In 2003, Congress passed amendments to the Fair Credit Reporting Act. One of the changes was a requirement for business that met a certain definition to implement procedures to prevent identity theft. The procedures were dubbed the "Red Flags Rule". Congress gave the businesses that met the definition of creditor until November 2008 (yes, five whole years, longer than a term in office for the President) to create and implement the Red Flags Rules. Shouldn't be too hard, just some common sense things to watch out for that might indicate that an identity thief is trying to pull a fast one.
Apparently, the creditors sat on their hands for the first five years, because right at the deadline, the creditors started seeking an extension of the deadline to implement the Red Flags Rule. And they got the extension. And another one, and another one and (I think) another extension (quite frankly, I've lost count). The latest Red Flags Rule implementation date was January 1, 2010. That was the new date, until Congress just extended it yet again ... this time all the way to June 1, 2010. So this law, seven years after it was enacted, has yet to take effect.
The Red Flags Rule is supposed to get companies to train all their employees (not just their handful of "fraud specialists" who aren't even contacted until after the proverbial excrement hits the fan) on how to spot the warning signs of identity theft (i.e. the red flags that would tip off a person of normal intelligence). From my 10 plus years of representing consumers in litigation against banks, credit card companies and the credit bureaus, I have learned one important, nearly universal fact ... the vast number of people that work for corporations check their common sense at the door when they report to work every morning. Most corporate clones are paid the same no matter the quality of their work. So most don't go out of their way to do a good job. As said by the main character of the movie Office Space, they just simply work hard enough not to get fired.
What's worse is that these corporate cronies follow the all mighty "policies and procedures" of their corporate employers, which are usually written by corporate higher ups with no idea how things are done at ground level. I swear, I think if the corporate policy said to murder all customers who complained of a certain widget, the streets would be filled with blood. I know the employees possess common sense, they just seem to leave it at home. The bottom line is ... most corporate employees just don't care about what they are doing.
This is why, time and time again, I see corporate employees ignore the obvious signs of identity theft, signs even my most under educated clients easily spot and, as a result, prolong the nightmare that is identity theft. For this reason, the prevention procedures required by the Red Flags Rule are critical to consumers all across the nation. Yet, these consumers, lacking the beneft of the lobbyists employed by the corporate sector, are repeatedly getting the shaft by the continued delay allowed by Congress. Maybe by the time my 2 year old gets his first credit card, some measure of the Red Flags Rule might be implemented. But, unlike my 2 year old when he's mad, I'm not holding my breath.
Custom Search
Showing posts with label red flag rules. Show all posts
Showing posts with label red flag rules. Show all posts
December 28, 2009
November 03, 2009
FTC does it again - Red Flag Rules enforcement pushed back to 2010
For a fourth time, the FTC has postponed the effective date of the Red Flag Rules. The most recent effective date was November 1, but its now pushed all the way back to June 1, 2010. Also, various groups are still trying to wiggle their way out of having to comply with the Red Flag Rules.
The American Bar Association won such a result for law firms. A D.C. federal judge ruled that law firms do not fall under the definition of a "creditor". I posted on this over the weekend. See my post here - http://fcralawyer.blogspot.com/2009/10/red-flag-rules-does-not-include.html.
Veterinarians and CPAs are also trying to win exemptions from the new requirements. But they don't have to sweat it too much until next June . . . if ever.
The American Bar Association won such a result for law firms. A D.C. federal judge ruled that law firms do not fall under the definition of a "creditor". I posted on this over the weekend. See my post here - http://fcralawyer.blogspot.com/2009/10/red-flag-rules-does-not-include.html.
Veterinarians and CPAs are also trying to win exemptions from the new requirements. But they don't have to sweat it too much until next June . . . if ever.
October 31, 2009
Red Flag Rules do not include attorneys
As I have reported before, the FTC's Red Flag Rules regarding prevention of identity theft go into effect (allegedly) tomorrow, November 1. The Red Flag Rules have been supposed to go into effect multiple times before, only to be delayed. But since tomorrow is almost here, maybe they will indeed go into effect this time.
Another development is that Judge Reggie B. Walton of the United States District Court for the District of Columbia has ruled that the Red Flag Rules do not apply to law firms. The D.C. Court agreed with the American Bar Association, finding that the Federal Trade Commission's interpretation of the Fair and Accurate Credit Transactions Act (FACTA - the amendment to the FCRA passed a few years ago) was overreaching and its application to lawyers and law firms unreasonable.
