Tuesday, March 15, 2011

Medical Identity Theft: The Growing Cost of Indifference

Second annual study reveals medical identity theft is on the rise, yet consumers remain unmoved by the risks

IRVINE, Calif., March 15, 2011 /PRNewswire/ -- While consumers grasp the importance of protecting their medical and personal information, few individuals take the necessary precautions to avoid medical identity theft. This finding comes from the second annual National Study on Medical Identity Theft by The Ponemon Institute(1) and sponsored by Experian's ProtectMyID™, a leading, full-service provider of identity theft detection, protection and fraud resolution.  

It is estimated that nearly 1.5 million Americans are victims of medical identity theft, up slightly from last year, according to this comprehensive study.(2) Alarmingly, the average cost to resolve a case of medical identity theft stands at $20,663, up from $20,160 in 2010. Other key findings from the survey include:  

Recognizing the importance of privacy does not equate to action
      Despite consumer desires for medical data privacy and statistical findings of data vulnerability, people are not taking action to protect their valuable health information. Nearly 70 percent of study respondents felt it was important to have personal control over their medical records, and 80 percent felt that healthcare organizations should ensure the privacy of these records.

However, these beliefs do not translate to action, as 49 percent of victims took no new steps to protect themselves after a crime.                              
Consumer indifference is fueled by lack of understanding of repercussions             
Fifty percent of former victims chose not to report the incident to law enforcement at all, up from 46 percent in the 2010 study. The number one reason for this failure to report was the lack of resulting harm and the desire to not make it a big deal (43 percent). In fact, more victims fear embarrassment (37 percent) than the loss of medical coverage (21 percent) or a diminished credit score (18 percent) as a potential result of medical identity theft.              
                       

"Our study shows that the risk and high cost of medical identity theft are not resonating with the public, revealing a serious need for greater education and awareness," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. "We also feel these results put an even greater onus on healthcare organizations to make the security of sensitive personal health information a priority in order to protect patient privacy."

 Medical data breach notification fails to protect the consumer        
The risk of medical identity theft lies beyond consumer control, as health care organization data breach accounts for a significant portion of reported incidents. When a breach occurs, the organization normally is required to inform the affected people, depending on state law notification requirements. However, only 5 percent of victims learned of their theft from a data breach notification, which is especially troubling when considering that data breach accounted for 14 percent of all theft instances. This includes breaches involving health care providers, insurers or other related organizations.          
                       

"The results of this study shed a troubling light on not only the pervasiveness and consumer perceptions of medical identity theft, but also the dangers of data breach," said Jennifer Leuer, general manager of Experian's ProtectMyID. "These factors can be unnerving, but luckily there are products like ProtectMyID that give people peace of mind, knowing that they are not alone in the fight to keep their identities safe."

 Consumers are uninformed of new health care reform policies           
The majority of survey respondents (55 percent) are not familiar or have no knowledge of the new policies, and 79 percent are not aware of the creation of a national electronic database of Americans' health information. Furthermore, 33 percent believe that a national electronic database will increase the risk of medical identity theft. The lack of general awareness makes consumer education about medical identity protection all the more critical in the face of shifting policy.              
                      
Medical identity theft is a family affair             
The study also revealed the startling rate at which medical identity theft occurs between family members. In fact, theft of this nature accounted for 36 percent of all victim responses, making it the most common type of theft. The frequency of family-related medical identity theft contributed to the most commonly stated reason (51 percent) why victims elected not to report a given incident: the victim discovered that he or she knew the thief and did not want to report him or her.          
                       

Based on the results of the second annual National Study on Medical Identity Theft, it is clear that the threat of medical identity theft poses a multitude of risks to consumers. In order to combat these risks, ProtectMyID offers assistance that can help victims of medical identity theft. The following features are currently available:

Medical Identity Theft Resource Center — Provides members with valuable information about how to protect themselves, obtain medical reports, understand Explanation of Benefits notifications and much more.

Dedicated Identity Theft Resolution Agents — These agents are trained to notify and work with health care providers on behalf of customers to resolve any theft-related issue. This removes the mystery and uncertainty from dealing with providers.

Lost Wallet Identity Protection — The ProtectMyID Lost Wallet and Card Protection protects members' credit, charge, debit, ATM and medical cards in the event that they are lost, stolen or misused.

Alerts — These inform members quickly when medically related collection actions occur. Forty-six percent of respondents learned of the medical identity theft from a collection letter. This number is up from 40 percent in 2010.

About the study
Fieldwork for this research was concluded in January 2011. More than 1,672 consumers in the United States participated in this study, completing a Web-based survey. Of these, 718 have been victims of identity theft. Fifty-one percent of respondents have private insurance, and 21 percent have Medicare or Medicaid. Fifty percent have a college or advanced educational degree.

About The Ponemon Institute®
The Ponemon Institute is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors, and verifies the privacy and data protection practices of organizations in a variety of industries.

About Experian's ProtectMyID
ProtectMyID™ is a leading, full-service provider of identity theft detection, protection and fraud resolution. ProtectMyID offers comprehensive identity theft protection products supported by experienced identity theft resolution professionals who deliver personal attention that customers can rely on. ProtectMyID.com is a Website owned by ConsumerInfo.com, Inc., an Experian company.

For more information about how ProtectMyID helps consumers protect themselves against identity theft, please visit http://www.protectmyid.com/.

