FTC lacks data breach authority, says accused medical lab
An Atlanta medical lab fires back at an FTC complaint that it lacked a reasonable cybersecurity program
IDG News Service - The U.S. Federal Trade Commission has no jurisdiction or legal authority to bring a data breach complaint against an Atlanta medical laboratory, the lab said in a response to FTC charges.
The FTC, in an administrative complaint in August against a small cancer-screening lab LabMD, acted in a way that was "arbitrary, capricious" and an abuse of discretion, lawyers for the lab wrote in a response to the FTC complaint Thursday. The agency has acted "contrary to constitutional right" and "in excess of statutory jurisdiction," LabMD's lawyers said.
LabMD, just the second U.S. company to challenge an FTC data breach complaint, is fighting back for the future of the company, the company's CEO, Mike Daugherty, has said. Daugherty, in a discussion a week ago, accused the agency of making up cybersecurity rules as it moves forward.
The FTC "has not published any rules, regulations or other guidelines clarifying and providing any notice, let alone constitutionally adequate notice, of what data-security practices" the agency believes it has authority to enforce, LabMD's lawyers wrote in the response.
LabMD has challenged the FTC's assertion that it has the authority to lodge complaints against companies that have data breaches after not taking, in the agency's eyes, appropriate cybersecurity measures. The challenges to FTC complaints by LabMD and Wyndham Worldwide could potentially end the agency's efforts to seek settlements in data breach cases, after 11 years of complaints and nearly 50 settlements.
Many of the settlements required the companies to implement new cybersecurity programs and submit to independent security audits every other year over 20 years. Among the companies that have settled FTC cybersecurity complaints are Twitter, Microsoft, data broker ChoicePoint, and retailers BJ's Wholesale Club and TJX.
A hearing on the FTC complaint against LabMD is scheduled before an administrative law judge next April. An FTC spokesman didn't immediately respond to a request for comments on LabMD's filing.
The challenge is an important one, LabMD's lawyers argued. Cause of Action, a government watchdog defending the company, "is taking up this fight because the FTC's attempt to exert authority that it does not have on a business that engaged in no wrongdoing is an abuse of agency authority that threatens American jobs," Cause of Action Executive Director Dan Epstein said in a statement.
The FTC accuses LabMD of having two significant data breaches, one in 2007-08 and one in 2012. In 2008, peer-to-peer security vendor Tiversa contacted the company, saying it had found a LabMD customer spreadsheet on a P-to-P network. The file contained personal information for more than 9,000 consumers, including names, Social Security numbers and medical treatment codes.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- OpenStack Hype vs. Reality: CIO Quick Pulse Open-source architecture can enable IT departments to build infrastructure-as-a-service (IaaS) clouds running on standard hardware.
- Building a Bridge to the Next Generation Data Center Selecting a widely adopted operating system is a foundational component of a standardization strategy.
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have.
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Cybercrime and Hacking White Papers | Webcasts