The decision turned on FACTA's definition of creditor. Only creditors, as defined by FACTA, have to comply with the Red Flag Rules' requirements to attempt to prevent identity theft. The Red Flag Rules require creditors to adopt written identity theft prevention procedures.
The FTC argued that lawyers and law firms fall under the definition of "creditor" and thus have to comply with the Red Flag Rules. Unfortunately for the FTC's argument, it was a stretch to call a law firm a creditor and Judge Walton agreed. As a result, Judge Walton granted the ABA's motion for partial summary judgment. This also means I don't have to write identity theft prevention procedures by tomorrow.
Another development is that Judge Reggie B. Walton of the United States District Court for the District of Columbia has ruled that the Red Flag Rules do not apply to law firms. The D.C. Court agreed with the American Bar Association, finding that the Federal Trade Commission's interpretation of the Fair and Accurate Credit Transactions Act (FACTA - the amendment to the FCRA passed a few years ago) was overreaching and its application to lawyers and law firms unreasonable.
The decision turned on FACTA's definition of creditor. Only creditors, as defined by FACTA, have to comply with the Red Flag Rules' requirements to attempt to prevent identity theft. The Red Flag Rules require creditors to adopt written identity theft prevention procedures.
The FTC argued that lawyers and law firms fall under the definition of "creditor" and thus have to comply with the Red Flag Rules. Unfortunately for the FTC's argument, it was a stretch to call a law firm a creditor and Judge Walton agreed. As a result, Judge Walton granted the ABA's motion for partial summary judgment. This also means I don't have to write identity theft prevention procedures by tomorrow.
September 30, 2009
Red Flag Rules to go into effect November 1
The Red Flag Rules are "scheduled" to go into effect on November 1. However, the effective date has been postponed three or four times. But those of you who are affected by the Red Flag Rules need to assume that it will go into effect this time.
A partial list of types of businesses that need to comply with the Red Flag Rules are the following:
• Doctors, dentists, and other health care providers;
• Accountants and lawyers;
• Utilities;
• Telecommunications companies;
• Debt collectors;
• Retailers; and
• Employee benefit plans sponsoring flexible spending account arrangements when the arrangement utilizes a debit card.
A good primer on what you need to do to comply can be found at http://wistechnology.com/articles/6563/.
A partial list of types of businesses that need to comply with the Red Flag Rules are the following:
• Doctors, dentists, and other health care providers;
• Accountants and lawyers;
• Utilities;
• Telecommunications companies;
• Debt collectors;
• Retailers; and
• Employee benefit plans sponsoring flexible spending account arrangements when the arrangement utilizes a debit card.
A good primer on what you need to do to comply can be found at http://wistechnology.com/articles/6563/.
September 03, 2009
ABA attempts to block Red Flags Rule's application to lawyers
The American Bar Association has filed litigation claiming that the FTC has overstepped its authority in trying to make attorneys and law firms comply with the Red Flag Rules set to go into effect November 1, 2009. Here's the article from http://www.insurancejournal.com/:
"The American Bar Association is seeking to bar the Federal Trade Commission from applying its Red Flags Rule, designed to prevent identity theft, to practicing lawyers.I agree with the ABA. I do not see how lawyers can be construed as "creditors" under FACTA.
An ABA suit filed in the U.S. District Court for the District of Columbia claims that the FTC is exceeding the powers delegated to it by Congress and misinterpreting the rule. It seeks declaratory and injunctive relief in advance of pending FTC rule enforcement on Nov .1, 2009.
The rule requires creditors to implement plans to detect and respond to activity signaling possible identity theft. The FTC's original enforcement policy in October 2008 and subsequent updates provided no indication that lawyers engaged in the practice of law fell within the definition of 'creditor,' according to the ABA. Only after implementation of the rule was delayed again in April 2009 - just one day before the expiration of an initial six-month extension - did the FTC publicly announce its position that lawyers were subject to the rule.
The ABA complaint alleges that the application of the rule to practicing lawyers is 'arbitrary, capricious and contrary to law,' and that the FTC has failed 'to articulate, among other things: a rational connection between the practice of law and identity theft; an explanation of how the manner in which lawyers bill their clients can be considered an extension of credit under the FACTA; or any legally supportable basis for application of the Red Flags Rule to lawyers engaged in the practice of law.'
