19 October 2011

TK and Trade Secrets

'A Trade Secret Approach to Protecting Traditional Knowledge' by Deepa Varadarajan in (2011) 36(2) Yale Journal of International Law comments that -
The skills and innovations of indigenous and local communities - their so-called “traditional knowledge” - go largely unrecognized by intellectual property law. Meanwhile, patent and copyright laws reward the innovative and creative contributions of individuals and firms that freely use traditional knowledge as inputs for a variety of products. The perceived inequity has inspired the ire of indigenous groups, advocates and developing country governments, led to impassioned accusations of “biopiracy” and “First-World imperialism,” and triggered various reform efforts. Despite a decade of trying, however, traditional knowledge holders and their advocates still seek meaningful recognition and rights within the international IP framework. This Article argues that the doctrinal and normative divide between traditional knowledge and intellectual property law has been overemphasized and that trade secret law can potentially narrow it. I argue that the application of trade secret law to protect traditional knowledge - a trade secret approach - is a practical path forward in the current international impasse. Moreover, I argue that the underlying justifications for trade secret law offer a useful normative guide for theorizing traditional knowledge protection and linking it to the broader purposes of IP law. Like trade secret law generally, the protection of traditional knowledge can ultimately serve the broader purposes of IP law by reducing holders’ distrust in negotiating with outsiders and by encouraging the disclosure of potentially valuable secret information to more productive users and improvers.
The author goes on to state that -
The relationship between intellectual property law, secrecy, and disclosure has important consequences for the traditional knowledge debate. In the traditional knowledge context too, society as a whole benefits from the disclosure of commercially valuable information. If bark from a tree and ashaman’s knowledge of its special properties can cure ulcers, then society has an interest in encouraging the disclosure of this knowledge to other entities that can improve upon it and bring it to the larger public.

At least some anecdotal evidence suggests that traditional knowledge holders are willing to share otherwise secret information with outsiders for research and commercial purposes, so long as they are afforded a degree of control over subsequent uses of the knowledge and, in some cases, a portion of the benefit. For example, traditional healers from indigenous communities in Uganda reported to WIPO IGC field researchers that they would be “willing to collaborate with modern health practitioners and the pharmaceutical industry to share information,” but that “[p]rotective measures should be in place before [they] would be willing to collaborate with outsiders.”

Evidence also suggests that in the absence of protection, traditional knowledge holders are warier of sharing and, in some cases, will go to great lengths to erect walls around potentially valuable information. A number of traditional knowledge holders interviewed during the course of the WIPO IGC’s nine fact-finding missions expressed an unwillingness to share their traditional knowledge out of fear that they would not have any control over the way the information was used or derive any economic benefits. Members of the Kuna community in Panama, for example, expressed their aversion toward collaborating with ethnobotanists or other scientists:
Expeditions by [these researchers] have started to be regarded with suspicion because community members are not involved in, nor informed of, the subsequent use of the information and biological material supplied by them. It is believed that if new products were to be developed or new scientific publications issued on the basis of that information, the communities of origin would probably never be informed and would in all likelihood not participate in any economic benefits deriving therefrom.
Some local and indigenous groups have taken more drastic steps to prevent the flow of information to outsiders. In 2000, a Wapishana indigenous community in the Guyanese Amazon banned all “researchers” from entering their villages. This community had previously shared valuable medicinal information with a British chemist about the healing powers of certain plants - Tipir, the nut of the Greenheart tree, and Cunani, a bush plant - used since ancient times. The chemist subsequently obtained U.S. and European patents based on the active ingredients in these plants, which he claimed were useful in treating malaria and preventing heart blockages. The community viewed the incident as a betrayal of their sharing. In response, they have banned the research efforts of all outsiders - to the potential detriment of society. Thus, even if an initial transmission of information - like the chemist’s initial acquisition of knowledge - can occur in the absence of traditional knowledge protection, the erosion of trust from such a one-sided transaction can pollute future transmissions.

To be sure, formal law’s role in lessening distrust may operate differently in the commercial context than in the traditional knowledge context, depending on the level of social or cultural significance that such knowledge may have for a particular community or the community’s level of wariness toward outsiders.

Information sharing in the traditional knowledge context may require greater indicia of respect or trustworthiness than the arms-length commercial licensing transactions that govern information sharing for modern firms. As Rosemary Coombe writes, “Acquiring traditional knowledge ... may require rather different forms of social relationship that involve trust [and] collaboration,” as well as a showing of “respect that our intellectual property laws ... do little to encourage.”

Here, too, a fair amount of variation is likely to exist among and between groups. But what is striking about the data collected by the WIPO IGC is that a number of traditional knowledge holders have voiced a greater willingness to share knowledge and collaborate upon receiving internationally recognized IP rights. And experimental projects such as Ecociencia’s closed-access registry of botanical knowledge suggest trade secret law’s potential for eliciting hitherto unknown and undisclosed traditional knowledge and encouraging its categorization, classification, and storage in forms that can be more easily shared with outsiders.

