March 25, 2007
Residential WiFi mapping database revealed
Skyhook Wireless has been scanning American neighborhoods for WiFi access points and putting them into a database. So far they've got 16 million detected wireless access points, covering the majority of the U.S. and Canadian population.
Remember again, if computer privacy and security are more important to you than convenience, don't network without wires. Information is out of your control once it hits the airwaves.
March 12, 2007
Comparison of Prepaid Credit Cards
Ryan Barrett at snarfed.org has an updated essay on protecting your privacy with prepaid credit cards and gift cards.
Labels:
data mining,
financial privacy,
identity theft,
paper trail
February 21, 2007
Prescription Records for Sale
In January 2007, the new National ePrescribing Patient Safety Initiative (NEPSI) debuted with a high-profile article in Time magazine.
This web-based system is supplied free of charge to physicians, ostensibly to reduce prescription error rates. Revenue to pay for the information system comes from the participating pharmacies and insurers who save time and money.
Now there are accusations that this database has been developed to give drug marketers, insurance risk assessors, and employers access to patients' private prescription records.
According to a Government Health IT article, all the prescription records stored in the new NEPSI database are for sale:
In another article, Dr. Peel says that NEPSI sells data to large employers:
But Allscripts CEO Tullman denies that prescription data will be misused:
What can you do?
Ask your medical care providers if they use the web-based NEPSI electronic prescription system.
Consider refusing prescriptions for conditions that you would not want your employers or government to know about. Some doctors will give out samples to their patients, and this might be a sufficient quantity to forgo a formal prescription.
A cash transaction by itself won't keep you out of the NEPSI database because it contains patient information and the prescription itself, not just billing information like an insurer's database might.
This web-based system is supplied free of charge to physicians, ostensibly to reduce prescription error rates. Revenue to pay for the information system comes from the participating pharmacies and insurers who save time and money.
Now there are accusations that this database has been developed to give drug marketers, insurance risk assessors, and employers access to patients' private prescription records.
According to a Government Health IT article, all the prescription records stored in the new NEPSI database are for sale:
Security makes little difference because every identifiable prescription in the country is data mined and sold daily. Nobody needs to break into pharmacies to steal our prescriptions; they are for sale. For example, market intelligence firm IMS Health reported revenues of $1.75 billion in 2005 solely from the sale of prescription records, primarily to drug companies.
In another article, Dr. Peel says that NEPSI sells data to large employers:
In 2006, the national Blue Cross and Blue Shield Association announced its Blue Health Initiative to aggregate and sell the claims, medical and prescription data of all 79 million enrollees to large employers. This database will include far more detail than e-prescription records, making the sales of Blues data worth far more than the billions in revenue from selling e-prescription records alone.
But Allscripts CEO Tullman denies that prescription data will be misused:
Patients and physicians will have unique access to all the information. It's not our data. We don't claim it's our data. [...] Google will have no access to data we receive as part of the electronic prescribing process.
What can you do?
Labels:
data mining,
medical privacy,
medical record,
paper trail
February 9, 2007
Laptop data searches at border checks
U.S. courts have approved border agents' search of traveler's laptops without articulable probable cause.
Indications are that U.S. and Candian customs officials are searching laptops for pornography and obscene material.
Some travelers report being asked if the laptop they were carrying was a personal or company unit. Presumably, corporate laptops are less likely to be checked for obscene material than personal units are.
Authorities also have the ability to conduct forensic computer searches at border crossings and have done so in the past.
Data transmitted across national borders via the Internet is more strongly protected than data hand-carried through Customs checkpoints, because wiretaps must comply with the requirements of Title III, 18 U.S.C. §§ 2510-2522, or the Pen/Trap statute, 18 U.S.C. §§ 3121-3127. The few advantages of hand-carry are totally lost if one cannot be assured that the data hasn't been copied, or that software or hardware spying mechanisms haven't been implanted within it.
Travelers with sensitive or legally privileged data will want to Customs-proof their laptop before crossing a controlled border. Strong encryption is the best tool to protect data that must be hand-carried through Customs instead of residing on a remote server. Some organizational IT departments are investigating hardware hard-disk encryption, sometimes combined with hardware biometric readers.
It is unclear at this time whether a traveler can be forced to divulge a password. One privacy wonk has suggested wearable or concealable USB drives as a measure of protection.
