Showing posts with label paper trail. Show all posts
Showing posts with label paper trail. Show all posts
February 16, 2008
The Anonymity Experiment
A Popular Science writer spends a week staying anonymous in the digital age: paying cash, dodging surveillance cameras and using disposable cellphones.
Labels:
documents,
mobile phone,
paper trail,
privacy,
surveillance,
travel privacy
January 16, 2008
Outfits mine Voter Registration records
Vanity Fair reports that database broker Aristotle is amassing, cross-referencing and selling voter registration and political donation information:
In most states, voter registration databases are public information, by law. The governments sell this information, along with driver's license data.
Aristotle's data gatherers might soon be taking photos in public and harvesting data-rich magstripe information from credit cards and identity cards:
The inescapable conclusions I draw from this are that voting and making political donations are much more likely to result in an individual's inclusion in a database, whether the data mining effort is governmental, political, or for more direct monetary profit. The magnetic-strip scanners are a reminder about how electronic cards can facilitate mass surveillance of a type unintended by their issuers.
In situations when Social Security Numbers and Social Insurance Numbers can't be used as database keys or for matching individuals, mailing addresses and date-of-birth (DOB) is frequently used. Therefore, remember to keep your full name, DOB and mailing address (hopefully it's not the same as your street address!) to yourself as much as possible.
“People are getting hassled by marketing firms and hassled by consultants, and much of that information comes from signing petitions or off the voting databases."
In most states, voter registration databases are public information, by law. The governments sell this information, along with driver's license data.
"One such [commercial data] supplier is Acxiom, the Arkansas-based behemoth that stores unimaginable quantities of data. In 2003, a single hacker stole Acxiom records on 20 million people, according to Washington Post reporter Robert O’Harrow’s 2005 book, No Place to Hide."
Aristotle's data gatherers might soon be taking photos in public and harvesting data-rich magstripe information from credit cards and identity cards:
"Phillips picks up one of the custom-designed pocket-P.C. scanners that go with the Aristotle 360 system. With them, canvassers working for campaigns will swipe credit cards and driver’s licenses, take pictures of voters using an embedded micro-camera, and instantaneously feed all of the resulting information into the database."
The inescapable conclusions I draw from this are that voting and making political donations are much more likely to result in an individual's inclusion in a database, whether the data mining effort is governmental, political, or for more direct monetary profit. The magnetic-strip scanners are a reminder about how electronic cards can facilitate mass surveillance of a type unintended by their issuers.
In situations when Social Security Numbers and Social Insurance Numbers can't be used as database keys or for matching individuals, mailing addresses and date-of-birth (DOB) is frequently used. Therefore, remember to keep your full name, DOB and mailing address (hopefully it's not the same as your street address!) to yourself as much as possible.
August 16, 2007
"Dietrich" tracked by medical bills
(CBS) LOS ANGELES A 26-year-old man was in custody Friday after being on the run for more than a year following a high-speed crash in Malibu that left a rare $1 million Ferrari Enzo in pieces.
The driver of the Ferrari, Swedish national Stefan Eriksson, had previously claimed that a mysterious German man named "Dietrich" had been driving when the collision with the utility pole occurred. Eriksson failed two alcohol breath tests at the scene of the crash, and was later charged with embezzlement related to leased car exports and his video game firm Gizmondo.
Irish native Kearney, who was a passenger in the Ferrari Enzo during the crash, fled the country after the crash but was smuggled back into the U.S. a year later from Tijuana, Mexico.
Authorities tracked him down this week, thanks to medical bills generated after his return to California and sent to a Marina del Rey address, the source said.
Kearney was charged with perjury and obstructing, both misdemeanor crimes. Why would police track this man via medical bills for two misdemeanors? In order to force him to testify against Eriksson in a media-frenzy drunk driving case, undoubtedly.
Medical records are an open book to anyone with a subpoena. All too often medical professionals allow access to records after only an informal request from a detective or investigator. More troubling is the ease with which private investigators and other outside parties seem to get medical records via bribery, pretexting, or court-ordered legal discovery.
If Kearney hadn't had his medical bills sent to his address of record -- the address he gave to police investigators at the crash site -- he might not be under indictment for two misdemeanors today.