Even outside of the traditional knowledge context, the effects of formal law on trust and behavior are difficult to measure in any absolute terms; its role is often “modest but [nonetheless] important.” As Dagan and Heller observe:
The myriad details of the law do not matter individually, but jointly they produce practices and experiences that in turn generate social expectations. For law to affect behavior, we do not assume widespread knowledge of any doctrinal detail, only that people generally believe that if things turn ugly, the law will serve as one form of social organization that protects them against extreme abuse and exploitation.
Thus, while the evidence may be limited, there are both logical and evidentiary reasons to suggest that without legal protection, traditional knowledge holders would disclose less and take more assertive steps to prevent the flow of information to outsiders. This is problematic for a number of reasons, including that it will “slow the process of commercialization and improvement of” relatively secret knowledge and ultimately interfere with “both the invention and disclosure functions of IP law.” For example, researchers might be prevented from entering these communities at all, or even if they did enter, traditional knowledge holders might be unwilling to share information that could lead to the next antimalarial or heart medicine.

The role of intellectual property law in facilitating trust and cooperation in the traditional knowledge context merits additional research and investigation. Trade secret law - and more specifically, a clarification of TRIPS Article 39’s commercial value requirement and a richer understanding of the intersection of reasonable secrecy efforts and customary law in the traditional knowledge context - may, in the end, comprise only part of a broader package of useful policy reforms. My purpose here is not to suggest that trade secret law is the only desirable path. Rather, I seek to illuminate the ways in which trade secret law can protect a subset of traditional knowledge and help frame the international discussion in a more fruitful way - a way that emphasizes important connections between traditional knowledge protection and the broader purposes of intellectual property, instead of merely its divisions.
Varadarajan concludes that -
For over a decade, the issue of traditional knowledge protection has posed an intractable problem for advocates, scholars, and developing country governments. Traditional knowledge advocates seek greater recognition and rights within international intellectual property law—particularly, the muscular TRIPS framework. But thus far, they have failed to effectively link their arguments to the IP framework or the broader purposes of existing IP regimes. Instead, traditional knowledge advocates have operated primarily within “human rights” and “preservation” approaches. These approaches appear more hospitable to traditional knowledge advocates than the conventional IP approach, especially given the latter’s focus on ex ante “incentives to create.” But the conventional IP approach need not be so narrow.

I have argued that trade secret law is useful to the traditional knowledge debate in two underexamined ways. First, a trade secret approach to traditional knowledge protection is a practical initial step forward in the international impasse. Trade secret law can be a useful legal vehicle for traditional knowledge holders when dealing with outsiders’ improper acquisition, disclosure, and use of relatively secret information. Admittedly, many traditional knowledge holders may view trade secret law as too limited - too fragile - because it does not apply to publicly available, reverse-engineered, or independently developed information. While I am sympathetic to such concerns, this Article takes a decidedly pragmatic approach; more idealized approaches that significantly undercut the purposes of existing intellectual property regimes are less likely to be accepted within the framework of international IP law and enforced by the international community. Absent a model for protection that incorporates some objective limits and preserves access to generally available information, “an international approach is likely to be a more abstract gesture” than a reality.

In addition to outlining trade secret law’s practical possibilities in the traditional knowledge arena, I have argued that trade secret law can serve as a normative guide to help ground an IP theory of traditional knowledge protection. One prominent justification for trade secret law’s inclusion in the IP law family is that it serves the “disclosure” purposes of IP law by reducing holders’ over-investment in secrecy, lessening distrust, and encouraging the disclosure of valuable information to those who can improve or make more productive use of it. Similarly, traditional knowledge protection may lessen the distrust of indigenous and local communities toward outsiders and encourage their disclosure of valuable information in socially beneficial ways.

17 October 2011

Try caring, not sharing

In following up the recent item regarding litigation against Stanford Hospital over a data breach involving 20,000 patient records I note a proposed US$4.9bn class action against the US Defense Department over the TRICARE healthcare system for military personnel and their families.

The lawsuit alleges that the DOD failed to adequately protect private data (ie did not encrypt sensitive personal information) and exhibited "intentional, willful and reckless disregard" for patient privacy rights, including delays in notifying people whose data had been exposed. The plaintiffs seek US$1000 in damages for each of the 4.9 million individuals affected by the breach.

Last month it was revealed [PDF] that names, addresses, phone numbers, clinical notes, Social Security Numbers, pathology and other personal health data regarding around 4.9 million people (over 20 years) featured on unencrypted backup tapes stolen from the car of a Science Applications International Corporation (SAIC) at the employee's residence. The corporation is a TRICARE contractor. We might wonder about the prudence of leaving such data lying around.

The DOD advises that -
The risk of harm to patients is judged to be low despite the data elements involved since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure," according to the Tricare statement. "Since we do not believe the tapes were taken with malicious intent, we believe the risk to beneficiaries is low.
As a result the Department and SAIC will identify individuals who were exposed; those people will receive a notifications by mail over a six week period. SAIC is reported to be paying for the contact exercise but will not be funding free consumer alert services under the Health Insurance Portability & Accountability Act (HIPAA) regulations, amid claims that the data is covered by weaker Federal Trade Commission rules.

Cybersecurity disclosure

The US Securities & Exchange Commission (Division of Corporation Finance) has issued a 'disclosure guidance' regarding cybersecurity risks and cyber incidents.