About Experian
Experian® is the leading global information services company, providing data and analytical tools to clients in more than 90 countries. The company helps businesses to manage credit risk, prevent fraud, target marketing offers and automate decision making. Experian also helps individuals to check their credit report and credit score and protect against identity theft.
Experian plc is listed on the London Stock Exchange (EXPN) and is a constituent of the FTSE 100 index. Total revenue for the year ended March 31, 2010, was $3.9 billion. Experian employs approximately 15,000 people in 40 countries and has its corporate headquarters in Dublin, Ireland, with operational headquarters in Nottingham, UK; Costa Mesa, California; and Sao Paulo, Brazil.
For more information, visit http://www.experianplc.com/.
Experian and the Experian marks used herein are service marks or registered trademarks of Experian Information Solutions, Inc. Other product and company names mentioned herein are the property of their respective owners.
(1) Study was conducted in January 2011 by The Ponemon Institute.
(2) Data extrapolated from survey respondents and current U.S. population multipliers.
Contact:              
Matt Lifson           
Edelman PR            
1 323 202 1047        
matthew.lifson@edelman.com            
              
Becky Frost           
Experian Consumer Direct              
1 9495676594          
bfrost@experianconsumerdirect.com              


Friday, March 11, 2011

Data Mining: How Companies Now Know Everything About You

By Joel Stein TIME, March 10, 2011

Three hours after I gave my name and e-mail address to Michael Fertik, the CEO of Reputation.com, he called me back and read my Social Security number to me. "We had it a couple of hours ago," he said. "I was just too busy to call."

In the past few months, I have been told many more-interesting facts about myself than my Social Security number. I've gathered a bit of the vast amount of data that's being collected both online and off by companies in stealth — taken from the websites I look at, the stuff I buy, my Facebook photos, my warranty cards, my customer-reward cards, the songs I listen to online, surveys I was guilted into filling out and magazines I subscribe to. (See pictures of a Facebook server farm.)

Google's Ads Preferences believes I'm a guy interested in politics, Asian food, perfume, celebrity gossip, animated movies and crime but who doesn't care about "books & literature" or "people & society." (So not true.) Yahoo! has me down as a 36-to-45-year-old male who uses a Mac computer and likes hockey, rap, rock, parenting, recipes, clothes and beauty products; it also thinks I live in New York, even though I moved to Los Angeles more than six years ago.

Alliance Data, an enormous data-marketing firm in Texas, knows that I'm a 39-year-old college-educated Jewish male who takes in at least $125,000 a year, makes most of his purchases online and spends an average of only $25 per item. Specifically, it knows that on Jan. 24, 2004, I spent $46 on "low-ticket gifts and merchandise" and that on Oct. 10, 2010, I spent $180 on intimate apparel. It knows about more than 100 purchases in between. Alliance also knows I owe $854,000 on a house built in 1939 that — get this — it thinks has stucco walls. They're mostly wood siding with a little stucco on the bottom! Idiots.

EXelate, a Manhattan company that acts as an exchange for the buying and selling of people's data, thinks I have a high net worth and dig green living and travel within the U.S. BlueKai, one of eXelate's competitors in Bellevue, Wash., believes I'm a "collegiate-minded" senior executive with a high net worth who rents sports cars (note to Time Inc. accounting: it's wrong unless the Toyota Yaris is a sports car). At one point BlueKai also believed, probably based on my $180 splurge for my wife Cassandra on HerRoom.com, that I was an 18-to-19-year-old woman.

RapLeaf, a data-mining company that was recently banned by Facebook because it mined people's user IDs, has me down as a 35-to-44-year-old married male with a graduate degree living in L.A. But RapLeaf thinks I have no kids, work as a medical professional and drive a truck. RapLeaf clearly does not read my column in TIME. (See 25 websites you can't live without.)

Intellidyn, a company that buys and sells data, searched its file on me, which says I'm a writer at Time Inc. and a "highly assimilated" Jew. It knows that Cassandra and I like gardening, fashion, home decorating and exercise, though in my case the word like means "am forced to be involved in." We are pretty unlikely to buy car insurance by mail but extremely likely to go on a European river cruise, despite the fact that we are totally not going to go on a European river cruise. There are tons of other companies I could have called to learn more about myself, but in a result no one could have predicted, I got bored. (Comment on this story.)

Each of these pieces of information (and misinformation) about me is sold for about two-fifths of a cent to advertisers, which then deliver me an Internet ad, send me a catalog or mail me a credit-card offer. This data is collected in lots of ways, such as tracking devices (like cookies) on websites that allow a company to identify you as you travel around the Web and apps you download on your cell that look at your contact list and location. You know how everything has seemed free for the past few years? It wasn't. It's just that no one told you that instead of using money, you were paying with your personal information.

See how college-admissions departments stalk Facebook.
See how one teacher's viral blog post sparked an angry debate.

The Creep Factor
There is now an enormous multibillion-dollar industry based on the collection and sale of this personal and behavioral data, an industry that Senator John Kerry, chair of the Subcommittee on Communications, Technology and the Internet, is hoping to rein in. Kerry is about to introduce a bill that would require companies to make sure all the stuff they know about you is secured from hackers and to let you inspect everything they have on you, correct any mistakes and opt out of being tracked. He is doing this because, he argues, "There's no code of conduct. There's no standard. There's nothing that safeguards privacy and establishes rules of the road."


At Senate hearings on privacy beginning March 16, the Federal Trade Commission (FTC) will be weighing in on how to protect consumers. It has already issued a report that calls upon the major browsers to come up with a do-not-track mechanism that allows people to choose not to have their information collected by companies they aren't directly doing business with. Under any such plan, it would likely still be O.K. for Amazon to remember your past orders and make purchase suggestions or for American Express to figure your card was stolen because a recent purchase doesn't fit your precise buying patterns. But it wouldn't be cool if they gave another company that information without your permission. (See "Will FTC's 'Do Not Track' Go Even Further than Expected?")

Taking your information without asking and then profiting from it isn't new: it's the idea behind the phone book, junk mail and telemarketing. Worrying about it is just as old: in 1890, Louis Brandeis argued that printing a photograph without the subject's permission inflicts "mental pain and distress, far greater than could be inflicted by mere bodily harm." Once again, new technology is making us weigh what we're sacrificing in privacy against what we're gaining in instant access to information. Some facts about you were always public — the price of your home, some divorce papers, your criminal records, your political donations — but they were held in different buildings, accessible only by those who filled out annoying forms; now they can be clicked on. Other information was not possible to compile pre-Internet because it would have required sending a person to follow each of us around the mall, listen to our conversations and watch what we read in the newspaper. Now all of those activities happen online — and can be tracked instantaneously.

