Database Hacks - Are Banks Required To Notify You
Published by
USAttorneysDirectory.com

The following article Database Hacks - Are Banks Required To Notify You was authored by Richard A. Chapo and is published or republished in this directory with the author's permission. This directory is provided as service to legal professionals and the internet community.


Database Hacks - Are Banks Required To Notify You?
 by: Richard A. Chapo

Ever wonder if banks are required to tell customers when their systems are hacked? You may be shocked to learn that they are not. The only exception to this standard has been database hacks that effect California residents. Companies doing business in California are required to give such notice under the California Security Breach Information Act. The situation is changing quickly on the federal level.

Regulations have been issued by federal finance agencies that now force banks to tell customers when their personal data has been exposed to unauthorized third parties. The regulations are issued pursuant to the Gramm-Leach-Bliley Act, which contains language requiring financial institutions to prevent unauthorized access and use of consumer information.

The new regulations appear to be a reaction to several recent high-profile data leaks. They include incidents such as Bank of America losing data tapes containing information for over 1 million government employees and the breach of databases for LexisNexis and ChoicePoint. It is well known that numerous other banks have also been hacked over the years, but the information has been hushed up.

The new regulations require financial institutions to notify account holders if the institution becomes aware of unauthorized access to sensitive customer information. The directives apply to banks and savings and loan companies, but not credit unions.

There are two serious loopholes in the regulations. First, a financial institution that discovers a database breach must only notify account holders if it is "reasonably possible" that personal details will be misused. Second, the regulations only apply to personal data, not business or commercial accounts.

While these new regulations are a positive step, one could drive a truck through the two loopholes. Determining whether it is “reasonably possible” that your information will be misused is a vague standard that many financial institutions will use to withhold information. Put bluntly, the notification regulations are gutless.

The best method for keeping an eye on database breaches is to look for stories in the news. Under California law, companies are required to give notice to California residents when breaches occur. If you see a story about your bank giving notice of a hack to California residents, your personal information may have also been exposed. Hackers do not restrict their attacks to California residents.

About The Author

Richard Chapo is an attorney with http://www.sandiegobusinesslawfirm.com - a law firm providing legal advice to California businesses. This article is for general education purposes and does not address every facet of the subject matter. Nothing in this article creates an attorney-client relationship.

This article was posted on April 4, 2005



The opinions, statements and information contained and expressed in the foregoing article are solely those of the author. No position for or against, agreeing with or disagreeing with anything contained in said article is taken by US Attorneys Directory.com. We do not assume or accept any liability for the use of the information contained herein. This article is published solely as a service to attorneys, lawyers and the internet community. Anyone who does not accept this disclaimer is not authorised to read or use this article in any way.


To browse articles see pages 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8

To view articles indexed by subject see Subject
To view articles indexed by author see Author


We need well written informative legal articles for our site. If you have articles that you have written regarding the law or the practice of law, and would like to see them published in this website at no charge, please go to Article Submission . Thank you.


Home | About Us | Contact | Resources | Article Submission
Attorney Directories | Process Servers | Court Reporters


Page Set Up ©Copyright 2004 US Attorneys Directory.com, a directory of legal and law practice articles, information and services. All Rights Reserved Worldwide.