The Guidance provides the Division of Corporation Finance's views regarding disclosure obligations. It states that -
For a number of years, registrants have migrated toward increasing dependence on digital technologies to conduct their operations. As this dependence has increased, the risks to registrants associated with cybersecurity1 have also increased, resulting in more frequent and severe cyber incidents. Recently, there has been increased focus by registrants and members of the legal and accounting professions on how these risks and their related impact on the operations of a registrant should be described within the framework of the disclosure obligations imposed by the federal securities laws. As a result, we determined that it would be beneficial to provide guidance that assists registrants in assessing what, if any, disclosures should be provided about cybersecurity matters in light of each registrant’s specific facts and circumstances.

We prepared this guidance to be consistent with the relevant disclosure considerations that arise in connection with any business risk. We are mindful of potential concerns that detailed disclosures could compromise cybersecurity efforts - for example, by providing a “roadmap” for those who seek to infiltrate a registrant’s network security - and we emphasize that disclosures of that nature are not required under the federal securities laws.
The Division comments that -
In general, cyber incidents can result from deliberate attacks or unintentional events. We have observed an increased level of attention focused on cyber attacks that include, but are not limited to, gaining unauthorized access to digital systems for purposes of misappropriating assets or sensitive information, corrupting data, or causing operational disruption. Cyber attacks may also be carried out in a manner that does not require gaining unauthorized access, such as by causing denial-of-service attacks on websites. Cyber attacks may be carried out by third parties or insiders using techniques that range from highly sophisticated efforts to electronically circumvent network security or overwhelm websites to more traditional intelligence gathering and social engineering aimed at obtaining information necessary to gain access.

The objectives of cyber attacks vary widely and may include theft of financial assets, intellectual property, or other sensitive information belonging to registrants, their customers, or other business partners. Cyber attacks may also be directed at disrupting the operations of registrants or their business partners. Registrants that fall victim to successful cyber attacks may incur substantial costs and suffer other negative consequences, which may include, but are not limited to:
* Remediation costs that may include liability for stolen assets or information and repairing system damage that may have been caused. Remediation costs may also include incentives offered to customers or other business partners in an effort to maintain the business relationships after an attack;
* Increased cybersecurity protection costs that may include organizational changes, deploying additional personnel and protection technologies, training employees, and engaging third party experts and consultants;
* Lost revenues resulting from unauthorized use of proprietary information or the failure to retain or attract customers following an attack;
* Litigation; and
* Reputational damage adversely affecting customer or investor confidence.
In relation to disclosure by public companies regarding "Cybersecurity Risks and Cyber Incidents" it indicates that -
The federal securities laws, in part, are designed to elicit disclosure of timely, comprehensive, and accurate information about risks and events that a reasonable investor would consider important to an investment decision.2 Although no existing disclosure requirement explicitly refers to cybersecurity risks and cyber incidents, a number of disclosure requirements may impose an obligation on registrants to disclose such risks and incidents. In addition, material information regarding cybersecurity risks and cyber incidents is required to be disclosed when necessary in order to make other required disclosures, in light of the circumstances under which they are made, not misleading.3 Therefore, as with other operational and financial risks, registrants should review, on an ongoing basis, the adequacy of their disclosure relating to cybersecurity risks and cyber incidents.
The specific disclosure obligations that may require a discussion of cybersecurity risks and cyber incidents are -
Risk Factors

Registrants should disclose the risk of cyber incidents if these issues are among the most significant factors that make an investment in the company speculative or risky.4 In determining whether risk factor disclosure is required, we expect registrants to evaluate their cybersecurity risks and take into account all available relevant information, including prior cyber incidents and the severity and frequency of those incidents. As part of this evaluation, registrants should consider the probability of cyber incidents occurring and the quantitative and qualitative magnitude of those risks, including the potential costs and other consequences resulting from misappropriation of assets or sensitive information, corruption of data or operational disruption. In evaluating whether risk factor disclosure should be provided, registrants should also consider the adequacy of preventative actions taken to reduce cybersecurity risks in the context of the industry in which they operate and risks to that security, including threatened attacks of which they are aware.

Consistent with the Regulation S-K Item 503(c) requirements for risk factor disclosures generally, cybersecurity risk disclosure provided must adequately describe the nature of the material risks and specify how each risk affects the registrant. Registrants should not present risks that could apply to any issuer or any offering and should avoid generic risk factor disclosure. Depending on the registrant’s particular facts and circumstances, and to the extent material, appropriate disclosures may include:
* Discussion of aspects of the registrant’s business or operations that give rise to material cybersecurity risks and the potential costs and consequences;
* To the extent the registrant outsources functions that have material cybersecurity risks, description of those functions and how the registrant addresses those risks;
* Description of cyber incidents experienced by the registrant that are individually, or in the aggregate, material, including a description of the costs and other consequences;
* Risks related to cyber incidents that may remain undetected for an extended period; and
* Description of relevant insurance coverage.
A registrant may need to disclose known or threatened cyber incidents to place the discussion of cybersecurity risks in context. For example, if a registrant experienced a material cyber attack in which malware was embedded in its systems and customer data was compromised, it likely would not be sufficient for the registrant to disclose that there is a risk that such an attack may occur. Instead, as part of a broader discussion of malware or other similar attacks that pose a particular risk, the registrant may need to discuss the occurrence of the specific attack and its known and potential costs and other consequences.

