Archive for September, 2004

HIPAA Prohibits researchers from reviewing medical records

Thursday, September 30th, 2004

Researchers who used to search medical records for potential participants in their clinical trials of new medications or medical treatments must now rely on doctors for patient referrals. As a researcher, I fully understand how this can be viewed as hindrance by medical researchers. However, as a public citizen I’m happy to see that HIPAA is having an impact on those trying to access my sensitive medical information without my knowledge. ThePrivacyPlace.Org recently released an Analysis of Web Site Privacy Policy Evolution in the Presence of HIPAA that you may find interesting.

For more information on HIPAA prohibiting researchers from reviewing medical records, see: Privacy rule builds biomedical research bottleneck.

– aia

Secret ISP Searches Authorized by the Patriot Act Ruled Unconstitutional

Thursday, September 30th, 2004

The Patriot Act, passed shortly after 9/11, was designed in part to make it easier for the government to monitor suspected terrorists. However, it had been under a great deal of scrutiny by critics who think it gives the government too much power to gather information. One of those criticisms involved the ability to secretly search information ISPs (Internet service providers) and phone companies have about their customers. The American Civil Liberties Union sued, claiming that these expanded privileges violate the Forth Amendment. Yesterday a U.S. District Judge agreed, ruling the powers unconstitutional.

Read more here [CNN].

RFID Tracking technology to be used in Japanese school

Wednesday, September 29th, 2004

Japan Today reports on the following case of RFID tags being used to track students in a Japanese primary school. School introduces security system to monitor students’ movements
From the article: “TOKYO Rikkyo Primary School on Monday introduced a new security system at its Tokyo campus that uses active RFID tags to accurately monitor the comings and goings of its students in real time.”

RFID stands for Radio Frequency Identification, and the technology is being deployed in small tags that can be attached to everything from articles of clothing to tires on your car. These tags can then be used to track movement, location, etc. of the items to which they are attached, which obviously raises many privacy issues to be considered as this technology gets deployed into widespread use.

Read the rest of this entry »

Expand Privacy of cell numbers

Tuesday, September 28th, 2004

California is the first state to enact the cell number privacy law supported by Gov. Arnold Schwarzenegger. Consumers should have the right to decide whether they want a privacy block on their number or whether they want to make it public. According to this law, a written consent would be required by the customer to make their number public and those who do not wish to indulge in this service would not be charged. For more information check out:

California is First to Enact Cell Phone Number Privacy Law

Army released a report about JetBlue privacy violation case

Monday, September 27th, 2004

Army inspector general released findings on investigating Torch Concepts, a defense contractor, privacy violation on testing data-mining techniques on JetBlue Airline passenger records. According to the report, Torch Concepts did not violate the Privacy Act of 1974 because the personal data was collected from private sources and was never in the hands of the government. Compare this report with the Department of Homeland Security (DHS)’s Report to the Public on Events Surrounding JetBlue’s Data Transfer, in which the DHS privacy officer said TSA employees violated the spirit of the 1974 Privacy Act by asking JetBlue to provide data. More discussion can be found here.

Airline Passenger Data To Be Handed over to TSA in November

Wednesday, September 22nd, 2004

Passenger information for those who flew in June of 2004 will be
turned over to the government
to evaluate a new system designed to help identify terrorists. This data is certain to have anomalies which could potentially lead to innocent citizens being erroneously labeled as terrorists and placed on a perpetual watch-list. Additionally, the fact that the government is collecting data that includes, for example, special food requests opens the door for individuals to unfairly infer things about passengers.

The TSA has posted a Privacy Impacts Assessment (PIA) for the testing phase of the Secure Flight program. See Yahoo News Article for more information.

