IDENTITY THEFT & THE RED FLAGS RULE Presented by Brady Keith, Assistant General Counsel CREDIT MANAGEMENT SERVICES, INC.

Slides:



Advertisements
Similar presentations
Red-Flag Identity Theft Requirements February 19th 2009 Cathy Casagrande, Privacy Officer.
Advertisements

Fair Credit Reporting Act You must be told if information in your file has been used against you You can find out what is in your file You can dispute.
Chapter 27 Your Credit and the Law pp Learning Objectives 1.Explain 1.Explain how government protects credit rights. 2. Name 2. Name federal.
UNDERSTANDING RED FLAG REGULATIONS AND ENSURING COMPLIANCE University of Washington Red Flag Rules Protecting Against Identity Fraud.
Red Flags Compliance BANKERS ADVISORY 1 Red Flags Compliance Fair & Accurate Credit Transactions Act (FACTA) Identity Theft Prevention.
Compliance with Federal Trade Commission’s “Red Flag Rule”
Red Flags Rule BAS Forum August 18, What is the Red Flags Rule? Requires implementation of a written Identity Theft Prevention Program designed.
Detecting, Preventing and Mitigating Identity Theft Presented by the Bursar’s Office.
1 Identity Theft Program Procedures Viewing RED FLAGS in the MEDITECH System.
Red Flag Rules: What they are? & What you need to do
Red Flag Identity Theft Training California State University, Fullerton Campus Information Technology Training August 2012.
Protecting Personal Information Guidance for Business.
FAIR AND ACCURATE CREDIT TRANSACTIONS ACT (FACTA)- RED FLAG RULES University of Washington Red Flag Rules Protecting Against Identity Fraud.
The Third International Forum on Financial Consumer Protection & Education “Fostering Greater Consumer Protection & Education” Preventing Identity Theft.
Are You Ready? Identity fraud and identity management are quickly becoming critical operational concerns for the financial industry. The Red Flags Guidelines.
Time to Wave the White Flag – Compliance with the FTC’s Identity Theft Red Flags Rule William P. Dillon, Esq. Messer, Caparello & Self, P.A Centennial.
©2012 CliftonLarsonAllen LLP Red Flags- Why This Matters to You An overview of the FACT Act Identity Theft Red Flag Rule and its current impact.
Identity Theft “Red Flags” Rules Under the FACT Act Reid Fudge CISSP, CISA Pulte Mortgage, LLC November 2008.
The Minnesota State Colleges and Universities system is an Equal Opportunity employer and educator. The Red Flag Rule Detecting, Preventing, and Mitigating.
Red Flags 101. What It’s All About Section’s 114 and 315 of the FACT Act were implemented in October 2007 and became effective January 1, These.
BEWARE! IDENTITY THEFT CARL JOHNSON FINANCIAL LITERACY JENKS HIGH CSHOOL.
RMG:Red Flags Rule 1 Regal Medical Group Red Flags Rule Identify Theft Training.
Red Flags Rule & Municipal Utilities
 Federal Trade Commission (FTC)  Final Regulations issued November, 2007 › Effective 1/1/08 › Compliance and Enforcement Date 11/1/08  Enforcement.
University of Minnesota Identity Theft Prevention Program: Red Flags Rule Detecting, Preventing, and Mitigating Identity Theft This presentation was adapted.
© 2008 Smith Moore Leatherwood LLP. ALL RIGHTS RESERVED. Raising a “Red Flag”: Understanding the Fair and Accurate Credit Transactions Act, the “Red Flag”
About ONLINE Industry leader for more than 50 years Headquartered in North Carolina Originally a small merchant credit bureau In 1997, focus shifted from.
1 The FACT Act – An Overview The FACT Act An Overview of the Final Rulemaking on Identity Theft Red Flags and Address Discrepancies Naomi Lefkovitz Attorney,
Identity Theft and Red Flag Rules Training Module The University of Texas at Tyler.
© Oklahoma State Department of Education. All rights reserved. 1 Beware! Consumer Fraud Standard 9. 1 Fraud and Identity Theft.