While registrants should provide disclosure tailored to their particular circumstances and avoid generic “boilerplate” disclosure, we reiterate that the federal securities laws do not require disclosure that itself would compromise a registrant’s cybersecurity. Instead, registrants should provide sufficient disclosure to allow investors to appreciate the nature of the risks faced by the particular registrant in a manner that would not have that consequence.
In discussing Financial Statement Disclosures the Guidance notes that "Cybersecurity risks and cyber incidents may have a broad impact on a registrant’s financial statements, depending on the nature and severity of the potential or actual incident". It comments -
Prior to a Cyber Incident

Registrants may incur substantial costs to prevent cyber incidents. Accounting for the capitalization of these costs is addressed by Accounting Standards Codification (ASC) 350-40, Internal-Use Software, to the extent that such costs are related to internal use software.

During and After a Cyber Incident

Registrants may seek to mitigate damages from a cyber incident by providing customers with incentives to maintain the business relationship. Registrants should consider ASC 605-50, Customer Payments and Incentives, to ensure appropriate recognition, measurement, and classification of these incentives.

Cyber incidents may result in losses from asserted and unasserted claims, including those related to warranties, breach of contract, product recall and replacement, and indemnification of counterparty losses from their remediation efforts. Registrants should refer to ASC 450-20, Loss Contingencies, to determine when to recognize a liability if those losses are probable and reasonably estimable. In addition, registrants must provide certain disclosures of losses that are at least reasonably possible.

Cyber incidents may also result in diminished future cash flows, thereby requiring consideration of impairment of certain assets including goodwill, customer-related intangible assets, trademarks, patents, capitalized software or other long-lived assets associated with hardware or software, and inventory. Registrants may not immediately know the impact of a cyber incident and may be required to develop estimates to account for the various financial implications. Registrants should subsequently reassess the assumptions that underlie the estimates made in preparing the financial statements. A registrant must explain any risk or uncertainty of a reasonably possible change in its estimates in the near-term that would be material to the financial statements.9 Examples of estimates that may be affected by cyber incidents include estimates of warranty liability, allowances for product returns, capitalized software costs, inventory, litigation, and deferred revenue.

Stanford

Last month I noted the breach of medical information (including patient names and diagnostic codes) at Stanford Hospital. Stanford is now facing a class action over that breach. It states that -
Stanford Hospital & Clinics (SHC) understands that a purported class action lawsuit was filed against it and Multi-Specialty Collection Services, LLC (MSCS), an outside vendor that caused some confidential information about patients who visited Stanford Hospital’s emergency room to be posted on a website. SHC intends to vigorously defend the lawsuit that has been filed as it acted appropriately and did not violate the law as claimed in the lawsuit.

SHC takes very seriously its obligation to treat its patient information as private and confidential. As soon as this was brought to SHC’s attention by a patient, the hospital demanded and had the spreadsheet taken down from the website and backup servers. SHC quickly notified the affected patients of this breach and offered to provide free identity protection services to all the patients, even though the information disclosed on the website is not the type used for identity theft. To date there is no evidence that anyone saw this information on the website and improperly used it for fraudulent or any other improper purpose. SHC has investigated this matter, terminated its relationship with MSCS, and reported this breach to law enforcement authorities.

MSCS is a California company that provided business and financial support to SHC and was operating under a contract with SHC that specifically required it to protect the privacy of the patient information sent to it and that prohibited unauthorized disclosure of that information. SHC properly sent the data to MSCS in an encrypted format to protect its confidentiality. SHC’s investigation of this regrettable incident has determined that MSCS then prepared an electronic spreadsheet from that data that had the names, addresses and diagnosis codes of almost 20,000 patients. Unfortunately, MSCS improperly sent the spreadsheet it had created to a third person who was not authorized to have that information and who improperly posted it on a website, apparently to get assistance in generating a graph from MSCS’s spreadsheet. This mishandling of private patient information was in complete contravention of the law and of the requirements of MSCS’s contract with SHC and is shockingly irresponsible.

SHC regrets that its patients’ confidentiality was breached and is committed to protecting the health and privacy of all of its patients
Elsewhere Stanford states that -
* SHC aggressively pursued a comprehensive investigation, which resulted in identifying the person who caused the information to be posted in violation of federal law and SHC’s contract. The individual who created the spreadsheet was SHC’s primary contact at MSCS and MSCS’s executive vice president. SHC has learned that his relationship with MSCS was that of an independent contractor.

* The vendor’s file, which was posted on September 9, 2010, had limited information about 20,000 patients treated in SHC’s Emergency Department from March 1 through August 31, 2009. The information included the patient’s name, medical record and hospital account numbers, an emergency department admission/discharge date, diagnosis codes related to the emergency department visit, and billing charges.

* Information generally associated with identity theft, such as credit card and social security numbers, was not published on the web site or otherwise breached.

* SHC notified appropriate government authorities and is cooperating fully. Letters were sent to affected patients informing them of the breach. Any patient receiving the letter may call 855-731-6016 for assistance with their questions or concerns.

