Sunday, August 28, 2016

Data Breach Insurance

Data breach insurance is becoming a growing concern and a topic for businesses to address their risk management administrative panoply. Considerations may sway a business towards a third-party insurance coverage or a first-party insurance coverage or both depending on the services provided.  Previously posted writing regarding the cyber insurance needs, we discussed the limits that the industry faces with their coverages and how businesses are not covered for cyber events.  Earlier this year the Fourth Circuit rendered a decision that sets a tone for insurers to keep a watch on regarding the commercial general liability insurance (CGLI) required the scope of coverage for data breaches.  That scope is the duty for the insurer to defend the insured business entity for a data breach event.
Initially, it is worth to note that cyber insurance or data breach incident insurance was created to address what general liability insurance did not intend to cover at first.  As these policies metamorphosed with the growth of cyber incident considerations, limitations are placed to account for the many different facets integral to a potential cyber incident, data breach, or sheer cyber negligence event.  The actual scope of coverage within a company’s CGLI is critical and is what was been battered about by the Fourth Circuit in Travelers Indemnity v. Portal Healthcare Solutions, LLC.[1]  The scope of coverage in question was whether data breaches were included in the coverage, and if so, to what extent and for what aspect.
Portal Healthcare Solutions, LLC, (Portal) is a company that provides electronic storage management of patient medical data.  Its  clients are medical service providers including hospitals, who after discovering that medical records were available on the web without password protection, filed a class action suit in the district court in Virginia.  Portal’s CGLI policy was under Traveler’s coverage policies.  Portal sued Travelers when it refused to cover Portal Portal argued that Traveler’s policy covered the cyber incident in question.  The District Court ruled for Portal depicting that Traveler’s coverage obligated it to defend Portal for the data breach incident.  Portal was seeking for Travelers to pay the amount that Portal was liable as a result of the data breach.
Companies considering CGLI will quickly recognize that the insurance vehicle enumerates conditions for liability coverage that include personal and advertising injury.  This addresses the duty of the insurer to pay and defend the insured for its liability and damages incurred as a result of violating privacy rights of customers and the like because of a publication of private information.  The contentious issue that insured companies and insurers wrestle when there is a data breach or cyber incident is to determine if there has occurred a publication of private information.