Part of the problem people have with data mining is that it seems so creepy. Right after I e-mailed a friend in Texas that I might be coming to town, a suggestion for a restaurant in Houston popped up as a one-line all-text ad above my Gmail inbox. But it's not a barbecue-pit master stalking me, which would indeed be creepy; it's an algorithm designed to give me more useful, specific ads. And while that doesn't sound like all that good a deal in exchange for my private data, if it means that I get to learn when the next Paul Thomas Anderson movie is coming out, when Wilco is playing near my house and when Tom Colicchio is opening a restaurant close by, maybe that's not such a bad return.

Since targeted ads are so much more effective than nontargeted ones, websites can charge much more for them. This is why — compared with the old banners and pop-ups — online ads have become smaller and less invasive, and why websites have been able to provide better content and still be free. Besides, the fact that I'm going to Houston is bundled with the information that 999 other people are Houston-bound and is auctioned by a computer; no actual person looks at my name or my Houston-boundness. Advertisers are interested only in tiny chunks of information about my behavior, not my whole profile, which is one of the reasons M. Ryan Calo, a Stanford Law School professor who is director of the school's Consumer Privacy Project, argues that data mining does no actual damage. (See "How Facebook Is Redefining Privacy.")

"We have this feeling of being dogged that's uncomfortable," Calo says, "but the risk of privacy harm isn't necessarily harmful. Let's get serious and talk about what harm really is." The real problem with data mining, Calo and others believe, arises when the data is wrong. "It's one thing to see bad ads because of bad information about you. It's another thing if you're not getting a credit card or a job because of bad information," says Justin Brookman, the former chief of the Internet bureau of the New York attorney general's office, who is now the director of the Center for Democracy and Technology, a nonprofit group in Washington. (Comment on this story.)
Russell Glass, the CEO of Bizo — which mines the fact that people are business executives and sells that info to hundreds of advertisers such as American Express, Monster.com, Citibank, Sprint and Google — says the newness of his industry is what scares people. "It's the monster-under-the-bed syndrome," Glass says. "People are afraid of what they really don't understand. They don't understand that companies like us have no idea who they are. And we really don't give a s — -. I just want a little information that will help me sell you an ad." Not many people, he notes, seem to be creeped out by all the junk mail they still get from direct-marketing campaigns, which buy the same information from data-mining companies. "I have a 2-year-old daughter who is getting mail at my home address," he says. "That freaks me out."

See pictures of Facebook's headquarters.
See "Google's War Against Rotten Search Results."

Why That Ad Is Following You
Junk mail is a familiar evil that's barely changed over the decades. Data mining and the advertising it supports get more refined every month. The latest trick to freak people out is retargeting — when you look at an item in an online store and then an ad for that item follows you around to other sites.


Last year, Zappos was the most prominent company in the U.S. to go all out in behavioral retargeting. And people got pissed off. One of the company's mistakes was running ads too frequently and coming off as an annoying, persistent salesman. "We took that brick-and-mortar pet peeve and implied it online," says Darrin Shamo, Zappos' director of direct marketing. Shamo learned, the hard way, that people get upset when their computer shows lingerie ads, even if they had been recently shopping for G-strings, since people share computers and use them in front of their kids. He also learned that ads that reveal potential Christmas gifts are bad for business. (See a brief history of online shopping.)

Since then, Zappos has been experimenting with new ads that people will see no more than five times and for no longer than eight days. Zappos has also dumbed the ads down, showing items that aren't the ones you considered buying but are sort of close, which people greatly prefer. And much like Amazon's "Customers who bought 1984 also bought Brave New World"–style recommendation engine, the new ads tell people what Zappos knows about them and how they got that information ("a company called Criteo helps Zappos to create these kinds of personalized ads"). It also tells them how they can opt out of seeing them ("Some people prefer rainbows. And others prefer unicorns. If you prefer not to see personalized ads, we totally get it").

If that calms the angry 15% of the people who saw these ads, Zappos will stick with them. Otherwise, it plans on quitting the retargeting business. Shamo thinks he'll just need to wait until the newness wears off and people are used to ads tailored for them. "Sometimes things don't move as fast as you think," he says. (Read about Shoefitr, a service that helps shoppers buy shoes online.)

They're not even moving that much faster with the generation that grew up with the Internet. While young people expect more of their data to be mined and used, that doesn't mean they don't care about privacy. "In my research, I found that teenagers live with this underlying anxiety of not knowing the rules of who can look at their information on the Internet. They think schools look at it, they think the government looks at it, they think colleges can look at it, they think employers can look at it, they think Facebook can see everything," says Sherry Turkle, a professor at MIT who is the director of the Initiative on Technology and Self and the author of Alone Together: Why We Expect More from Technology and Less From Each Other. "It's the opposite of the mental state I grew up in. My grandmother took me down to the mailbox in Brooklyn every morning, and she would say, 'It's a federal offense for anyone to look at your mail. That's what makes this country great.' In the old country they'd open your mail, and that's how they knew about you." (Comment on this story.)

Data mining, Turkle argues, is a panopticon: the circular prison invented by 18th century philosopher Jeremy Bentham where you can't tell if you're being observed, so you assume that you always are. "The practical concern is loss of control and loss of identity," says Marc Rotenberg, executive director of the Electronic Privacy Information Center. "It's a little abstract, but that's part of what's taking place."

See "Automated Theft Machines."
See "Is Your Facebook Account a Gold Mine for Identity Thieves?"

