Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, December 31, 2014

Cloud Computing is like online dating....

Cloud computing, incorporating Platform, Software, and Infrastructure as services (PaaS, SaaS, IaaS), has long been a topic of discord and interest. I think that I am an anomaly among privacy professionals in that I embrace cloud technology and have since I first faced it as a privacy officer in a work environment.

Why?

Because cloud technology offers advantages to enable entities to focus on their core business. It, being cloud technology, offers the ability to scale, store, be faster, stronger, and leap tall buildings in a single bound - well, okay, so you may not be able to successfully do everything, but it sure opens possibilities.

It is not a magic pill, but it is (hopefully) a long-term relationship.

Online dating. I met the love of my life that way, and so far, we have been just ducky!



1.   Once you decide to enter the online dating field, do your research. What do you want out of it? How much do you want to put into it? What is your risk and your risk appetite? How much of yourself are you willing to share?

2.   Create a profile of what you are looking for. What do you want your new partner to look like, act like? What are their specialties? How much do they make? Are these preferences or hard lines?

3.   Go live and enter the field! Don't get excited, this is by far not your last step.

4.   Now you start screening with the information that the potential mates have made available. You may not like what you see, so those are easy enough to screen out. But if they look attractive/sound appealing, be careful. They don't deliberately put out bad information.

5.   Here is where you make a decision - do you start talking to all of those who are appealing? or do you do further research?  It depends on whether you want the experience of getting to know a wide range of vendors or if you are sincerely just focused on finding the right partner for a specific, identified need. (I don't judge here - it's your need.)

6.   Once it looks like you may have found the perfect mate or at least a few potential ones who could be your perfect mate, meet them in person. Look past the courting to the substance; but do make sure they do the fancy courting - you deserve it. If they cannot afford it, find out why. But don't discount the poor ones, just because they are poor. Ask the hard questions.

7.   Narrow down your selection and get to know each of them intimately (again, no judging. your level of intimacy is your choice.) Put them through a trust test. Introduce them to your friends and family (key stakeholders, compliance, etc.).

8.   Meet their friends and family - and importantly, their current and former mates. You really do not want this to be a monogamous relationship. If their entire business or a significant portion of it depends one mate, then they may not survive the loss of that mate. In this, polygamous love is a good thing.

9.   Heart, head, or gut.. Make a choice. I recommend going with the head over the heart, but sometimes the gut also works. Seriously, this choice should not be made lightly. Bring all of your evaluation tools to bear and be skeptical.

10.   Have an exit strategy. Make sure your prenup is strong. Hopefully, you never need it, but be prepared for the worst.

Good luck and may the goddesses of love and clouds be on your side.

Wednesday, August 13, 2014

Implementing a Global Whistleblowing Program

Last month, I co-presented a short webinar with Jana Anderson, Partner, Foley & Lardner on implementing a global whistleblowing program with the Health Law Committee of ACC. If you are a member of the Association of Corporate Counsel, you can download the slides and materials here.

You may be asking yourself, why is a privacy attorney speaking to whistleblowing?

Believe it or not, many of the impediments to an effective (and legal) whistleblowing program are related to privacy laws and/or underlying privacy reasons.

Here are some of the highlights:

What is a whistleblower?

  • Ralph Nader coined the phrase in the early1970s to avoid the negative connotations found in words such as "snitches” or “tattle-tells.” 
  • Whistleblowers report perceived violations of a law by an entity (govt., private, educational, etc.) 
  • Whistleblowers are typically employees due to the need for insider knowledge. 
    • Internal – acts within entity to prevent/report violations 
    • External – reports externally, reward system 
Recent cases:

  • Medtronic Inc.’s recent settlement involved a business development manager as the whistleblower, who will receive $1.73 million as part of a $9.9 million settlement. 
  • Omnicare’s recent FCA actions involve a former collection manager and a former customer support employee as whistleblowers. 
  • Halifax Health Medical System’s recent Stark settlement for $85 million was a result of a qui tam suit brought by a former compliance officer for the system. 
The views on whistleblowing between the U.S. and other countries are vastly different. Here in the U.S. we view it as the right to keep businesses honest, to expose fraud, and to enforce compliance. Other countries view it as betrayal and that the U.S. is trying to govern business in their countries.

The laws that impact a global whistleblowing program fall into six categories. I give credit to the fabulous Don Dowling, Jr. of White and Case for his work in this area. Most of my knowledge in this area comes from intense study of his work.)

The six areas of laws that should be evaluated when implementing a global whistleblower program:
  • Mandating whistleblower procedures specifically
  • Requiring disclosures and cooperation with authorities
  • Restricting reporting hotlines (most especially anonymous reports or minor misbehavior)
  • Retaliation laws
  • Laws around internal investigations
  • Laws silent on whistleblowing, but programs possibly triggering data protection laws or work rules
Most of the legal implications are in Europe, which is no surprise given their fundamental right to personal data privacy.

Global whistleblowing programs fall into one of these categories:
  • One global program 
    • Meet both US law requirements and EU restrictions 
  • Two hotlines 
    • one in EU (meet SOX and most conservative EU country); another everywhere else 
  • Tailored hotlines to each local jurisdiction 
  • No EU hotline 
  • Informal EU reporting 
Last, a short checklist to implementing a global whistleblowing program (drawn heavily from Mr. Dowling's work):
  • Pay attention to EU particularly 
  • Check whistleblowing laws and privacy laws 
  • Disclose hotlines where required 
  • Secure data (calls, reports, investigations) 
    • That includes destroying the file after investigating 
  • Adhere to data transfer requirements 
  • Limit reporting topics to ensure proportionality
    • several nations only permit reporting of potential major criminal activity
    • Have routing for other reports that are not major crimes to a less formal process
  • Enable alternate reporting channels 
    • phones, emails, supervisor, HR, online
  • Do not encourage anonymity 
    • if you cannot bar anonymous in applicable countries, at least do not encourage or advertise it
  • Have a list of due process rights for accused 
  • Translations and multi-lingual operators should be easily available
  • Verify compliance, knowledge, capability of hotline vendor 

Wednesday, July 30, 2014

Sensitive Personal Information

Personally Identifying Information ("PII") is often defined by law. In the U.S., this generally occurs in sectoral law, such as the Health Information Portability and Accountability Act ("HIPAA").