The facet of ‘publication’ was at issue as to whether it took place as understood.  What was clear from the facts is that the medical records were available on the Internet without password protection.  It was claimed that their availability was tantamount to a publication.   Portal argued that its policies with Travelers obligated Travelers to cover if Portal was liable for an incident where an injury occurred due to electronic publication of information or that causes publicity of a person’s private life.  By virtue that patients’ information was available by searching the Internet, the court deemed that it sufficed as a publication.  The court did not believe that there had to be intent to publish in order for it to constitute a publication.  According to the court, the simple fact of medical record exposure in the realm of the Internet is substantial for publication. The court found that because a publication had occurred by Portal exposing confidential medical records, Travelers became obligated to defend Portal under the policies.[2]
It is noteworthy to consider the precedent of the Recall Total Info case[3] where some transported records that were in containers fell off the vehicle on the highway, in light of the Portal case.  The court in Portal distinguished Recall from its instant case by virtue that the data in Portal was available on the Internet and was easily accessible whereas, in Recall, the data records in containers falling off a transport vehicle could not be construed as accessible and disclosed.   The court in Portal noted that the Connecticut Supreme Court in Recall held that absent information that demonstrates that the confidential data and records were accessed, the incident of private data in containers falling off a transport vehicle on the highway cannot be construed as a publication of private information creating a publicity.  The Court found that to be distinguishable from Portal’s case regarding the public disclosure of confidential records on the Internet.
Furthermore, the element of publicity is not the only limitation of CGLI policies.  The tenor of the knowledge or of the acts of the insured is also imperative to the viability of the insurer’s duty to cover.  For instance, in the Sony Corp. case[4], the court in New York ruled that the insurer did not have a duty to defend and pay for Sony because of  the actions of a hacker and not the acts of Sony.  The hacking was not considered to meet the occurrence of there being a publication or advertising of private information.  Another limitation is when the insured acts with intention and knowingly causing the breach of private information.   A Utah District court in the Federal Recovery Services case[5], held that the insurer was not liable to cover the insured where the insured acted knowingly, willfully and intentionally.
In essence, the policy condition of ‘publication’ was expanded by the Fourth Circuit and it also delineated limitations to the insurer’s duty to pay and defend.  The court noted the importance to consider insured’s actions pertaining to its intention, deliberateness, and awareness with the regard of the data breach incident.  It also noted the importance to distinguish the existence of the acts of third-parties regarding a data breach incident - an intervening factor - compared to where the insured’s actions resulted in a publication.   The absence of the insured’s intention to have private personal information placed on the Internet for anyone to see does not deny that a publication has occurred. Overall, the realm of coverage by CGLI policies will now have a broader appeal to consider amid the limitations for insurers’ duty to cover data breaches.
[1]35 F. Supp. 3d 765, 768 (E.D. Va. 2014).
[2] Id. at 769.
[3] 147 Conn. App. 450, 83 A.3d 664 (Ct. App. Conn. 2013) (aff’d Recall Total Information Mgmt., Inc. v. Federal Ins. Co., SC19201 (Conn. May 18, 2015)).
[4] Zurich Am. Ins. v. Sony Corp. of Am., No. 651982/2011 (NY Sup. Ct. Feb. 21, 2014).
[5] Travelers Property Casualty Co. v. Federal Recovery Servs., Inc.(D. Utah May 11, 2015).
Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.

Monday, August 22, 2016

Data Breach Case Standing and Relevance of Harm


Data breach case standing is the critical element in determining the case’s viability to continue along with the relevance of harm incurred.  As data security breach occurrences amount with frequency, the menu of their handling also adds to the list of settled and or filed. The usual person is petrified when hearing that his or her personal identifiable information (PII) has been compromised in some way or another.  No matter if the compromised data was due to a company’s or agency’s disgruntled former employee, an unidentified hacker, or a nefariously loaded email, the concern is the same.  The internal or external manner of intrusion cause is nevertheless and intrusion to acquire PII of hundreds of not thousands of individuals.  The consternation that lingers is not to be weighed by the courts as having value.  This is despite the apparent value of PII in the open illicit market for social security, birthdate, and credit/debit card numbers.  The claim that by the simple fact of the misappropriation of PII there is a harm and that the PII has value to the plaintiff has historically not swayed courts to conclude that Article III criteria are met.

