Red Flag Laws and You

A lot of people didn’t know, but Congress enactedconfigure the firewall to get the most out of its
some new security measures for businesses thatpotential. A lawyer recommended to me that I have a
offer credit (of any type) and health care providers towritten security policy in place for how to handle
start taking action in protecting their client’s data.employees getting fired and keeping the data secure
Companies that are subject to HIPAA andfrom them—most thieveries comes from current or
Sarbanes-Oxley regulations are still included in thesepast employees.
new Red Flag regulations. Since HIPAA andRestrict access to your data! This means you
Sarbanes-Oxley only refer to verbal and writtenshouldn’t have your QuickBooks database on the
communication, the new Red Flag laws are supposedsame computer that your employees use for product
to specifically target data systems and clientresearch and checking their email. Separate important
databases in companies—regardless of thedata from a general work space to keep security
company’s size.costs down, and to keep an additional (physical) layer
Now, Mom and Pop stores can’t ignore the factof protection in place. Remember, security breaches
that they lack a firewall protecting their point of saleare physical first and afterwards is when the data is
system or accounting information anymore. This alsovirtually stolen.
means that even the smallest one-man-band businessSo what do all of these things mean for you? It means
up to the SMB of 150 employees is required to takethat security costs are going to rise, due to the extra
extra steps in securing their company database ofmeasures that are now required by Federal Law, but it
client information. Sounds like something that shouldalso means that the extra time is going to have to be
have already been going on, but needless to say manytaken to figure out security holes in your company.
people are careless and don’t perceive any valueSecurity holes don’t have to be virtual. A hole in
in protection until after it’s too late.security can be something physical that allows easy
So what are some things you can do to help protectaccess to confidential information about your company
your client’s data and also keep your head offor its clients. If your company does have a data
Uncle Sam’s chopping block? First, I highlybreach, many states now require that you report it to
recommend having an encrypted backup solution ina specialized department, and then you have to notify
place. Always have a back up, but if you can haveall of your customers about the danger they may be
your backup encrypted, then you are in a greatin. How many customers would you lose if this
position. Always make sure you have an up to datehappened to your business? Are you completely sure
firewall on your network to protect from unrecognizedyou are totally safe? Have you had a professional
traffic. Try not to just buy a firewall and use standardhelp you take the necessary steps to stay protected?
settings; have a real IT professional sit down and