Protection of CONSUMER information

Slides:



Advertisements
Similar presentations
/0403 © 2004 Business & Legal Reports, Inc. BLRs Training Presentations Privacy Issues in the Workplace.
Advertisements

Protect Our Students Protect Ourselves
COMPLYING WITH PRIVACY AND SECURITY REGULATIONS Overview MHC Privacy and Security Committee Revised 1/17/11.
Red Flags Rule BAS Forum August 18, What is the Red Flags Rule? Requires implementation of a written Identity Theft Prevention Program designed.
Copyright © 2012, Big I Advantage®, Inc., and Swiss Re Corporate Solutions. All rights reserved. (Ed. 08/12 -1) E&O RISK MANAGEMENT: MEETING THE CHALLENGE.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
HIPAA: FEDERAL REGULATIONS REGARDING PATIENT SECURITY.
Springfield Technical Community College Security Awareness Training.
Gramm-Leach-Bliley Act for Financial Aid Val Meyers Associate Director Michigan State University.
Protecting Personal Information Guidance for Business.
I.D. Theft Alaska’s New Protection of Personal Information Act Ed Sniffen Senior Assistant Attorney General Alaska Department of Law.
FAIR AND ACCURATE CREDIT TRANSACTIONS ACT (FACTA)- RED FLAG RULES University of Washington Red Flag Rules Protecting Against Identity Fraud.
The Third International Forum on Financial Consumer Protection & Education “Fostering Greater Consumer Protection & Education” Preventing Identity Theft.
Identity Theft Solutions. ©SHRM Introduction Identification theft became the number one criminal activity issue in 2004 and has remained at the.
Computers, Freedom and Privacy April 23, 2004 Identity Theft: Addressing the Problem in California Joanne McNabb, Chief CA Office of Privacy Protection.
Identity Theft: How to Protect Yourself. Identity Theft Identity theft defined:  the crime of obtaining the personal or financial information of another.
Guide to Massachusetts Data Privacy Laws & Steps you can take towards Compliance.
Copyright © 2014 Merck Sharp & Dohme Corp., a subsidiary of Merck & Co., Inc. All rights reserved. In practice, how do we recognize a potential Privacy.
What You Need to Know Customer Service 1 08/09/2012.
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Protecting Sensitive Information PA Turnpike Commission.
CONSUMER PROTECTION AND LITIGATION: CONSUMER PROTECTION AND LITIGATION: Ryan Mehm Attorney Bureau of Consumer Protection Federal Trade Commission The views.
April 23, Massachusetts’ New Data Security Regulations: Ten Steps To Compliance Amy Crafts
2015 ANNUAL TRAINING By: Denise Goff
Security and Privacy Strategic Global Partners, LLC.
Privacy and Information Management ICT Guidelines.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
PRIVACY, SECURITY & ID THEFT PREVENTION - TIPS FOR THE VIGILANT BUSINESS - SMALL BUSINESS & ECONOMIC DEVELOPMENT FORUM October 21, WITH THANKS TO.
© Copyright 2010 Hemenway & Barnes LLP H&B
1 st Choice Document Destruction th Avenue, Milaca, Minnesota Office: Cell:
Protecting Yourself from Fraud including Identity Theft Personal Finance.
Identity Theft PD Identity Theft Identity theft is a serious crime which can: Cost you time and money Destroy your.
Protecting Yourself from Fraud including Identity Theft Advanced Level.
Information Security Everyday Best Practices Lock your workstation when you walk away – Hit Ctrl + Alt + Delete Store your passwords securely and don’t.
Jeff loses his identity! Lesson 5: Identity Theft.
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Government Protection Consumers protected by both laws and agencies at different levels Look at table on page 30.
Data Breach ALICAP, the District Insurance Provider, is Now Offering Data Breach Coverage as Part of Our Blanket Coverage Package 1.
Canada’s Breach Reporting Law What you need to know Timothy M. Banks, CIPP/C Dentons Canada LLP July 21, 2015.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Protect Our Students Protect Ourselves
Protecting PHI & PII 12/30/2017 6:45 AM
Surveillance around the world
Indiana Access to Public Records Act (APRA) Training
E&O Risk Management: Meeting the Challenge of Change
Responding to a Data Breach 360° of IT Compliance
E&O Risk Management: Meeting the Challenge of Change
Chapter 3: IRS and FTC Data Security Rules
Protecting Personal Information Guidance for Business.
Cyber Issues Facing Medical Practice Managers
Protecting Your Credit
Red Flags Rule An Introduction County College of Morris
Current Privacy Issues That May Affect Your Credit Union
CompTIA Security+ Study Guide (SY0-401)
Computer Programming I
Protecting Yourself from Fraud including Identity Theft
Identity Theft Prevention Program Training
Protecting Yourself from Fraud including Identity Theft
Clemson University Red Flags Rule Training
HIPAA SECURITY RULE Copyright © 2008, 2006, 2004 by Saunders an imprint of Elsevier Inc. All rights reserved.
Move this to online module slides 11-56
Your Credit and the Law Chapter 27 5/24/2019.
Protecting Yourself from Fraud including Identity Theft
Colorado “Protections For Consumer Data Privacy” Law
Protecting Student Data
Anatomy of a Common Cyber Attack
School of Medicine Orientation Information Security Training
Presentation transcript:

