What is Personally identifiable information (PII)

Clients are often surprised when I list what is considered Personally identifiable information (PII). It is critical to keep this information private to be in compliance with various laws, and I always include the full list of PII in a client’s Privacy Policy.

In the broadest sense, PII is Information which can be used to distinguish or trace an individual’s identity. Personal Information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.

Recently, “Biometrics” were added to the list of PII in a handful of states. I always tell my client’s to keep their list as broad as possible to avoid any unintended data breach.

Finally, if the PII is encrypted, even if you have a data breach, there is a safe harbor provided in most data breach law that says it is not a data breach as the data cannot be read by third parties.

Below is my most current list of individual items considered to be PII:
1. First and last name;
2. Home or other physical address, including street name and name of a city or town;
3. Email address;
4. Telephone number;
5. A government issued identifier (e.g. Drivers license) ;
6. Any other identifier that permits the physical or online contacting of a specific individual;
7. Biometric Identifiers (e.g. fingerprint or eye scan);
8. Any complete login information (which is usually a big surprise to the client.); or
9. An individual’s name plus one or more of the following: a) Social security number, b) Driver’s license or State identification card number, c) Financial account numbers, d) Medical information or e) Health insurance information.

As I said above, encryption of this information provides a safe harbor. I always insist the client encrypt any and all of the above information.

Please feel free to contact me with any questions you may have about this list.

Data Breach Risks Exist Even Without a Website and Need “Reasonable Security”

In my last blog post, I discussed that “Reasonable Security” was now defined by a legal authority when California Attorney General, Kamala Harris, released a document entitled “The California Data Breach Report February, 2016. In that post, I focused on E-Commerce sites being hacked by bad actors on the Internet.

Today I want to discuss the risks all businesses or agencies face for any Personally Identifiable Data that is kept on their premises; whether on servers, laptops or phones; and whether connected to the Internet or not.

Data Breaches often occur because employees are not well trained in how to protect data, and that is much of what California has defined in their “Reasonable Security” Report. Further, while this is the California standard, all states now have Data Breach laws, and they will probably use this definition if you have a data breach.

Consider these areas of Data Breach occurrences, and how they can happen to you:
1. A lost or stolen lap top;
2. A lost or stolen thumb drive;
3. An untrained employee falls prey to a phishing scheme; or
4. A former or current disgruntled employee releasing data to harm their employer.

The legal obligations to secure personal information include an expanding set of laws, regulations, enforcement actions, common law duties, contracts, and self-regulatory regimes. California’s information security statute requires businesses to use “reasonable security procedures and practices…to protect personal information from unauthorized, access, destruction, use, modification, or disclosure.” Federal laws, including the Gramm Leach Bliley Act (GLBA) and the Health Insurance Portability and Accountability Act (HIPAA), contain general security requirements for the financial services and healthcare industries. Authoritative security standards describe the measures that organizations should take to achieve an appropriate standard of care for personal information.”

“Recommendation 1:
The 20 controls in the Center for Internet Security’s Critical Security Controls define a minimum level of information security that all organizations that collect or maintain personal information should meet. The failure to implement all the Controls that apply to an organization’s environment constitutes a lack of reasonable security.”

(Just so I am clear, by stating that not having these 20 controls in place constitutes a lack of reasonable security, your site just became liable for a huge fine from every state’s Attorney General who has a citizen on the data breach list and to whom you must report the data breach. Further, you will be required to report the data breach to the FTC. Even if you are not fined, you will spend thousands of dollars in legal fees and I.T. consulting if you have a Data Breach. Further, never forget, if it is not in writing it didn’t happen. You will need to keep records of all your actions and training to comply with the definition of Reasonable Security.)

“Formerly known as the SANS Top 20, the Controls are now managed by the Center for Internet Security (CIS), a non-profit organization that promotes cyber security readiness and response by identifying, developing, and validating best practices. The Controls were originally developed by federal agencies in 2008 and since then have been the product of a public-private partnership that includes cyber security experts from government and the private sector in the U.S., as well as around the world.

“The CIS Critical Security Controls for Effective Cyber Defense”
CSC 1 Inventory of Authorized and Unauthorized Devices
CSC 2 Inventory of Authorized and Unauthorized Software
CSC 3 Secure configurations for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers
CSC 4 Continuous Vulnerability Assessment and Remediation
CSC 5 Controlled Use of Administrative Privileges
CSC 6 Maintenance, Monitoring, and Analysis of Audit Logs
CSC 7 Email and Web Browser Protection
CSC 8 Malware Defenses
CSC 9 Limitation and Control of Network Ports, Protocols, and Services
CSC 10 Data Recovery Capability
CSC 11 Secure Configurations for Network Devices such as Firewalls, Routers, and Switches
CSC 12 Boundary Defense
CSC 13 Data Protection
CSC 14 Controlled Access Based on the Need to Know
CSC 15 Wireless Access Control
CSC 16 Account monitoring and Control
CSC 17 Security Skills Assessment and Appropriate Training to Fill Gaps
CSC 18 Application Software Security
CSC 19 Incident Response and Management
CSC 20 Penetration Tests and Red Team Exercises

If you would like to review the entire report it can be found here: https://oag.ca.gov/breachreport2016

Please feel free to call me to discuss the implications of this report to your specific websites.