'Congress did not intend to cover lawyers under the rule,' said ABA President Carolyn Lamm. 'The FTC's decision to apply the Rule to lawyers is contrary to an unbroken history of state regulation of lawyers and intrudes on traditional state responsibilities.'
Lamm said the rule requires 'extensive reporting and bureaucratic compliance' that would increase the cost of legal services.
According to the ABA, nearly 30 state and local bar associations also have officially registered their opposition.
The ABA is seeking to have the Red Flags Rule's application to lawyers engaged in the practice of law declared unlawful and void."
July 29, 2009
FTC delays enforcement of the Red Flag Rules ... again!
The Red Flag Rules, which require certain types of businesses, including some small businesses, to come up with and implement procedures to prevent identity theft, was supposed to go into effect on August 1. Key words being "supposed to". It was also supposed to go into effect on May 1 and even on November 1 of last year.
Its now delayed to November 1, 2009, one year to the day from when it was "supposed to" go into effect. Joe Campana at the Identity Theft Examiner sums up what this latest delay means:
"Further delay in enforcement may mean that many businesses will sit on the sidelines again to wait and see what happens when November 1st comes around. For most businesses, enforcement does not mean an audit, inspection or test. It simply means that if an identity theft incident occurs within a business, and there was a violation of the Red Flags Rule, then the law can be enforced by the FTC, the state attorney general or through a private right of action.
In the press release, the FTC suggests it would not enforce the law against to small low-risk businesses that are likely to 'know their customers.' Reviewing FTC enforcement of other laws over the last few years, shows that the FTC in general does not enforce laws against small businesses, and that it brings few enforcement actions, which some consumer advocates have already criticized.
This delay a compliance date may suggest that small low-risk businesses do nothing. Many already do not comply with other laws such as the FACT Act Disposal Rule, the Gramm-Leach Bliley Act and state breach notification laws. However, once an enforcement date is finalized, private citizens can sue businesses under the law if they can show harm resulting from the negligent authentication of a thief using their identity. Even today, small businesses are at risk of such lawsuits brought under common law."
As I have said before, the threat of FTC enforcement of any law is virtually meaningless. I am glad that the Red Flags Rule includes a private cause of action, thereby giving it enough teeth to actually give someone pause enough to at least attempt to comply with it. That is, if it ever actually goes into effect.
Its now delayed to November 1, 2009, one year to the day from when it was "supposed to" go into effect. Joe Campana at the Identity Theft Examiner sums up what this latest delay means:
"Further delay in enforcement may mean that many businesses will sit on the sidelines again to wait and see what happens when November 1st comes around. For most businesses, enforcement does not mean an audit, inspection or test. It simply means that if an identity theft incident occurs within a business, and there was a violation of the Red Flags Rule, then the law can be enforced by the FTC, the state attorney general or through a private right of action.
In the press release, the FTC suggests it would not enforce the law against to small low-risk businesses that are likely to 'know their customers.' Reviewing FTC enforcement of other laws over the last few years, shows that the FTC in general does not enforce laws against small businesses, and that it brings few enforcement actions, which some consumer advocates have already criticized.
This delay a compliance date may suggest that small low-risk businesses do nothing. Many already do not comply with other laws such as the FACT Act Disposal Rule, the Gramm-Leach Bliley Act and state breach notification laws. However, once an enforcement date is finalized, private citizens can sue businesses under the law if they can show harm resulting from the negligent authentication of a thief using their identity. Even today, small businesses are at risk of such lawsuits brought under common law."
As I have said before, the threat of FTC enforcement of any law is virtually meaningless. I am glad that the Red Flags Rule includes a private cause of action, thereby giving it enough teeth to actually give someone pause enough to at least attempt to comply with it. That is, if it ever actually goes into effect.
July 26, 2009
Red flags rule may also help prevent medical identity theft
An article from fiercehealthcare.com by Anne Zieger:
"About 250,000 times per year, a thief uses someone else's personal identity information--such as their name, Social Security number and date of birth--to bill medical services to an unsuspecting stranger, according to the Federal Trade Commission. While that's only about 1.3 percent to 3 percent of all identity theft crimes, this is a growing phenomenon which the agency is attempting to nip in the bud with a new set of regulations known as Red Flags Rules.
