Congressman questions FTC breach probe amid claims of 'corporate blackmail'
House Oversight Committee questions reliability of Tiversa data used by FTC in filing complaint against LabMD
Computerworld - A U.S. House committee has called on the Federal Trade Commission's Inspector General to probe the agency's relationship with a peer-to-peer network-monitoring firm whose data is key evidence in an FTC complaint filed against LabMD.
The agency's case is dependent on claims by Tiversa that in 2008 it found a 1,718 page billing spreadsheet belonging to LabMD floating about on a public file-sharing network. Tiversa said the data included Social Security Numbers, treatment codes and insurance data on about 10,000 people.
At the time, Tiversa said the document was one of several sensitive files belonging to multiple firms it found when conducting research on the inadvertent leakage of personal health data on P2P networks.
The House Committee on Oversight and Government Reform disputes Tiversa's claims.
In a letter sent Wednesday, Committee Chairman Darrell Issa (R-Calif.) requested that FTC acting Inspector General Kelly Tshibaka investigate those claims and allegations of "corporate blackmail" against Tiversa.
In the letter, Issa said the oversight committee is investigating Tiversa and its relationships with the FTC and other federal agencies. "The Committee has received information from current and former Tiversa employees indicating a lack of truthfulness in testimony Tiversa provided to federal government entities," Issa said in the letter.
The FTC filed its complaint in August 2013, alleging that LabMD practiced deceptive and unfair trade practices for allowing a document containing sensitive health information to sit on a peer-to-peer network. The complaint was filed after a lengthy two-year discovery process.
FTC Chief administrative law judge Michael Chappell has delayed the trial due to the oversight committee's questions about the case.
Issa contends that Tiversa attempted to sell its security monitoring services to LabMD immediately after its purported discovery of the file. When LabMD refused the services, Tiversa then provided the information to the FTC, Issa said in his letter.
Though there are competing claims about who is responsible for disseminating false information, "it is now clear, however that Tiversa provided incomplete and inaccurate information to the FTC," Issa said
Issa also said the oversight committee has also learned of allegations that Tiversa, in conjunction with the FTC, created an entity called the Privacy Institute to provide information about data breaches to the agency. "If these allegations are true, such coordination between Tiversa and the FTC would call into account the LabMD enforcement action, and other FTC regulatory matters that relied on Tiversa supplied information," the letter said.
The FTC declined to comment on Issa's letter.
In an email to Computerworld, Tiversa CEO Robert Boback, denied that his company has a special relationship with the FTC.
"This is absolutely and unequivocally NOT true," Boback said. "Tiversa has never been paid by the FTC nor was a contract ever discussed in any way!"
- Gartner MarketScope for Group Video Systems The Gartner "MarketScope for Group Video Systems" evaluates 7 group video system vendors based on 6 customer-focused criteria such as customer experience, market...
- The Role of the User Experience in Video Conferencing While video conferencing can offer significant benefits to companies and their employees, all video conferencing solutions are not alike. To ensure successful deployment...
- Video is the New Document: Four Things You Can't Miss Download this research summary to find out the 4 reasons why video is quickly replacing print media and see how this can fit...
- How Four Citrix Customers Solved the Enterprise Mobility Challenge Managing mobile devices, data and all types of apps-Windows, datacenter, web and native mobile- through a single solution.
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily...
- On Demand: Mastering the Art of Mobile Content Management Mobile device usage in the enterprise has skyrocketed, and it continues to escalate. IT must answer to users who demand access to their... All Gov't Legislation/Regulation White Papers | Webcasts