The Facebook and Google Troves
Our identities, however, were never completely within our control: our friends keep letters we've forgotten writing, our enemies tell stories about us we remember differently, our yearbook photos are in way too many people's houses. Opting out of all those interactions is opting out of society. Which is why Facebook is such a confusing privacy hub point. Many data-mining companies made this argument to me: How can I complain about having my Houston trip data-mined when I'm posting photos of myself with a giant mullet and a gold chain on Facebook and writing columns about how I want a second kid and my wife doesn't? Because, unlike when my data is secretly mined, I get to control what I share. Even narcissists want privacy. "It's the difference between sharing and tracking," says Bret Taylor, Facebook's chief technology officer.


To get into the Facebook office in Palo Alto, Calif., I have to sign a piece of physical paper: a Single-Party Non-Disclosure Agreement, which legally prevents me from writing the last paragraph. But your privacy on Facebook — that's up to you. You choose what to share and what circle of friends gets to see it, and you can untag yourself from any photos of you that other people put up. However, from a miner's point of view, Facebook has the most valuable trove of data ever assembled: not only have you told it everything you like, but it also knows what your friends like, which is an amazing predictor of what you'll like. (See "Your Thoughts About Facebook.")

Facebook doesn't sell any of your data, partly because it doesn't have to — 23.1% of all online ads not on search engines, video or e-mail run on Facebook. But data-mining companies are "scraping" all your personal data that's not set to private and selling it to any outside party that's interested. So that information is being bought and sold unless you squeeze your Facebook privacy settings tight, which keeps you from a lot of the social interaction that drew you to the site in the first place.

The only company that might have an even better dossier on you than Facebook is Google. In a conference room on the Google campus, I sit through a long privacy-policy PowerPoint presentation. Summary: Google cares! Specifically, Google keeps the data it has about you from various parts of its company separate. One category is the personally identifiable account data it can attach to your name, age, gender, e-mail address and ZIP code when you signed up for services like Gmail, YouTube, Blogger, Picasa, iGoogle, Google Voice or Calendar. The other is log data associated with your computer, which it "anonymizes" after nine months: your search history, Chrome browser data, Google Maps requests and all the info its myriad data trackers and ad agencies (DoubleClick, AdSense, AdMob) collect when you're on other sites and Android phone apps. You can change your settings on the former at Google Dashboard and the latter at Google Ads Preferences — where you can opt out of having your data mined or change the company's guesses about what you're into.

Nicole Wong, deputy general counsel at Google, says the company created these tools to try to reassure people who have no idea how all this information is being collected and used. "When I go to TIME.com as a user, I think only TIME.com is collecting my data. What I don't realize is that for every ad on that page, a company is also dropping a code and collecting my data. It's a black box — and we've tried to open up the box. Sometimes you're not even sure who the advertisers are. It's just a bunch of jumping monkeys or something." Google really does want to protect your privacy, but it's got issues. First, it's profit-driven and it's huge. But those aren't the main reasons privacy advocates get so upset about Google. They get upset because the company's guiding philosophy conflicts with the notion of privacy. As the PowerPoint says right up top: "Google's mission: to organize the world's information and make it universally accessible and useful." Which is awesome, except for the fact that my information is part of the world's information. (See "Quilting for Data: How Google Gets Information from Inside People's Heads.")

Tracking the Trackers
To see just what information is being gathered about me, I downloaded Ghostery, a browser extension that lets you watch the watchers watching you. Each time you go to a new website, up pops a little bubble that lists all the data trackers checking you out. This is what I discovered: the very few companies that actually charge you for services tend not to data mine much. When you visit TIME.com, several dozen tracking companies, with names such as Eyeblaster, Bluestreak, DoubleClick and Factor TG, could be collecting data at any given time.


If you're reading this in print as a subscriber, TIME has probably "rented" your name and address many times to various companies for a one-time use. This is also true if you subscribe to Vanity Fair, Cosmopolitan or just about any other publication. (Comment on this story.)

This being America, I don't have to wait for the government to give me an opt-out option; I can pay for one right now. Michael Fertik, the CEO and founder of Reputation.com, who nabbed my Social Security number, will do it for me for just $8.25 a month. His company will also, for a lot more money, make Google searches of your name come up with more flattering results — because when everyone is famous, everyone needs a public relations department. Fertik, who clerked for the chief judge of the Sixth Circuit after graduating from Harvard Law School, believes that if data mining isn't regulated, everyone will soon be assigned scores for attractiveness and a social-prowess index and a complainer index, so companies can avoid serving you — just as you now have a credit score that they can easily check before deciding to do business with you. "What happens when those data sets are used for life transactions: health insurance, employment, dating and education? It's inevitable that all of these decisions will be made based on machine conclusions. Your FICO score is already an all-but-decisional fact about you. ABD, dude! All but decisional," says Fertik.

See how Apple and Google became the two most admired companies in the world.
See how social media is helping old media.

Even if I were to use the services of Reputation.com, there's still all the public information about me that I can't suppress. Last year, thousands of people sent their friends a Facebook message telling them to opt out of being listed on Spokeo.com, which they described as the creepiest paparazzo of all, giving out your age, profession, address and a photo of your house. Spokeo, a tiny company in Pasadena, Calif., is run by 28-year-old Stanford grad Harrison Tang. He was surprised at the outcry. "Some people don't know what Google Street View is, so they think this is magic," Tang says of the photos of people's homes that his site shows. The info on Spokeo isn't even all that revealing — he purposely leaves off criminal records and previous marriages — but Tang thinks society is still learning about data mining and will soon become inured to it. "Back in the 1990s, if you said, 'I'm going to put pictures on the Internet for everyone to see,' it would have been hard to believe. Now everyone does it. The Internet is becoming more and more open. This world will become more connected, and the distance between you and me will be a lot closer. If everybody is a walled garden, there won't be an Internet."

