FACEbook

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, March 29, 2017

In California, Undercover Video of Abortion Clinics, Bad; But For Smog Tests, Great!

    This week, California Attorney General Xavier Becerra charged two pro-life activists from the Center for Medical Progress who recorded secret video of Planned Parenthood representatives discussing selling baby parts from abortion. The two are charged with 15 felonies for violating privacy laws (a questionable decision in and of itself, as I noted on Twitter.)
    Becerra replaced Kamala Harris as CA's attorney general when Harris was elected to the US Senate in 2016. Harris began the investigation of the CMP's secret videos, including arranging an FBI raid of one of the defendant's homes.
    Harris, however, has not always taken a dim view of undercover video. In a 2014, Harris used undercover surveillance video to nab a... smog test scofflaw (scoughlaw?).



    So undercover video to reveal abortion industry misconduct and fraud: bad! Smog test fraud? Good! Thanks, California.

Saturday, January 3, 2015

Feds Looking for Company to Run 'National Data Warehouse' for Obamacare, Medicare

    The Department of Health and Human Services (HHS) is looking for vendors to run its "National Data Warehouse", a database for "capturing, aggregating, and analyzing information" related to beneficiary and customer experiences with Medicare and the federal health insurance Marketplaces. Although the database primarily consists of quality control metrics related to individuals' interactions with customer service, potential contractors are to "[d]emonstrate ... experience with scalability and security in protecting data and information with customer, person-sensitive information including Personal Health Information and Personally Identifiable information (personal health records, etc.)." Vendors are also instructed that one of the requirements of a possible future contract would be "[e]nsuring that all products developed and delivered adhere to Health Insurance Portability and Accountability Act (HIPAA) compliance standards[.]"
    For a number of years, the Centers for Medicare and Medicaid Services (CMS), the division of HHS responsible for Medicare and now Obamacare also, has maintained a "national data warehouse" (NDW) related to the 1-800-MEDICARE helpline. The passage of the Affordable Care Act and subsequent establishment of the Marketplaces has expanded the scope of the NDW. The CMS notice explains the NDW as follows:
The NDW performs a significant role with oversight and monitoring functions under the Virtual Call Center Strategy (VCS) initiative and Medicare Reform legislation. The NDW acts as the central repository for capturing, aggregating, and analyzing information related to the beneficiary experience with Medicare and the consumer experience with Marketplaces. The NDW also serves as a foundation for operational and management reporting to support improved decision-making, business practices, and services to callers. 
    The type of data included in the NDW "includes information for CMS’ Virtual Contact Center operations including, but not necessarily limited to" items such as "Workforce management data", "Quality monitoring", "Medicare disenrollments", "Beneficiary satisfaction surveys", and "Web Chat metrics." The NDW is part of CMS's larger $15 billion "Virtual Data Center" program awarded to multiple vendors in 2012. The eventual vendor for the NDW must be able to integrate and share data with the other Virtual Data Center vendors.
    The description for the "NDW Functional Requirements" included thirty-six items, several with multiple subpoints, and even this list is not meant to be "all inclusive" according to CMS. In addition to these functions, the "contractor shall implement a security program that adheres to CMS security standards." Interested vendors have until January 19, 2015, to respond.


Note: A version of this post first appeared at The Weekly Standard.

Sunday, November 3, 2013

Obamacare Website Source Code Revised to Remove "No Reasonable Expectation Of Privacy" After Sebelius Testimony

    When Kathleen Sebelius testified at a Congressional hearing on Wednesday, she acknowledged the presence of a worrisome statement included in the source code of Healthcare.gov and promised that work was already underway to remove it.  A search of one portion of the code later on Wednesday revealed that the revision was at least partially complete.  The "no reasonable expectation" statement is gone from a large section of code where it had previously appeared.  Repeated attempts on Wednesday to verify that the code had been revised on the specific page where users are asked to accept the privacy policy were unsuccessful due to a system outage at Healthcare.gov for much of the day. However, Thursday morning, a successful logon revealed the statement has been removed there as well:


    As THE WEEKLY STANDARD first reported two weeks ago:
Buried in the source code of Healthcare.gov is this sentence that could prove embarrassing: "You have no reasonable expectation of privacy regarding any communication or data transiting or stored on this information system."  Though not visible to users and obviously not intended as part of the terms and conditions, the language is nevertheless a part of the underlying code for the "Terms & Conditions" page on the site.
    Representative Joe Barton (R-TX) confronted Cheryl Campbell, senior vice president of CGI Federal Inc., one of the main contractors responsible for coding the site, about the language last week and she declined to take responsibility for including it, but said that it was a matter for the Centers for Medicare and Medicaid Services (CMS) to address.  Wednesday, Rep. Barton took up the question with Sebelius, the head of Health and Human Services (HHS) of which CMS is a part.  The Washington Free Beacon reported on Sebelius's response:
“It is my understanding that that is boilerplate language that should not have been in this particular contract because there are — the highest security standards in place and people have every right to expect privacy,” Sebelius said to Rep. Joe Barton (R., Texas). 
Sebelius assured Barton that the language would be removed saying, “we have had those discussions with CGI [Federal] and it is underway. I do absolutely commit to protecting the privacy of the American public and we have asked them to remove that statement.”
    Sebelius's response is a tacit admission from the federal government that the inclusion of the statement posed a legitimate privacy concern, a position not shared by Rep. Frank Pallone (D-NJ) who uttered his widely reported "monkey court" remark in response to Rep. Barton's inquiry at last week's hearing.
    The removal of the inappropriate privacy-related code is not the only revision made recently at the Obamacare website.  Earlier this week, copyright language was restored to an open-source script that was used by programmers at Healthcare.gov without proper attribution.  The change followed a mid-October report by THE WEEKLY STANDARD on the license violation.


Note: A version of this article first appeared at The Weekly Standard.

Thursday, October 17, 2013

Obamacare Exchange Confirms: 'We Are Required to Respond to Certain Requests from Law Enforcement'

    On October 8, THE WEEKLY STANDARD reported that the privacy policy of the Maryland Health Connection (MHC), the state's Obamacare insurance marketplace, included a statement that the marketplace "may share information provided in your application with the appropriate authorities for law enforcement and audit activities."  An email had been sent to the MHC on October 3 requesting clarification of the policy, and included these inquires: Does that include both federal and state authorities?  What type of information from the application might be of interest to law enforcement and/or state/federal auditors?  However, no response was received, and the story was published.
    A follow up email sent to the MHC a day after the story ran was answered by the MHC with the promise of a response the following day, but none was forthcoming.  A third email sent on Friday, October 11, was finally answered late that evening by Communications Manager Betsy Charlow.  The full response reads as follows:
The Maryland Health Connection Privacy Policy has been developed in compliance with federal regulations codified at 45 C.F.R. § 155.260 and 45 C.F.R. § 155.280 to ensure consumer protections and operations of the insurance marketplace. Like all state agencies, we are required to respond to certain requests from law enforcement.
     The regulations cited by Ms. Charlow, while stating that sharing personally identifiable information is proscribed for reasons "that are not permitted or required by law," do not specifically address what types of law enforcement and/or audit activities might qualify for an exception, nor do the regulations detail who is authorized to make the determination for what qualifies for an exception.


Note: A version of this article first appeared at The Weekly Standard.