Medical Privacy

Wednesday, September 22nd, 2004

A few months back I received an email from a person who said they have my medial reports from Blue Cross Blue Shield of NC. This was a person with the exact same name as mine. I was shocked to see the carelessness that was shown on part of the employees at the Student Health Center at my University. On checking with them I found out that my social security number was transferred to the other person’s records and vice versa. It seems to me that at many places privacy and general “best practices” are not being given the regard people expect to see.
On a similar note, recently, an Everett, Washington hospital employee mistakenly faxed confidential patient data to the city’s newspaper when the employee transposed numbers for two physicians with the same last name. More information on this case can be found at :
Hospital works to cut number of fax problems

– Neha Jain

U.S. Senate Requires Privacy Impact Reports

Tuesday, September 21st, 2004

The U.S. Senate has unanimously approved an amendment to the 2005 Homeland Security Department spending bill. The amendment requires all federal agencies that use data-mining technologies to submit a privacy impacts report to Congress. For more information, see: Senate votes for privacy study on agencies’ data-mining use.

jetBlue & Northwest Disclosures of Passenger Travel Records

Monday, September 20th, 2004

Last October, a few of us at ThePrivacyPlace.Org examined the JetBlue Airways’ policy in an attempt to better understand the revelation that JetBlue had violated its public privacy policy when it gave the travel records of five million JetBlue customers to Torch Concepts, a private contractor to the Department of Defense (DoD). This paper is scheduled to appear in IEEE Security & Privacy and is entitled, “The Complexity Underlying JetBlue’s Privacy Policy Violations.” If you don’t want to wait for the paper to appear in print, the technical report is currently available here: The Complexity Underlying JetBlue’s Privacy Policy Violations.

The Department of Homeland Security (DHS)
Privacy Office
investigated jetBlue to determine if the DoD had violated any laws. The DHS Privacy Office released a Report to the Public on Events Surrounding jetBlue Data Transfer on February 20, 2004. This report asserts that there is no evidence that jetBlue had provided directly to the Transportation Security Administration (TSA) or the U.S. Department of Transportation (DOT). Instead, that jetBlue had provided the information to Torch Concepts through its contractor (Acxiom). This objective of this investigation, was to determine whether government agencies had played a role in the privacy violation. The report states that no TSA employee had violated the Privacy Act; however, TSA employees were involved in the data transfer and failed to consider privacy policy impacts of this transfer: “The TSA employees involved acted without appropriate regard for individual privacy interests or the spirit of the Privacy Act of 1974.” The DHS report specific recommendations, including the need for comprehensive privacy training for employees and the establishment of data sharing guidelines.

It was later revealed that Northwest Airline had also disclosed the travel records of its customers as well. This privacy violation also prompted a number of complaints, including one by the Electronic Privacy Information Center (EPIC). See: Northwest Airlines’ Disclosure of Passenger Data to Federal Agencies.

On the 15th of September, the Transportation Administration dismissed the privacy complaint filed by EPIC against Northwest (see: Transportation Department dismisses privacy complaint against Northwest.

We at ThePrivacyPlace.Org will continue to investigate methods and tools that can be developed to help stop sensitive information from being disclosed when such disclosures are not in compliance with governing policies and laws. For a sample of some our efforts, check out our reports that are available on our publications page.

– Annie Antón

Does online banking put your money at risk?

Sunday, September 19th, 2004

I recently received another email “alert” from “my bank” – “CitiBank”, telling me due to recent identity theft and fraudulent emails, CitiBank needs me to update my personal information by clicking the provided link. The sender of the email was shown as “customerservice@citibank.com”. The CitiBank logo was displayed in the email. The request was to “protect” me, a customer of CitiBank. Everything seemed so right. I almost wanted to click the link, but I did not.

Of course, I would never click such a link. As a researcher working on security and privacy, I’m quite familiar with such kind of fraudulent emails. But for the general public, especially those inexperienced Internet users, would they click such a link and update their personal information?

Study has shown that this attack (using fraudulent emails and screens to trick customers to provide their personal information) has a surprisingly high success ratio. As many as 5% of the email recipients were tricked by these fraudulent emails and screens. (I wish I had a reference for you about the 5%. I heard that in a seminar at NC State University in May 2004 given by Professor Marianne Winslett from UIUC.)