I deeply believe that, but it's still too easy to find our gardens. Your political donations, home value and address have always been public, but you used to have to actually go to all these different places — courthouses, libraries, property-tax assessors' offices — and request documents. "You were private by default and public by effort. Nowadays, you're public by default and private by effort," says Lee Tien, a senior staff attorney for the Electronic Frontier Foundation, an advocacy group for digital rights. "There are all sorts of inferences that can be made about you from the websites you visit, what you buy, who you talk to. What if your employer had access to information about you that shows you have a particular kind of health condition or a woman is pregnant or thinking about it?" Tien worries that political dissidents in other countries, battered women and other groups that need anonymity are vulnerable to data mining. At the very least, he argues, we're responsible to protect special groups, just as Google Street View allows users to request that a particular location, like an abused-women's shelter, not be photographed. (See the top 10 Twitter moments of 2010.)

Other democratic countries have taken much stronger stands than the U.S. has on regulating data mining. Google Street View has been banned by the Czech Republic. Germany — after protests and much debate — decided at the end of last year to allow it but to let people request that their houses not be shown, which nearly 250,000 people had done as of last November. E.U. Justice Commissioner Viviane Reding is about to present a proposal to allow people to correct and erase information about themselves on the Web. "Everyone should have the right to be forgotten," she says. "Due to their painful history in the 20th century, Europeans are naturally more sensitive to the collection and use of their data by public authorities."

After 9/11, not many Americans protested when concerns about security seemed to trump privacy. Now that privacy issues are being pushed in Congress, companies are making last-ditch efforts to become more transparent. New tools released in February for Firefox and Google Chrome browsers let users block data collecting, though Firefox and Chrome depend on the data miners to respect the users' request, which won't stop unscrupulous companies. In addition to the new browser options, an increasing number of ads have a little i (an Advertising Option Icon), which you can click on to find out exactly which companies are tracking you and what they do. The technology behind the icon is managed by Evidon, the company that provides the Ghostery download. Evidon has gotten more than 500 data-collecting companies to provide their info.

It takes a lot of work to find out about this tiny little i and even more to click on it and read the information. But it also took people a while to learn what the recycling symbol meant. And reading the info behind the i icon isn't necessarily the point, says Evidon CEO Scott Meyer, who used to be CEO of About.com and managed the New York Times' website. "Do I look at nutritional labeling? No. But would I buy a food product that didn't have one? Absolutely not. I would be really concerned. It's accountability." (See "Google Street View Goes Off-Roading.")
FTC chairman Jon Leibowitz has been pleased by how effective he's been at using the threat of legislation to scare companies into taking action and dropping their excuse that they don't know anything about you personally, just data associated with your computer. "We used to have a distinction 10 years ago between personally identifiable information and non-PII. Now those distinctions have broken down." In November, Leibowitz hired Edward Felten, the Princeton computer-science professor famous for uncovering weaknesses in electronic-voting machines and digital-music protection, to serve as the FTC's chief technologist for the next year. Felten has found that the online-advertising industry is as eager as the government is for improved privacy protections. "There's a lot of fear that holds people back from doing things they would otherwise do online. This is part of the cost of privacy uncertainty. People are a little wary of trying out some new site or service if they're worried about giving their information," Felten says.

He's right: oddly, the more I learned about data mining, the less concerned I was. Sure, I was surprised that all these companies are actually keeping permanent files on me. But I don't think they will do anything with them that does me any harm. There should be protections for vulnerable groups, and a government-enforced opt-out mechanism would be great for accountability. But I'm pretty sure that, like me, most people won't use that option. Of the people who actually find the Ads Preferences page — and these must be people pretty into privacy — only 1 in 8 asks to opt out of being tracked. The rest, apparently, just like to read privacy rules.

(Comment on this story.)
We're quickly figuring out how to navigate our trail of data — don't say anything private on a Facebook wall, keep your secrets out of e-mail, use cash for illicit purchases. The vast majority of it, though, is worthless to us and a pretty good exchange for frequent-flier miles, better search results, a fast system to qualify for credit, finding out if our babysitter has a criminal record and ads we find more useful than annoying. Especially because no human being ever reads your files. As I learned by trying to find out all my data, we're not all that interesting.
With reporting by Eben Harrell / London

Track Back. Use these sites to protect yourself and your information
Reputation.com
For $8.25 a month, the site, founded by CEO Fertik, will work to keep trackers off your browser. For more, it'll massage the results of a Google self-search into something more flattering

PrivacyChoice.org
This site tells you only what Google, Yahoo, BlueKai, Bizo and eXelate know, but it also lists more than 300 tracking companies and helps you opt out of being tracked by them

Ghostery.com
With this free download, every time you go to a website, a pop-up window tells you all the companies that are grabbing your data

Your Browser
Forget your browser's "privacy" option; that just prevents people borrowing your computer from seeing what sites you've been to. New features on Firefox and Chrome allow you to request that companies not mine your data

NetworkAdvertising.org and AboutAds.info
There's no one clearinghouse where you can put yourself on a "do not track" list, but you can opt out of data mining by all members of these two industry associations


Thursday, March 10, 2011

Proposed Bill Would Put Curbs on Data Gathering

By JULIA ANGWIN, WSJ March 10, 2011

Sens. John McCain and John Kerry are circulating proposed legislation to create an "online privacy bill of rights," according to people familiar with the situation, a sign of bipartisan support for efforts to curb the Internet-tracking industry.

John McCain
Mr. McCain, an Arizona Republican, and Mr. Kerry, a Massachusetts Democrat, are backing a bill that would require companies to seek a person's permission to share data about him with outsiders. It would also give people the right to see the data collected on them. The bill is expected to be introduced ahead of a Senate Commerce Committee hearing next Wednesday on online privacy.

The move comes amid widening scrutiny of the tracking industry. In the past year, The Wall Street Journal's "What They Know" series has revealed that popular websites install thousands of tracking technologies on people's computers without their knowledge, feeding an industry that gathers and sells information on their finances, political leanings and religious interests, among other things.

