), requires businesses and organizations to develop and implement a written Identity Theft Prevention Program designed to detect signs, or “red flags” of identity theft in their daily operations, take steps to prevent it and mitigate the danger caused by it.</p>
<p>The <strong>Red Flags Rule</strong> applies to “financial institutions” and “creditors” who have “covered accounts.” <span style="text-decoration: underline;">Financial institutions</span> include banks, credit unions, or any other entity that holds a transaction account belonging to a customer, whether directly or indirectly, and that offers accounts where the customer can make payments or transfers to third parties.</p>
<p> <span style="text-decoration: underline;">Creditors</span> include businesses or organizations that regularly defer payment for goods or services, or who provide goods and services and bill customers later.  Creditors are also entities who regularly offer, arrange for or extend credit to customers.  Utility companies, health care providers, telecommunications companies, finance companies, mortgage brokers and real estate agencies, automobile dealers and retailers that offer financing or help consumers get financing from others fall into this category.   </p>
<p><strong>NOTE</strong>:  Simply accepting credit cards as a form of payment does <span style="text-decoration: underline;">not</span> designate you a creditor under the <strong>Red Flags Rule</strong>. </p>
<p><span style="text-decoration: underline;">Covered accounts</span> are those that are offered primarily for personal, family or household uses that permit multiple payments or transactions, or an account for which there is a reasonable risk of identity theft.  Examples are credit card accounts, loans, utility accounts, bank accounts and small business accounts.</p>
<p>An Identity Theft Program must include four (4) basic elements:</p>
<p>1.  Reasonable policies and procedures to identify the “red flags” that companies may run across in the daily operation of business, suspicious patterns, practices, or specific activities that indicate the possibility of identity theft.</p>
<p>2.  The program must be designed to detect the red flags described in the policies.  For example, if you have identified fake driver’s licenses as a red flag, then you must have procedures in place to detect them.</p>
<p>3.  The program must spell out the appropriate actions to take when red flags are detected.</p>
<p>4.  Employers must address the methods by which they will re-evaluate their procedures periodically to ensure they are relevant at all times.</p>
<p>Employers will also need to designate the person from the organization who will be responsible for implementing and administering the plan effectively, and offer appropriate staff training.  Employers must also address how to monitor contractors’ compliance.  Finally, the head of the company must approve the plan, whether it be the Board of Directors or an appropriate senior employee in the organization. </p>
<p>For more information, please see the FTC’s pamphlet, <a title="http://www.ftc.gov/bcp/edu/pubs/business/idtheft/bus23.pdf" href="http://www.ftc.gov/bcp/edu/pubs/business/idtheft/bus23.pdf">Fighting Fraud with the Red Flags Rule:  A How-To Guide For Business</a>.</p>
<div class="share-this"><div id="twitter-share-button" style="width:100px;float:left"><a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal">Tweet</a></div><div class="plusone" style="width:70px;float:left"><g:plusone size="medium" annotation="bubble" href="http://blog.csihro.com/index.php/2010/05/26/red-flags-rule-scheduled-to-take-effect-june-1-2010/"></g:plusone></div><div class="facebook-share-button">
					<iframe src="https://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fblog.csihro.com%2Findex.php%2F2010%2F05%2F26%2Fred-flags-rule-scheduled-to-take-effect-june-1-2010%2F&amp;send=&amp;layout=&amp;width=&amp;show_faces=&amp;action=&amp;colorscheme=&amp;font=&amp;height=21" 
						scrolling="no" 
						frameborder="0" 
						style="border:none; overflow:hidden; width:px; height:21px;" 
						allowTransparency="true"></iframe>
				</div></div>]]></content:encoded>
			<wfw:commentRss>http://blog.csihro.com/index.php/2010/05/26/red-flags-rule-scheduled-to-take-effect-june-1-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Massachusetts Identity Theft/Data Security Regulations Effective March 1, 2010</title>
		<link>http://blog.csihro.com/index.php/2010/02/16/the-massachusetts-identity-theftdata-security-regulations-effective-march-1-2010/</link>
		<comments>http://blog.csihro.com/index.php/2010/02/16/the-massachusetts-identity-theftdata-security-regulations-effective-march-1-2010/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 20:08:13 +0000</pubDate>