But PII has layers, like an onion a la Shrek. There is your regular everyday PII, such as name, date of birth, and address. Then there is sensitive PII and sometimes even highly sensitive PII. These distinctions are generally found in countries other than the U.S. In addition, where sensitive information is being collected, there are generally laws or rules around having clear consent of the person to collect it as well as how this information can be stored, shared, used, transmitted, and protected. Let's explore these definitions and where they can be found.

For this exercise, I relied heavily on two publicly available resources:
What I am looking at here is what is considered sensitive PII ("sPII"). The laws or rules may not include a category of data called "sensitive personal information." For these purposes, if there are requirements to protect certain data at a higher level, then we will consider it "sensitive."

The typical definition of sPII, if there is such a thing, is: racial and ethnic origin, political opinions, religious, philosophical or moral beliefs, labor union membership, and information concerning health conditions or sexual habits or behavior. 

Most countries with a definition of sPII explicitly include the elements listed above or some statement in the law that anything that would cause discrimination against the person or that the government would consider to be private information. 

The European Union, in general, uses the definition above - they actually set the standard as the strongest multi-national privacy laws in the world. Some of their countries add criminal records, proceedings, and/or investigations to sPII. Switzerland goes a little further and includes social welfare programs along with government identifiers.

Argentina and the Republic of Turkey also use the definition above. Russia and Chile use most of the standard definition, but do not include trade unions.

Australia and Hungary build on the standard plus criminal definition above, but both add membership in a trade association. A trade association is like the American Medical Association, where individuals voluntarily or perhaps are required to join based on their profession. Interestingly, Hungary specifically includes "abnormal addictions" as sPII. Australia adds biometrics.

Speaking of biometrics, two other countries list that as sPII, along with the standard plus criminal elements: the Czech Republic and Azerbaijan. However, Azerbaijan goes on to include social welfare, domestic violence, taxes, marriage or family matters, and child adoption. Likewise, the Philippines take sPII to a more detailed level. In addition to the standard plus criminal definition, the Philippines add taxes, family or marriage matters, age, education, and government issued numbers.

Some of the more economically active Asian countries are strengthening their privacy laws. Commonly, these countries may not define sPII, but they do include general provisions that private data either is prohibited from being collected or deserves greater protection, without necessarily listing examples of sPII.  These nations include China, India, Indonesia, Japan, Malaysia, South Korea, Thailand, Taiwan, and Vietnam. Vietnam includes taxes and financial account information, while Japan includes financial data,  marriage and family matters, social status, and registered domicile. India includes biometrics and passwords. South Korea includes unique identifying numbers, such as passport numbers.

Although respect is a common foundation for privacy, many of the privacy protections in the Asian region are centered on this concept. An individual's personal information is expected to be respected and therefore, protected. So in many cases, sPII is simply afforded the same protection as regular PII.

A few other countries also do not necessarily define sPII, but require a judgment call on private information: Canada, Colombia, Egypt, Israel, and Mexico. Thus, everything discussed in this entry could be considered sensitive. (oh, Israel considers information about one's personality to be sPII.)

And last, keep in mind, in nearly all cases if there is something not specifically listed in the law that would be discriminatory to the individual or disclose highly personal information, you should err on the side of caution and protect that information.








Sunday, May 18, 2014

Why you should not sign everything put in front of you: HIPAA Business Associate Agreements

courtesy of backstage.com

The Health Insurance Portability and Accountability Act of 1996 and its subsequent amendments ("HIPAA") includes the contractual arrangements between Covered Entities and Business Associates, and now downstream Business Associates, or subcontractors (under the Health Information Technology for Economic and Clinical Health Act "HITECH").

This entry presumes the reader has a basic knowledge of HIPAA, but if not, please see the above link for HIPAA.

Today, we look at the evolving and complicated nature of Business Associate Agreements ("BAAs"). These are the agreements mandated by HIPAA, and now HITECH, although the recent amendments and the preamble make clear that the requirements of HIPAA and the HITECH Act apply to a Subcontractor regardless of whether the Business Associate fails to enter into a contract with the Subcontractor. This is very important below when we cover some of the complications.

First:
HIPAA requires certain provisions to be covered in BAAs. Often, the Covered Entity will put in additional provisions, usually around indemnity, audits, breach notification timelines, and data protection minimums not required by HIPAA, such as encryption.  These provisions are unduly burdensome, especially given the characteristics of most Business Associates - small operations. It is understandable why an entity would want to put these protections in place, but it may may stifle the ability to outsource and place a strain on relationships.

Second:
It is understandable why the government wants to reach further than Covered Entities and have direct oversight of Business Associates. Think about it, Dr. Jones on the neighborhood corner may not have the wherewithal to properly secure data or to respond to breaches. Or given that the new provisions provide for the State Attorneys General to bring civil actions on behalf of state residents for HIPAA violations, for damages or to enjoin further violations. I once had a privacy attorney argue with me via email (which cc'd numerous colleagues) that HIPAA as amended by HITECH absolutely did not provide for a private right of action. Well, duh - but given that the states can now do so on behalf of its citizens...it is practically the same thing. But I understand, in the law, one must be precise.

Third:
Large organizations that are now clearly defined as Business Associates, according to the guidance issued with the final rules, at first stated they would not sign BAAs. Remember above, where the new rules provide for liability whether a BAA is signed or not...?  Well, their refusal did not last long. See a discussion about Amazon Web Services here. What large providers who do not wish to be rolled under HIPAA have done, is placed administrative requirements on the Covered Entities or Business Associates which use their services, such as list all accounts for which they have patient data. Many organizations are unable to fulfill these requirements. So what is the solution - sign something they cannot fulfill or don't sign and HIPAA applies anyway. This is yet to be tested, but it is a popular conundrum.