A plaintiff is required, under article III of the U.S. Constitution, to establish certain elements in federal court that constitute its ability to demonstrate case and controversy enough to stay on and be emblematic of “standing” in a case.   To support this critical element, the complaint must demonstrate that the plaintiff[s] have incurred an injury-in-fact that is a result of its connection to the act claimed to cause the injury and must also demonstrate that the sought after court’s decision can redress the harm by its own decision. The factor of injury-in-fact must be supported by actual or imminent injury and cannot be out of conjecture.[1]  A data breach event presents different circumstances that courts have had to adjust to in order to assess the element of incurred harm by plaintiffs’.
This analytical adjustment took place in the approach taken by the United States Supreme Court to address standing in a data breach case.  In Clapper, the Supreme Court set a standard regarding the injury claimed to have been incurred to be ‘certainly impending’.  The Court stated that it was not enough to make the conclusion that by virtue of the act to acquire PII one cannot make the logical conclusion that harm has occurred or that there is a likelihood or ability of the intruders to read the data and misuse it.  The Court also stated that the nature of the data requires assessment as well in order to ascertain the criticality of the data in unauthorized hands, especially the accessibility of Social Security and credit card numbers with the date of birth data. In Spokeo, despite there being a claimed violation of the D.C. Consumer Protection Procedures Acts, the Court determined that plaintiffs did not demonstrate a concrete harm to substantiate the determination of standing. In Remijas, the Seventh Circuit assessed the possibilities of events from a data breach.  In its analysis, it considered the loss of value of the time the plaintiffs incurred in all their involved efforts to address the breach and circumstances that arose out of the breach that required plaintiff’s action.  The Remijas court seriously considered the costs of time from work and effort by the plaintiff to deal with credit card companies, law enforcement, investigators, and governmental agencies regarding their misappropriated PII.  As the court assessed that the plaintiffs experienced the bother and torment of dealing with the circumstance of their PII being misappropriated.
The element of financial impact has been considered by the Minnesota District Court in In re Target Corp to substantiate the element of standing by virtue of demonstrated financial injuries, including charges, impaired bank account access, the impairment to pay bills, and incurred late payment charges and fees.  In determining the financial impact incurred by plaintiffs, the courts are peering into assessing if the costs were indeed incurred or if there were reimbursable costs.  In  P.F. Chang’s case, the court assessed if the claimed financial harm would uphold the requirement of standing when there were nonmonetary damages.  The court decided that actual injury cannot coexist with a reimbursable cost and it denied the plaintiff’s claims for the risk of identity theft and those associated with mitigation of damages.
In In re Zappos.com case, the court shed light on the guessing that is involved in predicting the time and actions unidentified assailant[s] and their capacities to interpret and use the data.  The noted that it is not absolutely clear that the stolen data would be misused or that it can be used to construe the event of harm to the plaintiff.  Such analysis could be attributed to the Anthem case determination in its second round where the court gave import to the value of PII in the open market and that the disclosure of that information has imputed economic injury.  That economic injury, however, was incurred by the merchants and not the plaintiffs.
No matter the twists and turns that standing has undergone in data breach cases the element of causation is unmovable to interpretation. The harm that a plaintiff incurs from a data breach is always open to analysis that begs to question of who, what, where, and how about the harm, value, and costs, including the impact of what future impact the data breach will have.
[1] See, Lujan v. Defenders of Wildlife, 504 U.S. 555, 560 (1992).
Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.

Friday, August 19, 2016

Computer Abuse by Password Sharing

Computer abuse can occur by the simple act of password sharing to gain access to a computer and its network. Password sharing for use of a computer is seldom realized as a wrongful use.  It is as well not realized by many account holders that sharing their account passwords or access passwords is as well problematic. Accessing digital media accounts of others through the sharing of passwords is construed as an “unauthorized” access to the content. The password bears the meaning of a license for use that has been granted to a specific individual.
The computer use under fraudulent purposes adheres as well to the work environment where a company’s system is accessed with authority essentially equal to a trespasser.  It is important to keep in mind, that that access to particular sections of a company’s data network may not be uniform throughout the company, agency, or entity. A particular person’s position may not allow access to accounting data, employee records, and latest results in IT audits of the company.
The Ninth Circuit, in United States v. Nosal had to determine the confines of sharing passwords with the Computer Fraud & Abuse Act (CFAA), 18 U.S.C. § 1030.  The argument shifts from a hacking concern which is the thrust of the CFAA’s purpose to who is the rightful grantor of authority to use a person’s password.  Amid these two quadrants of analysis lies the conundrum of why did the purpose access the computer system using another’s passwords?  The facts speak that it was about former employees using an employee’s password to access the former employer’s network database. The hinge in the case is more about the intent to intrude into the former employer’s network database than the ramifications of the decision.  The ramifications of the decision clouds over the occurrence of password sharing and accessing digital accounts of friends with their friend’s password.
This case leaves open to determine how to construe “authorized” access to account data and product subscriptions and the permissive grant of such access.  The defendant, in this case, was a former employee who received login credentials from employees in order to access former employer’s system. The lower court did not hold that charges under the CFAA met federal criminal standards.  The United States appealed the lower court’s decision.  Amid concerns of how this action would expand the reach of the CFAA into the criminal sphere by the occurrence of a company computer use policy, the Ninth Circuit in 2012 held that it is not a CFAA violation for accessing a workplace computer in violation of a business computer policy.  Now more recently, the court held that based on the Act’s language “knowingly and with intent to defraud, access a protected computer without authorization or exceed authorized access, and by means of such conduct further the intended fraud and obtain anything of value….” (CFAA Sec 1030 (a)(4), Nosal did acquire access without permission and with an intent that met the criteria of the criminal stigma of the CFAA.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved, Lorenzo Law Firm, P.A.