* While information generally used for identity theft was not compromised, SHC has made arrangements for affected patients to receive free identity protection services if they wish to.

* From Diane Meyer, Chief Privacy Officer at Stanford Hospital & Clinics: “We sincerely apologize for the concern this has caused our patients. We value the privacy of patient health information and are committed to protecting it at all times. Our contractors are explicitly required to commit to strong safeguards to protect the confidentiality of our patients’ information. We have worked extremely hard to identify all the parties responsible. No Hospital staff member was involved in posting the file to the website. We will continue to take aggressive action to hold all responsible parties accountable.
The New York Times has meanwhile reported that -
an e-mail sent to a victim of the breach, the billing contractor, Joe Anthony Reyna, president of Multi-Specialty Collection Services in Los Angeles, explained that his marketing vendor, Frank Corcino, had received the data directly from Stanford Hospital, converted it to a new spreadsheet and then forwarded it to a woman he was considering for a short-term job.

The position was with Mr. Corcino’s one-man shop, Corcino & Associates, Mr. Reyna wrote in the e-mail, which was authenticated by his lawyer, Ellyn L. Sternfield. The job applicant apparently was challenged to convert the spreadsheet — which included names, admission dates, diagnosis codes and billing charges — into a bar graph and charts, Stanford Hospital officials said.

Not knowing that she had been given real patient data, the applicant posted it as an attachment to a request for help on studentoffortune.com, which allows students to solicit paid assistance with their work. First posted on Sept. 9, 2010, the spreadsheet remained on the site until a patient discovered it on Aug. 22 and notified Stanford.

The hospital, located on the campus of Stanford University in Palo Alto, demanded that the spreadsheet be removed, and the Web site quickly complied. Pressed for time, the job prospect wound up completing the assignment herself and, in the end, did not get hired, Ms. Sternfield said.
Not hiring the contender doesn't make the problem go away, and the claims and counterclaims have become nasty.

The NYT reports that
Mr. Corcino, in his first public statement, attributed the breach to "a chain of mistakes which are far too easy to make when handling electronic data." ...

The Stanford breach was notable for the duration of public exposure, and for spotlighting the vulnerability created by a medical provider’s business relationships with outside parties.

Last week, lawyers filed suit in state court in Los Angeles, seeking certification as a class action and $20 million in damages from Stanford Hospital & Clinics and Multi-Specialty Collection Services, which is known as MSCS. The threat of liability set off a predictable round of finger-pointing.

In written responses to questions, Lisa Lapin, Stanford University’s assistant vice president for university communications, said, “MSCS bears the complete and sole responsibility for the breach.”

Ms. Lapin said the hospital had sent the data in encrypted form to Mr. Corcino, who requested it on behalf of MSCS to analyze a strategy for improving billing collections. She said Mr. Corcino had regularly represented himself as MSCS’s executive vice president and had been Stanford’s “primary contact” during a seven-year relationship. MSCS, a five-person firm that audits hospital accounts to maximize reimbursement, possessed the passwords to unencrypt the data, she said.

“This mishandling of private patient information was in complete contravention of the law and of the requirements of MSCS’s contract and is shockingly irresponsible,” the hospital said in a statement.
FRelying on the Casablanca model, various people are expressing shock, distress and amazement -
Ms. Sternfield, Mr. Reyna’s lawyer, said Mr. Corcino had never been an MSCS employee, but rather was paid a monthly fee to drum up business, typically in face-to-face meetings with health care executives. Mr. Reyna, she said, had no knowledge that the Stanford data had been sent to Mr. Corcino, or that he had passed it on.

Mr. Corcino was not authorized to use an MSCS title, Ms. Sternfield said, but she declined to say whether Mr. Reyna was aware of the practice. She acknowledged that Mr. Corcino sometimes used an MSCS e-mail account.

In his e-mail to the breach victim, who shared it with The Times, Mr. Reyna wrote that Stanford had sent the file to Mr. Corcino “for a potential MSCS project that would audit paid accounts to verify that the reimbursement was correct.”

For his part, Mr. Corcino said in a statement that he was an independent contractor but was “the marketing face of the company,” and that MSCS “allowed me to use the title of executive vice president.” He wrote: “Stanford sent the file to me at MSCS, and I imported the data into a spreadsheet that was forwarded to the job applicant as part of a skills test. I did not intend to provide any personal health information in the file. This was a marketing project.”

Without explaining how or why he sent the data to the applicant, Mr. Corcino said MSCS had not trained him properly and faulted Stanford for sending him private information that he did not need. That, he said, was the “first link in a chain of mistakes.”

“I regret that Stanford released a file containing unnecessary information,” Mr. Corcino said, “that MSCS did not have an appropriate training and audit system for the handling of electronic data and that I was not more careful with the file. While Stanford and MSCS left the information in the file I received, it was my mistake to not catch its inclusion and remove the data.”
Oh dear.

The NYT notes that "breaches of private medical data have become distressingly commonplace, with two substantial ones disclosed in the last week alone" -
officials with Florida Hospital reported that three employees had improperly combed through emergency department records of 2,252 patients, apparently to forward information about accident victims to lawyers. The employees were fired, and law enforcement officials are investigating.