Monday, October 14, 2013

Obamacare Website Source Code: "No Reasonable Expectation of Privacy"

    The launch of federal government's Obamacare insurance exchange, Healthcare.gov, has been plagued with delays, errors, and poor website design, prompting USA Today to call it an "inexcusable mess" and a "nightmare".  Now comes another example of why the website's reputation is in tatters.  Buried in the source code of Healthcare.gov is this sentence that could prove embarrassing: "You have no reasonable expectation of privacy regarding any communication or data transiting or stored on this information system."  Though not visible to users and obviously not intended as part of the terms and conditions, the language is nevertheless a part of the underlying code for the "Terms & Conditions" page on the site.
    After creating an account on Healthcare.gov, users are asked to click an "I accept" button under some routine Terms & Conditions prohibiting unauthorized attempts to upload information or change the website.  Once users click the button, they may proceed to shop for insurance and enter detailed personal information.  However, when the Terms & Conditions page is visible, the hidden sentence mentioned above along with several others can be seen by using a web browser's "View Source" feature.  A screen grab below shows the visible Terms & Conditions page along with a simultaneous view of the code underlying it:


    The full portion of the code which does not appear on the visible page displayed for users reads as follows:
You have no reasonable expectation of privacy regarding any communication or data transiting or stored on this information system.  At any time, and for any lawful Government purpose, the government may monitor, intercept, and search and seize any communication or data transiting or stored on this information system.  Any communication or data transiting or stored on this information system may be disclosed or used for any lawful Government purpose. [The sentence beginning "To continue" also appears again, but is only visible once on the page as displayed for users.]
    It is unclear why these sentences appear in the code at all since they are not displayed, although the code may simply have been copied from another website that does use the full warning.  In this case, the unwanted portion of the warning was rendered inert with HTML coding tags ("<!--" and "-->") usually used by programmers for inserting comments to explain the purpose of a section of code.  However, the code can be rendered "live" again by simply removing those tags, in which case the full text would appear on the screen to users.  However, it is unclear why the paragraph containing "no reasonable expectation of privacy" would ever have even been considered appropriate in this context.
    The phrase "no reasonable expectation of privacy" is actually a stock phrase used in the terms and conditions of many government websites and information systems, but those who are entering personal, medical and financial information at Healthcare.gov may not find that fact reassuring.  An email sent on Thursday, October 10, requesting comment from Department of Health and Human Services, the agency responsible for the website, has not yet been returned.


Note: A version of this article first appeared at The Weekly Standard.

Tuesday, October 8, 2013

Obamacare Marketplace: Personal Data Can Be Used For "Law Enforcement and Audit Activities"

    Maryland's Health Connection, the state's Obamacare marketplace, has been plagued by delays in the  first days of open enrollment.  If users are able to endure long page-loading delays, they are presented with the website's privacy policy, a ubiquitous fine-print feature on websites that often go unread.  Nevertheless, users are asked to check off a box that they agree to the terms.
    The policy contains many standard statements about information automatically collected regarding internet browsers and IP addresses, temporary "cookies" used by the site, and website accessibility.  However, at least two conditions may give some users pause before proceeding.
    The first is regarding personal information submitted with an application for those users who follow through on the sign up process all the way to the end.  The policy states that all information to help in applying for coverage and even for making a payment will be kept strictly confidential and only be used to carry out the function of the marketplace.  There is, however, an exception: "[W]e may share information provided in your application with the appropriate authorities for law enforcement and audit activities."  Here is the entire paragraph from the policy the includes the exception [emphasis added]:
Should you decide to apply for health coverage through Maryland Health Connection, the information you supply in your application will be used to determine whether you are eligible for health and dental coverage offered through Maryland Health Connection and for insurance affordability programs. It also may be used to assist you in making a payment for the insurance plan you select, and for related automated reminders or other activities permitted by law.  We will preserve the privacy of personal records and protect confidential or privileged information in full accordance with federal and State law. We will not sell your information to others.  Any information that you provide to us in your application will be used only to carry out the functions of Maryland Health Connection. The only exception to this policy is that we may share information provided in your application with the appropriate authorities for law enforcement and audit activities. 
     The site does not specify if "appropriate authorities" refers only to state authorities or if it could include the federal government, as well.  Neither is there any detail on what type of law enforcement and/or audit activities would justify the release of the personal information, or who exactly is authorized to make such a determination.  An email to the Maryland Health Connection's media contact seeking clarification has not yet been answered
    The second privacy term that may prompt caution by users relates to email communications.  The policy reads:
If you send us an e-mail, we use the information you send us to respond to your inquiry. E-mail correspondence may become a public record. As a public record, your correspondence could be disclosed to other parties upon their request in accordance with Maryland’s Public Information Act.
    Since emails to the marketplace could conceivable involve private matters regarding finances, health history, and other sensitive issues, the fact that such information could be made part of the "public record" could prevent users from being as free with their information than they might otherwise be.  However, as noted, any requests for such emails would still be subject to Maryland's Public Information Act which contains certain exceptions to the disclosure rules.