Scams and Schemes. Today’s Objective I can understand what identity theft is and why it is important to guard against it, I can recognize strategies that.
Detecting, Preventing, and Mitigating Identity Theft
CONSUMER PROTECTION AND LITIGATION: CONSUMER PROTECTION AND LITIGATION: Ryan Mehm Attorney Bureau of Consumer Protection Federal Trade Commission The views.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
UAMS Identity Theft Program—Red Flag Rule Computer Based Training (CBT) Module Prepared for UAMS Registration and Admissions Personnel Each slide contains.
Copyright 2007, Integrated Compliance Solutions, LLC FACT Act Red Flags Bank Compliance Association of Connecticut September 3, 2008 Copyright 2007, Integrated.
Tiffany George Attorney, Division of Privacy & Identity Protection Federal Trade Commission COMPLYING WITH THE RED FLAGS RULE & ADDRESS DISCREPANCY RULE.
FAIR CREDIT REPORTING ACT.  Serves the following principal purposes:  To regulate the consumer-reporting industry.  To prohibit unfair actions from.
2015 ANNUAL TRAINING By: Denise Goff
Understanding the Fair and Accurate Credit Transaction Act, the “Red Flag” Regulations, and their impact on Health Care Providers Raising a “Red Flag”
The FTC’s Red Flag Rule. FTC Red Flag Regulations Why the Red Flag Regulations?
Red Flag Rules Training Class SD 428. Red Flag Rules SD 428 The Red Flag Rules course (SD 428) was implemented at UTSA to meet the requirements and guidelines.
Identity Protection (Red Flag/PCI Compliance/SSN Remediation) SACUBO Fall Workshop Savannah, GA November 3, 2009.
FTC RED FLAG RULE As many as nine million Americans have their identities stolen each year. Identity thieves may drain their accounts, damage their credit,
Lydia E. Payne-Johnson Peter A. Rabinowitz PricewaterhouseCoopers, LLP Harvard University August 20, 2008 New Identity Theft Red Flags Rule: What is New.
IDENTITY THEFT. RHONDA L. ANDERSON, RHIA, PRESIDENT ANDERSON HEALTH INFORMATION SYSTEMS, INC.
Copyright© 2010 WeComply, Inc. All rights reserved. 10/10/2015 FACTA Red Flags.
Available from BankersOnline.com/tools 1 FACT ACT RED FLAG GUIDELINES.
Red Flag Training IDENTITY THEFT PREVENTION PROGRAM OVERVIEW AUTOMOTIVE.
New Identity Theft Rules Rodney J. Petersen, J.D. Government Relations Officer Security Task Force Coordinator EDUCAUSE.
Technology Supervision Branch Interagency Identity Theft Red Flags Regulation Bank Compliance Association of CT Bristol, CT September 3, 2008.
Back to Table of Contents pp Chapter 27 Your Credit and the Law.
Chapter 27 Your Credit and the Law pp Learning Targets 1.Explain 1.Explain how government protects credit rights. 2. Name 2. Name federal laws.
Prevention of Identity Theft. Why now, Why us? Federal Trade Commission (FTC) regulations for Identity Theft which may not apply, but it is good business.
Protecting Yourself from Fraud including Identity Theft Personal Finance.
Protecting Your Assets By Preventing Identity Theft 1.
Protecting Yourself from Fraud including Identity Theft Advanced Level.
Unit Five Your Money – Keeping It Safe and Secure Identity Theft Part II Resource: NEFE High School Financial Planning Program.
1 Identity Theft Prevention and the Red Flag Rules.
Red Flags Rule Red Flags Rule Staff Training Course Practice Administrator SAMPLE AAP PEDIATRICS.
By Amanda Cowan.  When another person steals your information and uses it to commit fraud or other crimes  The information stolen can be:  Credit Card.
University of St. Thomas
Protecting Personal Information Guidance for Business.
Red Flags Rule An Introduction County College of Morris
Identity Theft Prevention Program Training
Protecting Yourself from Fraud including Identity Theft
Clemson University Red Flags Rule Training
FACT Act Training for Staff Identity Theft “Red Flags”
Getting the Green Light on the Red Flags Rule
Presentation transcript:

IDENTITY THEFT & THE RED FLAGS RULE Presented by Brady Keith, Assistant General Counsel CREDIT MANAGEMENT SERVICES, INC.

Important Notice This presentation is not intended to be a full and exhaustive explanation of the law in any area. This presentation is not legal advice and may not be used as legal advice. Legal advice must be tailored to the specific circumstances of each question, case, or controversy. This presentation should not and may not be used to replace the advice of your own legal counsel.

Identity Theft Identity theft occurs when someone uses another person’s identifying information to obtain goods, services, money, etc. Identifying information may include a person’s: name Social Security number medical insurance number credit card number According to the Federal Trade Commission’s (“FTC”) Bureau of Consumer Protection, an estimated nine million Americans have their identities stolen each year. Identity thieves may drain accounts, damage credit, and even put medical treatment at risk. The cost to business — left with unpaid bills racked up by scam artists — can be staggering, too.

The Red Flags Rule The Red Flags Rule is a federal law that’s enforced by the FTC and other agencies. The Red Flags Rule requires many businesses and organizations to implement a written identity theft prevention program designed to detect the “red flags” of identity theft in their day-to-day operations, take steps to prevent the crime, and mitigate its damage.

The Red Flags Rule The Red Flags Rule requires certain financial institutions and creditors to conduct a periodic risk assessment to determine if they have covered accounts. The determination isn’t based on the industry or sector, but rather on whether a business’ activities fall within the relevant definitions. A business must implement a written identity theft prevention program only if it has covered accounts.

The Bottom Line Regardless of whether your facility is required to follow the Rule, the bottom line is that an identity theft detection and prevention program can help spot suspicious patterns and prevent the costly consequences of identity theft.

Identifying Red Flags What are “red flags”? They’re the potential patterns, practices, or specific activities indicating the possibility of identity theft.

Identifying Red Flags - Considerations Risk Factors. Different types of accounts pose different kinds of risk. For example, red flags for deposit accounts may differ from red flags for medical accounts, and those for consumer accounts may differ from those for business accounts. When you are identifying key red flags, think about the types of accounts you offer or maintain; how you open accounts; how you provide access to accounts; and what you know about identity theft in your business.

Identifying Red Flags - Considerations Sources of Red Flags. Consider other sources of information, including the experience of other members of your industry. Technology and criminal techniques change constantly, so it’s important to keep up-to-date on new threats.

Identifying Red Flags - Considerations Categories of Common Red Flags. The examples given during this presentation are illustrations of how to think about relevant red flags in the context of your own business; 1. Alerts, Notifications, and Warnings from a Credit Reporting Company 2. Suspicious Documents 3. Personal Identifying Information 4. Account Activity 5. Notice from Other Sources

Suspicious Documents Documents can offer hints of identity theft. For example; identification looks altered or forged the person presenting the identification doesn’t look like the photo or match the physical description information on the identification differs from what the person with identification is telling you or doesn’t match the person’s signature

Personal Identifying Information Personal identifying information can indicate identity theft. For example; inconsistencies in the information a patient has given you a bogus address, a disconnected phone number or one that’s associated with an unrelated patient a Social Security number used by another patient an address or telephone number used by several unrelated/unassociated patients a patient who can’t accurately provide his or her medical history – even in general terms

Notice from Other Sources A patient, a victim of identity theft, a law enforcement authority, your facility’s accounts receivable collector, or someone else may be trying to tell you that an account has been opened or used fraudulently. Listen, and respond appropriately. Your response will depend on the degree of risk posed.

Prevent and Mitigate Identity Theft Your response will depend on the degree of risk posed. The Guidelines in the Red Flags Rule offer examples of some appropriate responses, including; monitoring an account for evidence of identity theft contacting the customer not trying to collect on an account or not placing an account with a debt collector notifying law enforcement determining that no response is warranted under the particular circumstances

Developing a Program A program should include reasonable policies and procedures to identify the red flags of identity theft that may occur in your day-to-day operations. Again, red flags are suspicious patterns or practices, or specific activities that indicate the possibility of identity theft. For example, if a patient has to provide some form of identification when presenting for treatment, an ID that doesn’t look genuine is a “red flag” for your facility.

Developing a Program A program should be designed to detect the red flags you’ve identified. If you have identified fake IDs as a red flag, then you should have procedures in place to detect possible fake, forged, or altered identification. A program should spell out appropriate actions that you’ll take when you detect red flags. A program should detail how you’ll keep it current to reflect new threats.

Developing a Program The Red Flags Rule has requirements on how to incorporate your program into the daily operations of your business. The Rule also gives you the flexibility to design a program appropriate for your business — its size and potential risks of identity theft. While some businesses and organizations may need a comprehensive program to address a high risk of identity theft, a streamlined program may be appropriate for businesses facing a low risk.

Administering and Maintaining Your Program Once you’ve developed an identity theft prevention program, administer it. Just getting something down on paper won’t reduce the risk of identity theft. Train and monitor your employees; they’re the people who will encounter identity thieves. Monitor your service providers. If they’re conducting activities covered by the Rule – for example, collecting debts – they should have, administer, and maintain an identity theft prevention program.

Administering and Maintaining Your Program The person responsible for your program should report to your Board of Directors or a designated senior manager at regular intervals. The report should evaluate how effective your program has been in addressing the risk of identity theft; how you’re monitoring the practices of your service providers; significant incidents of identity theft and your responses; and recommendations for major changes to the program.

Updating Your Program New red flags emerge as technology changes or identity thieves change their tactics. So, you should periodically update your program to address new and changing flags. Factor in your own experience with identity theft; changes in how identity thieves operate; new methods to detect, prevent, and mitigate identity theft; and changes in your business, like mergers, acquisitions, alliances, joint ventures, and arrangements with new service providers.

Does the Rule Apply to Me? Ask your legal counsel. Again, regardless of whether your facility is required to follow the Rule, an identity theft detection and prevention program can help spot suspicious patterns and prevent the costly consequences of identity theft.

Brady Keith Assistant General Counsel Tel. (308) Fax (308)