Can existing laws protect consumers after Target breach? - KPLC 7 News, Lake Charles, Louisiana

Can existing laws protect consumers after Target breach?

Posted: Updated:
  • More Local NewsLocalMore>>

  • BREAKING: Suspect in 2008 murder of Lake Charles woman captured

    BREAKING: Suspect in 2008 murder of Lake Charles woman captured

    Wednesday, July 30 2014 11:05 AM EDT2014-07-30 15:05:53 GMT
    Jose Manuel Garcia Guevara. (Source: FBI)Jose Manuel Garcia Guevara. (Source: FBI)
    Jose Manuel Garcia-Guevara, the man wanted in connection with the 2008 murder and rape of a Lake Charles woman, has been captured and is in custody in Calcasieu Parish.More >>
    Jose Manuel Garcia-Guevara, the man wanted in connection with the 2008 murder and rape of a Lake Charles woman, has been captured and is in custody in Calcasieu Parish.More >>
  • Cameron ferry back in service

    Cameron ferry back in service

    Wednesday, July 30 2014 6:11 AM EDT2014-07-30 10:11:06 GMT
    Officials have said the Cameron Ferry will be out of service until early Wednesday morning.No reason was given for the outage.Copyright 2014KPLC. All rights reserved.More >>
    Officials have said the Cameron Ferry will be out of service until early Wednesday morning.No reason was given for the outage.Copyright 2014KPLC. All rights reserved.More >>
  • BP claim forms circulating in LC area

    BP claim forms circulating in LC area

    Tuesday, July 29 2014 8:42 PM EDT2014-07-30 00:42:19 GMT
    Over the last couple of weeks someone has been circulating so-called BP oil claim forms in the Lake Charles area. While man, if not most medical claims associated with the Deepwater Horizon oil spill have been settled, someone is holding meetings around the Lake area trying to get people to sign up. But they're not too forthcoming when it comes to saying who they are or who they represent. Last week there were crowds at Miss Street Church of Christ during various times of the day."People ther...More >>
    Over the last couple of weeks someone has been circulating so-called BP oil claim forms in the Lake Charles area. While man, if not most medical claims associated with the Deepwater Horizon oil spill have been settled, someone is holding meetings around the Lake area trying to get people to sign up. But they're not too forthcoming when it comes to saying who they are or who they represent. Last week there were crowds at Miss Street Church of Christ during various times of the day."People ther...More >>
PHOENIX (CBS5) -

At least 70 million people are now in the crosshairs of the Target breach. And alarmingly, that number could soar past 100 million.

"It's a game changer," said Mark Pribish, an identity theft expert and vice-president with Merchants Information Solutions, Inc. in Phoenix. "They still don't have a handle on it," he said about the big box retailer's security breach of customers' personal information.

CBS 5 News is asking if there are any protections for consumers, considering potentially a third of American's have now been affected by the hack.

We found laws on the books here in Arizona may not go far enough to protect you. It's not clear yet how many Arizonans have been affected by this breach, but the number could be huge. Arizona Federal Credit Union reports 20 percent, or 20,000 of its 100,000 total card holders had their personal information stolen due to the Target breach.

"The "Arizona" law is one of 46 state breach-notification laws in the U.S.," Pribish said in referring to Arizona civil statute 44-7501. But as we discovered, that statute only requires that a business notify people affected by a breach. "The requirements are minimal," Pribish added.

He says times have changed, and so have data breaches. Arizona's law needs an update, he says.

Pribish, and some politicians alike, suggest there be "...some information security and governance requirements standards for all business regardless of the size of the business," Pribish said.

That's actually the aim of legislation re-introduced in the U.S. Senate just this past Wednesday.
The Personal Data Privacy and Security Act was first proposed in 2005.

"Since that time, it's been proposed virtually every year, and each year, to be polite, there's a watered down version," Pribish said.

It calls for businesses to have a detailed security program. But it also allows for states and the Federal Trade Commission to levy legal action, including fines, against companies liable for data breaches.

"You could be fined up to $500,000 per incident for each data breach event," Pribish explained.

But Ken Colburn with Data Doctors says those "standards" may be a bit futile.

"There's already requirements as a retailer for anybody that's taking credit cards, to comply with the processing card industry requirements," Colburn said.

He points to a more frightening risk not addressed in either PDPSA bill or Arizona's current legislation.

As Colburn put it, "The human on the inside of a system has always been the number one security risk."

The cost of a breach to you, the consumer, could be high. And to companies too. A computer software security company called Symantec found the cost of detection and notification of a breach could cost $188 per customer. If 70 million Target customers are at risk, the breach could cost Target $1.3 billion.

Copyright 2014 CBS 5 (KPHO Broadcasting Corporation). All rights reserved.

Powered by WorldNow