Remember, also, that lying to police is usually a misdemeanor and lying to federal agents is a felony. Just ask Martha Stewart.
Read the Findlaw article "How to Avoid Going to Jail under 18 U.S.C. Section 1001 for Lying to Government Agents" for more information on lies within federal jurisdiction and how to decline a federal interview by invoking counsel.
Labels:
lawyer,
mailing address,
medical privacy,
medical record,
paper trail
July 30, 2007
Check your assets every year
The San Francisco Chronicle on "unclaimed assets" seized under California state law, unbeknownst to its owners:
Elaborate privacy arrangements can discourage us from checking up on our assets as frequently as we should. Sometimes it's difficult to verify financial arrangements while maintaining strict privacy procedures such as mail drops, or depositing cash into accounts in person in lieu of automated transfers (to avoid creating a paper trail linking the accounts together through the transaction).
Nonetheless, it behooves anyone with assets held by an outside institution or with agreements with business associates to check their status occasionally. It's something we should plan for when setting up privacy arrangements:
Years ago, Carla Ruff stored her grandmother's jewelry and a file of personal documents in a safe-deposit box at her bank in San Francisco's Noe Valley, thinking they would always be there when she wanted them.
Not so. Without giving her notice or acting on evidence that she'd forgotten about her cache, the bank's staff, under the auspice of the state, determined the contents of her box to be unclaimed property.
In July 1997, bank records show, the pearl necklace and diamond-encrusted pin, real estate and insurance documents as well as her birth certificate were all removed. The paperwork was shredded and thrown away. Her jewelry was auctioned off on eBay -- for a fraction of its $80,000 value.
Ruff said she didn't know what had happened until January 2006, when an illness in the family sent her to the Bank of America branch looking for the deed to her house. Weeks later, the bank manager told Ruff that her property had been seized by the state under a law that requires the government to take control of lost or abandoned assets.
Elaborate privacy arrangements can discourage us from checking up on our assets as frequently as we should. Sometimes it's difficult to verify financial arrangements while maintaining strict privacy procedures such as mail drops, or depositing cash into accounts in person in lieu of automated transfers (to avoid creating a paper trail linking the accounts together through the transaction).
Nonetheless, it behooves anyone with assets held by an outside institution or with agreements with business associates to check their status occasionally. It's something we should plan for when setting up privacy arrangements:
- U.S. Post Office box fees can usually only be paid a year in advance -- a renewal notice should come 30 days before payment is due.
- Safe deposit boxes should be visisted at least yearly.
- Financial accounts should be checked monthly for evidence of unauthorized access or identity theft.
- Many types of insurance contracts must be renewed yearly.
- LLC costs may be due after the first three years depending on provider.
- Trusts and attorneys should be contacted yearly or more frequently.
- Financial accounts with tax implications must be verified at the required tax intervals.
June 13, 2007
How Insurance companies price your Car Insurance
Insurance can be an adversarial business relationship, unfortunately. In some circumstances, the more your insurer knows about you, the higher the rate they will charge you. This gives them every incentive to ferret out information pertinent to your insurance risks -- or what they believe affects your insurance risks, anyway.
A Consumerist article gives insight into the privacy implications and pricing strategy of auto insurance.
Note that insurance companies access the following databases to actuarially determine liklihood of an insurance claim: CLUE report, credit report, and driving history.
As with credit reports, a critical source of information is what you tell the insurance company:
It is illustrative how your credit report affects your insurance score, and thus your insurance rates. By 2001, 92% of insurers were considering credit scores when quoting insurance.
Remember that information you give to an insurance company may well end up on your credit report. Along with the usual distinguishing characteristics (name, date of birth, SSN or other national number), insurers will likely report your submitted information to the credit reporting bureay. This could happen even if you're just getting an insurance quote, and needs to be taken into account if you're keeping your street address confidential.
Complete truthfulness doesn't always pay when it comes to dealing with insurers who will collect every personal detail to accurately assess you with their actuarial tables.
A Consumerist article gives insight into the privacy implications and pricing strategy of auto insurance.
Note that insurance companies access the following databases to actuarially determine liklihood of an insurance claim: CLUE report, credit report, and driving history.