Meanwhile, Science Applications International Corporation disclosed that computer backup tapes containing medical data for 4.9 million military patients had been stolen from an employee’s car in San Antonio. The data included Social Security numbers, clinical notes, laboratory test results and prescriptions. The company said the risk of harm was low because retrieving data from the tapes would require specialized knowledge, software and hardware.

The Texas breach is by far the largest since September 2009, when a new federal law began requiring disclosures of medical privacy violations involving at least 500 people. Some 330 such episodes have been tallied, including four others that affected more than one million people each.

Officials at the Department of Health and Human Services said the new reporting requirements had exposed deep vulnerabilities and encouraged renewed vigilance.

“We’re moving in the right direction in terms of a culture of compliance,” said Leon Rodriguez, director of the department’s Office for Civil Rights, which investigates medical privacy cases. “Are there still a lot of problems out there? Yeah, my sense is there are still a lot of problems.”

Media Issues

Australia's Independent Inquiry into Media and Media Regulation has released a short Issues Paper [PDF].

The Inquiry indicates that "the list of issues is not set out in any order of importance. Nor is the list intended to be comprehensive. The issues are, however, among the important matters that the inquiry will consider."

The issues are -
Access

1.1 One common justification for freedom of the press (nowadays referred to as freedom of the media) is that given by Mr Justice Holmes in his dissenting opinion in Abrams v United States 250 US 616, 624 (1919). He said:
[T]he ultimate good desired is better reached by free trade in ideas—that the test of truth is the power of thought to get accepted in the competition of the market.
1.2 Does this ’marketplace of ideas’ theory assume that the market is open and readily accessible?

1.3 Are there alternative or preferable justifications for freedom of the media?

1.4 Regardless of the justification, is it appropriate, especially in the search for the ‘truth’ on political issues, that persons holding opposing views have an opportunity to express their views in the media?

2.1 If a substantial attack is made on the honesty, character, integrity or personal qualities of a person or group, is it appropriate for the person or group to have an opportunity to respond?

2.2 What factors should be considered in determining (a) whether there should be an opportunity to respond? (b) how that opportunity should be exercised? Would those factors differ depending on whether the attack is published in the print or the online media?

Standards

3 Is it appropriate that media outlets conform to standards of conduct or codes of practice? For example, should standards such as those in the Australian Press Council’s Statements of Principles (1999) apply to the proprietors of print and online media?

4 Is it appropriate that journalists conform to standards of conduct or codes of practice? If it is, are the standards in the Media Entertainment and Arts Alliance’s Code of Ethics (1999) an appropriate model?

5 Do existing standards of conduct or codes of practice such as those mentioned in 3 and 4, as well as those established by individual print and/or online media organisations, fulfil their goals?

6 To what extent, if any, does the increased use of online platforms affect the applicability or usefulness of existing standards of conduct or codes of practice?

7 Can and should the standards of conduct or codes of practice that apply to the traditional print media also apply to the online media?

Regulation

8 Is self-regulation via standards of conduct or codes of practice necessary to maintain the independence of the media?

9.1 Is there effective self-regulation of (a) print media and (b) online media by the Australian Press Council?

9.2 What are the Australian Press Council’s strengths and limitations as a regulator of those two forms of publication?

9.3 Is it necessary to adopt new, and if so what, measures to strengthen the effectiveness of the Australian Press Council, including in the handling of complaints from members of the public (for example, additional resourcing, statutory powers)?

9.4 As an alternative to strengthening the effectiveness of the Australian Press Council, would it be preferable to establish a statutory body to take over its functions?

9.5 Concerning any proposed new measures, which are specific to the print media and which the online media?

10 If self-regulation is not an effective means of regulation, what alternative models of regulation could be adopted that would appropriately maintain freedom of the media?

11 Would it be appropriate for such a model to include rules that would:
(a) prohibit the publication of deliberately inaccurate statements
(b) require a publisher to distinguish between comment and fact
(c) prevent the unreasonable intrusion into an individual’s private life
(d) prohibit the gathering of information by unfair means (for example, by subterfuge or harassment)
(e) require disclosure of payment or offers of payment for stories
(f) deal with other topics such as those currently covered in the Australian Press Council advisory guidelines?
12 If an alternative model was to be a statutory complaints tribunal, is it appropriate for that tribunal to have power to:
(a) obtain information necessary to resolve a complaint
(b) require a publisher to do an act (for example, publish a correction of unfair or misleading reporting)
(c) impose sanctions for a failure to do that act?
13 Is there any reason why the regulation of the print media should be different from the regulation of broadcast or online media?

New media and business models

14 To what extent has the development of digital and online platforms had an impact on the traditional business model for media organisations, and to what extent is the further development of these platforms likely to affect the business model/s for media organisations over the medium to long term?

15 What are the other key factors that have an impact on the business models of media organisations, what is the magnitude of their impact to date, and to what extent are they likely to be significant over the medium to long term?

16 What is the impact to date on the level of investment in quality journalism and the production of news and what is the expected impact over the medium to long term?

Support

17 Is there need for additional support to:
(a) assist independent journalism
(b) assist the media to cater for minority audiences
(c) remove obstacles that may hinder small-scale publications
(d) promote ease of entry to the media market
(e) foster other aspect of the media’s operations?
18 What are the best methods for providing that support?