		<dc:creator>Teresa DeSousa</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Massachusetts]]></category>

		<guid isPermaLink="false">http://blog.csihro.com/?p=259</guid>
		<description><![CDATA[Massachusetts updated its identity theft policy requirements, effective March 1, 2010.  The rule applies to all businesses in the Commonwealth, who collect and retain personal information in connection with the provision of goods and services or for the purposes of employment. All policies must be in writing, but the scope and complexity of the policy [...]]]></description>
			<content:encoded><![CDATA[<p>Massachusetts updated its identity theft policy requirements, effective March 1, 2010. </p>
<p>The rule applies to all businesses in the Commonwealth, who collect and retain personal information in connection with the provision of goods and services or for the purposes of employment. All policies must be in writing, but the scope and complexity of the policy is dependent on the nature and scope of each business.  Employees must be trained on what they need to do to protect confidential information.</p>
<p>The updates to the legislation cover four (4) areas:</p>
<ol>
<li>The rule adopts a risk-based approach.  Businesses are required to establish a written security program that takes into account the particular business&#8217; size, scope of business, amount of resources, nature and quantity of data collected or stored, and the need for security.  This is particularly important for small businesses who typically do not handle or store large amounts of personal and confidential information.</li>
<li>What had been requirements for inclusion in policies have been removed, and should be used as guidance only.</li>
<li>The encryption requirement has been changed to be technology neutral and technical feasibility has been applied to all computer security requirements.</li>
<li>The third party vendor requirements have been changed to be consistent with Federal law.</li>
</ol>
<p>The statute can be found at <a href="http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf">http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf</a>, and FAQs can be found at <a href="http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf">http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf</a>.</p>
<div class="share-this"><div id="twitter-share-button" style="width:100px;float:left"><a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal">Tweet</a></div><div class="plusone" style="width:70px;float:left"><g:plusone size="medium" annotation="bubble" href="http://blog.csihro.com/index.php/2010/02/16/the-massachusetts-identity-theftdata-security-regulations-effective-march-1-2010/"></g:plusone></div><div class="facebook-share-button">
					<iframe src="https://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fblog.csihro.com%2Findex.php%2F2010%2F02%2F16%2Fthe-massachusetts-identity-theftdata-security-regulations-effective-march-1-2010%2F&amp;send=&amp;layout=&amp;width=&amp;show_faces=&amp;action=&amp;colorscheme=&amp;font=&amp;height=21" 
						scrolling="no" 
						frameborder="0" 
						style="border:none; overflow:hidden; width:px; height:21px;" 
						allowTransparency="true"></iframe>
				</div></div>]]></content:encoded>
			<wfw:commentRss>http://blog.csihro.com/index.php/2010/02/16/the-massachusetts-identity-theftdata-security-regulations-effective-march-1-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Flag Rules Take Effect November 1, 2009</title>
		<link>http://blog.csihro.com/index.php/2009/10/23/red-flag-rules-take-effect-november-1-2009/</link>
		<comments>http://blog.csihro.com/index.php/2009/10/23/red-flag-rules-take-effect-november-1-2009/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 14:18:55 +0000</pubDate>
		<dc:creator>Teresa DeSousa</dc:creator>
				<category><![CDATA[Main]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Red Flags Rule]]></category>

		<guid isPermaLink="false">http://blog.csihro.com/?p=48</guid>
		<description><![CDATA[The Red Flags Rule will take effect on November 1, 2009.  This rule, enforced by the Federal Trade Commission (FTC), requires businesses and organizations to develop and implement a written Identity Theft Prevention Program designed to detect signs, or “red flags” of identity theft in their daily operations, take steps to prevent it and mitigate [...]]]></description>
			<content:encoded><![CDATA[<p>The <span style="color: #ff0000;"><strong>Red Flags Rule</strong> </span>will take effect on <strong>November 1, 2009</strong>.  This rule, enforced by the Federal Trade Commission (FTC), requires businesses and organizations to develop and implement a written Identity Theft Prevention Program designed to detect signs, or “red flags” of identity theft in their daily operations, take steps to prevent it and mitigate the danger caused by it.</p>
