Using the Equifax Data Breach, please explain in a few paragraphs what regulations or laws that would have been applicable. Also include a discussion of what penalties were or could have been assessed as a result of the incident.
For example, if your incident involved a health insurer with a data breach, HIPAA (medical info), PCI (payment info), and state breach notification regulations might all be applicable.
Will give thumbs up if good!
Equifax Inc. is a consumer credit reporting agency. Equifax collects and aggregates information on over 800 million individual consumers and more than 88 million businesses worldwide.
The theft of an estimated 143 million Americans’ personal details in the breach of consumer-credit reporting agency Equifax and the Russian hack of the U.S.
They were partly possible because our personal data has no legal protections. Though the U.S. Constitution provides Americans with privacy rights and freedoms, it doesn’t protect us from modern-day scavengers who obtain information about us and use it against us. Our privacy laws were designed many years ago and are badly in need of modernization. Much damage has already been done to our finances, privacy, and democracy — but worse lies ahead.
The FTC can possibly fix this problem by requiring data brokers to provide industrial-strength security. University of California at Berkeley law professor Pamela Samuelson says the FTC has “statutory authority to regulate unfair and deceptive practices can act on that authority by initiating claims against those who fail to maintain adequate security.”
Equifax’s handling of the breach investigation and response has spurred numerous states to enact new or amended data security laws and regulations,
These emerging standards around breach notification have gotten legal departments’ attention, particularly around issues of timing, Most, if not all, of the newly enacted laws and regulations establish express timeframes for notifying affected individuals and regulators of a data breach.
And there have also been attempts to create broader cybersecurity frameworks through federal legislation. Some of these have been revived in the last 12 months after the Equifax incident.
As with HIPAA, they have capitalized certain GDPR-defined terms below. GDPR is comprised of 99 articles set forth in 11 chapters, and 173 “Recitals” explain the rationales for adoption. Similar to the way regulatory preambles and guidance published by the U.S. Department of Health and Human Services (HHS) can be helpful to understanding HIPAA compliance, the Recitals offer insight into GDPR applicability and scope.
Under Article 3, GDPR applies:
(1) To the Processing of Personal Data in the context of the activities of an establishment of a Controller or Processor in the EU, regardless of whether the Processing takes place in the EU;
(2) To the Processing of Personal Data of data subjects who are in the EU by a Controller or Processor not established in the EU, where the Processing activities are related to:
(a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the EU; or
(b) the monitoring of their behavior as far as their behavior takes place within the EU; and
(3) To the Processing of Personal Data by a Controller not established in the EU, but in a place where EU member state law applies by virtue of public international law.
The Genetic Information Nondiscrimination Act of 2008 prohibits the use of genetic information in health insurance and employment. But it provides no protection from discrimination in such matters as long-term care, disability, housing, and life insurance, and it places few limits on commercial use. There are no laws to stop companies from using aggregated genomic data in the same way lending companies and employers use social media data, or to prevent marketers from targeting ads at people with genetic defects.
Using the Equifax Data Breach, please explain in a few paragraphs what regulations or laws that...
Qn
based on the laboratory data what is a likely diagnosis for this
patient?
Question 2 How does this patient ‘s condition differ from the
conditions of other patients who might have similar laboratory
findings?
Case Study #1 udent health service. A A 20-year-old female college student with a sore throat is seen in the st throat swab is cultured with an intramuscular injection of pen and reported positive for group A β-hemolytic streptococci. She is treated icillin. Two weeks...
what resear questions can be asked and why on the topic; Why
Doctors Still Offer Treatments That May Not Help
Why Doctors Still Offer Treatments That May Not Help idence-based medicine has made progress since doctors' infamous bloodletting of George Washington, but less than you might think New York Times By Austin Frakt . Aug. 26, 2019 X Image LEECHES A leech basin and other bloodletting instruments, taken by Meriwether Lewis and William Clark on their expedition to the West...
For this paper, the following five elements must be addressed: Describe a current IT-related ethical issue: Since this is a paper exercise, not a real-time situation, you may want to construct a brief scenario where this issue comes into play, and thus causes an ethical dilemma. The dilemma may affect you, your family, your job, or your company; or it may be a matter of public policy or law that affects the general populace. See the list below for a...
please answer this after reading the article What is the actual problem? What are the known facts? What decision is to be made? How the problem ought to be solved? What are the alternatives? What are your recommendations? New AI tools make BI smarter — and more useful Data science democratized: What used to take data scientists months to prepare may soon be put together in a few days by data-astute business users. By Maria Korolov, Contributing Writer, CIO |...
Using the book, write another paragraph or two: write 170
words:
Q: Compare the assumptions of physician-centered and
collaborative communication. How is the caregiver’s role different
in each model? How is the patient’s role different?
Answer: Physical-centered communication involves the specialists
taking control of the conversation. They decide on the topics of
discussion and when to end the process. The patient responds to the
issues raised by the caregiver and acts accordingly. On the other
hand, Collaborative communication involves a...
Please explain how to make an IRAC for this case IRAC METHOD of J.T. ex rel. Thode v. Monster Mountain, LLC I: What is the Legal Issue in This Case? R: What is the Rule (law) of the Case? A: What is the Court's Analysis and Rationale? C: What Was the Conclusion or Outcome of the Case? Summary of this case In late January of 2009, J.T.—a minor from Indiana and a competitive motocross rider—traveled to Monster Mountain MX Park...
Case 7-3: Wentworth Hospital Discussion Questions: essay paragraph Is there anything irregular here? What is your impression of Robinson and Neha Khera? What is your impression of Irvine and Steven Bowles? What is going to happen with the use of endoscopes in hospitals in the future? What are the costs of an endoscope failure? As Rebecca Hogan, what is your analysis of the endoscope repair situation at Wentworth Hospital? What action would you take and why? Article Case 7–3 Wentworth...
What happened on United flight 3411?What service expectations
do customers have of airlines such as United and How did these
expectations develop over time?
Thank You!
In early April 2017, United Airlines (United), one of the largest airlines in the world, found itself yet again in the middle of a service disaster this time for forcibly dragging a passenger off an overbooked flight. The incident was to become a wake-up call for United, forcing it to ask itself what to...
Please read the article and answer about questions. You and the Law Business and law are inseparable. For B-Money, the two predictably merged when he was negotiat- ing a deal for his tracks. At other times, the merger is unpredictable, like when your business faces an unexpected auto accident, product recall, or government regulation change. In either type of situation, when business owners know the law, they can better protect themselves and sometimes even avoid the problems completely. This chapter...
Actions that damage a company and its employees should be stamped out, everyone would agree. But should the people responsible be stamped out, too? HBR CASE STUDY The Reign of Zero Tolerance by Ben Gerson "Mr. Pemberton?" manager. The guards had radioed her that the "Yes, that's me," Simon replied distractedly, his back turned. target wasn't putting up much resistance. "Your personal belongings will be messen The two burly gentlemen who had suddenly gered to your home later today," Sallie...