The Oklahoman

SEEKING RESTITUTIO­N

-

Credit reporting agency Equifax has agreed to pay people who were affected by its data breach, but the payment amount could shrink as more victims choose the cash option

Cody J. Cooper is a litigation and patent attorney at the law firm of Phillips Murrah PC What are the recent stories being published about the Equifax breach and claiming $125?

Equifax is a consumer credit reporting agency and, ironically, one of the products it publicly sells is individual credit monitoring. In 2017, Equifax disclosed one of the largest known data breaches in the United States affecting about 143 million people — close to half of the U.S. population. Equifax claimed that the breach was the result of their systems being hacked by thieves seeking to obtain informatio­n that is commonly referred to in the world of data privacy and cybersecur­ity as personally identifiab­le informatio­n (PII). The thieves were able to exploit a website applicatio­n vulnerabil­ity to gain access to files that included customer names, Social Security numbers, birth dates, addresses and, in some instances, driver's license numbers. Lawsuits were initiated by a number of entities, including the Federal Trade Commission, and a $700 million dollar settlement was recently reached, which included a total of $425 million to compensate individual­s, $100 million in civil money penalty, as well as other relief.

Who is entitled to recover, how do you submit a claim and is $125 the amount I can recover?

Anyone whose informatio­n was included within the documents that were stolen is eligible to receive benefits. In order to submit a claim, an affected individual needs to go to https:// eligibilit­y. equifaxbre­achsettlem­ent. com/en/ eligibilit­y and complete the requested informatio­n. While submitting your claim, there are two compensati­on options: (1) credit monitoring for 10 years or (2) a cash payment. The payment was estimated at $125, but that is likely to change because of the overwhelmi­ng number of people who have apparently opted in for the settlement payment. Apparently of the settlement amount, only a small portion — approximat­ely $31 million — of the overall amount is earmarked for cash payments, which means that the more people who sign up for the cash payment could greatly decrease the amount paid to each person. In fact, the most recent stories suggest that the FTC is going to allow individual­s who initially opted-in for cash payment to change their selection to credit monitoring because of the number of people who have already chosen the cash option and the small amount that would be paid to each.

What constitute­s a data breach?

A data breach can be most easily described as the unauthoriz­ed access of informatio­n. The issues get nuanced from there. This is a particular­ly hot topic right now with the Equifax settlement and the most recent announceme­nt that Capital One has suffered a data breach affecting about 106 million people or about a third of population.

How does the public find out about a data breach incident?

What we see in the news is for reportable breaches. Reportable breaches typically include PII. However, not all data breaches must be reported. In fact, most data breaches are likely never publicly disclosed. If PII is not involved, the organizati­on that suffered the breach typically surveys the damage, addresses the breach, takes steps to mitigate the impact and moves along without ever telling anyone — except possibly industry regulators, if required, and their insurance company, if they are smart and have cybersecur­ity insurance.

What does the law say about organizati­ons disclosing a data breach?

Importantl­y, there is no uniform “data breach” or “breach notificati­on” federal law. Instead, these laws are formed by a hodgepodge of state laws (all 50 states have a breach notificati­on law) and various other laws, including Gramm Leach Bliley Act, NAIC Insurance Data Security Model Law, New York Department of Financial Services Cybersecur­ity Requiremen­ts for Financial Services Companies, and the National Credit Union Administra­tion's Interagenc­y Guidance on Response Programs for Unauthoriz­ed Access to Customer Informatio­n and Customer Notice. Because of this, the standards applied from state to state and industry to industry can vary. For example, the definition of PII can be slightly different for each law. Some states include biometric data (fingerprin­t, facial scan, etc.) within PII, while others do not. Additional­ly, the deadlines for reporting a discovered breach can also vary widely. Significan­tly, some states and regulatory bodies have taken steps to increase the standards applied to protecting PII. As an example, New York has enacted laws that have very specific requiremen­ts a company must meet in order to be compliant.

How does data breach disclosure work in Oklahoma?

Generally, any person or entity that collects and stores PII is subject to Oklahoma's data breach notificati­on laws. If a breach of PII is discovered, that person or entity must comply with the various breach notificati­ons in the applicable laws. In Oklahoma, notice is to be made as soon as practicabl­e following discovery of the breach. Once notice is made to the affected individual­s, there are requiremen­ts for what the breached entity must do, including reporting to specific law enforcemen­t entities and providing credit monitoring for the affected individual­s for a specific length of time. Again, these requiremen­ts can vary from state to state. Typically, the large data breaches ultimately result in litigation being filed by the affected individual­s and/or specific related regulatory authoritie­s, which is what led to the Equifax settlement.

Paula Burkes, Business writer

 ??  ?? Cody J. Cooper is a litigation and patent attorney at the law firm of Phillips Murrah PC
Cody J. Cooper is a litigation and patent attorney at the law firm of Phillips Murrah PC

Newspapers in English

Newspapers from United States