The Red Flags Rules, which actually went into effect November 1, 2008 but only imposes penalties as of August 1, will require physicians' offices and hospitals, along with some other businesses, to create procedures to spot some classic "red flags" for identity theft, such as signs of fake or altered IDs, telltale inconsistencies in medical records or fraud alerts from consumer credit reporting agencies.
Doctors will also be required to set up procedures for detecting signs of bogus IDs or other warning signs, but also create policies for how they'll handle problems, such as alerting victims and holding off on billing for services."
The whole article can be seen here - http://www.fiercehealthcare.com/story/medical-identity-theft-protections-take-effect-next-month/2009-07-24.
"About 250,000 times per year, a thief uses someone else's personal identity information--such as their name, Social Security number and date of birth--to bill medical services to an unsuspecting stranger, according to the Federal Trade Commission. While that's only about 1.3 percent to 3 percent of all identity theft crimes, this is a growing phenomenon which the agency is attempting to nip in the bud with a new set of regulations known as Red Flags Rules.
The Red Flags Rules, which actually went into effect November 1, 2008 but only imposes penalties as of August 1, will require physicians' offices and hospitals, along with some other businesses, to create procedures to spot some classic "red flags" for identity theft, such as signs of fake or altered IDs, telltale inconsistencies in medical records or fraud alerts from consumer credit reporting agencies.
Doctors will also be required to set up procedures for detecting signs of bogus IDs or other warning signs, but also create policies for how they'll handle problems, such as alerting victims and holding off on billing for services."
The whole article can be seen here - http://www.fiercehealthcare.com/story/medical-identity-theft-protections-take-effect-next-month/2009-07-24.
July 24, 2009
Red Flag Rule deadline draws nearer
The August 1 deadline to have your identity theft prevention program in place is looming. With it is coming more articles about what is called the Red Flag Rule. Here's a good article about this new law going into effect:
"With the deadline to implement the Federal Trade Commission's Identity Theft rules looming, federal agencies issued a set of frequently asked questions to help affected businesses, such as veterinary practices, comply.
The questions provide guidance on numerous aspects of the rules, including which types of entities and accounts are covered, establishment and administration of an Identity Theft Prevention Program, address validation requirements applicable to card issuers and the obligations of users of consumer reports upon receiving a notice of address discrepancy.
The FTC also developed a Web site, www.ftc.gov/redflagsrule, with additional resources and guidance for creditors and financial institutions that are within its jurisdiction.
Identity Theft Prevention Programs must include four basic elements:
Reasonable policies and procedures to identify the 'red flags' of identity theft you may run across in day-to-day operations; the program must be designed to detect the red flags identified; it must spell out appropriate actions to be taken when red flags are detected and it must address how the program will be re-evaluated periodically to reflect new risks that arise.
The 'Red Flags and Address Discrepancy Rules,' in effect since January 2008, become mandatory Aug. 1. They implement sections of the Fair and Accurate Credit Transactions Act of 2003, which requires financial institutions and creditors to develop and implement written identity-theft prevention plans and requires issuers of credit cards and debit cards to assess the validity of notifications of changes of address.
The rules also provide guidance for users of consumer reports regarding reasonable policies and procedures to employ when consumer reporting agencies send them notices of an address discrepancy.
The Federal Reserve System, Federal Deposit Insurance Corp., National Credit Union Administration, Office of the Comptroller of the Currency, Office of Thrift Supervision and Federal Trade Commission all collaborated on the rules."
Remember, the requirement for your red flag rules begins August 1.
"With the deadline to implement the Federal Trade Commission's Identity Theft rules looming, federal agencies issued a set of frequently asked questions to help affected businesses, such as veterinary practices, comply.
The questions provide guidance on numerous aspects of the rules, including which types of entities and accounts are covered, establishment and administration of an Identity Theft Prevention Program, address validation requirements applicable to card issuers and the obligations of users of consumer reports upon receiving a notice of address discrepancy.
The FTC also developed a Web site, www.ftc.gov/redflagsrule, with additional resources and guidance for creditors and financial institutions that are within its jurisdiction.
Identity Theft Prevention Programs must include four basic elements:
Reasonable policies and procedures to identify the 'red flags' of identity theft you may run across in day-to-day operations; the program must be designed to detect the red flags identified; it must spell out appropriate actions to be taken when red flags are detected and it must address how the program will be re-evaluated periodically to reflect new risks that arise.
