home    |    contact us    |    reader services    |    Bookmark Us

Atlanta Business Events

Current Issue

November / December 2008

Mount Sustainability
It's higher than Everest, says the Atlanta businessman who, more than any other capitalist, has been scaling it for more than a decade. And he says time is short before humankind plunges into the abyss.
In For The Long Haul
With a diverse and expanding portfolioin an imploding economy, HD Supply is not only built to weather an economic firestorm, but to grow as well. CEO Joe DeAngelo doesn't know any other way.
Changing The Health Culture Of Your Workplace
Employers are feeling the pain of high healthcare costs ... and they're doing something about it.
CatalystMag.com's Top 25 Entrepreneurs + Ones To Watch
Find out who made the list!

New FTC "red flag" rules will apply to more than 2 million businesses

Matthew Wilson

October 13, 2008

 
The Federal Trade Commission, along with the OCC, FDIC, Federal Reserve and various other federal agencies, have issued a set of rules and guidelines to combat the proliferation of identity theft. These new "red flag" rules and guidelines mandate that all financial institutions and creditors -- a category that is broadly defined -- develop and implement an identity theft prevention program designed to detect, prevent, and mitigate the effects of, identity theft.

The new rules apply to an extremely broad range of businesses that offer certain "covered accounts" to consumers (approximately 2 million entities according to FTC estimates), including, automobile dealers, telecommunications providers and hospitals, as well as any other person or entity that regularly extends, renews or arranges for the continuation of credit to its customers.  Under the rules, the definition of "covered account" is quite broad and will encompass any consumer account that permits multiple payments or transactions or any other account that may pose a reasonably foreseeable risk to consumers or businesses from identity theft.  This category will include many healthcare providers given the common post-services payment for healthcare services.    

These rules require that all covered entities develop and implement a written compliance program that includes each of the following four basic elements: (1) the identification of red flags, (2) the detection of such red flags, (3) an appropriate response to any such detection, and (4) the periodic review and updating of the overall program.  In addition to the inclusion of these guidelines, each program must be specifically tailored to the size, nature and complexity of the applicable business and should consider trends in the marketplace along with any historical experiences dealing with identity theft. Upon development, each program must be formally authorized and adopted by the entity's governing body or senior management, and such body or persons are required to provide on-going administrative oversight of the program's implementation, which includes staff training, audit compliance, and the generation of annual assessment reports.

While federally regulated financial institutions are subject to oversight by the appropriate federal banking regulators, the majority of effected persons and entities will fall under the regulatory wing of the FTC.  Accordingly, in the event of any knowing violation of the rules, the statute provides that the FTC may commence a civil action with respect to any violation and may seek pecuniary penalties not to exceed $2,500 per infraction.  In addition to the prescribed regulatory enforcement actions, any failure to comply with the rules can also serve as the basis for private civil and/or class action lawsuits.

Matthew Wilson is an attorney at law at Arnall Golden Gregory LLP.


Related Content:



Loading

Events | Business Resources | Real Estate | Health Care | Economic Development
Reader Services | Newsletters Signup | Terms & Conditions
Contact Us | Advertise with Us | Subscribe