Sunday, March 23, 2014

Who needs theives when you have businesses dumping your records.

A Topeka (KS) business discovered numerous boxes with medical records in a dumpster at his business complex. The unidentified businessman was putting stuff in the dumpster at his new office location when he discovered the boxes of sensitive information. The hoard of information contained confidential medical records, complete with names, phone numbers, and social security numbers from several midwest states. Federal laws strictly restrict the handling of medical and patient information. The information was in the dumpsters for at least a couple of days - lots of time for someone to make use of it. And it would not even take a sophisticated ID theft ring to do this. Anyone could have reached in and grabbed 2,3,4 or 5 sets of file and been able to make $1,000 in a matter of days. The intrusion of doctors into your personal lives grows each day. Doctors now request not only your medical history but your employment information, your living arrangements and other information that has no direct issue with your medical treatments. The more information they have about you, the more information that is subject to being released to unauthorized parties. It would be great if this was an isolated incident, however, these breaches of customer information is happening with more and more regularity. The problem is that no one is every being held accountable. While the news reports of people finding such bulk dumping of information in public dumpsters is regular, there is never any follow up to the events. I see no way that police and other officials can not trace the information back to the sources, but there appears to be a lack of desire to investigate. The only reason that the sources of these data breaches are not discovered is a lack of simple and basic research. The acceptable methods for properly disposing of the information, while not exactly cheap, are also not overly expensive. For a person to dump the records in a dumpster underscores that someone made a decision to save time and money and avoid the proper steps. The old business saying is that the boss sets the tone for the business. The boss is the doctor in charge. The decision to short change the customers may have been made by the office manager, but that would only be if the doctor(s) involved blessed the action. If the office manager is not making the case for spending the money or the doctor(s) are rejecting the request then it is the doctor(s) that are showing a disregard for federal law and their own patients. It is time that doctors start being held accountable for breaches of information. In this case, since the records involved people from numerous states, it is likely a specific doctor's office is not responsible for the information. However, holding doctors accountable for the conduct of companies they contract with and their handling of patient information would force doctors to select contractors based on more then just who is cheapest. A growing area of Identity Theft is theft of Medical Services. Once someone has your identity, they can then use your information to get expense medical services and treatments. And access to your medical records could allow them to obtain prescriptions or other restricted items in your name. You could be held accountable for receiving $1,000 of narcotics and charged with federal drug crimes because your doctor used the cheapest company to out source billing or other services. The next time you are in the doctor's office - ask them, who has access to your information and do they use any out side contractors? If they do - you may want to consider getting a new doctor.

California DMV Credit Card Data Attacked

It had to happen. You secure government data is secure no more. Please say it ain't so. Although officials at the California Department of Motor Vehicles are denying that any information was stolen from their servers, they admit that their is an investigation ongoing into a possible breach somewhere. California not only accepts credit cards/debit cards at it's office location, but also online and at some self service kiosks. Reports indicate that it was law enforcement agencies that alerted the DMV as opposed to internal sources. The blog Krebs on Security was apparently the 1st one to publicly report the breach by citing sources in the financial industry. Early in the investigation, the DMV has not released any information on the numbers of possible victims or when the issues may have happened. External sources has reported that it may have happened between August 2 (2013) to January 31 (2014). The stolen information have included card numbers, expiration dates and PIN numbers. While denying that the internal servers at the DMV were breached, a spokesperson for the department did confirm that information was requested from the company that handles the transactions on contract for the DMV and the credit card companies themselves. California, the most populous state in the USA, has already been identified as a key target for cyber criminals including financial fraud and or identity theft. Both at the government level and the private business levels, the opportunities for committing crime are enormous. Government agencies, such as the DMV or taxing authorities hold vast amounts of customer lists. Of course, with leading technology companies based with in the state, cracking even a small percentage of the data bases available could provide a worldwide list of possible victims. If anyone thinks that the California DMV will be the biggest or last breach of government data, they have no clue of the efforts cyber crooks will go to access your information. And while the media and the government are quick to point out the slow pace at which big business moves at making decisions about upgraded technology, businesses generally move at the speed of light compared to the movement of government to fund improvements to their own internal systems.

Thursday, March 20, 2014

Check Cashing Scams

With check cashing scams, some one sends you a check and has you cash it with your bank and then send them back the excess money. It is later that you discover the check is fraud and your bank then debits your account for the entire amount.


A common way this is done is during the purchase of an item from a site such as craigslist or other classified site. The way this scam works is that you list something for sell. A buyer makes you an offer and then sends you a check. Say the item is for $100 plus shipping. They send you $200 and tell you to subtract shipping costs and send the item and the balance back to them. A couple of weeks later, the check is returned as fraud or non-sufficient funds. Your account is now deducted $200 and you are out the item, the shipping costs and the difference you sent them. Plus your bank may have charged you bad check fees.

That was a minor example. It has happened often for $100s or $1000s of dollars when it involves property rental or automobiles.



Check Cashing Scams are also used a lot against businesses. In fact, businesses can be easier targets of Check Cashing Scams. Sales can receive an order with a check. After the order is shipped, the customer immediately returns the items requesting a refund. If a refund is issued and the refund check is cashed before the payment check is completely processed, the thief keeps the money. This is one important reason why many business put up to 10 business day holds on orders payed with checks. Even PayPal places holds on payments that involve checking accounts.

You may be wondering how this can happen. You take a check to your bank and deposit it. The bank makes the funds available to you in 1 to 5 business days and you think everything is okay. Well it is not, maybe. The actually processing of checks can take several days, especially the farther apart the banks may be located. Checks are 'processed' by sending the information to regional centers. At this centers, all the credits and debits for each member bank are added up. If a check submits for total money in deposited checks then all the other banks submit to be charged to the bank, the bank has a net income. Obviously, if more checks are submitted against the bank then the bank cashed on behalf of other banks, the bank will owe money. When the checks being processed are processed out of different centers, it take longer for the check to make it to the target bank. If the account attached to the fraudulent check does not have sufficient money the check is refused. However, most banks have an automatic 2nd try for checks that are returned to them. If your bank resubmits the check, it is now additional time for the check to go back thru the system. When the check comes back the second time, your account is then debited the fraudulent amount.

The best protection for Check Cashing Scams is primarily to not accept checks from people you do not know. If you sell on craigslist or other online sites, do not accept checks. If you do accept checks for any reason, if the "buyer" does request a refund, explain that you have a 30day hold before you ship anything or provide any refunds.

Thieves will put as much effort into stealing your money as you put into earning it. Protect your bank account.