Businesses required to protect customer data
Rhode Island’s state employees, totaling some 15,000, are no longer classified by their Social Security numbers, but by a 12-digit code.
Seifert Systems Invests in Energy Efficiency to Strengthen Operations
For manufacturers, energy is more than just another operating expense. It plays a critical role…
Learn More
The state’s businesses are required to maintain firewalls in their computers, which store customer information.
Document-destruction outfits have said they are posting double-digit profit growth in the state.
Fueling these realities is one of the nation’s top white-collar crimes: identity theft. And state Attorney General Patrick C. Lynch’s consumer protection unit has waged war on the problem, using a multi-pronged approach that includes backing legislation and educating small-business owners.
“The big businesses have actually budgeted for the amount that is going to be lost to identity thieves,” said John R. Palangio, the attorney general’s director of consumer protection. “But the small businesses obviously can not do that.”
“Sometimes (small businesses’) working capital is so small that if they get scammed they literally close their doors,” he added.
According to the attorney general’s office, about one in every 2,000 Rhode Islanders was a victim of identity theft in 2003. Last year, the attorney general’s consumer protection unit received more than 300 calls from victims of identity theft.
How much money state residents have lost as a result of identity theft is unknown. However, the Federal Trade Commission reported that more than 10 million Americans had their identities stolen last year. Victims’ total loss was some $48 billion.
Early this year, a criminal ring bilked information from more than 400,000 consumer records held by Atlanta-based credit reporting firm ChoicePoint Inc. Yet, California was the only state with a law that required ChoicePoint to notify victims of the security breach.
Lynch was among several attorneys general in the country to push an identity-theft prevention package in their legislative agendas following the mass identity theft at ChoicePoint.
In July, the Rhode Island General Assembly passed the Rhode Island Identity Theft Protection Act of 2005.
The act, which took effect upon passage, requires the state’s businesses that maintain records of individuals’ personal information to implement several policies and safeguards to prevent identity theft.
The law mandates that companies destroy consumer information – through various means such as shredding documents to erasing computer records – no longer in use.
Businesses must also immediately notify customers of any security breach in their records systems, such as in the ChoicePoint case.
Companies in violation of the new law could face lawsuits from customers seeking damages as a result of their information getting stolen. Companies can also be fined up to $3,000 per violation, according to the law.
Palangio said there have been no major security breaches at companies in the state since the law passed. “Again, the greatest success of the bill has been that there have been no breaches that have gone unreported,” he added.
Still, the law doesn’t require businesses to report to authorities how they have implemented its mandates. Therefore, it’s incumbent upon businesses to put the law’s provisions into practice.
“If you think about the concept of the bill, it is reactive – it is requiring businesses to notify customers after the fact,” said Michael J. Healy, a spokesman for the attorney general’s office. “So it’s certainly hard to prove that businesses haven’t done what the law requires them to do, the only way we would know about it is if there is a breach and consumers do not get notified,” Healy added.
In the meantime, the attorney general’s office posts warnings about identity-theft scams through the media and via e-mail, Palangio said. The office has worked with the state’s chambers of commerce and the Small Business Administration’s local office to educate business owners about the issue, as well.
The attorney general’s office said it also plans to continue to back legislation submitted to the state Legislature in February that would provide consumers with more protection from identity theft.
Still working its way through the House Judiciary Committee, the legislation would enable victims of identity theft to obtain “identity theft passports.” The passport would include a person’s photo and personal information, which they could present to authorities and those who may ask for identification, according to the bill.
Seven other states have already adopted similar legislation, according to the attorney general’s office, and four other states are also considering the bill.
“This just speaks to the enormity of the problem of identity theft that we are facing not only in the United States but in the world,” said Healy of the office’s efforts to block identity theft.
“We are largely in a reactive, defensive position. And some of the things we have had to do amount to the canary in the coal mine.”












