Discussion: Information and the Internet—Laws and Regulation (150+150 = 300 words)

profiledk1913
Discussion2.docx

Discussion: Information and the Internet—Laws and Regulation

 

Part A:

Normally, it depends on how much information anyone share online, and sometimes other companies for example Banks, credit card companies, mortgage brokers, data brokers, utilities, etc. collect information to track your preferences.

It's important to note here that there are no free lunches in the world. You must pay in either way, in terms of money or in terms of your privacy etc. if you make an account on google and it seems like it’s free for customers, but everyone is paying back by sharing their information.  For many reasons, online privacy is crucial. Nobody wants to share their personal data with strangers, and it's difficult to know what personal information is collected and by whom.  data obtained by one company may be shared with another. and for me its identity theft.

Many people share information online very causally with no thought about how it will be used. On its own, perhaps that single piece of information is useless, but added to everything else a data broker may have, a more complete picture can be seen. The risks to you are somewhat in your control, but not all.

 

Part B:

The various laws and regulation associated with cybercrimes are

· Electronic Communications Privacy Act (ECPA): Sections of this law address e-mail, cellular communications, workplace privacy, and a host of other issues related to communicating electronically.

· Computer Fraud and Abuse Act (1986): amended many times and serves as the current foundation for criminalizing unauthorized access to computer systems.

· Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM): to regulate commercial e-mail by establishing national guidelines and giving the FTC enforcement powers.

· The USA PATRIOT Act of 2001, laws related to privacy in the United States

· Gramm-Leach-Bliley Act (GLBA) a major piece of legislation affecting the financial industry that includes significant privacy provisions for individuals.

· Privacy Laws: There are laws for healthcare and education record , as well as other types of records, including video rental records.

· Payment Card Industry Data Security Standard (PCI DSS): The Payment Card Industry Data Security Standard (PCI DSS) is a set of contractual rules governing how credit card data is to be protected.

· U.S. Digital Signature Laws: This law implements a simple principle: a signature, contract, or other record may not be denied legal effect, validity, or enforceability solely because it is in electronic form.

 

The HIPAA Security Rule: HIPAA (Health Insurance Portability and Accountability) is federal legislation that was designed to protect patient’s personal health information (PHI).  HIPAA was enacted before the technological revolution in the global community.  At that time the data was not regulated and there was no accountability regarding the privacy and confidentiality of the data. For these reasons, officials decided to develop guidance that could be followed universally by all healthcare providers to protect the personal health information of the patients they served.

The creation of the Security Rule (HIPAA) stemmed from growing concerns about patient privacy and data breaches in the healthcare industry due to non-standardized data management processes.

 

General Data Protection Regulation GDPR: briefs about how data should be shared on the internet. It introduced new rules around how a company should use User's data.

The main points are Companies will ask you for permission more often, Companies won't be able to share data behind the scenes without explaining their agenda when it comes to that data.

 individuals will have more rights on how businesses use their data, and it is an advantage. In some instances, they have the ‘right to be forgotten’ if they no longer want you to process their personal data and you have no other legal grounds (for example the individual is no longer a customer so your contract with them no longer gives you a legal right) to keep the data.

There are following challenges regarding GDPR.

•           Data Storage and Access

•           Team Compliance and Training

•           Data Subject Requests

 

Part 2 & 3:

Here are some suggestions to enhance and could it be more completely and efficiently enforced

· Data is critical in healthcare organizations because they behave as data exchanges. Therefore, adequate training must be provided to all employees, to protect the privacy and confidentiality of PHI.

· Security policies according to geographical regions must be developed to comply with local and international regulations.

· Cross-training of technical staff will be required in case global IT staff is managing devices and data across the globe. For example, staff in the US and Pakistan will need to be trained on GDPR if they are providing shared services to any country.

· The company has to bear the additional cost of human resources and technical controls to comply with GDPR. For example, GDPR compliant devices need to be implemented to comply with data confidentiality, integrity, validation, and compliance rules.

· Additionally, legal staff must be hired to meet the demands of the new regulations.

 

United States does not have a centralized privacy law like GDPR, some of the privacy laws are specific to state and others are industry specific. The act enforces citizens right of GLBA has two rules, one is financial privacy rule and other is safeguard rule. Financial privacy rule requires financial companies to provide privacy notice to customers. Privacy notice must include what information is collected, how it is collected, who will it be shared with and how it is protected. Safeguard rule requires organization to have an information security plan, it includes risk assessment plan, incident handling along with other security practices.