The 'Red Flags and Address Discrepancy Rules,' in effect since January 2008, become mandatory Aug. 1. They implement sections of the Fair and Accurate Credit Transactions Act of 2003, which requires financial institutions and creditors to develop and implement written identity-theft prevention plans and requires issuers of credit cards and debit cards to assess the validity of notifications of changes of address.
The rules also provide guidance for users of consumer reports regarding reasonable policies and procedures to employ when consumer reporting agencies send them notices of an address discrepancy.
The Federal Reserve System, Federal Deposit Insurance Corp., National Credit Union Administration, Office of the Comptroller of the Currency, Office of Thrift Supervision and Federal Trade Commission all collaborated on the rules."
Remember, the requirement for your red flag rules begins August 1.
July 20, 2009
Red Flags Rule
Joe Campana at the Identity Theft Examiner has an article about the new Red Flags Rule. Here's a quote:
"The Red Flags Rule is a U.S. federal law that requires most every business and organization to develop and implement an identity theft prevention program. The purpose of the identity theft prevention program is to authenticate the identity of customers to reduce incidences of identity theft. Authentication is required when a new financial or credit account is opened or when a change is requested on an existing covered account. The law covers consumer and business accounts.
The broad definitions of 'covered account' and 'creditor' include most every business and organization. If a business or organization accepts payment for products or services after they are delivered, they are a creditor under the law and must comply. Those that only accept payment prior to or upon delivery are not creditors regardless of how payment is accepted—cash, check or credit card.
Compliance is risk based, meaning that entities must implement a compliance program that is reasonable and appropriate to cover the risks the organization is likely to encounter. For most entities, especially small businesses, compliance is simple, straightforward and will prevent fraud and financial loss by assuring the entity is doing business with a legal person or legal business, and not with an identity thief.
The Red Flags Rule was enacted on January 1, 2008 under the Fair and Accurate Credit Transactions Act of 2003 (FACT Act), the first revision to the Fair Credit Reporting Act (FCRA). Compliance under the Red Flags Rule was effective on November 1, 2008 for those entities under the purview of any of five federal banking and credit union regulators (OCC, Federal Reserve System, FDIC, OTS, NCUA). Compliance has been required on August 1, 2009 for those entities regulated by the Federal Trade Commission (FTC).
The law requires that entities regularly conduct a risk assessment to determine if they have covered accounts and to determine if they have any other accounts for which there may be a reasonably foreseeable risk to identity theft. If there are, a written identity theft prevention program is required to describe how the entity will authenticate customers that open new accounts, change existing accounts and access accounts electronically. The program also requires top-level management support and oversight as well as regular risk assessments and program review.
The law gets its name from methods commonly used to authenticate the identity of customers. For example, if new customers are authenticated by requesting picture identification and the picture and description of the person does not bear any resemblance to the person presenting the identification, this is a red flag."
Oddly enough, I use powerpoint presentations in almost all of my trials, particularly cases involving the FCRA. I almost always use a timeline with pictures of "red flags" every time the credit bureau was told or should know that what it was reporting was wrong. Been doing that for years. Glad Congress finally caught up with me. :)
"The Red Flags Rule is a U.S. federal law that requires most every business and organization to develop and implement an identity theft prevention program. The purpose of the identity theft prevention program is to authenticate the identity of customers to reduce incidences of identity theft. Authentication is required when a new financial or credit account is opened or when a change is requested on an existing covered account. The law covers consumer and business accounts.
The broad definitions of 'covered account' and 'creditor' include most every business and organization. If a business or organization accepts payment for products or services after they are delivered, they are a creditor under the law and must comply. Those that only accept payment prior to or upon delivery are not creditors regardless of how payment is accepted—cash, check or credit card.
Compliance is risk based, meaning that entities must implement a compliance program that is reasonable and appropriate to cover the risks the organization is likely to encounter. For most entities, especially small businesses, compliance is simple, straightforward and will prevent fraud and financial loss by assuring the entity is doing business with a legal person or legal business, and not with an identity thief.
The Red Flags Rule was enacted on January 1, 2008 under the Fair and Accurate Credit Transactions Act of 2003 (FACT Act), the first revision to the Fair Credit Reporting Act (FCRA). Compliance under the Red Flags Rule was effective on November 1, 2008 for those entities under the purview of any of five federal banking and credit union regulators (OCC, Federal Reserve System, FDIC, OTS, NCUA). Compliance has been required on August 1, 2009 for those entities regulated by the Federal Trade Commission (FTC).