Indications are that U.S. and Candian customs officials are searching laptops for pornography and obscene material.
Some travelers report being asked if the laptop they were carrying was a personal or company unit. Presumably, corporate laptops are less likely to be checked for obscene material than personal units are.
Authorities also have the ability to conduct forensic computer searches at border crossings and have done so in the past.
Data transmitted across national borders via the Internet is more strongly protected than data hand-carried through Customs checkpoints, because wiretaps must comply with the requirements of Title III, 18 U.S.C. §§ 2510-2522, or the Pen/Trap statute, 18 U.S.C. §§ 3121-3127. The few advantages of hand-carry are totally lost if one cannot be assured that the data hasn't been copied, or that software or hardware spying mechanisms haven't been implanted within it.
Travelers with sensitive or legally privileged data will want to Customs-proof their laptop before crossing a controlled border. Strong encryption is the best tool to protect data that must be hand-carried through Customs instead of residing on a remote server. Some organizational IT departments are investigating hardware hard-disk encryption, sometimes combined with hardware biometric readers.
It is unclear at this time whether a traveler can be forced to divulge a password. One privacy wonk has suggested wearable or concealable USB drives as a measure of protection.
Labels:
border crossing,
computer security,
privacy,
travel privacy
February 3, 2007
The power of data mining
An exercise in finding subversives through Amazon.com wishlists illustrates the power of data mining:
It used to be you had to get a warrant to monitor a person or a group of people. Today, it is increasingly easy to monitor ideas. And then track them back to people. Most of us don't have access to the databases, software, or computing power of the NSA, FBI, and other government agencies. But an individual with access to the internet can still develop a fairly sophisticated profile of hundreds of thousands of U.S. citizens using free and publicly available resources. Here's an example.
There are many websites and databases that could be used for this project, but few things tell you as much about a person as the books he chooses to read. Isn't that why the Patriot Act specifically requires libraries to release information on who's reading what? For this reason, I chose to focus on the information contained in the popular Amazon wishlists.
January 5, 2007
Medical Identity Theft
From the January 8, 2007 issue of Businessweek, an article about medical identity theft and health care databases:
...but, as usual, the weakest link is usually a human:
But some privacy advocates fear that the rush toward digital health records could ironically create new nightmares for victims of medical ID theft. Rather than residing in a single doctor's paper files, fraudulent information—such as the erroneous diabetes diagnosis in Lind Weaver's records—could circulate in other medical databases across the country. Given that some medical ID thefts are "inside jobs," wherein rogue clerks sell patient data to fraudsters on the outside, privacy advocates believe that allowing data to flow more freely around a national network could make such thefts even easier. "We can expect [medical ID theft] to grow the more we move toward an electronic health-care system. It's going to be a disaster," says Dr. Deborah Peel, an Austin (Tex.) psychiatrist and founder of the Patient Privacy Rights Foundation.
...but, as usual, the weakest link is usually a human:
In September, federal authorities arrested a scheduling clerk at the Cleveland Clinic's Weston (Fla.) hospital who allegedly had passed on the personal identification information of more than 1,100 patients to her cousin—who in turn submitted $2.8 million in false claims to Medicare. "Hospitals have done a poor job of implementing security procedures on their computer systems," says one federal investigator. "You'd be astonished how many people have access to your medical records."
Labels:
identity theft,
medical privacy,
medical record,
paper trail,
privacy
U.S. Mint Data Mining & Credit Card Privacy
This freetimes.com article on U.S. federal government surveillance mentions the U.S. Mint's credit card data mining program:
The article also mentions the DIA's purchase of Verity K2 Enterprise software to search the databases of other intelligence agencies, and IRS's Reveal, and others from the GAO report on government data mining.
Unlike the NSA and Treasury spy programs, a U.S. Mint program that trawls through your credit card data when you make online purchases isn't aimed at terrorists. It was built to spy on ordinary Americans in an effort to "detect criminal activities or patterns" and "stop fraudulent activity involving stolen credit cards." Yet very little has ever been written or reported about it.
The article also mentions the DIA's purchase of Verity K2 Enterprise software to search the databases of other intelligence agencies, and IRS's Reveal, and others from the GAO report on government data mining.
Labels:
data mining,
financial privacy,
paper trail,
surveillance
Subscribe to:
Posts (Atom)