Organizations should be careful about signing any old BAA placed in front of them. Watch your salespeople, too. They are likely presented individual BAAs when they show -  either the BAA does not apply or the employees are committing the company to a BAA without proper review. And this can be costly given the additional items that are in a BAA as discussed above.  And how can an organization signing tens or hundreds of BAAs possibly manage to push all the same provisions to downstream vendors? They conflict with each other - and Covered Entities need to understand that with the additions of clauses that are not required by HIPAA, they are setting their Business Associates up for failure.

Last, many small business owners that are Covered Entities do not understand HIPAA completely. Heck, neither do I. After a professional conference, Business Associates or potential Business Associates will be deluged with requests to sign BAAs. Sometimes, the exact same template is used, including with various clauses that include internal directions such as [choose one of the two clauses below]. It can be frustrating on all sides. Most individuals, however, are just trying to do the right thing. If a Covered Entity wants an organization to sign a BAA and the relationship does not exist, the organization can easily respond with a tight explanation. If still pushed, adding a line such as "This agreement only applies where the organization acts in the capacity of a Business Associate under HIPAA" will generally satisfy the needs of both sides. This is another untested, yet relatively popular strategy.

The conclusion here is that you should not sign everything put in front of you - or your employees. Educate all individuals to send the BAAs to a central office. Push back, or scale back, non-HIPAA provisions. It will be interesting to see how these natural conflicts play out in the next few years.



Tuesday, April 22, 2014

InBloom: Seeded before its time

Yesterday, inBloom (non-profit education software company) announced its plans to wind down operations over the next few months due to objections by parents and legislators. Adults became concerned about putting in too much information into this database (400 fields), such as students' social security numbers, details about school withdrawals, and family relationships. This month, New York passed legislation prohibiting their department of education from providing data to aggregators (like InBloom).

In mid-November of last year, parents in New York petitioned for a restraining order against the state department of education preventing them from providing student data to inBloom. Parents cited that providing this information was a dramatic departure from the then current practice and seemed to be taking steps backwards in terms of privacy.

inBloom describes its mission and goals as:
"a set of shared technology services that includes a secure, multi-tenant data store and middleware for identity management and data integration . . .  designed to help School Districts and State Educational Agencies provide educators, parents, elementary and secondary school students with learning data from many sources and connect them to relevant instructional resources to support personalized learning through inBloom. The service also helps State Educational Agencies in evaluating federal- and state-supported education programs."

The goal was to provide  "districts and states as a utility for them to more easily synchronize and transfer data, including student personally identifiable information (PII), across the various learning applications they deploy to teachers, students, and families."

So now it ends. inBloom is Out. 

But let's think about this for a few moments...

Is the population of the United States seriously considering the privacy rights of its vulnerable citizens? What?? This turns my privacy meter on its head. Since when did we care what information we share as long as no one gets hurt. What harm can come from this type of data aggregation? It's not like inBloom was going to turn over its education records to the department of child services to show that certain students had certain educational challenges - or home challenges that interfered with education. Data would not be misused or misinterpreted, right? Or shared with watchdog groups or even governmental agents who would put a spin on the data that might adversely affect students, families, school districts, or state funding, right?

Good googli moo

Thursday, April 10, 2014

Privacy: Don't let it go (our take on the ubiquitous song)

Information is shared around the world today
With a few data laws to be seen
One might wish for regulation
So do I, the Privacy Queen

Companies collect data like a swirling storm inside
Couldn’t keep them straight, heaven knows we’ve tried

Don’t let them in, don’t let them see
Be the private person you always want to be
Conceal, don’t reveal, don’t let them know
How much do they know?

Don’t let it go, don’t let it go
We can stop it furthermore
Don’t let it go, don’t let it go
Block cookies and slam the door

Someone should care
What they’re going to say
The argument rages on
Cause breaches don’t bother them anyway

It’s great how some countries protect personal data by law
And the companies that once controlled it can’t get to it at all

It’s time to see what we can do
To test the limits and break through
Do right, not wrong, pass data laws
For all

Don’t let it go, don’t let it go
Pass some laws and rules
Don’t let it go, don’t let it go
Scrap those data tools

Take a stand, the data stays
Let your rights rage on

Big data flurries through the web and into the ground
Information spirals in millions of bits all around
And one thought crystallizes like an icy blast
Data is rarely deleted – the past is never past

Don’t let it go, don’t let it go
New uses rise like the breaking of the dawn
Don’t let it go, don’t let it go
Once given, that data’s gone

Take a stand
In this big data reign
Should data brokers rage on?
Privacy never stopped them anyway



Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.

Thursday, March 13, 2014

My Privacy Heroes

I haven't written in a while, so please forgive me. Privacy issues remain daily headliners and I have no excuse for not writing. First, last week, I was at the International Association of privacy Professionals' Global Summit. It was sold out, which I think means a total of 3000 people attended. Wow.

I know, right? 3000 people from around the globe care about privacy. Yes, we are all dorks. But we're really cool dorks and have our own set of heroes and villains. Some of my own personal privacy heroes are listed below.

Dan Solove, John Marshall Harlan Research Professor of Law at the George Washington University Law School. He is a Senior Policy Advisor at Hogan Lovells. He is also the founder of TeachPrivacy, a company that provides privacy and data security training programs to businesses, schools, healthcare institutions, and other organizations. I had the privilege of getting to know Dan a little over the past two years and still have that little piece inside me that still squeals like a little girl simply because my privacy hero talks to me. The IAPP did a little blurb on me once (the link only works for those who log into IAPP, sorry) and soon thereafter, Dan sent me an email. Please understand that at the time, I probably had 5 articles and three books of his sitting on my desk. So I did a little happy dance before I calmly replied to him. I am happy to say that we have maintained a friendly relationship and I hope - I pray - to one day be on his level of competency.

Kirk Nahra a partner with Wiley Rein, LLC. Kirk has been involved with IAPP, I think since its inception. He has been on the IAPP's Board of Directors several times and currently serves as editor of the publications. I do not remember if I met him at a Blue Cross forum in Colorado or at an IAPP event, but either way, we seem to cross paths often, just not often enough. He sends out privacy law updates and observations - and frankly, is simply my most favorite U.S. privacy attorney.