Protection of CONSUMER information PowerPoint Presentation By Deanna Sabey, General Counsel CITYWIDE HOME LOANS

PROTECTION OF CONSUMER INFORMATION SUMMARY The security and integrity of consumer non-public personal information is important to Citywide. We take the protection of this information seriously, and expect our employees to take measures so the information is protected from any prohibited disclosure or improper use. This presentation is designed to help you understand: what “consumer non-public personal information” means, what Citywide does to protect the information, and what you are expected to do to help protect the information. This presentation also explains what happens if there is an unintentional disclosure or a theft or conversion of protected information.

Protection of consumer personal information GRAMM-LEACH-BLILEY ACT What consumer information is protected? Social security numbers Account numbers Driver’s license numbers Bank statements Financial information W-2s Employment information and verifications Credit reports Applications and any information provided in the applications Credit scores Any other information a consumer provides to obtain a residential mortgage loan Non-public financial information Protection of consumer personal information

Protection of consumer personal information GRAMM-LEACH-BLILEY ACT What is publicly available information? Any information a lender has a reasonable basis to believe is legally available to the general public from: federal, state, or local government records; widely distributed media; or disclosures to the general public required by law. Examples: information found in a telephone book, information available on a website, information recorded in a county recorders office or court clerk’s office. Protection of consumer personal information

GRAMM LEACH BLILEY ACT Citywide Privacy Notice to Consumers Permits disclosure of nonpublic personal information (protected consumer information) to: a third party, but only when required in the normal course of business (such as warehousing lenders, investors), and on a need-to-know basis; regulatory authorities and law enforcement officials; protect against or prevent actual or potential fraud, unauthorized transactions, claims or other liability; report account activity to credit bureaus; consumer reporting agencies; and respond to a subpoena or court order, judicial process or regulatory authorities.

PROTECTION OF CONSUMER INFORMATION What Citywide does to protect consumer information Conducts criminal background checks on employees as part of the hiring process. Prohibits employees from storing consumer non-public personal information on any personal or non-Citywide device. Uses firewalls to protect and encrypt network communication. Critical systems are backed up and stored at a secure, third-party vendor. Servers are located in a locked room with restricted access. Employees with remote access are required to use a VPN with encryption to access Citywide’s system. Provides secure storage for hard-copy files. Requires use of document shredding services. Restricts access to systems. Requires employees to follow password policy. Conducts third party vendor due diligence and periodic review.

Protection of consumer information Employee Actions to Protect Consumer Information Avoid storing protected information on personal devices (laptop, smartphone, hard-drive, etc.) or in personal emails. Devices can be stolen and emails can be hacked. Keep hard-copy documents in a locked cabinet or locked office. Make sure guests are escorted to a location rather than let them walk through the office unattended. Place discarded documents in a shredding bin. Do not give passwords to any other person to use. You could be held responsible for what that person does with your password. Only share protected information with third-parties as authorized by Citywide on a need-to-know basis in the normal course of business. Make sure computer screen is locked while not in use to prevent unauthorized access/viewing.

What happens if protected information is accidentally disclosed? Inform Citywide’s General Counsel. She will oversee the process to: document the disclosure; notify the consumer; provide the consumer with information from the Federal Trade Commission instructing the consumer on how to take protective measures on credit reports; give the consumer a designated Citywide employee’s contact information for any further questions; and take measures to prevent further disclosure issues.

PROTECTING CONSUMER NON-PUBLIC INFORMATION What if someone has taken protected information from Citywide? Notify Citywide’s General Counsel. Senior Management will then assess the nature and scope of the incident. If appropriate, Citywide will: Notify appropriate law enforcement authorities. Notify appropriate regulators. Take measures to contain and control the incident. Prevent further unauthorized access. Notify customers when warranted. PROTECTING CONSUMER NON-PUBLIC INFORMATION