February 14, 2006 5:29 PM PST

Judge: Firm not negligent in failure to encrypt data

A federal court has thrown out a lawsuit that accused a student-loan provider of negligence in failing to encrypt a customer database that was subsequently stolen.

Stacy Lawton Guin, a customer of Brazos Higher Education Service, sued the corporation on the grounds that encryption should be used as a routine security precaution.

But U.S. District Judge Richard Kyle in Minnesota dismissed the case last week, saying Brazos had a written security policy and other "proper safeguards" for customers' information and that it acted "with reasonable care" even without encrypting the database.

ID fraud help

Identity fraud isn't that likely to happen to you, but it does occur. CNET News.com has compiled a resource center with background information, statistics, and tips. A recent debit-card theft case has also drawn attention, and in response we've created a list of frequently-asked questions. Security protection is also being discussed at this week's RSA Conference.

The case arose as a result of a burglary at the Silver Spring, Md., home of John Wright, a Brazos financial analyst who worked remotely and analyzed loan portfolios. During that September 2004 burglary, a laptop with personal information about Brazos customers was stolen.

Brazos hired a private investigative firm, Global Options, to recover the laptop, but this was unsuccessful. The judge noted that there was no evidence that the database on the stolen laptop was used for identity fraud. After the theft, Brazos contacted approximately 550,000 of its customers to let them know of the situation and to suggest they place a security alert on their credit bureau files.

Even though he had not actually been harmed as a result of the theft, Guin argued, Brazos was required by the Gramm-Leach-Bliley Act to encrypt personal information and limit its disclosure. The 1999 law requires financial service companies "to protect the security and confidentiality of customers' nonpublic personal information."

Judge Kyle disagreed, saying that the house was in a relatively low-crime neighborhood and that the law does not specifically mandate encryption. "The GLB Act does not prohibit someone from working with sensitive data on a laptop computer in a home office," Kyle wrote. "Despite Guin's persistent argument that any nonpublic personal information stored on a laptop computer should be encrypted, the GLB Act does not contain any such requirement."

See more CNET content tagged:
Gramm-Leach-Bliley Act, identity fraud, personal information, Judge, laptop computer

Add a Comment (Log in or register) 8 comments
It's a policy the company should enforce
by caxaca51 February 14, 2006 9:42 PM PST
Any sensitive data that is allowed to be mobile should undergo
some basic security precautions such as encryption. If I
understand correctly, this judge is saying that since no harm was
done, the company did no wrong. This is negligence at it's best.
Reply to this comment View reply
WTH? A *laptop*
by duerra February 15, 2006 6:12 AM PST
Maybe I missed something, but what the h*ll is half a million records of personal data doing on somebody's *laptop*? That sounds pretty negligent to me.
Reply to this comment
Is there a low crime network online?
by baswwe February 15, 2006 7:22 AM PST
"Judge Kyle disagreed, saying that the house was in a relatively low-crime neighborhood and that the law does not specifically mandate encryption."

What about online? Is there a low crime network that you shouldn't have your stuff safeguarded?
Reply to this comment
How do you figure?
by February 15, 2006 7:44 AM PST
"So it's more like the judge is saying..."

The judge mentions the factors as being, one, a low crime-rate neighborhood, and, two, no specificity in the law, itself, requiring encryption.

So what twisted logic gives you the idea that 'what he's saying" is about actual damages as a prerequisite to going to Court there buddy? Misconstruing arcane laegalese is one thing, but fabrication is something else, no?

Reply to this comment
A desktop would have been better?
by booboo1243 February 15, 2006 8:06 AM PST
Desktop machines get stolen, too. Note that the laptop wasn't being used as a mobile machine, but as a remote machine. It was being used in a physical location thought to be secure.

Security is never absolute. The fact that something bad happened does not, itself, imply negligence. The fact that further safeguards could have been taken that would have protected against a specific threat does not, itself, imply negligence.
Reply to this comment
Firm not negligent in failure to encrypt
by skobryan February 16, 2006 6:41 PM PST
Well, if this is how the Judge sees it then I guess the banking and healthcare regulators better re-write the audit programs and save everyone the time audits cost to companies. Wow, the judge totally missed the point on this one!
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Ad trade group opposes Yahoo-Google search deal

    Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.