jheary
Distinguished Systems Engineer

FTC’s ID theft prevention rules affect more businesses than you think

Analysis
Nov 1, 20086 mins

My guess is many of you have never heard of the FTC’s Red Flag Rules. Even so, I would bet that a fair number of you work for a business that needs to comply with the rules. This unawareness is the reason behind the FTC’s decision to extend the enforcement date. Here are just a few example business types that may need to comply: car dealers, mortgage brokers, and healthcare entities. Read on to find out if your business falls under the rules and what that means. The FTC just announced that it is moving the Red Flag enforcement date from November 1st 2008 to May 1st 2009. The FTC released this statement explaining the reason behind the extension.

During the course of these efforts, Commission staff learned that some industries and entities within the FTC’s jurisdiction were uncertain about their coverage under the Rule. These entities indicated that they were not aware that they were engaged in activities that would cause them to fall under the FACT Act’s definition of creditor or financial institution.

Many entities also noted that, because they generally are not required to comply with FTC rules in other contexts, they had not followed or even been aware of the rulemaking, and therefore learned of the Rule’s requirements too late to be able to come into compliance by November 1, 2008.

The Commission’s delay of enforcement will enable these entities sufficient time to establish and implement appropriate identity theft prevention programs, in compliance with the Rule.

So how do you figure out if your business needs to comply with the Red Flag Rules?

The FTC says, “The Red Flags Rules apply to “financial institutions” and “creditors” with “covered accounts.” Most financial institutions already know they fall under these rules so that leaves the “creditors”. The broad scope of businesses that fall under the FTC’s definition of a “creditor” is why the huge lack of awareness exists for Red Flag. To help gain awareness the FTC released this business alert:

The Red Flags Rules apply to “financial institutions” and “creditors” with “covered accounts.”

A creditor is any entity that regularly extends, renews, or continues credit; any entity that regularly arranges for the extension, renewal, or continuation of credit; or any assignee of an original creditor who is involved in the decision to extend, renew, or continue credit. Accepting credit cards as a form of payment does not in and of itself make an entity a creditor. Creditors include finance companies, automobile dealers, mortgage brokers, utility companies, and telecommunications companies. Where non-profit and government entities defer payment for goods or services, they, too, are to be considered creditors. Most creditors, except for those regulated by the Federal bank regulatory agencies and the NCUA, come under the jurisdiction of the FTC.

Under the Rules, a financial institution is defined as a state or national bank, a state or federal savings and loan association, a mutual savings bank, a state or federal credit union, or any other entity that holds a “transaction account” belonging to a consumer. Most of these institutions are regulated by the Federal bank regulatory agencies and the NCUA. Financial institutions under the FTC’s jurisdiction include state-chartered credit unions and certain other entities that hold consumer transaction accounts.

A transaction account is a deposit or other account from which the owner makes payments or transfers. Transaction accounts include checking accounts, negotiable order of withdrawal accounts, savings deposits subject to automatic transfers, and share draft accounts.

A covered account is an account used mostly for personal, family, or household purposes, and that involves multiple payments or transactions. Covered accounts include credit card accounts, mortgage loans, automobile loans, margin accounts, cell phone accounts, utility accounts, checking accounts, and savings accounts. A covered account is also an account for which there is a foreseeable risk of identity theft – for example, small business or sole proprietorship accounts.

So what do you do if you find out you fall under the enforcement of the Red Flag Rules? The Federal Trade Commission Red Flag Rules require that every financial institution or creditor setup an identify theft prevention program. If you fall under the purview of red flag rules then at this point the FTC is requiring you to develop and implement a written identity theft prevention program. Here is what the FTC says that ID theft programs must include:

The final regulations list the four basic elements that must be included in the Program of a financial institution or creditor. The Program must contain ‘‘reasonable policies and procedures’’ to:

•Identify relevant Red Flags for covered accounts and incorporate those Red Flags into the Program;

•Detect Red Flags that have been incorporated into the Program;

•Respond appropriately to any Red Flags that are detected to prevent and mitigate identity theft; and

•Ensure the Program is updated periodically, to reflect changes in risks to customers or to the safety and soundness of the financial institution or creditor from identity theft

The regulations also enumerate certain steps that financial institutions and creditors must take to administer the Program. These steps include obtaining approval of the initial written Program by the board of directors or a committee of the board, ensuring oversight of the development, implementation and administration of the Program, training staff, and overseeing service provider arrangements.

For more information here are some helpful links Red Flag Laws http://ftc.gov/os/fedreg/2007/november/071109redflags.pdf Extension Notice http://www.ftc.gov/opa/2008/10/redflags.shtm FTC Business Alert that describes who is affected http://www.redflagrules.net/Home_Page.html A good Red Flag Rules fact site http://www.redflagrules.net/Home_Page.html Previous NW article on Red Flag Rules http://www.networkworld.com/news/2008/101508-ftcs-red-flag-rules-cast.html Disclosure: I am not a lawyer. My blogs are not legal advice, are for educational and discussion purposes only, and are not a substitute for proper consultation with legal counsel.

The opinions and information presented here are my personal views and not those of my employer.

More from Jamey Heary: Credit Card Skimming: How thieves can steal your card info without you knowing it Cisco enters the crowded AV and DLP client marketCisco’s new ASA code allows you to securely take your Cisco IP Phone with you anywhereCisco targets Symantec, McAfee with its new antivirus client Google’s Chrome raises security concerns and tastes like chicken feet a>Go to Jamey’s Blog for more articles on security.
jheary

Jamey Heary, CCIE #7680, is a Distinguished Systems Engineer at Cisco Systems. Jamey sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey has authored several security books, his latest is Cisco ISE for BYOD and Secure Unified Access. He also has a patent on a new DDoS mitigation and firewall IP reputation technique. Jamey leads numerous security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is also recognized as a Distinguished Speaker at Cisco Live. He has been working in the IT field for 19 years and in IT security for 15 years.

More from this author