Saturday, August 6, 2016

Advertising Disclosures

Advertising disclosures required by the Federal Trade Commission are becoming numerous.  As creativity increases so will the efforts for the FTC to find aspects, not to their liking.  As the FTC pursues companies using native advertisers or influencer programs, restrictions will appear clearer to businesses.  FTC’s concern is over the possibility of consumers being confused or deceived by ads that do not appear as ads but as story lines and such.  The FTC’s native advertising guidelines state that under its FTC Act, “an act or practice is deceptive if there is a material misrepresentation or omission of information that is likely to mislead the consumer acting reasonably in the circumstances.  A misrepresentation is material if it is likely to affect consumers’ choices or conduct regarding an advertised product or the advertising for the product.
As their guidelines state, that the information conveyed is seen as well as to how it is conveyed.  It is the means of conveying the message that could lead to consumer deception.  Greater disclosure is seen by the FTC as a needed piece to prevent consumers from being misled.  Therefore the FTC is pushing for clear disclosures revealing the source of the representation in the ad.  What the FTC is zeroing in on are ads that make it appear that the representation is independent of a company’s product or service being conveyed to the general public.  The public should be aware that an ad is a sponsorship of the service or product paid by the company.
There have been several companies that the FTC has targeted, i.e., Machinima, Lord & Taylor, and Warner Bros.  The FTC sought Machinima for ways of promoting Xbox through influencers without adequate disclosure to the general public.  Lord & Taylor was found to have not disclosed the nature of its Nylon Instagram ads where influencers were paid by Lord & Taylor to post.  Warner Bros. was seen to have not disclosed the sponsor for video in a conspicuous manner.  Digital advertising through Internet means using platforms such as YouTube, Twitter, and even Facebook is not going away.  But the FTC will continue to eye the hidden relationship between a paid sponsorship and a nonpaid sponsorship.  The ease in which a company can influence consumer choice and consumer spending through digital means and the opportunities for fraud on the Internet cause concern for consumer protection advocates.  Disclosure of the source of the comment stated in a video promoting a product or service will be required in order to ensure that the general public recognizes it is viewing paid subjective content rather than non-paid objective content.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.