Cass Sunstein is currently a professor at Harvard Law School and is a scholar beyond reproach. This is the only privacy hero I have that I do not know personally and have not met. I was supposed to hear him last year at a conference that my travel was cancelled due to weather. Oddly, I know more of him through my PhD program in Public Affairs than I do my privacy work. I would probably give my right kidney to talk with him for a hour or so (my right kidney is pretty shot, so that might not be a high enough payment).

So there is my list of heroes. I am not currently providing a list of villains, but let's just agree that most of them are corporate level, not individuals.

Saturday, February 15, 2014

HIPAA encounters of the Personal Kind

I wish today's post to be light-hearted, but realize in the end, there may be some lessons learned....be careful. You, too, may become conscious of your own privacy.

My cell phone rang the other day and I answered it "hello."  What follows is the gist of the conversation. I could be partially wrong in the exact wording, but the meaning remains the same. I have changed Paul's name to protect the unknowing.

K: Hello
Bob: Hi. I'm calling to speak with K Royal about an emergency room visit to blah blah hospital on this past Saturday on February 8.
(please note - at this point, he has disclosed my protected health information if someone other than me had answered the phone).
K: this is K.
B: Hi, this is Bob, an RN at blah blah hospital. Before I go any further, I need to confirm your identity to maintain confidentiality. What is your date of birth?
K: (really?! you've already blown it, mister) Hi Bob, can you confirm your identity to me before I provide you with my date of birth?
B: Uh, no. 
K: So there is nothing you can do, at all, to prove you are calling from the hospital? (I was expecting him to say - sure, call the hospital and ask for me or my extension)
B: No. can't think of anything. I just want your date of birth.
K: Okay, let's try this - tell me if you are calling to survey me on how well your service was or if you want to discuss something of a medical nature.
B: Ma'am, I can't tell you that. It violates HIPAA.
K: Actually, it does not. I am not asking you to give me any personal or protected information. I am just asking for the general nature of your call.
B: Ma'am that does violate HIPAA. HIPAA won't let me tell you the purpose of my call. 
K: Bob, I am a privacy attorney and very familiar with HIPAA, I can assure you that it does not. How about this...are you calling to survey me about your service? cause if you are, it was fabulous and I felt everything went smoothly. 
B: Ma'am, I cannot answer that question because it would violate HIPAA. And if you won't give me your date of birth, we seem to have a problem. I know HIPAA very well - and it won't let me continue without it.
K: Bob, I actually seem to know HIPAA better than you do ... at least in this instance ... because HIPAA would not stop you from answering that question. 
B: So what do you want to do?
K: I guess we're at an impasse, Bob. You cannot verify who you are or where you are calling from, you want me to provide you with even further personal information, and you won't tell me the purpose of your call. Sooooo, I think we're done here - and I truly hope you were not calling to tell me something popped up on the tests and I am dying. Feel free to call me back when you either learn more about what you can say under HIPAA or can provide verification of who you are. Have a good afternoon. Bye bye.

I called the privacy officer and left a message to call me. Nothing.

So what did we learn here (other than stupid stuff like this brings out my snarky side)?
1) It is a HIPAA violation for a covered entity to give out information before verifying the patient's identity - as in his opening statement.
2) When people ask for personal information, verify who they are.
3) Not all health care personnel in the US really know and understand HIPAA rules.
4) Patients need to be vigilant about their health care AND their personal information.

Monday, February 10, 2014

Why are the people in the U.S. so blase' about Privacy?

So this was the question I received today about privacy: "Why are people in the U.S. so blase' about privacy?"

Frankly, my dear, I don't know.

I do have some theories that my mind is sorting through as I write - and if you have some thoughts (yes, you, the one person who is reading this), please do write me and let me know your opinion.

First, I do not think it is related to the fact that we do not have an explicit right to privacy guaranteed to us in the U.S. Constitution. However, I do think it is related to what rights we are guaranteed and how those rights have been enforced over the years. Most importantly, I think the freedom of speech as personified through the freedom of the press has been a huge factor in how blase' we are about privacy. As citizens, we are allowed to say what we want to say (in general), do what we want to do (shy of breaking laws), move where we want to move, live how we want to live, love as we desire - and act on that love. Freedom of speech includes our actions, our apparel, and our writings. And this freedom comes with a price - that we are ever so willing to pay - the lack of privacy.

Next, the American dream reinforces the lack of privacy. To achieve our dreams - or at least for those ridiculously mega-rich people to achieve their dreams, they take chances and go where no one has gone before, with information, brazenness, and wild willingness to use any tools at their disposal. Information is mostly free and can be used in ways that the average person would find mind-boggling.

Additionally, most Americans have not suffered atrocious crimes and deeply personal invasions like countries with currently strong privacy laws have in the past - where thousands of people were tortured and killed based on information, like their race, religion, or even just their name.

Thus on one hand, we see benefits in the freedom of information and on the other hand, we see no penalties in the misuse of information. I have often been told that if a company treats personal information with the respect other nations require, the company would lose its competitive edge. So what would motivate us to care? When I posted previously questioning why we are not outraged at the NSA, one of the responses I got was that once the PATRIOT ACT was enacted, any person who read it or watched the news knew that we now had no right to privacy. In a way, I agree. Not enough people were outraged then - and you cannot let the exploding holes in the dam go unnoticed and then complain about a flooded home.

We need a fundamental shift in our thinking. Information is a power tool. And it can be dangerous in the wrong hands. It can be dangerous in the right hands - if those are not your hands holding your own information. We need to be stingy. For example, unless you are on a government health insurance program or workers' comp, your doctor does not need your social security number. Such a simple thing. But try telling your doctor he/she does not need it and they freak out - they are so used to getting it, they just want to fill the blank. So I just pretend not to know it. "Ooops sorry. Don't carry the card either, but I'll really try to remember to bring it the next time." Not.


