Posted in

Making the Case: Enforcing Harsher Penalties for Data Debauchery

As the Facebook and Cambridge Analytica data scandal cools down somewhat, the revelation that yet another tech giant has mishandled user data is still fresh in the minds of regulators and senators as CEO Mark Zuckerberg’s recent meeting with Congress wraps up.

Where this meeting will lead the tech and data industry is anybody’s guess. For data protection advocates, this could be the dawn of a new and hopeful day, heralding the birth of tighter regulations and penalties for tech giants involved in data debauchery. On the other hand, this could just be another drop in the bucket, a going-through-of-the-motions, so to speak.

The latter is believable, because this isn’t the first time that the CEO of a major corporation was made to testify in front of Congress. Richard F. Smith, the former CEO of Equifax, was in a similar situation as the head of the company when a data breach exposed lifetime data of over 146 million Americans. He found himself, much like Zuckerberg was, grilled by a council of Washington lawmakers.

In his testimony before the House Energy and Commerce Committee, he apologized repeatedly,   But he also sought to play down the severity of the problems that had led to the breach, defended the company’s response to the crisis and deflected questions about how far Equifax would go to compensate consumers who were financially harmed, according to the New York Times.

Unfortunately, Smith’s October 3, 2017 hearing brought little in terms of justice. Many thought that this might be the long-envisioned incident that prompted Congress to finally fix the country’s confusing and ineffectual data security laws, writes Politico’s Martin Matishak. Instead, the aftermath of the breach played out like a familiar script: white-hot, bipartisan outrage, followed by hearings and a flurry of proposals that went nowhere.

What makes this worse is that the American public has been demanding harsher penalties and enforcement for data breach and protection for years now ” but these pleas have obviously fallen on deaf ears.

Existing Compliance Measures

Interestingly, the government already has extensive regulation for companies that handle personal information and data. HIPAA and PCI-DSS provide regulatory compliance measures to the healthcare and fiscal sectors, respectively.

While the existence of these measures has undoubtedly been beneficial, we can do better. Fiscal Tiger cites company database breaches as a major reason for credit fraud, while multiple authorities in the healthcare field confirm that several HIPAA violations are common among health organizations, such as failing to store private healthcare information properly, failing to obtain written consent from patients and sharing photos of patients on social media.

Credit fraud is a serious problem. But is failing to store private healthcare information properly that bad? You’d be surprised. While these latter infractions may not seem malicious, nefarious, or altogether serious, that assumption couldn’t be any further from the truth. Improper information storage and sharing put personal data at risk that could be sold on the black market and used to commit identity theft.

Indeed, Duquesne University’s online resources concur that EHR security breaches range from simple flaws in network security to determined, focused attacks maliciously orchestrated by expert hackers.

To illustrate just how impactful minor infractions can be, they use Molina Healthcare’s network as an example, in which, in May 2017, a simple authentication flaw was discovered that exposed up to 4.8 million patient records. This exposed data included names, addresses, birth dates, diagnoses, and other medical information about individual patients.

The catch here is that most HIPAA violations ” and violations of other compliance protocols ” are already well enforced with steep penalties. But are these penalties enough to keep our data safe from willfully neglectful companies like Facebook and Equifax?

A Time for Change

During his meeting with the Senate, Zuckerberg was asked by Senator Richard Durbin, a Democrat from Illinois, whether he would be comfortable sharing the name of the hotel he was staying at, or the names of people he’d been messaging.

No. I would probably not choose to do that publicly here, Mr. Zuckerberg said.

I think that may be what this is all about, Mr. Durbin said. Your right to privacy. The limits of your right to privacy. And how much you give away in modern America in the name of, quote, connecting people around the world.

These quotes were delivered by Zach Wichter with the New York Times, who recently covered Zuckerberg’s trip to DC. Among other things, he sounds hopeful that this time, things are different. This time, things might change.

Privacy experts agree with the calls for regulation, saying there is now enough social consciousness to make real and important changes in the way the internet user data is handled and regulated, he writes.

The problem is that this isn’t the first time we’ve been in this situation. However, as long as outrage isn’t followed by absolute complacency, we could truly make a change this time. Only time will truly tell whether or not new technologies, legislation, or even standards are set forth in relation to user data. The question of just how one would go about regulating the data landscape beyond its current regulatory standard also looms.

There’s only one thing that’s for sure ” it’s a time for change. We shouldn’t wait until the next data disaster necessitates new measures of protection. Instead, we should be proactive and hold companies to a higher standard.

They profit off of our data. It’s time they paid us back.

I'm a Big Data, IoT nerd who is also a performing artist out of Boise, ID. I started working in IT while I was attending College of Idaho '08 to '12 and then moved into web development and social/internet marketing and blogging shortly after. After ghost-writing a couple of whitepapers on data warehouse management software, I slowly but surely found myself increasingly interested in Big Data and Analytics and how it's seeping into basically every aspect of our lives. This opens up a whole new world of possibilities--both good and bad. I'm here to write about them. Follow me on Twitter @AndyO_TheHammer

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.