Saturday, July 30, 2016

Cloud Storage Across Borders

Cloud storage of data for business brings efficiencies and as well could bring unbeknown reasons for concern.  Data is not static and neither is how it be directed for load balancing.  It is not only stored, it is shared via transfers and as such it is accessed by users. How the data is accessed and managed differs among businesses.  Whether the processes occur across national borders that is the issue being raised for consideration. If the operating server is located overseas that punctuates the issue of jurisdiction and welcomes international law to the realm of cloud computing via the protocols of the Internet in business practices.
The idea of a national law applying overseas, i.e., ‘extraterritoriality’, is common by the design of international agreements says in the Telecomm industry and natural gas referring to antitrust.[1]  Countries engage in mutual agreements to foster assistance with enforcement of law such as the mutual legal assistance treaties that the U.S. has engaged in with European and South American countries.  But when the national law addresses a function that has the capability of crossing borders, it must not be silent in order to apply cross-border .  When a law was written without cognition of its need to address international aspects of business, the law then is rendered ineffective to address the desired reach.
This transpired with the United Stated government seeking to apply the Stored Communications Act[2] for the purposes of acquiring data in an investigation.  When a law such as the SCA that was promulgated several decades ago without contemplation of business practices extending into cross-border digital records management, it will appear archaic and drastic need of congressional action to enhance its currency to today’s business practices.  In Microsoft Corp. v. U.S.[3], Microsoft sought to appeal the previous magistrate’s and district court’s determination of the United States District Court for the Southern District of New York, which denied Microsoft’s motion to quash a warrant.  The U.S. issued a warrant for records under the SCA that were stored on servers stationed outside of the U.S.  The records sought by the U.S. the contents of users emails.  Microsoft ran the risk of being held in contempt for failure to abide by the warrant.
The actual rendition of the SCA that was overturned was the depiction of the SCA warrant as if it was subpoena and not a search warrant.  With this depiction, the district court construed that Microsoft was compelled to produce that which it has control over and it operated and maintained.  The district court did not consider the location of the where the sought data to be an important consideration.  The district court stated that Congress intended the SCA to oblige ISP (internet service providers) to produce information that was under their control even if it was outside the United States. It, however, stayed its decision allowing for Microsoft’s appeal.
As Microsoft appealed, the issues of extraterritoriality reach of SCA and explicit intent of the statute to apply abroad became crucial was contemplated by the Second Circuit.  It also noted that the data content being sought by the United States was abroad located on a server in Ireland.  With the absence of the SCA having an international scope and the United States conceding the absence, the court determined that a warrant only applied if it is contemplated to be executed within the territorial confines of the United States.  The court depicted that an SCA warrant is not a subpoena and that it did not have that authority.  The Second Circuit rejected the district court’s description that the SCA warrant was equal to a subpoena.
As Congress proceeds to address enhancing the SCA it will encounter the various methods of data storage and integrated data sharing processes.  It will also have to embrace how the SCA will chime with European Union’s new General Data Protection Regulation (GDPR) and the EU-US Privacy Shield.  Privacy of user records remains the central point that will dominate the discourse as the SCA is placed under the microscope for contemporary relevance.
[1] Author’s doctorate in international law:  ‘Determining Jurisdiction Across Borders - Extraterritorial Application of Antitrust’. Doctoral dissertation, 2004 – Josef Korbel School of International Studies, University of Denver, Denver, Colorado.
[2] Stored Communications Act, 18 U.S.C. § 2701-2712.
[3] Microsoft Corporation v. the United States of America, No. 14-2985 (2d Cir. July 14, 2016)

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2013- 2016, all rights reserved, Lorenzo Law Firm, P.A.

