New Risks Facing Business this Fall
The "Red Flags" rule created on January 1, 2008 and put in effect on August 1st of this year requires many businesses and organizations to implement a written Identity Theft Prevention program designed to detect the warning signs – or “Red Flags” – of identity theft.
This rule is enforced by the Federal Trade Commission (FTC), the federal bank regulatory agencies and the National Credit Union Association (NCUA).
The “Red Flags” rule picks up where failed data security leaves off. It places requirements on financial institutions and creditors to have plans and training in place to thwart the use of stolen information.
While the definition “financial institution” is straightforward, the definition of “creditor” is broad and includes businesses or organizations that routinely defer payment for goods or services. Consequently, many businesses have a requirement for writing plans and training employees. SSC can help!

Does your firm handle personal information about a resident of Massachusetts regardless of where it is housed? As of January 1st under the regulation every person (the definition of “person includes business entities) that owns, licenses, stores or maintains personal information on such resident is required to develop, implement and maintain and monitor a comprehensive, written information security program (WISP).
Not prepared to roll that out or train to it? SSC can help!
HITECH ActA $19.2 billion Health Information Technology for Economic and Clinical Health (HITECH) Act that President Obama signed into law on February 17th of this year will have a dramatic effect on the adoption and use of Electronic Health Records (EHR).
However, among other things, the act expands the definition of what is considered as a reportable breach of protected health information (PHI) to paper and other records in addition to non-encrypted electronic media. Breaches of less than 500 identities will be required to be posted on the Health and Human Services website; while larger breaches will also be required to post appropriate notices in major publications. The FTC will also be included in some notifications.
Expansion of this HIPAA related law grows from covered entities (typically health insurance companies, hospitals and providers) to business associates of them. Does your organization touch PHI in any form? You probably have additional work to do for compliance. SSC can help!

The world’s brush with H1N1 has many evaluating how they will ensure continuity of operations during a pandemic. Planning from a human capital and security perspectives is in high gear around the country.
Research shows at least 25 percent of those businesses that close due to events such as hurricane, tornado, fire, or other life changing events never reopen. Many that do, struggle to stay in business.
If you have not yet prepared to continue your business with a realistic plan for pandemic or another situation - SSC can help you become prepared!
![]()
SSC News!
New management team additions|
For more about Mike Wanik, please follow the link below: |
|
|
For more about Brian D'Angelo, please follow the link below: |
![]()
Experienced, pro-active, and dedicated to your business. Contact SSC for a confidential Security Consultation. Our e-Newsletter: SSC Security Matters.