Note: A version of this post first appeared at The Weekly Standard.

Saturday, August 17, 2013

Health Company Agrees to Pay HHS $1.2M After Security Breach

    Even as questions remain about the security of the Federal Services Data Hub to be used in conjunction with the Obamacare marketplaces beginning October 1st, the Department of Health and Human Services (HHS) has agreed to a settlement with the not-for-profit Affinity Health Plans, Inc., for the company's "potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules."  The case stemmed from a photocopier purchased by CBS News and previously leased by Affinity that still contained sensitive personal health information on up to 344,579 individuals:
Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act...   
Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.
    In addition to a payment of $1,215,780, Affinity must attempt to locate other copiers previously leased to remove hard drives containing additional personal data. 
    The OCR director for HHS stressed that this incident should be a lesson to entities that are responsible for storing and using sensitive data [emphasis added]:
"This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent," said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.
    This settlement could also put additional pressure on the Obama administration to provide assurance that necessary precautions are in place before the new healthcare exchanges are opened for business.  As John McCormack noted in THE WEEKLY STANDARD earlier this week, Michael Astrue, former HHS general counsel and Social Security commissioner, has warned
that "unless delayed and fixed" the Obamacare exchanges will "inflict on the public the most widespread violation of the Privacy Act in our history."
    It is unclear what if any consequences HHS will be subject to if privacy breaches occur due to inadequate safeguards in the Obamacare marketplaces.


Note: A version of this article first appeared at The Weekly Standard.

Friday, May 17, 2013

AG Holder's Non-Answer on Warrants for Email

    At a Congressional hearing on May 15, Attorney General Eric Holder faced some rather hostile questions from lawmakers regarding recent Obama administration scandals, such as the IRS targeting of conservative non-profits, the Justice Department acquisition of Associated Press phone records, and Benghazi. However, about three hours into the hearing, a relatively friendly questioner, Susan DelBene (D-WA), inquired about a recent report from the ACLU concerning FBI documents that suggest that the FBI does not need a warrant to obtain access to at least some private emails.  The attorney general's answer was barely an answer at all, despite The Hill's assertion that "Holder backs warrant requirement for most email searches":
Attorney General Eric Holder said on Wednesday that the Justice Department will likely support legislation requiring law enforcement officers to obtain a warrant before accessing private online messages, such as emails or Facebook messages.
"It is something that I think the Department will support," Holder said in testimony before the House Judiciary Committee.
He urged Congress to exempt "certain very limited circumstances" such as civil investigations.
"But the more general notion of having a warrant to obtain the content of communications from a service provider is something that we support," Holder said.
    However, The Hill's article actually reports Holder's answer to DelBene's follow up question.  Here is the full exchange, beginning with DelBene's original question regarding obtaining certain emails without a warrant:


    Perhaps The Hill was simply being kind to the attorney general by not printing his initial answer given the lack of coherence.  Whatever enthusiasm Mr. Holder showed for updating legislation, he was clearly not anxious to surrender the freedom the FBI and the Justice Department currently assume the right to exercise.  This non-answer combined with the non-apology for the seizure of AP phone records cannot give privacy advocates a good feeling about this administration's view of government's limits on its investigative powers.