As with credit reports, a critical source of information is what you tell the insurance company:
Driving histories go back 36 months, except in New York (which is 40 months). Your history is composed from three reports; your MVR or Motor Vehicle Report, the state database of your ticketed driving history; your CLUE report, a collection of previous insurance companies reports stating the numbers of claims you've had, and YOU. If you say you got in an accident, were never sited for it and never claimed it on your insurance, but you still tell us, it'll be put on your record with an approximate date.
Credit score and insurance rates
It is illustrative how your credit report affects your insurance score, and thus your insurance rates. By 2001, 92% of insurers were considering credit scores when quoting insurance.
Remember that information you give to an insurance company may well end up on your credit report. Along with the usual distinguishing characteristics (name, date of birth, SSN or other national number), insurers will likely report your submitted information to the credit reporting bureay. This could happen even if you're just getting an insurance quote, and needs to be taken into account if you're keeping your street address confidential.
Complete truthfulness doesn't always pay when it comes to dealing with insurers who will collect every personal detail to accurately assess you with their actuarial tables.
June 12, 2007
Confessions of a Money Launderer
Money launderer Kenneth Rijock kept a low profile and
avoided creating a paper trail despite constant financial entanglements for his clients:
avoided creating a paper trail despite constant financial entanglements for his clients:
"I maintained absolutely no bank accounts in the US, operating on a strict cash payment basis to ensure that no records of any business transactions for criminal clients existed. This is much harder that it sounds, for though one might use third-party accounts that don't alert law enforcement investigators, it is more prudent to avoid it all together. I had no US bank accounts for five years, using an overseas tax haven account to obtain cashier's cheques drawn on a New York correspondent account very sparingly, and only for totally innocent personal transactions."
"Own nothing in your own name: rent your home and office, either lease an automobile or place it in the name of a third party. In short, make enquiries of your assets more difficult to discover, and information about your operation more difficult to link to you or your clients. If possible, reduce your profile even more by closing out legitimate business, whilst maintaining a fictitious facade that legitimate business is ongoing. return all telephone calls, but decline new business due to purported schedule overload."
April 3, 2007
Keep those grandfathered bank accounts
Remember the proposed "Know Your Customer" (KYC) rules, where the U.S. government was going to force banks and related financial institutions to develop a profile on each of the insitution's customers?
But Know Your Customer was defeated, right? Not so fast.
Know Your Customer rules have been quietly resurrected as two separate programs, with other benign-sounding names.
Meet Customer Identification Program (CIP) and Enhanced Due Diligence (EDD).
Customer Identification Program, or CIP, requires that financial institutions (including casinos, pawnbrokers, insurers and money transmitters) positively identify the individual or organization with which they have a formal business relationship. The actual CIP procedure will vary by institution, but will be documented.
CIP requires the following information on each customer: legal name, date of birth (DOB), street address, and taxpayer identification number. Taxpayer Identification Number, or TIN, is usually a Social Security Number for U.S. citizens, or a Social Identification Number, or SIN, for Canadians. For addresses, P.O. boxes and accomodation addresses are explicitly disallowed for accounts opened after October 1, 2003.
Almost all financial institutions require goverment-issued ID for the CIP process, although many banks are accepting the Mexican matricula consular card in an effort to garner the business of Mexican nationals who may not have identification documents issued by U.S. agencies.
Enhanced Due Diligence is a program where banks monitor their customer's activity on an ongoing basis for illegal activity or suspicion of illegal activity. Bank compliance officers are looking for evidence of terrorist financing, transactions with blacklisted entities, fraud, check kiting, identity theft, tax evasion and money laundering.
Enhanced Due Diligence screening is usually done by data mining account transaction records, looking for patterns that might be indicative of these crimes. Many firms offer software packages to help automate the data sifting, but similar results can be obtained with basic data analysis tools like a spreadsheet, as long as criteria are previously defined. It's worthwhile to keep grandfathered bank accounts that date from before the Patriot Act. These accounts, and accounts at the same institution, are not subject to Customer Identification Program requirements.
In other words, if you are a long-time customer of a bank, but that bank doesn't already have a full CIP profile on you, they are not required to collect all of the CIP information for you to open additional accounts or financial products with them. Sometimes bank procedures encourage account representatives to collect the information, but most do not.