My review of the book: The Future of Privacy posted on IAPP

https://www.privacyassociation.org/publications/book_review_the_future_of_privacy  

January 28, 2014
By K Royal, CIPP/US, CIPP/E

Being a strong believer in taking a pragmatic approach to compliance, I was incredibly pleased to read The Future of Privacy by Eduardo Ustaran, CIPP/E, published by DataGuidance. In general, I find the books available through the IAPP to be thorough, on point and useful to privacy professionals. This book went the further step and was actually fun to read and useful to those of the general public who have an interest in privacy.

Ustaran writes in a manner that is easy to comprehend and practical, yet steeped in substantive law. It’s like sitting comfortably with an expert who shares his insight and expertise as a conversation—at times relaxed and sometimes highly animated. And the timing for this book is perfect. At no other time in recent history have privacy and its challenges been at the forefront of global news.

The Future of Privacy is divided into three parts: “Catalysts,” “Policy Making” and “Compliance.” “Catalysts” provides a simplistic yet robust summary in three chapters covering of the evolution of technology, the value of data and data globalization. We start with the terminology: Information Superhighway, the Internet of Things, the cloud, cookies, social networking and the mobile ecosystem. This foundational coverage continues with analytics, Big Data and behavioral targeting.

Part I segues into Part II, “Policy Making” with frank coverage of the globalization of data. Ustaran clearly believes that the prohibition on data exportation prevalent in many nations’ laws is exasperating. It is also naïve in the technological age in which we live and function. Part II discusses regulating technology, policy-making, interoperability and incentivizing compliance. Ustaran recommends “just in time” regulation that is lean and consistent. Within these three chapters come the concepts of Privacy by Design, a global privacy blueprint and mutual recognition.

The book concludes with Part III on “Compliance,” perhaps the most critical section for privacy professionals. In Chapter 7, we start to see more of Ustaran’s European roots. He discusses the evolution of transparency in the use of an individual’s data, recognizing the debate about whether individuals have true control over the use of said data, anonymization, privacy and security by default rather than design and finally, the role of safe processors. He continues this discussion in the next chapter from the perspective of data as an asset—which may be controversial to some privacy professionals. He is clear that irrespective of a privacy professional’s belief in the idea of data as an asset, our roles depend on managing this idea and being committed to finding the right approach. The concluding chapter of the book addresses accountability in an era of competing regimes, uncertainty of law and the cost of consistency. He supports privacy within an organization as a team effort and advocates for the use of privacy impact assessments. He tackles the topic of global privacy compliance and advocates for the EU’s Binding Corporate Rules as a corporate framework. Ustaran concludes with two sentences: “We just need to get cracking because the future is here. Now.”

Generally, I read privacy and/or compliance books because I must in order to do my job. It’s rarely amusing or captivating, even when the book is well-written by a noted expert in the subject matter. Yet, this book is different. And the difference is in the presentation and writing style. The law is provided through thoughtful analysis wrapped in delightful examples and honest opinions. Whether you are new to privacy law or already immersed in its depths, this book is one that you should have—and not just on the bookshelf. Take notes in the margins, because you are just as likely to find yourself disagreeing with various points, questioning their validity or simply taking a deeper look into certain elements. This is the challenge of such a book; rather than merely absorbing the law dryly and reciting it back iteratively, it initiates thinking processes. It dares you to skim across and engages you in thought-provoking analysis.

Ustaran presents his beliefs without hesitation, but in his forthrightness, the reader responds with the same honesty—whether in agreement or not. This is the power of such a book, defining one’s own professional and personal belief system about privacy and forming a foundational understanding of technology and policy-making. I do not know if a global compliance program is truly achievable, but like many other privacy professionals, I have to attempt it. I agree with Ustaran in that the future is here and we need to stop playing catch-up and develop a workable regulatory framework where there is a basic understanding of the role data plays and how to be transparent in that use. I highly recommend this book for privacy professionals and anyone else with an interest in data handling.

Friday, February 7, 2014

Privacy in the Toilet

So I cannot help but take a cue from all the mimes and stories going around about the toilet conditions in Sochie at the Winter Olympics. Talk about a lack of privacy...

I don't know if the pictures and/or stories are real, but they sure are fun. And like most online authors, I plan to make the most of it, perpetuate the myth, and basically exploit the heck out of it. oo rah.

Let's compare the supposedly lack of privacy of Sochi Olympic toilets to the sanitary conditions of some countries. Sochi has toilets. Some countries do not. Are we as a leading world power spoiled? We have indoor plumbing, filtered water, sophisticated waste management, and private commodes almost everywhere. Is there some reason why Olympians cannot tolerate something less than the best? Is there some reason why our Olympians cannot see what it feels like to live on the other side?  We have antibiotics, right? Is privacy required to take a poop? As a nurse, we often had to deal with a patient's inability to urinate on command - hesitation. It's prevalent in pre-employment physicals and drug screens as well. Some people simply cannot perform with an audience.

So let's transfer some of these same considerations over to privacy. In the U.S., we are horrified of being asked to use the restroom in front of someone, but we don't consider personal information to be private. Bowel movements, yes. Date of birth, no. So that's our scale of privacy need. We don't flinch at sharing a lot of information or categories of information. We expect that companies who possess our information in certain contexts to be using that information to gain a business or competitive edge or to use it in some way that is advantageous to them. Thus, when there is a breach, fewer than 10%  of people contact the company or take them up on mitigation offers (anecdotally and my own experience dealing with breaches - seriously was closer to 3-5%).

Yet, in the E.U., people have other expectations. They expect privacy. They expect their information will only be used for the purpose it is collected and nothing else. Nothing else. And once the purpose is achieved, the information should be deleted. Deleted. So they are horrified at U.S. citizens' and businesses' cavalier attitudes towards privacy.

This would be a different world if we were as horrified at our information being gathered, shared, used, and kept as we are having to poop side-by-side with someone else. Take that and flush it. 

Tuesday, February 4, 2014

Happy Birthday, Facebook!

So today is Facebook's 10th anniversary or birthday...

What were you doing 10 years ago? It was 2004...I was graduating law school. I recall hearing about the new service for college kids and some scandal about posting pictures. My daughters were in junior high, so they were on the infamous MySpace (where is that now, anyway?).  That proves that first-to-market is not always market leader.

