+ All Categories
Home > Documents > 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

Date post: 14-Apr-2018
Category:
Upload: educause
View: 212 times
Download: 0 times
Share this document with a friend
19
7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255) http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 1/19 26 of 1… Compliance With the Red Flags Rule in Higher Education Sarah Morrow, MBA-ISM, CIPP/US, GISP Chief Privacy Officer  The Pennsylvania State University Maura Johnston, JD, CIPP/US University Privacy Officer University of Pennsylvania
Transcript
Page 1: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 1/19

26 of 1…Compliance With the Red Flags Rule

in Higher Education

Sarah Morrow, MBA-ISM, CIPP/US,

GISPChief Privacy Officer The Pennsylvania State University

Maura Johnston, JD, CIPP/USUniversity Privacy Officer

University of Pennsylvania

Page 2: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 2/19

 Abstract

Compliance with financial regulations inhigher education, especially the Red FlagsRule, is as complex as it gets; it is aregulation with elusive requirements. Join twouniversity privacy officers to hear about howcompliance was achieved at their respectiveinstitutions.

Page 3: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 3/19

Objectives

• This presentation will provide an overview of the Red Flags Rule;

• How IT is an integral part of universitycompliance in this area; and

• Answer questions you may have aboutwhere, when, and why this law applies toinstitutions of higher learning.

Page 4: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 4/19

Page 5: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 5/19

Red Flags Rule Was Adopted by FTC to require:

• financial institutions and creditors thatmaintain certain accounts to have an identity theftprevention program;

• users of consumer reports to implement

procedures for handling notices of addressdiscrepancy from credit bureaus; and

• credit/debit card issuers to have procedures toassess validity of change of address notices.

Who has to comply with the Red Flags Rule?

• Financial institutions

• “Creditors” who have “covered accounts”

Page 6: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 6/19

Effective date(s)

•  The rule was vague and compliance seemeddifficult in many ways; theeffective/compliance date was postponed

several times.

November 2008

May 2009

August 2009

November 2009

 June 2010

December 2010

Page 7: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 7/19

“Creditor”

• Under Red Flags Program Clarification Act of 2010, a“creditor” is an entity that regularly, in the ordinarycourse of business:

• Obtains or uses credit reports in connection with a credittransaction;

• Provides information to credit bureaus, in connectionwith a credit transaction; or

• Advances funds that must be repaid in the future.

• Interpreted by FTC to cover higher education institutions.

Page 8: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 8/19

“Covered Accounts”

• “Covered account" is an account

offered primarily for personal,family, or household purposesthat either:

• permits multiple payments ortransactions; or

• involves a reasonably foreseeable

risk of identity theft.

Page 9: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 9/19

Identity Theft Prevention Program

Identify Relevant Red Flags• Identify the red flags of identity theft

you’re likely to come across

Detect Red Flags• Set up procedures to detect those red flags

in your day-to-day operationsPrevent and Mitigate Identity Theft•

If you spot the red flags you’ve identified,respond appropriately to prevent and/ormitigate harm

Design program appropriate to

organization’s size and complexity, andnature of operations

Update program periodically• Risks of identity theft can change

rapidly, so keep program current and

Page 10: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 10/19

Some Potential Red Flags

• Federal Trade Commission identifies 26, in fivecategories:

• alerts, notifications, or warnings from a consumer

reporting agency

• suspicious documents

• suspicious identifying information, such as a suspiciousaddress

• unusual use of – or suspicious activity relating to – acovered account

• notices from customers, victims of identity theft, lawenforcement authorities, or other businesses about

possible identity theft in connection with “coveredaccounts”

Page 11: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 11/19

Penn State’s Approach

• Committee formed to create and vet the requiredtraining.

• Bursar (leader)

• Corporate Controller Office

• Privacy

Financial Officers• IT and Security Offices

• CPO had final approval sign off 

• Implemented prior to actual effective date

• Annual training

Page 12: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 12/19

Penn State’s Approach

• At Penn State

• Financial Officers

• Student Aid

• Bursar

• Credit Card Transaction locations…. (all around us)

•Milton S. Hershey Medical Center

• University Health Services

• ID+ LionCash

• Security Operations and Services

● PCI

Page 13: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 13/19

Penn State’s Approach

• Security Operation and Services

• Watches my back

• PCI-DSS may find more than simple credit cardfraud

•  Teaching moments

 Technological advances make identity theft morecommon and easier to achieve

• Keep APT on the radar

• Devise more accurate methods to assess risk

Page 14: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 14/19

It’s just my opinion

• This is a really difficult rule with which to comply

 because it is so vague

• It probably shouldn’t apply to colleges and

universities

Page 15: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 15/19

Penn’s Approach

Formed Red Flags Task Force•Representatives from potentially covered areas

•Narrowed group to areas we concluded were covered

•Central policy developed

•Simplified content of Rule

•Specific to Penn•Procedures and training developed by each covered area

Page 16: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 16/19

Penn’s Approach

•Covered areas:•Student Financial Services

• Tuition refunds

•Collections

•Student Health

•Dental Medicine

•Veterinary Medicine

•Home Ownership Services

•PennCard

•Health System

Page 17: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 17/19

Penn’s Approach

IT’s role in preventing identity theft

Example: Health System - Medical Office Visit●If Red Flags present (such as ID that looks altered or forged)

Incident Report is created●Incident Report is forwarded to team that reviews and, if appropriate, posts Red Flags Alert●Alert interfaces with all core registration databases●Incident Report is scanned into electronic health record system

●  

Page 18: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 18/19

Penn’s Approach

• Review/update Red Flags program

periodically•

Experienced incidents of identitytheft in the past year?

• Experienced changes in methods of 

identity theft in the past year?• Amended Red Flags procedures

since they were first adopted?• Any changes that might present

new potential opportunities for

identity theft?•

Staff received training on Red Flagsprocedures?• Suggestions for changes to Red

Flags program?

Page 19: 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

7/29/2019 26 of 1: Compliance with the Red Flags Rule in Higher Education (166215255)

http://slidepdf.com/reader/full/26-of-1-compliance-with-the-red-flags-rule-in-higher-education-166215255 19/19

Questions?

• Sarah Morrow

[email protected]

(814)863-3049

• Maura Johnston

[email protected]

(215)898-1934


Recommended