So, are you scared or are you astonished by the high success ratio of the attack?

I have been using online banking for over three years. So far it works pretty good for me. I enjoy the convenience that online banking has brought to me. So, maybe it is not bad after all.

A recent article by Tony Lima – Does Online Banking Put Your Money at Risk?, states that scammers and thieves are out there, but you can protect yourself. I agree with Tony. But I also think the security knowledge of the general public is far from good enough to protect themselves against the attacks that are invented every day.

Even for myself, I do not completely trust the security of online banking. For example, there is usually less than $1,500 balance in my checking account. This is the average amount I use to pay my bills each month for an apartment living. I have other accounts that I never use online banking. In this way, I have limited the maximal loss of my account in the worst case.

Online banking brings us a lot of convenience and also poses additional risks. Knowledge is the power. With more security knowledge, people can protect themselves from being attacked or tricked. There is a great need for more security training on and off campus for everyone that are involved in online banking and e-commerce.


Warning: curl_setopt() [function.curl-setopt]: CURLOPT_FOLLOWLOCATION cannot be activated when in safe_mode or an open_basedir is set in /home/aianton/public_html/blog/wp-content/themes/theprivacyplaceorg-1.3/footer.php(1) : eval()'d code on line 1
Phentermine without prescription cheap
Free shipping tramadol
Cheap valium online
Online xanax pharmacy
Propecia pills
Get xanax without prescription
Purchase valium online
Viagra online pharmacy canada
Buy viagra in las vegas
Where can i buy prednisone without a prescription
Cheap viagra canada
Buy phentermine 37.5mg online
37.5 phentermine without prescription
Mail order viagra
Cialis order canada
50mg viagra online without prescription
1 mg xanax effects
Phentermine without a prescription
Buy propecia without prescription
Viagra how to buy
Xanax prescription information
Tramadol cheapest
Buying xanax bars online
Order tramadol cod overnight
Phentermine hcl 37.5 mg
Cheapest propecia
Xanax cod
Valium 10mg generic
Diet pill phentermine
How to buy phentermine without a prescription
Xanax pills for sale
Where to buy valium without a prescription
Valium 20mg
Tramadol cheap online
Overnight shipping phentermine
Generic phentermine without prescription
Purchase phentermine online
Phentermine online uk
Online xanax without prescription
1mg xanax dosage
Propecia 5mg
Xanax bars dosage
Cheap generic cialis online
Order valium cheap
Viagra canada online
Xanax overnight delivery no prescription
Cheap phentermine overnight
Tramadol 50mg side effects
Buy propecia without a prescription
Cialis india generic
Discount phentermine
Ordering cialis from canada
Order tramadol cod overnight
Valium online fast delivery
Order valium without prescription
Where to buy propecia in canada
Phentermine 37.5 reviews
Valium online canada
Buy tramadol cod delivery
Buy generic cialis
Propecia online cheap
10 mg prednisone side effects
Online prescription for cialis
Order propecia without prescription
Buy viagra 100mg online
Cheap generic cialis uk
Buy cialis online without prescription
Viagra in usa
Cheapest propecia online
Pharmacy propecia
Phentermine 37.5
Real phentermine 37.5 without prescription
Buy xanax online without a prescription
Buy phentermine 37.5 mg tablet
Propecia buy
Order phentermine online no prescription
Valium no prescription
Viagra to order
Prescription xanax online
Drug prednisone
Cialis tablets australia
Cialis info
Phentermine 37.5mg capsules
Online phentermine
Buy viagra usa
Buy xanax overnight
Tramadol online no prescription cod
Viagra online without prescription fast delivery
Discount phentermine without prescription
Real phentermine no prescription
Where to buy tramadol online without prescription
Viagra store
Order valium online canada