16 October 2011

Dot stupid

From Evgeny Morozov's 12 October 2011 TNR evisceration of Jeff Jarvis' Public Parts: How Sharing in the Digital Age Improves the Way We Work and Live (Simon & Schuster, 2011) -
For Jarvis, privacy is the preserve of the selfish; keep too much to yourself, and the “Privacy Police” may pay you a visit.

Why are we so obsessed with privacy? Jarvis blames rapacious privacy advocates — “there is money to be made in privacy” — who are paid to mislead the “netizens,” that amorphous elite of cosmopolitan Internet users whom Jarvis regularly volunteers to represent in Davos. On Jarvis’s scale of evil, privacy advocates fall between Qaddafi’s African mercenaries and greedy investment bankers. All they do is “howl, cry foul, sharpen arrows, get angry, get rankled, are incredulous, are concerned, watch, and fret.” Reading Jarvis, you would think that Privacy International (full-time staff: three) is a terrifying behemoth next to Google (lobbying expenses in 2010: $5.2 million).

“Privacy should not be our only concern,” Jarvis declares. “Privacy has its advocates. So must publicness.” He compiles a long and somewhat tedious list of the many benefits of “publicness”: “builds relationships,” “disarms strangers,” “enables collaboration,” “unleashes the wisdom (and generosity) of the crowd,” “defuses the myth of perfection", "neutralizes stigmas", "grants immortality ... or at least credit", "organizes us", and even "protects us". Much of this is self-evident. Do we really need to peek inside the world of Internet commerce to grasp that anyone entering into the simplest of human relationships surrenders a modicum of privacy? But Jarvis has mastered the art of transforming the most trivial observations into empty business maxims.

In one respect — his unrivaled ability to attract attention to his diva-like self — Jarvis has outdone even the fictional Dr. Kirk. Jarvis’s public parts are truly public: his recent battle with prostate cancer has become something of an online Super Bowl, with Jarvis tweeting from the operating table and blogging about the diaper problems that followed. And like the fictional Kirk, Jarvis likes his privacy when he likes it: the evangelist for publicness does not want his credit card numbers, his passwords, his e-mails, his calendar, his salary, his browsing habits, or his iTunes playlist made public. The digital disclosure of such things is off-limits for Jarvis — but not because of a scruple about privacy. He prefers to justify such immunities by appealing to other rights, fears, and concerns: he won’t share his passwords out of a fear of crime; or his calendar, because he is a busy man and doesn’t want any more commitments; or his salary, because of “cultural conventions”; or his iTunes playlist, because, well, it’s too trivial.

Had Jarvis written his book as self-parody — as a cunning attack on the narrow-mindedness of new media academics who trade in pronouncements so pompous, ahistorical, and vacuous that even the nastiest of post-modernists appear lucid and sensible in comparison — it would have been a remarkable accomplishment. But alas, he is serious. This is a book that should have stayed a tweet. Stripped of all the inspirational buzzwords, it offers a two-fold, and insipid, argument. First, a democratic society cannot afford to have privacy as its main — let alone its only — value. Second, the acts of information disclosure — by individuals, corporations, or public institutions — can be beneficial, under certain conditions, to some or all of the parties involved. Jarvis believes that these points are new and original and heroically subversive of the conventional wisdom. Public Parts is meant to be a polemic, but Jarvis has a hard time finding anyone who disagrees with either of his premises. Forced to introduce at least some contention into the book, he has to venture very far from his main themes, opining on the Arab Spring, the fall of the Soviet Union, and the future of the car industry.

A few such diversions are entertaining, but Jarvis cannot joke his way through the banality of his book’s central argument. Here is Jarvis at his most typical: “Memo to doctors, lawyers, and manicurists: You’d better be online and public.” What an incredible insight, in 2011: an online presence can help your business! Or consider this breakthrough in marketing theory: “If you are known as the company that collaborates with customers to give them the products they want, you may end up with more loyal customers.” Better products boost customer loyalty! Such bland pronouncements make Public Parts sound less cutting edge than the 1996 edition of The Complete Idiot’s Guide to the Web. ...

As if to live up to the old joke about an expert being someone who knows more and more about less and less until eventually he knows everything about nothing, Jarvis casts his eye over a gazillion different industries — from cars to airlines and from retail stores to public institutions — but rarely ventures beyond the most obvious analysis anywhere he looks. There are only two pages on WikiLeaks — an oddity in a book on the virtues of publicness — and even those pages are filled with generalities (the WikiLeaks scandal “demonstrated the banality of secrecy” and showed that “government keeps too much secret”). According to Jarvis, Julian Assange is driven by a law that posits that “those who held secrets once held power. Now those who create transparency gain power.” What does that actually mean? Journalists, NGOs, even Google: all of them create transparency in one way or another. But is it true that they now hold more power? What does the WikiLeaks disclosure of all those diplomatic cables imply about the powers lost or gained by the likes of Human Rights Watch, which needs secrecy to work in difficult countries but also needs publicness to make the world aware of those countries’ dire human rights record? Jarvis doesn’t say. If, as a result of legislative changes triggered by WikiLeaks, whistle-blowers end up getting much weaker legal protection, would it mean that they, too, gain power?