<p>The <strong><span style="color: #ff0000;">Red Flags Rule</span></strong> applies to “financial institutions” and “creditors” who have “covered accounts.” <span style="text-decoration: underline;">Financial institutions</span> include banks, credit unions, or any other entity that holds a transaction account belonging to a customer, whether directly or indirectly, and that offers accounts where the customer can make payments or transfers to third parties.</p>
<p><span style="text-decoration: underline;">Creditors</span> include businesses or organizations that regularly defer payment for goods or services, or who provide goods and services and bill customers later.  Creditors are also entities who regularly offer, arrange for or extend credit to customers.  Utility companies, health care providers, telecommunications companies, law firms, finance companies, mortgage brokers and real estate agencies, automobile dealers and retailers that offer financing or help consumers get financing from others fall into this category.</p>
<p><strong>NOTE</strong>:  Simply accepting credit cards as a form of payment does <span style="text-decoration: underline;">not</span> designate you a creditor under the <strong><span style="color: #ff0000;">Red Flags</span> <span style="color: #ff0000;">Rule</span></strong>.</p>
<p><span style="text-decoration: underline;">Covered accounts</span> are those that are offered primarily for personal, family or household uses that permit multiple payments or transactions, or an account for which there is a reasonable risk of identity theft.  Examples are credit card accounts, loans, utility accounts, bank accounts and small business accounts.</p>
<p>Your Identity Theft Program must include four (4) basic elements:</p>
<ol>
<li>You must institute reasonable policies and procedures to identify the “red flags” that you may run across in the daily operation of your business, suspicious patterns, practices, or specific activities that indicate the possibility of identity theft.</li>
<li>The program must be designed to detect the red flags described in your policies.  For example, if you have identified fake driver’s licenses as a red flag, then you must have procedures in place to detect them.</li>
<li>Your program must spell out the appropriate actions to take when red flags are detected.</li>
<li>You must address the methods by which you will re-evaluate your procedures periodically to ensure they are relevant at all times.</li>
</ol>
<p>You will also need to designate the person from your organization who will be responsible for implementing and administering the plan effectively, and offer appropriate staff training.  You must also address how you will monitor your contractors’ compliance.  Finally, the head of your company must approve the plan, whether it be the Board of Directors or an appropriate senior employee in your organization.</p>
<p>For more information, please see:</p>
<p><a href="http://www.ftc.gov/bcp/edu/pubs/business/idtheft/bus23.pdf" target="_blank">http://www.ftc.gov/bcp/edu/pubs/business/idtheft/bus23.pdf</a> and frequently asked questions at <a href="http://www.ftc.gov/bcp/edu/microsites/redflagsrule/faqs.shtm" target="_blank">http://www.ftc.gov/bcp/edu/microsites/redflagsrule/faqs.shtm</a>.</p>
<div class="share-this"><div id="twitter-share-button" style="width:100px;float:left"><a href="http://twitter.com/share" class="twitter-share-button" data-count="horizontal">Tweet</a></div><div class="plusone" style="width:70px;float:left"><g:plusone size="medium" annotation="bubble" href="http://blog.csihro.com/index.php/2009/10/23/red-flag-rules-take-effect-november-1-2009/"></g:plusone></div><div class="facebook-share-button">
					<iframe src="https://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fblog.csihro.com%2Findex.php%2F2009%2F10%2F23%2Fred-flag-rules-take-effect-november-1-2009%2F&amp;send=&amp;layout=&amp;width=&amp;show_faces=&amp;action=&amp;colorscheme=&amp;font=&amp;height=21" 
						scrolling="no" 
						frameborder="0" 
						style="border:none; overflow:hidden; width:px; height:21px;" 
						allowTransparency="true"></iframe>
				</div></div>]]></content:encoded>
			<wfw:commentRss>http://blog.csihro.com/index.php/2009/10/23/red-flag-rules-take-effect-november-1-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  blog.csihro.com/index.php/tag/identity-theft/feed/ ) in 0.13745 seconds, on May 19th, 2012 at 10:25 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on May 19th, 2012 at 12:25 pm UTC -->