In another sign of Washington's efforts to regulate tracking, the Obama administration is moving to fill two key jobs related to privacy policy. People familiar with the matter said the administration is in talks with Jules Polonetsky, who currently heads the Future of Privacy Forum, an industry-funded think tank, to run a new privacy office in the Commerce Department. Mr. Polonetsky was previously chief privacy officer at online-advertising companies AOL Inc. and DoubleClick, now part of Google Inc.

John Kerry
Daniel Weitzner, a Commerce Department official who pushed for creation of the agency's new privacy office, is expected to become deputy chief technology officer in the White House, where he would oversee a privacy task force, the people familiar with the matter said.

Sen. McCain's endorsement of privacy legislation adds a prominent Republican voice to the issue, indicating that concern over Internet tracking crosses party lines.

In December, the Federal Trade Commission urged Congress to authorize creation of a "do-not-track" system, modeled after the do-not-call list that governs telemarketers. Rep. Jackie Speier, a California Democrat, introduced such a bill in January.

The draft Kerry-McCain bill would create the nation's first comprehensive privacy law, covering personal-data gathering across all industries. That was a key recommendation of a recent Commerce Department's report, developed in part by Sen. Kerry's brother Cameron, the department's general counsel. Current laws cover only the use of certain types of personal data, such as financial and medical information.

The Kerry-McCain bill would cover data ranging from names and addresses to fingerprints and unique IDs assigned to individuals' cellphones or computers. It would also establish a program to certify companies with high privacy standards. Those companies would be allowed to sell personal data to outsiders without seeking permission in each instance.

A spokeswoman for Sen. McCain confirmed that the two senators were "in discussion" but said "we don't have anything to announce at this time." A spokeswoman for Sen. Kerry declined to comment.

Last week, Florida Republican Rep. Cliff Stearns said he would introduce draft privacy legislation soon, although his approach would largely allow the industry to continue many current practices.

Speaking at the Technology Policy Institute, Rep. Stearns said his proposal would allow the FTC to approve a five-year self-regulatory program that would encourage companies to offer more information to consumers about how they were being tracked. "The goal of the legislation is to empower consumers to make their own privacy choices," he said.

Write to Julia Angwin at julia.angwin@wsj.com


Monday, March 7, 2011

Tuning In to You

 
The television is channeling you.

Data-gathering firms and technology companies are aggressively matching people's TV-viewing behavior with other personal data—in some cases, prescription-drug records obtained from insurers—and using it to help advertisers buy ads targeted to shows watched by certain kinds of people.
At the same time, cable and satellite companies are testing and deploying new systems designed to show households highly targeted ads.

The goal: emulate the sophisticated tracking widely used on people's personal computers with new technology that reaches the living room.

One of the most advanced companies, Cablevision Systems Corp., has rolled out a system that can show entirely different commercials, in real time, to different households tuned to the same program. It can deliver targeted ads to all the company's three million subscribers concentrated in New York, Connecticut and New Jersey.

In an early test of Cablevision's technology, the U.S. Army used it to target four different recruitment ads to different categories of viewers.

One group, dubbed "family influencers" by Cablevision, saw an ad featuring a daughter discussing with her parents her decision to enlist. Another group, "youth ethnic I," saw an ad featuring African-American men testing and repairing machinery. A third, "youth ethnic II," saw soldiers of various ethnicities doing team activities. An Army spokesman declined to comment.

This new wave in monitoring Americans is driven, in part, by fear: The TV industry is moving quickly lest it lose ground to Internet advertising companies, which have found they can charge a premium for online ads that target individual people based on their specific interests.
In a rallying cry last month at a TV ad-targeting conference hosted by Broadcasting & Cable, one keynote speaker cited the space race of a half-century ago: "This is our Sputnik moment," said Tracey Scheppach, senior vice president at Starcom MediaVest Group, a unit of advertising firm Publicis Groupe SA.

Targeted ads are getting in front of people a few ways. In one method, TV providers such as Cablevision can beam different ads to different set-top boxes, even when they're tuned to the same channel.

This technology figures out which subscribers should see which ad by anonymously matching the names and addresses of Cablevision's subscribers with data provided by advertisers and others, via a third party. Cablevision says it doesn't share subscriber data with advertisers, or use or share viewership information.

How to Opt Out of Having TV Data Put to Use for Advertising Purposes
Many—but not all—companies let people opt out of having their anonymous TV-viewership information used for ad purposes.

DirecTV subscribers can opt out by contacting the company at (800) 531-5000, www.directv.com/email, or DirecTV Privacy Policy, P.O. Box 6550, Greenwood Village, CO, 80155-6550.

TiVo Inc. says users can opt out by contacting customer support. Details at support.tivo.com/app/answers/detail/a_id/1279.

A Charter Communications official says customers can't opt out of collection of audience-measurement data. The firm says it removes personal details, including names, before sending data to outside companies.

Cablevision Systems Corp., which can show different ads to different households, lets users opt out of seeing targeted ads by calling (888) 425-2591 or by going to ww.optimum.net/Privacy/Preferences and selecting an option to not receive Addressable Third Party Advertising. Cablevision says it doesn't license viewership information.

Comcast Corp. is gearing up for a test of ad-targeting this year. A spokesman said the firm has yet to determine whether there will be an opt-out option, but that "privacy and notification will be key considerations."
--Jessica E. Vascellaro

A second method for targeting ads works differently. Companies including TRA Inc., Rentrak Corp. and WPP PLC's Kantar Media, along with tech titan Microsoft Corp., are taking data on TV-viewing behavior harvested from set-top boxes and matching it with a broad array of household data. Then they, and other tech firms including Google Inc., help advertisers buy ads targeted to shows watched by certain types of people.

One newcomer with another tactic is Simulmedia Inc. of New York, founded by Dave Morgan, a pioneer of Internet ad targeting. His company works with databases detailing when channels are changed on set-top boxes. "Some data is second-by-second," he says.