Be aware that this only applies if you are a grandfathered, existing customer of the bank. If you have previously closed all of your accounts with that institution, you're classified as a new customer for purposes of the Customer Identification Program and will have to supply all of the ID and documentation required of a new customer. Accounts opened after October 1, 2003 cannot be opened with P.O. box or commercial mailbox, as many people used to do to preserve their privacy.
Keeping those grandfathered accounts around, with minimum balances if necessary, can save you from having to provide information that you'd rather not provide to open an account in the future. This includes keeping your old accounts open when you move, especially if you are going to open a new account at the local branch of the same institution at your new home or office.
Remember, though, to keep old account checkbooks and paperwork in a very secure location with the rest of your financial documents.
But Know Your Customer was defeated, right? Not so fast.
Know Your Customer rules have been quietly resurrected as two separate programs, with other benign-sounding names.
Meet Customer Identification Program (CIP) and Enhanced Due Diligence (EDD).
Customer Identification Program, or CIP, requires that financial institutions (including casinos, pawnbrokers, insurers and money transmitters) positively identify the individual or organization with which they have a formal business relationship. The actual CIP procedure will vary by institution, but will be documented.
CIP requires the following information on each customer: legal name, date of birth (DOB), street address, and taxpayer identification number. Taxpayer Identification Number, or TIN, is usually a Social Security Number for U.S. citizens, or a Social Identification Number, or SIN, for Canadians. For addresses, P.O. boxes and accomodation addresses are explicitly disallowed for accounts opened after October 1, 2003.
Almost all financial institutions require goverment-issued ID for the CIP process, although many banks are accepting the Mexican matricula consular card in an effort to garner the business of Mexican nationals who may not have identification documents issued by U.S. agencies.
Enhanced Due Diligence is a program where banks monitor their customer's activity on an ongoing basis for illegal activity or suspicion of illegal activity. Bank compliance officers are looking for evidence of terrorist financing, transactions with blacklisted entities, fraud, check kiting, identity theft, tax evasion and money laundering.
Enhanced Due Diligence screening is usually done by data mining account transaction records, looking for patterns that might be indicative of these crimes. Many firms offer software packages to help automate the data sifting, but similar results can be obtained with basic data analysis tools like a spreadsheet, as long as criteria are previously defined. It's worthwhile to keep grandfathered bank accounts that date from before the Patriot Act. These accounts, and accounts at the same institution, are not subject to Customer Identification Program requirements.
In other words, if you are a long-time customer of a bank, but that bank doesn't already have a full CIP profile on you, they are not required to collect all of the CIP information for you to open additional accounts or financial products with them. Sometimes bank procedures encourage account representatives to collect the information, but most do not.
Be aware that this only applies if you are a grandfathered, existing customer of the bank. If you have previously closed all of your accounts with that institution, you're classified as a new customer for purposes of the Customer Identification Program and will have to supply all of the ID and documentation required of a new customer. Accounts opened after October 1, 2003 cannot be opened with P.O. box or commercial mailbox, as many people used to do to preserve their privacy.
Keeping those grandfathered accounts around, with minimum balances if necessary, can save you from having to provide information that you'd rather not provide to open an account in the future. This includes keeping your old accounts open when you move, especially if you are going to open a new account at the local branch of the same institution at your new home or office.
Remember, though, to keep old account checkbooks and paperwork in a very secure location with the rest of your financial documents.
March 12, 2007
Comparison of Prepaid Credit Cards
Ryan Barrett at snarfed.org has an updated essay on protecting your privacy with prepaid credit cards and gift cards.
Labels:
data mining,
financial privacy,
identity theft,
paper trail
February 21, 2007
Prescription Records for Sale
In January 2007, the new National ePrescribing Patient Safety Initiative (NEPSI) debuted with a high-profile article in Time magazine.
This web-based system is supplied free of charge to physicians, ostensibly to reduce prescription error rates. Revenue to pay for the information system comes from the participating pharmacies and insurers who save time and money.
Now there are accusations that this database has been developed to give drug marketers, insurance risk assessors, and employers access to patients' private prescription records.