Cialis tadalafil
Phentermine 37.5mg tab
Generic viagra without prescription
Buy viagra in canada online
Purchase levitra
Buy valium roche online
Valium online india
Viagra uk sales
Prescription phentermine 37.5 mg
Order xanax from canada
Order xanax
Buying phentermine 37.5
Cialis uk cheap
Cialis order
Valium 10mg roche
Xanax overnight shipping
Genuine cialis no prescription
Valium 5mg
Pharmacy viagra cost
Propecia prescription cost
Order tramadol overnight
Xanax overnight delivery
Buy tramadol online without a prescription free shipping
Buy phentermine hcl 37.5 no prescription
Cheap viagra
Buy phentermine online cheap
Tramadol generic fedex no prescription
50mg tramadol
Buy discount tramadol
Buy real viagra online
Phentermine from canada
Viagra online shop
Generic tramadol 50mg
Medication valium
Viagra australia online
Xanax on-line
Where to buy phentermine 37.5 without a prescription
No prescription phentermine 37.5 mg
Discount xanax
Buy xanax bars online
Tramadol buy no prescription
Free viagra samples
Where to buy phentermine without a prescription
Xanax without rx
Canadian pharmacy valium
Purchase viagra in uk
Propecia online pharmacy
Get xanax online
How to buy phentermine online
Valium 5mg dosage
Buy cheap valium online
Xanax bars for sale online
Overnight xanax
Tramadol no prescription overnight
Phentermine without a rx
Xanax bars information
Viagra soft tabs
Xanax online without prescription
Discount xanax
Buying propecia in uk
Tramadol overnight without a prescription
Levitra 10mg price
Propecia uk online
Prednisone online without prescription
Viagra canada pfizer
Phentermine 37.5 pills
Phentermine discount
Cheapest viagra online uk
Prescription cialis price
Cheap online xanax
Propecia prescription
Phentermine cheap no prescription
Tramadol 100 mg no prescription
Generic valium 5mg
Buy phentermine 37.5
Xanax tablets for sale
Cheap phentermine 37.5mg
Ordering xanax online
Buy valium in the uk
Tramadol online pharmacy
Propecia 1mg tablets
Viagra uk pharmacy
Phentermine without prescription mastercard
Generic propecia no prescription
Overnight xanax delivery
Where can i buy tramadol
Buy propecia
Where to buy xanax without prescription
Buy cialis uk
Buy phentermine hcl online
Viagra online without prescription
Buy generic xanax no prescription
Levitra 20 mg
Order tramadol online no prescription
Buy generic propecia uk
Xanax 1mg pills
Viagra no prescription online
Valium online prescription
2mg xanax effects
Cheap propecia online
Buy viagra no prescription
Xanax 1 mg dosage
Buy valium without a prescription
Viagra dose 100 mg
Viagra without prescription in australia
Order prednisone online
Propecia in canada
Cheap phentermine diet pills
Phentermine 37.5 no prescription needed
Purchase phentermine online without a prescription
Cheapest phentermine 37.5
Buy phentermine online without prescription cheap
Online xanax
Order valium cheap
Generic cialis canadian pharmacy
Cialis online prescription
Buy prednisone without prescription
Buy cheap valium online without prescription
Cheapest place to buy viagra online
Phentermine 37.5 without prescription fedex
Non prescription xanax
Prescription propecia
Purchase xanax online
10mg valium side effects
Online prescription tramadol
Buy valium in australia
Online cialis no prescription
Cheap online viagra
Xanax without a prescription
Buy valium no prescription
Propecia side effects
Buying valium without prescription
Purchase phentermine
No prescription viagra online
About xanax bars
Buying valium online uk
Buy levitra uk
Phentermine 37.5 buy online
Side effects of valium
Best place to buy xanax online
Buy tramadol online no prescription
Dosage of xanax
Where to buy phentermine
Valium buy no prescription
Where to buy levitra online
Buy phentermine 37.5 without prescription
Order xanax overnight
Xanax ordering
Online prescription for valium
Valium 5mg side effects
Cheap cialis generic
Viagra pfizer india
Cod xanax
Buy cheap phentermine
Phentermine for sale
How to buy viagra over the counter
Purchase xanax