Facebook has faced (pardon the pun) many challenges in the U.S. and globally about their privacy practices, which seem to change daily without notice. Which is not true, by the way. Facebook does not change its policies daily. On the other hand, since they eliminated the public voting process last year or so, now we as users don't know when it is changed.

Much of the controversy over Facebook has been based in its for-profit side - we, as users, don't provide it any money directly so they have to get it from somewhere. They get it from ads. You may recall how users' likes were used as product endorsements at one time. Now, we get served targeted behavioral ads in our newsfeeds. You can report these as spam. 

But let's move away from the negatives and look at the positives. There are people I have not even thought about in over 25 years...and now, through Facebook, I see what they are doing in their lives - pictures of them and their children, families, colleagues, and friends. It is kinda cool. Many people who I love that I do not get to see for years, now I am a permitted peeping Tom in their lives. It's wonderful.

Facebook made our 25th high school reunion a huge success - cause we could find people!

Facebook let me know when some older family friends passed away - I could send flowers and/or make it to the funeral.

Facebook sometimes provides me more of a look into lives than I wish to have - don't need to know when someone has a bowel movement or is mad at the cashier at Wal-Mart. But in general, I like Facebook, which is why I use it. Under my real name. I also get to "like" the pages of actors and writers I like and they frequently have contests and cool information. It's fun.

So Happy Birthday, Facebook - may the next decade see you enjoy even more success and more maturity in your practices.

Sunday, February 2, 2014

When can Employers share your Information?

My daughter, Dazlin, asked this question on privacy..."Under what circumstances can or should my employer share my information?"

What a brilliant inquiry.

And I have no brilliant, quick responses, yet I am forcing her to wait for the answer on here even though I am currently comfortably ensconced in her apartment, sitting across from her. 

First, for me, the easy answer is about medical information. Any information in the medical context, whether as part of disability accommodation, employment prescreening, genetic information, employer medical coverage, or workers' compensation must be kept confidential. This means, generally, in HR, there are two files for each employee or a bifurcated file where the health information is kept separated from discipline, hiring and firing, pay, etc.

Can they ever share it? Of course they can. They can share it with people and entities who have a need to know, such as benefit managers, health care professionals who are treating you, risk management, and so forth. But in general, the information should not be shared anywhere without a legitimate reason. Most of the protection here is federal - EEOC (disability, genetic information), OSHA (injuries on the job) - but there is also state law that applies (workers' comp, HR law, data breach law).

I am not going into a terrible amount of detail here if for no other reason than it is a blog and not a legal treatise. Some factors also depend on whether your employer is a public or private entity and/or what job you hold. But if anyone is curious, write me and let me know that you have questions. I'll see what I can do.

Now, for the sharing...in almost all laws, there are exceptions and privacy law is no exception to that. In general, the exceptions are around subpoenas, law enforcement, public health, emergencies, and business operations that require disclosures. Business operations could include mergers, account houses, and other entities that are contracted to perform some duty on your employer's behalf, like mailing 1099s. To do so, the other entity has your information. Do you also remember all the stories about how many subpoenas and requests for information are being served on internet service providers? If information is part of an investigation, your employer will likely give it up.

Other than medical information, employers are required to keep certain information secure - like your date of birth and social security number. In countries other than the U.S., who have data protection laws, certain information is considered sensitive information. Sensitive information includes ethnicity, political views, member of professional organizations, etc. Now here in the U.S., race, age, gender is also considered confidential, but mainly because an employer can be sued for discrimination if negative decisions are based on race, gender, being over 40, disabled - things that make you a member of a protected class. Also, credit reports and background checks must be performed and retained securely. In fact, after the financial troubles of 2008, several states placed background check laws in place - mainly either the employer could not ask certain questions in an application or could not do a background check before meeting the person.

Many states have laws protecting certain information, although Massachusetts with 17 CMR 201 is the strongest. In Massachusetts, if you have information on their residents, to include name (either first name/initial with last name) plus some other elements (SSN, driver license number, or financial account number), then you are required to have a security program in place and provide certain data protections.

Mainly states have data breach notification laws, meaning that if your data is breached somehow, your employer must let you know (these are general law not employment laws, but apply to entities that collect certain information). Thus, if your employer wants to be excluded in most of these states from notification provisions, then they need to encrypt and take precautions with your information. Not all states recognize encryption as an exception, but most do - and of course, this only applies to electronic information.

Speaking of electronic information: analyzing whether employers can access your electronic communications such as email, texts, and social media is a full blog on its own. Morality consideration is another - think of teachers fired for posting naked party pictures on their own facebook or sports figures who get into scandals and lose endorsements. And last, lifestyle (which includes morality) is also a very deep discussion of law. 

So this is part of her answer. In reality, not all employers follow the laws - and certainly not all employees of your employer will follow the law. Training and awareness are huge for data protection and training is not generally a high budget item for many employers, especially towards protecting their employees' data.

So my advice point coming out of this is to be careful of your own information in the workplace. It is not necessarily a good idea to friend people on social media that you work with - you just may have information disclosed to your employer that you wish was not - and if a negative action is taken towards you based on this information, then you likely will have a very hard time proving it.

Saturday, February 1, 2014

What is a Privacy Counsel, anyway?

My name is K and I am a privacy counsel.

Most of the time when people ask what I do, they have no clue when I say "I am a privacy counsel." Confession time, I usually only say I'm an attorney, but sometimes they want to know what I practice. I don't practice. I am in-house. For those that don't know, in-house means that I am not with a law firm and do not take clients. I work for a company as an employee. The company is my client.

And given that I blog about privacy, I have to always disclaim that my views are not those of my employer.

But back to the question, what is a privacy counsel anyway? If I said I was an employment counsel or IP counsel, people would not be confused. I work in privacy. That is what is confusing, because people in the U.S. don't get privacy and I'm a dork.

Working in Silicon Valley does make for a little more acceptance. With the number of global companies here, they all pretty much have people doing what I do. It's kinda cool. There are lots of other privacy counsels.