According to a Government Health IT article, all the prescription records stored in the new NEPSI database are for sale:
In another article, Dr. Peel says that NEPSI sells data to large employers:
But Allscripts CEO Tullman denies that prescription data will be misused:
What can you do?
Ask your medical care providers if they use the web-based NEPSI electronic prescription system.
Consider refusing prescriptions for conditions that you would not want your employers or government to know about. Some doctors will give out samples to their patients, and this might be a sufficient quantity to forgo a formal prescription.
A cash transaction by itself won't keep you out of the NEPSI database because it contains patient information and the prescription itself, not just billing information like an insurer's database might.
This web-based system is supplied free of charge to physicians, ostensibly to reduce prescription error rates. Revenue to pay for the information system comes from the participating pharmacies and insurers who save time and money.
Now there are accusations that this database has been developed to give drug marketers, insurance risk assessors, and employers access to patients' private prescription records.
According to a Government Health IT article, all the prescription records stored in the new NEPSI database are for sale:
Security makes little difference because every identifiable prescription in the country is data mined and sold daily. Nobody needs to break into pharmacies to steal our prescriptions; they are for sale. For example, market intelligence firm IMS Health reported revenues of $1.75 billion in 2005 solely from the sale of prescription records, primarily to drug companies.
In another article, Dr. Peel says that NEPSI sells data to large employers:
In 2006, the national Blue Cross and Blue Shield Association announced its Blue Health Initiative to aggregate and sell the claims, medical and prescription data of all 79 million enrollees to large employers. This database will include far more detail than e-prescription records, making the sales of Blues data worth far more than the billions in revenue from selling e-prescription records alone.
But Allscripts CEO Tullman denies that prescription data will be misused:
Patients and physicians will have unique access to all the information. It's not our data. We don't claim it's our data. [...] Google will have no access to data we receive as part of the electronic prescribing process.
What can you do?
Labels:
data mining,
medical privacy,
medical record,
paper trail
January 5, 2007
Medical Identity Theft
From the January 8, 2007 issue of Businessweek, an article about medical identity theft and health care databases:
...but, as usual, the weakest link is usually a human:
But some privacy advocates fear that the rush toward digital health records could ironically create new nightmares for victims of medical ID theft. Rather than residing in a single doctor's paper files, fraudulent information—such as the erroneous diabetes diagnosis in Lind Weaver's records—could circulate in other medical databases across the country. Given that some medical ID thefts are "inside jobs," wherein rogue clerks sell patient data to fraudsters on the outside, privacy advocates believe that allowing data to flow more freely around a national network could make such thefts even easier. "We can expect [medical ID theft] to grow the more we move toward an electronic health-care system. It's going to be a disaster," says Dr. Deborah Peel, an Austin (Tex.) psychiatrist and founder of the Patient Privacy Rights Foundation.
...but, as usual, the weakest link is usually a human:
In September, federal authorities arrested a scheduling clerk at the Cleveland Clinic's Weston (Fla.) hospital who allegedly had passed on the personal identification information of more than 1,100 patients to her cousin—who in turn submitted $2.8 million in false claims to Medicare. "Hospitals have done a poor job of implementing security procedures on their computer systems," says one federal investigator. "You'd be astonished how many people have access to your medical records."
Labels:
identity theft,
medical privacy,
medical record,
paper trail,
privacy
U.S. Mint Data Mining & Credit Card Privacy
This freetimes.com article on U.S. federal government surveillance mentions the U.S. Mint's credit card data mining program:
The article also mentions the DIA's purchase of Verity K2 Enterprise software to search the databases of other intelligence agencies, and IRS's Reveal, and others from the GAO report on government data mining.
Unlike the NSA and Treasury spy programs, a U.S. Mint program that trawls through your credit card data when you make online purchases isn't aimed at terrorists. It was built to spy on ordinary Americans in an effort to "detect criminal activities or patterns" and "stop fraudulent activity involving stolen credit cards." Yet very little has ever been written or reported about it.
The article also mentions the DIA's purchase of Verity K2 Enterprise software to search the databases of other intelligence agencies, and IRS's Reveal, and others from the GAO report on government data mining.
Labels:
data mining,
financial privacy,
paper trail,
surveillance
Subscribe to:
Posts (Atom)