|
ALBANY---The state Attorney General's office has announced the first settlement under New York's Information Security Breach and Notification Law.
CS Stars LLC, a Chicago-based claims management company, failed to notify the owner of computerized data and approximately 540,000 New York consumers that their personal information was at risk for seven weeks. The company has agreed to implement precautionary procedures and comply with New York's notification law in the event of a security breach.
On May 9, 2006, an employee at CS Stars noticed that a computer was missing that held personal information, including the names, addresses, and social security numbers of recipients of workers' compensation benefits. The New York Special Funds Conservation Committee, a not-for-profit organization created to assist in providing benefits to workers under the New York Workers' Compensation Law, was the owner of the data contained in the missing computer.
It was not until June 29, 2006 that CS Stars first notified Special Funds of the security breach. On the same date, CS Stars notified the FBI and requested assistance. The FBI requested that no notifications be sent at that time to potentially affected persons regarding the computer because the FBI was concerned that the notifications would impede its investigation. CS Stars notified the Attorney General's office, the Consumer Protection Board, and the state office of Cyber Security of the breach on June 30, 2006.
On July 18, 2006, CS Stars, on behalf of its client, Special Funds, and with the permission of the FBI, began sending notices to the approximately 540,000 potentially affected New York consumers notifying them of the security breach. On July 25, 2006, the FBI determined that the computer had been stolen by an employee of a cleaning contractor, and the missing computer was located and recovered. In addition, the FBI's investigation indicated that the data on the missing computer had not been improperly accessed.
Under New York's Information Security Breach and Notification Law, any business which maintains private information which it does not own must notify the owner of the data of any security breach "immediately following discovery" of the breach and must notify all affected consumers in the "most expedient time possible." Notice of the breach must also be given to the Attorney General's office, the Consumer Protection Board, and the state office of Cyber Security.
Without admitting to any violation of law and cooperating fully with the Attorney General's investigation, CS Stars agreed to comply with the law and ensure that proper notifications will be made in the event of any future breach. The company also agreed to implement more extensive practices relating to the security of private information. CS Stars will pay the Attorney General's office $60,000 for costs related to this investigation. 4-27-07
© 2007 North
Country Gazette
|