Okay, Okay - back to the question. It means I make sure that the laws of the nations who have privacy laws are followed. Every other country who has privacy laws at all approach privacy vastly different than does the U.S.  We look at data on a sectoral level - health care, education, financial. There is no national privacy law in the U.S. and no national protections for general data on individuals. The states are a little different. 46 states have data breach laws - and they have many commonalities and some differences. The strongest data protection laws are in California, Texas, and Massachusetts. 

So in the U.S., I make sure we abide by sectoral laws and state laws. Globally, I deal with the laws of the European Union (28 or so different sets of law for the various countries, if you include the EEA 30 or so), APAC, Canada, Mexico, etc. etc. And I love it.

As stated above, I love privacy law. I caution people not to think of it as privacy, because most people tend to have tunnel vision. Think of it as personal data management - and in many cases, the most sensitive data I deal with (and thus, protect) is that of employees.

But like any area of compliance, it is always an uphill battle. Compliance is a cost center not a money maker. Ensuring certain protections are in place can slow down innovation and development. And especially given that most would prefer to build the house, then add the fence for privacy - we (privacy professionals) would prefer you to bring us the blueprints and make sure you are not building on someone else's property and/or get the right permits. Privacy by Design, or Privacy by Default. Build the product right to begin with. Then I am not a roadblock, I am a roadsign. I can point you in the right direction if you come to me early. If you come to me when you are ready to roll it out...well, I have to come up to speed on the product, check the contracts, vet the vendors, and know every data element you collect, how, when, what, where you get it, share it, and store it, how to send it, back it up, and delete it. 

So that is what a privacy counsel does.

It is one of the fastest growing fields in the world.

And when it is me - you get all this personality with the package. fun time, my friends, fun times.

Thursday, January 30, 2014

Practical HIPAA basics for Patients and their Families

My daughter was rushed to the ER one evening and I joined her. She was 18, maybe 19. They took her to do an ultrasound and I started walking with the bed. The employees stopped me and said I could not accompany her, she was an adult. She looked at them and said "I want her with me." And they replied that HIPAA would not permit me to accompany her. I explained that I could take the time to educate them as to why that statement was not true and would be happy to educate their supervisors if they also held the same mistaken beliefs, but given my daughter's emergency - if she was okay with going alone, I would not object at this time. My daughter agreed and off they went. I complained the next day.

I have another daughter who was having x-rays done as an outpatient and was also told I could not accompany her due to HIPAA. She was actually a minor. I was prepared in a non-emergent situation with a minor to object, but this daughter was actually quite happy for me not to accompany her - she was 15. Very independent. 

In one case, my mother was in the hospital following surgery and the nurses were giving her a hard time about her lack of following their instructions....and my mom is a nurse. She wasn't following the instructions, because the nurses were only taking into account the immediate situation and not the full history - which was clearly in the record. I called to inform them. Upon the nurse haughtily telling me she could not speak to me about my mother due to HIPAA, my response was that first, HIPAA would not stop her and second, I am not asking her for information, merely providing information to her. She need only listen - not speak. (Yeah, I can be a bit of a prat, but while firm, I was also very polite in all situations described above). 

I have heard HIPAA used as an excuse for so many things - doctors cannot talk to a family, nurses cannot listen to information from families, companies cannot respond to patients directly, etc. ad nauseum. 

So in this post, let me share a few things about HIPAA with you. (HIPAA is the Health Insurance Portability and Accountability Act of 1996, including all its subsequent amendments under the Affordable Care Act and implementing regulations that were effective in 2013 with the HIPAA Omnibus Rule). HIPAA has never been intended to interfere with medical care and in fact, to share patient information for treatment between health care providers, a patient authorization is not required. 

But to help address the situations above, 1) when a person verbally states that they want someone with them, that is patient authorization. And patient authorization is all that is required in HIPAA in order for a health care provider to share information - it does not need to be in writing, especially when the patient, the person, and the provider are standing there together. So when my daughter said she wanted me with her - that was sufficient. And yes, the hospital privacy officer agreed with me and sent us written apologies stating he would ensure that all staff were appropriate educated on that factor. It did not matter that we were related or that she was an adult and I her mother - what mattered was she gave permission. 

This leads into the situation with my other daughter. As a minor, she is not legally capable of providing legal consent, therefore, the parent was the appropriate person to grant consent. Perhaps at 15, her assent is desired or even required under certain state laws for medical treatment, but if an authorization to share medical information was required in writing, the parent or guardian would have to sign for it to be legal (foregoing any discussion here of emancipation and exceptions). Thus, as her parent, it was my right to give myself access to her information and accompany her to testing. 

Let's take that one step further. Perhaps the medical technician in either situation intended to protect the privacy of other patients. So? HIPAA provides for incidental disclosures, which covers situations in which patients are in close proximity and it is near impossible to maintain strict confidentiality. One should take reasonable precautions, but there is nothing illegal about an emergency room that has curtains instead of walls or stage all patients waiting on surgery in the same waiting area. That's not a valid enough reason to override a scared person's need to have their support person with them.

Last, my mother. Believe it or not, providers can share patient information with people the provider feels/knows is involved in the patient's care and wellbeing. Thus, knowing I was the daughter, the choice could have been made legally to provide me with information about my mother. True, this scenario can get complicated and ugly quickly - how could they verify who I am, or whether my mother and I were close, or any number of other variables. And so, it is logical that an entity would not permit employees to make this decision - but there are other ways to handle it. One could check with the patient, ask the doctor, or have an escalation process to find a potential solution rather than shutting out what may have been the only person in the patient's life (not the case here, but the nurse might not have known that). 

I hope this helps you with some basic misunderstandings about HIPAA. Please do not assume that your providers, health care employees, or even all privacy officers understand this - and by no means do I claim to know everything about HIPAA. Few take the time to fully understand all of HIPAA and sometimes a simple straightforward policy by the entity is much easier to train and enforce than are policies that enable HIPAA to be followed in full. And sometimes state law is more strict (I do not know of any, but they could exist). 

One final point, pl ease note that HIPAA is spelled with two As and NOT two Ps, e.g. HIPPA. If you are a consultant or vendor trying to get my business, you at least need to spell it right.

