Showing posts with label Identity Theft. Show all posts
Showing posts with label Identity Theft. Show all posts

February 19, 2010

93H: There Is A Reason For This

As the deadline for compliance with the Massachusetts Data Security Law approaches (March 1st is now two weeks away), many businesses are undoubtedly looking at the new burdens that are being thrown at them and wondering if it’s necessary.  Perhaps the Massachusetts legislature got bored one day and decided to inconvenience businesses by requiring them to write information security policies and implement safeguards.  Maybe they have friends in the encryption or consulting industries.  But a recent report has given further evidence to what many already knew:  Identity theft is a growing problem and businesses that handle people’s sensitive information should make efforts to make sure that if this data is stolen, they are not the ones responsible for it.

A research group concluded there were over 11 million US identity fraud victims in 2010, a 12-percent increase perhaps caused by bad economic times (hat tip to the ISMG).  Surprisingly, over two-thirds of this crime was executed using non-technical methods, emphasizing that identity theft prevention is not specifically an IT burden.  This growing crime cost victims $54 billion in 2010.  By comparison, ID theft victims lost three times what all of Bernie Madoff’s victims lost during Madoff’s entire career.

GraVoc Associates, Inc’s information security team, which has worked primarily with the highly-regulated financial services industry in the past, has begun to work with non-financial clients with Massachusetts Data Security Law (M.G.L. 93H or 201 CMR 17.00) compliance services.  A free on-demand webinar has been recorded and distributed to existing GraVoc clients, and will be made available on GraVoc.com later on this week.  The standards required by this law, while they are not nearly as aggressive as they were when originally penned, can require a lot of work, and many businesses have gone to GraVoc for advisory and help with compliance with this law.

GraVoc Associates, founded in 1994, provides a wide range of solutions in the fields of information security, information systems, and professional services.  The GraVoc News Blog has been following developments regarding the Mass. Data Security Law since the blog’s inception in 2008, and you may find value in perusing the archives for more information.  For additional information about GraVoc’s services in all three fields, we strongly encourage you to browse GraVoc.com.

March 4, 2009

New MGL 93-H Deadline: January 1, 2010

The Massachusetts Office of Consumer Affairs and Business Regulation (OCABR) has again pushed back the date at which the new Massachusetts General Law 93-H goes into effect. The new date is January 1, 2010.

MGL 93-H is better known as the "Massachusetts Data Protection Law."

A press release from the OCABR is available here.

Massachusetts General Laws 93-H and 93-I are generally considered the toughest laws in the nation regarding identity theft prevention. This law requires businesses containing either paper or electronic files with personal identifiable information to have a comprehensive information security policy. The specification of the information security policy are available in PDF format here.

Governor Deval Patrick announced the impending enforcement of this law last fall and GraVoc Associates, Inc. was one of the first firms to address the law’s tough standards. Starting in November, GraVoc began offering services to help small businesses safeguard its customers’ and employees’ personal information and comply with MGL 93-H. Since, the OCABR has given businesses more time to undertake 93-H compliance efforts, pushing back the January 1, 2009 deadline to May 1, 2009, and now to January 1, 2010.

GraVoc Associates, Inc, a full-service consulting firm based in Peabody, MA, is celebrating 15 years of business in Greater Boston and throughout New England. A versatile business, GraVoc offers a wide range of services in the fields of information systems, information technology, financial services, and information security. For more information on GraVoc, please visit GraVoc.com or call GraVoc’s offices at 978-538-9055.

December 5, 2008

Cracking Down: GraVoc Information Security Practice launches the latest version of its identity theft risk assessment

Since the introduction of the FACT Act Red Flags Rule in November 2007, our Information Security consultants have been hard at work developing risk assessment tools and solutions to help our clients comply with the regulatory standards and ultimately develop an Identity Theft Prevention Program. We have continued to update our identity theft risk assessment methodology according to our latest research of risk mitigation tactics and, more importantly, our experience from prior assessments. For more information on how to keep your information and business secure visit our Information Security page.