The law requires that entities regularly conduct a risk assessment to determine if they have covered accounts and to determine if they have any other accounts for which there may be a reasonably foreseeable risk to identity theft. If there are, a written identity theft prevention program is required to describe how the entity will authenticate customers that open new accounts, change existing accounts and access accounts electronically. The program also requires top-level management support and oversight as well as regular risk assessments and program review.
The law gets its name from methods commonly used to authenticate the identity of customers. For example, if new customers are authenticated by requesting picture identification and the picture and description of the person does not bear any resemblance to the person presenting the identification, this is a red flag."
Oddly enough, I use powerpoint presentations in almost all of my trials, particularly cases involving the FCRA. I almost always use a timeline with pictures of "red flags" every time the credit bureau was told or should know that what it was reporting was wrong. Been doing that for years. Glad Congress finally caught up with me. :)
June 23, 2009
New article about Red Flag Rules going into effect
Here's a quote from an article written by Susan M. Wissink and Mark R. Bolton about the new Red Flag Rules going into effect soon.
"The Federal Trade Commission ('FTC') recently enacted rules that will require many businesses and other organization to implement a written identity theft prevention program designed to identify and detect warning signs of identity theft. All businesses and organizations subject to the 'Red Flag Rules' must have their identity theft prevention program drafted and in place by August 1, 2009. The FTC can obtain penalties of $3,500 per knowing violation of the Red Flag Rules.
All businesses and organizations that meet the rules' definition of 'creditors' or 'financial institutions' and maintain 'covered accounts' are required to implement an identity theft prevention program. The term 'creditor' is defined broadly and includes businesses or organizations that defer payment for goods or services or provide goods or services and bill customers later. This definition could apply to everyone from healthcare providers to non-profit groups, government agencies, telecommunications companies, and homebuilders. The term 'creditor' is further defined to include organizations that regularly grant loans, arrange for loans or the extension of credit, or make credit decisions, including automobile dealers, mortgage brokers, mortgage bankers, real estate agents, finance companies, and retailers that offer financing or help consumers obtain financing from another organization.
Additionally, all 'financial institutions' may be subject to the Red Flag Rules. The rules define 'financial institution' as any bank, savings and loan association, mutual savings bank, credit union, or institution that maintain deposits or accounts from which the account holder is permitted to make withdrawals by negotiable or transferable instrument. The extremely broad application of the Red Flag Rules will catch many businesses and organizations off guard. Simply deferring payment for goods or services provided may require a business to implement a written Identity Theft Prevention Program."
The full article can be read here - http://www.endonurse.com/hotnews/ftc-identity-theft-rules.html.
"The Federal Trade Commission ('FTC') recently enacted rules that will require many businesses and other organization to implement a written identity theft prevention program designed to identify and detect warning signs of identity theft. All businesses and organizations subject to the 'Red Flag Rules' must have their identity theft prevention program drafted and in place by August 1, 2009. The FTC can obtain penalties of $3,500 per knowing violation of the Red Flag Rules.
All businesses and organizations that meet the rules' definition of 'creditors' or 'financial institutions' and maintain 'covered accounts' are required to implement an identity theft prevention program. The term 'creditor' is defined broadly and includes businesses or organizations that defer payment for goods or services or provide goods or services and bill customers later. This definition could apply to everyone from healthcare providers to non-profit groups, government agencies, telecommunications companies, and homebuilders. The term 'creditor' is further defined to include organizations that regularly grant loans, arrange for loans or the extension of credit, or make credit decisions, including automobile dealers, mortgage brokers, mortgage bankers, real estate agents, finance companies, and retailers that offer financing or help consumers obtain financing from another organization.
Additionally, all 'financial institutions' may be subject to the Red Flag Rules. The rules define 'financial institution' as any bank, savings and loan association, mutual savings bank, credit union, or institution that maintain deposits or accounts from which the account holder is permitted to make withdrawals by negotiable or transferable instrument. The extremely broad application of the Red Flag Rules will catch many businesses and organizations off guard. Simply deferring payment for goods or services provided may require a business to implement a written Identity Theft Prevention Program."
The full article can be read here - http://www.endonurse.com/hotnews/ftc-identity-theft-rules.html.
Subscribe to:
Posts (Atom)