His company divides set-top boxes into interest groups based on the channels they tune to, such as "heartstringers" (romantic-comedy watchers), and "fake news followers" (satire lovers). Using sophisticated algorithms, Simulmedia says it can then deduce what categories of viewers are swayed by a particular ad.

Some in the industry want "rifle-shot targeting," Mr. Morgan says, where people get "only those ads they care about." That's still well in the future, Mr. Morgan says.

But companies including Cablevision are now deploying technologies that let advertisers like the Army show different commercials to different households based on demographic data.
The Army may try similar campaigns in the future, says Gary Barsky of ad company Universal McCann, a unit of Interpublic Group of Cos., which worked on the campaign.

Targeting technologies represent a sweeping shift in the multibillion-dollar TV-ad business, one of marketing's most popular media. Since the dawn of television, viewers watching the same shows almost always saw the same ads as other people in their market. Advertisers bought commercials based on estimates of what shows were generally popular with broad groups, such as "18-to-49-year-olds."

That's now too blunt an instrument for some advertisers, whose expectations have been raised by the Internet. Online ads can now target people based on narrowly defined characteristics—Chicago residents shopping for plane tickets to Los Angeles, for instance. Online ads can also follow specified Internet users, in real time, as they surf from website to website. These ad services command premium prices.

For years, the TV industry has been gushing about the potential to deliver more targeted ads. There have been false starts. In 2008, cable companies formed a consortium to deploy targeted ads nationally, among other things. Initial efforts were thwarted by issues such as outdated infrastructure.
So, individual companies are proceeding on their own. Bank of America estimates the market for "addressable ads"—those targeted to specific household segments—could reach $11.6 billion by 2015.

Ms. Scheppach of Publicis, addressing the February TV-advertising conference, had sober words: Adapt quickly, or go the way of other media whose business has been eaten by the Internet, like newspapers. "We have to shape our future before it shapes us," she said, predicting that, within six years, technology could be in place to allow all TV ads to be targeted.
Some industry executives urge caution, saying they are reluctant to make the investment when the benefits are unknown. Others warn advertisers should proceed cautiously in light of the intensifying regulatory scrutiny of Internet tracking.

"This could be marketing nirvana, or fraught with potential peril," says Tim Hanlon, chief executive of Velociter, the investment arm of Mediabrands, a unit of Interpublic Group. For the first time, TV tracking could combine viewership data, telemarketing data and online data to examine people's lifestyles. People might see a greater volume of ads they find "personally intrusive," he says, citing political campaigns as examples.

Companies involved in TV targeting say the household-level matching is done by outside companies that provide only aggregated data, stripped of personally identifiable details such as names. Many say TV targeting is less intrusive than online tracking, because TV technologies don't target individuals, but instead use the data to draw inferences about aggregated groups of set-top boxes or households.
The Internet and TV businesses face different regulatory regimes. There is no specific law governing Internet tracking, but cable and satellite companies are restricted from sharing names and addresses of subscribers tied to viewing information without their permission under the 1984 Cable Act and a related rule for satellite TV.

Phone companies that offer video services differ on whether the Cable Act applies to them. Still, they say they don't share personally identifiable information about subscribers without consent. The law doesn't address activities like combining TV-viewing data with mobile or Web browsing, practices barely imaginable when the Cable Act took effect a quarter-century ago.

TiVo Inc., maker of TV recording devices, isn't covered by the Cable Act. TiVo says it doesn't disclose personally identifiable viewing information to third parties without a customer's consent.
TiVo categorizes some of its customers into "attitudinal" segments—including Republicans, Democrats or fans of a particular celebrity chef—by surveying 35,000 users about their habits and combining the data with the shows they watch. It sells the data to marketers via a service called PowerWatch.

TiVo users must opt in to be included, the company says. It solicits participants with offers such as the chance to win a $1,000 Amazon shopping spree.

TiVo says it also licenses anonymous viewing data to TV-targeting upstarts like New York-based TRA, which matches second-by-second data from 1.7 million TiVo set-top boxes and a cable operator with other data types—including 57 million frequent-shopper cards. The matching is done through Experian PLC, a major data company that knows which set-top box and which frequent-shopper card belong to a particular street address. (Experian doesn't share addresses with TRA, or gain access to viewing or frequent-shopping data.)

The method can turn up surprising associations: TRA found that watchers of "Jersey Shore" are regular buyers of yogurt."It really helps you drill down," says David Shiffman of ad agency MediaVest.

Rentrak, a TV-measurement and advertising-services firm, can in some cases associate households' video-on-demand viewing with their live-TV viewing and DVR-television viewing. The company, in some cases, measures videos watched on mobile devices, too.

That kind of data could make it possible for advertisers to target their campaigns at different consumer groups, via different video media, at the time the desired viewers are most likely to watch, says CEO Bill Livek. He says the process is an "evolution" of the direct-marketing business.
Operating out of an old Brooks Brothers factory in downtown Manhattan, Simulmedia is drawing upon the online model for targeting ads. Its raw material is more than 75 terabytes of data from TiVo, DirecTV, Charter Communications and others.

The companies give Simulmedia the times when channels are changed on set-top boxes, along with a unique ID for each box. This lets the company associate one day's viewing with the next. Mr. Morgan says Simulmedia can't tie the data back to individuals.

After determining what programs and ads the set-tops have been tuned to, Simulmedia bundles the boxes into more than two dozen groups based on viewing patterns—"wild n' crazies" (young male-themed shows), "hecklers" (stand-up comedy) and "animated grownups" (cartoon sitcoms), among others.
Advertisers and stations have run more than 50 campaigns using the data, Mr. Morgan says. He declined to name participants.

Given a year of viewing data, Simulmedia can almost perfectly predict around 70% of what types of shows a given set-top box is likely to be tuned to, and when, Mr. Morgan says. He likens the process to helping advertisers "choke the shotgun blast and bring it in close," rather than scattering their ad messages widely.