Friday, July 22, 2016

Privacy Policy and Terms of Use of Smartphone Games

Privacy concerns over the use of a fun new game are not high among many users who by and large may not read the fine print of terms of use and the game’s privacy policy.  The manner in which the game is subscribed to via the use of an existing social media account for authentication purposes permits the sharing of personal information.  I call this ‘cross-identification’.  This all is under the rubric of making sure the user is who he or she says they are and for security reasons as well.  The concern that emerges is the extent of access that a game may receive unbeknownst to the newly subscribed gamer.
While there are concerns that will be addressed later, the benefits are for the immediate gratification of access and ease of use. The designers of the game believe that the easier it is for the player to sign-up the more the game will be accessed.  The designers use the vehicle already provided by the authenticating credentials that reside in the player’s smartphone.  By using the method, the subscriber does not have to establish a new account.  The broader view of this benefit also causes security minded individuals to imagine a centralizing source of credentials that all soon to be subscribed games, apps, programs, you name it, will just resort to in order to prove who actually is the subscriber.  That centralizing source will house and collect subscriber’s device identification, operating system, location information, personal settings and use information of the device.
This concern arose with Pokémon Go’s success as reported by the Guardian, that it caught Congress’ attention. The concern actually raised by Senator Al Franken was the extent of data that the game would be collecting on the subscribers, which would include children.  What lurks is the possibility of the data being used in ways undisclosed.  The reasons for the information collected as well is important to discern.   In a letter from Senator Franken, the Senator voiced his concern over the extent and need for the collecting and using and sharing of players/subscribers private data and if there has been appropriate informed permission to do so.  These concerns were sent to the developer of Pokémon Go game.
Games and Apps have privacy policies that state their sharing protocol but seldom do the subscribers learn to whom their personal information is given and the purpose for the sharing.  The creeping issue is the matter of how to deal with rogue apps that can be nefarious especially once infiltrating Google’s app store.  The would-be gamer seeking a game may subscribe to a rogue game that extracts the gamers personal information and beyond as unknowingly full access is given to the users Google account as he or she is setting up the game on their iOS device.
To this day, rogue apps are getting harder to identify as they share information by being able to gain full access to accounts on user devices.  With cross-identification, the adage that a chain’s strength is determined by its weakest link may hold true where an email account can serve as a way into a user’s personal treasure trove identifying information.  How that Google linkage for subscription serves a viable vehicle for external and or internal intruder to pierce the veil of a network to garner email information, and the valued token that allows for the linking and user information to be transacted.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2013- 2016, all rights reserved, Lorenzo Law Firm, P.A.

Privacy Policy and Terms of Use of Smartphone Games

Privacy concerns over the use of a fun new game are not high among many users who by and large may not read the fine print of terms of use and the game’s privacy policy.  The manner in which the game is subscribed to via the use of an existing social media account for authentication purposes permits the sharing of personal information.  I call this ‘cross-identification’.  This all is under the rubric of making sure the user is who he or she says they are and for security reasons as well.  The concern that emerges is the extent of access that a game may receive unbeknownst to the newly subscribed gamer.
While there are concerns that will be addressed later, the benefits are for the immediate gratification of access and ease of use. The designers of the game believe that the easier it is for the player to sign-up the more the game will be accessed.  The designers use the vehicle already provided by the authenticating credentials that reside in the player’s smartphone.  By using the method, the subscriber does not have to establish a new account.  The broader view of this benefit also causes security minded individuals to imagine a centralizing source of credentials that all soon to be subscribed games, apps, programs, you name it, will just resort to in order to prove who actually is the subscriber.  That centralizing source will house and collect subscriber’s device identification, operating system, location information, personal settings and use information of the device.
This concern arose with Pokémon Go’s success as reported by the Guardian, that it caught Congress’ attention. The concern actually raised by Senator Al Franken was the extent of data that the game would be collecting on the subscribers, which would include children.  What lurks is the possibility of the data being used in ways undisclosed.  The reasons for the information collected as well is important to discern.   In a letter from Senator Franken, the Senator voiced his concern over the extent and need for the collecting and using and sharing of players/subscribers private data and if there has been appropriate informed permission to do so.  These concerns were sent to the developer of Pokémon Go game.
Games and Apps have privacy policies that state their sharing protocol but seldom do the subscribers learn to whom their personal information is given and the purpose for the sharing.  The creeping issue is the matter of how to deal with rogue apps that can be nefarious especially once infiltrating Google’s app store.  The would-be gamer seeking a game may subscribe to a rogue game that extracts the gamers personal information and beyond as unknowingly full access is given to the users Google account as he or she is setting up the game on their iOS device.
To this day, rogue apps are getting harder to identify as they share information by being able to gain full access to accounts on user devices.  With cross-identification, the adage that a chain’s strength is determined by its weakest link may hold true where an email account can serve as a way into a user’s personal treasure trove identifying information.  How that Google linkage for subscription serves a viable vehicle for external and or internal intruder to pierce the veil of a network to garner email information, and the valued token that allows for the linking and user information to be transacted.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2013- 2016, all rights reserved, Lorenzo Law Firm, P.A.