There is not much consistency in Jarvis’s thought about technology. Whenever he needs to explain something positive, his instinct is always to credit the Internet: it is the one factor responsible for more publicness, more democracy, more freedom. And every time he turns to darker and more difficult subjects — like discrimination, or shame — he announces that they have nothing to do with the Internet and are simply the product of outdated social mores or ineffective politics. In Jarvis’s universe, all the good things are technologically determined and all the bad things are socially determined.

This perverse analytical framework is most pronounced when he criticizes privacy advocates for not wanting to tackle more fundamental problems — such as social stigmas — that are made less severe by invoking one’s privacy rights. Jarvis writes that “a larger fear of sharing health information is the stigma associated with illness. That stigma is most certainly society’s problem. Why should anyone be ashamed of being sick?” He applies the same logic to discrimination based on sexual orientation: “That anyone would still feel shame about being revealed as gay ... is also our failing. If we think that technology is the problem, we risk ignoring the deeper faults and more important lessons.” Yet Jarvis seems blind to ways in which the rhetoric of publicness could be mobilized to distract from finding equally “deeper faults and more important lessons” about the sprawling national security state. “Knowing that no security at all is not an option, what’s your choice: body scans, physical searches, facial recognition via surveillance cameras, more personal data attached to travel records?” he asks — and quickly informs us that he objects to none of the above. He includes this tirade in a section called “publicness protects us” — but he presents no evidence that it does protect us. And why, one might ask, is the choice so stark? Why not entertain the option of extirpating the roots of terrorism rather than investing more money in surveillance technology and embracing “publicness”? It seems that Jarvis wants to fight root causes only of problems such as shame and discrimination; for everything else, there are quick technological fixes.

Victorian Privacy Case Notes

The Victorian Privacy Commissioner has released two Case Notes.

Complainant AU v Public Sector Agency [2011] VPrivCmr 3 concerns handling of a bullying complaint from a female state government employee. The Complainant made a written complaint regarding co-workers and was advised that a full copy of the documentation would be provided to each of the alleged bullies. She initially agreed, in the belief that there was no choice but later attempted via to withdraw consent. She was then advised that the complaint documentation had already been forwarded to the unit manager (an alleged bully) who had forwarded it to other alleged bullies, consistent with the employer's internal policy. She claimed that the disclosure to the alleged bullies breached her privacy under Information Privacy Principles 2.1, 4.1 and 1.3 and argued that the alleged bullies should only have had access to the information that was relevant to each individual rather than the entire document containing all alleged incidents. She also argued that the policy statement provided to her was out of date.

The Privacy Commissioner found that in dealing with a complaint about staff members an employer must disclose only what those people 'need to know' in order to respond to the complaint. In considering the employer's handling of the bullying complaint -
the disclosure of all of the Complainant’s documentation in full (setting out the Complainant’s state of mind, emotional responses to the incidents, and outcomes sought) to all of the alleged bullies appeared to be far more than what they needed to respond to the complaint about their own alleged behaviour.

Disclosure of information in this context should have been kept to the minimum necessary to investigate the matter and would not require the wholesale disclosure that had occurred in this instance.
The Commissioner considered that it was possible to edit the document to protect the Complainant’s privacy.

The Commissioner considered the notion of consent, deciding that in this instance consent could not be relied on by the employer because under 2.1(b) individuals must be provided with a real choice about what will happen with their personal information.

In considering IPP 4 (Data Security) the Commissioner found that by providing more information to the alleged bullies than was necessary the employer had not taken reasonable steps to protect the personal information it held.

In Complainant AV v Body Established for a Public Purpose [2011] VPrivCmr 4 the Commissioner referred a complaint to conciliation, on the basis that there were insufficient grounds to exercise discretion to decline the complaint under s 29 of the Act.

The Complainant had attended two performances at a theatre (a body established for a public purpose under statute). Each time the Complainant was asked for his name, address, email address and telephone number, despite wanting to pay with cash.
Staff of the theatre informed him that refusal or failure to provide the requested information would result in him being refused entry to the venue. The Complainant complained at the time about the unnecessary collection of his personal information, but the complaint was not logged by the organisation and was not escalated further. He was admitted to the venue, however, as he already had an account under his name with the theatre.

The Complainant complained to the Privacy Commissioner, arguing that the theatre had breached IPP 1.1 by collecting personal information about him that was not necessary for its functions or activities, and had failed to provide him with the option of transacting anonymously with the organisation under IPP 8.1.
The theatre argued that there was no breach of the Complainant’s privacy as it had conducted an investigation into the complaint and found that staff at the ticket office could not recall the incident. It also argued that because the Complainant had only complained to ticket office staff and had not escalated the complaint higher the theatre did not have a chance to respond to the complaint.

The Commissioner took a positive stance, noting that there was disagreement about whether the information had been collected at all. The Commissioner stated that a ticket person's failure to escalate a complaint was insufficient reason for the Commissioner to decline the complaint. The Commissioner indicated that whether information collected was necessary for a function or activity of an organisation, and accordingly whether an option to transact anonymously was practicable, depended on the circumstances.