Not all companies that send data to Simulmedia and others let people opt out.
Mr. Morgan has aspired to bring Web-like targeting to TV for years. He took his first crack more than a decade ago in the U.K. and Switzerland. The effort fizzled, he says, amid struggles to adapt online techniques to cable-TV technologies.

"Most of the work that has been in online advertising over the past 20 years has really been preparation for the big screen," he says, referring to TV. "That's where the money is."
The plumbing is being put in place. Satellite-TV company DirecTV says it will be able to deliver different ads during the same programming to 10 million homes in the fourth quarter of this year. Comcast Corp., the country's largest cable system by subscribers, has run two targeted-ad trials in recent years and is planning a third for later this year.

Cablevision is the furthest ahead, having completed its rollout of targeted ads across all its set-top boxes late last year. Its system is powered by Visible World Inc., which makes technology that can switch different commercials in and out of different set-top boxes based on criteria that advertisers can specify. The company is also powering the new Comcast test.

Today, the scope of the Cablevision effort is on display in a monitoring room at Visible World in New York. There, large TVs along one wall play the ads being inserted into Cablevision programming, in real time. Other monitors show grids indicating how many households in a geographic zone are seeing a particular ad; the numbers flicker from the single digits to a few thousand.

Visible World's founder, Seth Haberman, says his company doesn't know the names or personally identifying information about the people sitting in front of a given set-top box. "We don't want to look in the window," he says. "It is a little spooky."


Republican lawmaker promises new online privacy legislation


An upcoming bill would aim to give online users more control over their personal data, Cliff Stearns says

By Grant Gross, IDG News Service  March 04, 2011 03:29 PM ET
A senior Republican member of the U.S. House of Representatives will soon
introduce legislation designed to give Web users more control of their personal data and to give the U.S. Federal Trade Commission power to enforce voluntary privacy standards developed with Internet companies, he said Friday.

Representative Cliff Stearns, a Florida Republican and senior member of the House Energy and Commerce Committee, said he plans to introduce online privacy legislation soon. The bill's focus will be on allowing Web users to know what personal information Internet companies are collecting about them and to control how it's used, said Stearns, co-author of past online privacy bills.

The bill would encourage Web-based companies to develop industry standards for privacy but would give the FTC some enforcement power, Stearns said during a speech at a Technology Policy Institute (TPI) forum on privacy.

Finding the right balance between privacy and online commerce is a "tough issue," but consumers are demanding more privacy protections. "We are at a tipping point where we have to come to grips with the information that's being collected," he said.
Still, Stearns suggested that online advertising could be hurt if regulations go too far. Online tracking to deliver behavioral, or targeted, ads is a legitimate practice if companies notify consumers what information is collected and allow them to turn off the collection, he said.

"Online advertising ... supports much of the commercial content, applications and services that are available today," he said. "We do not want to disrupt a well-established and successful business model."

Stearns' approach to online privacy would likely be different from a bill introduced in February by Representative Jackie Speier, a California Democrat. Speier's bill woulddirect the FTC to create standards for a nationwide do-not-track mechanism that would allow Web users to opt out of online tracking and the sharing of consumer data among online businesses.

The FTC, in a report released in December, called for the technology industry to create more do-not-track tools. Mozilla, Microsoft and Google all announced do-not-track features for their browsers shortly after the FTC report.

The U.S. Department of Commerce called for a privacy bill of rights for Web users in its own December privacy paper.

But William Kovacic, a Republican commissioner at the FTC, questioned what agencies would enforce new privacy standards and whether lawmakers and privacy advocates would stop pushing for more privacy protections if Internet companies met current demands. "Do you believe the promises of the regulators and others that if you do X, they will be satisfied?" he said at the TPI event. "Or is X a revise-and-resubmit process ... in which you never ultimately satisfy the referees?"

The FTC and Commerce reports, as well as some legislative proposals on online privacy, are "very fuzzy" on details on whether there should be strong regulations or voluntary compliance with industry privacy standards, he added.

Before new privacy regulations are created, lawmakers should look at the potential impact on Internet commerce, added Thomas Lenard, president at TPI, an antiregulation think tank. "More privacy generally means less information available" on the Internet, he said.

But Daniel Weitzner, associate administrator at the Department of Commerce's National Telecommunications and Information Administration (NTIA), disagreed, saying recent studies suggest that Internet-based companies that give users more control over their personal data can build loyalty and advertising click-through rates at the same time. Giving consumers greater control over their privacy doesn't necessarily mean that online companies will lose access to all that data, he said.

"We really see no evidence that there's some trade-off" between privacy and e-commerce, Weitzner said.

Grant Gross covers technology and telecom policy in the U.S. government forThe IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.







Wednesday, March 2, 2011

The Failure of Online Social Network Privacy Settings

The Failure of Online Social Network Privacy Settings
Michelle Madejskiy. Maritza Johnson, Steven M. Bellovin

CUCS-010-11


Abstract

Increasingly, people are sharing sensitive personal information via online social networks (OSN). While such networks do permit users to control what they share with whom, access control policies are notoriouslydifficult to con gure correctly; this raises the question of whether OSN users' privacy settings match theirsharing intentions.

We present the results of an empirical evaluation that measures privacy attitudes andintentions and compares these against the privacy settings on Facebook. Our results indicate a seriousmismatch: every one of the 65 participants in our study con rmed that at least one of the identi ed violationswas in fact a sharing violation. In other words, OSN users' privacy settings are incorrect.

Furthermore, a majority of users cannot or will not fix such errors. We conclude that the current approach to privacy settingsis fundamentally awed and cannot be fixed; a fundamentally different approach is needed. We presentrecommendations to ameliorate the current problems, as well as provide suggestions for future research. 


Available at https://mice.cs.columbia.edu/getTechreport.php?techreportID=1459&format=pdf&