Wednesday, January 29, 2014

Why are we not Outraged?

Edward Snowden (of the now infamous and controversial U.S. National Security Agency rampant surveillance) has spoken out in his first television interview . He speaks frankly about the threats to his life due to his revelations, but more importantly why he did what he did. A friend of mine posted the link on facebook and I asked this same question there - why are we not more outraged? Why do TV or music celebrities get more comments from both fans and haters than does someone who opened the U.S. pandora's privacy box? It is scandalous!

It is scandalous what the NSA has done. 

It is scandalous that we as a nation do not seem to care. 

In fact, it appears and I allege that the only reason we are starting to hear from our political leaders about fixing the problem is because nations which actually provide privacy rights to their citizens are outraged. They are outraged. We are not.

The White House has spoken now. President Obama finally laid out a plan: consider reforming the PATRIOT Act; improve the public's confidence in governmental oversight; have the Intelligence Community make public information about their surveillance programs - including hiring a privacy officer (more on this later as one has now been appointed); and last, having a high-level group of experts review intelligence and communication technologies. Yours truly was not invited. durn.

What will it take for the people of this nation to actually pay attention to their own privacy and to the entities violating that privacy?? I am honestly perplexed, outraged on your behalf, and frankly, wishing there was a privacy cattle prod that someone with integrity could wield as rampantly as the government wields surveillance. 

Tuesday, January 28, 2014

Global Data Privacy Day and a 21 year old

I would be remiss if I did not post something about today being Global Data Privacy Day - so woot woot - everyone may now celebrate their privacy!!

right.

Perhaps Snowden is celebrating, but the rest of us in the U.S. at least are dealing with data breaches and privacy violations with little to no government intervention and lots of outrage towards the government from large megadata corporations. I try to be positive and not abscribe deflection motivations towards these large technology companies, but it does require some effort. Yet, I remain optimistic that those companies who collect, share, analyze, combine, and use our data in every way imaginable and some ways never imagined by the common person actually are becoming privacy conscious. If not, fake it till you make it.

But more importantly in my own family - today is my youngest child's 21st birthday. WOW. Happy birthday to her and I am sure everyone reading this (anyone reading this) wishes her the best. 

So what does a 21 year old think about privacy? She grew up in the information age, where every thought, emotion, intention, and action is immediately shared, judged, and forgotten. Except nothing on the internet is ever forgotten. (California just passed a law that minors can request their information on social media to be erased. No one really knows what this means yet, but it's a start.).

It has been proposed that millenials, GenY'ers, have no comprehension of privacy and have missed learning basic etiquette of society - there is no period of reflection when something happens - it is immediate reaction, instantly shared, no sense of privacy. I disagree to some extent. I think the new group of young professionals completely understand what being on the job/on call for the job 24/7 due to smartphones means. I think they treasure quality of life more knowing they have to fit in life around work and school. That leaving work at 6 pm does not mean being off work - and they compensate by enjoying life more.

So I asked my newest adult daughter what privacy means to her. Her first response was "What? What about?" - but perhaps I was a bit blunt and unexpected in my question. So I explained more and am anxiously awaiting her answer as I type this. 8 minutes later, I am still waiting. Perhaps it is not only the newest generation who expect immediate gratification...

We are seeing changes every day in privacy - some for the good, some not so much. Young and old, U.S. or not, corporate or individual - we are all impacted and some will care more than others. Some will do more than others. It's a brand new world every time the sun rises. Take the opportunity to make a change in the way you share/use data whether your own or someone else's - take the opportunity to think about what privacy means to you.

Happy Global Data Privacy Day and Happy Birthday, my child. 


Thursday, September 27, 2012

HIPAA to the BA

Today's issue is HIPAA and Business Associate Agreements.

Under the HITECH Act, HIPAA will apply to Business Associates like it currently applies to Covered Entities. There is a proposed rule to implement this, which was expected to be finalized this past summer. It was not.  If Obama wins, there is no telling when the final rule will be issued.  If he loses, it is a safe bet that his regime will push to have the final rule issued before the end of the year in order to forestall its complete death.

The key to these proposed rules is that Covered Entities are trying to build in the elements of the proposed rules to their current Business Associate Agreements.  At present, certain elements are not expected out of Business Associates, but certainly Covered Entities would love to have these elements present now - like downstream enforcement to subcontractors of the Business Associates, audit trails, and the physical, administrative, and technical safeguards of the security rule.

There is a hope and a prayer that reasoning will overcome our Congress and some pieces of the HITECH Act will get repealed. But it's only a hope. and LOTS of prayer.

Friday, August 17, 2012

Writing Papers to Publish

This week, I have been working on finishing papers to submit for publication.  It is a rite of passage and a way of life for those in academia.  A year ago, I would have stated that being an academia was my one goal. Now, I have a job I love, pays well, in a great area albeit an expensive one, and I am not sure I want to give this up to be in academia.  But I still want to publish to have that option open to me.  Unfortunately, part of my rationale is to prove a professor wrong. He spent an awful amount of time reiterating to us students that working in academia at a research institution was stressful and difficult.  That if he had to start over now, he would not do so. It's a tremendous amount of work.

Considering that the people he was talking to worked full-time jobs, high-stress ones, and attended a PhD program part-time...I'm thinking that not even a tenure-track professorship at a research university could be more demanding than an average of 60-70 hours on the job, plus school, kids, home, animals, chronic disabilities, volunteer work, mentoring, and well - whatever else I had going on at the same time. So I'd like to show him that he should not judge how un-busy we are not. Good googli moo.

But back to the topic.  The two papers are vastly different and wonderfully interesting.  One is on electronic communications in the workplace that the professor volunteered to help me prep for submission for publication as long as he could be co-listed.  Sure - he had good feedback and hopefully, connections.

The other is related to my desired dissertation topic, jury decision-making and reform. I asked a friend of mine from law school to join with me on this paper - cause I like the way she thinks and writes.  She has two published papers already, so apparently, she knows the formula.  I want to know the formula. So together, we are writing a paper on how civic education can improve jury decision making as part of the jury reform movement.  It's turning out to be a heck of a paper.