<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rights.com &#187; privacy</title>
	<atom:link href="http://www.rights.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rights.com</link>
	<description>Individual rights and today's issues.</description>
	<lastBuildDate>Wed, 10 Mar 2010 22:40:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>AT&amp;T and Mordecai Alpert again</title>
		<link>http://www.rights.com/2010/01/15/att-and-mordecai-alpert-again/</link>
		<comments>http://www.rights.com/2010/01/15/att-and-mordecai-alpert-again/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 00:28:38 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[personal responsibility]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=916</guid>
		<description><![CDATA[[Moved to Jan 15, 2010 so it shows up lower on the site]
After numerous calls over the last few months, including several emails to privacy@att.com and assurances from them that they do protect client privacy, AT&#38;T sent us Mordecai Alpert&#8217;s payment information from today.  AT&#38;T has still refused to answer questions regarding how little they [...]]]></description>
			<content:encoded><![CDATA[<p>[Moved to Jan 15, 2010 so it shows up lower on the site]</p>
<p>After numerous calls over the last few months, including several emails to privacy@att.com and assurances from them that they do protect client privacy, AT&amp;T sent us Mordecai Alpert&#8217;s payment information from today.  AT&amp;T has still refused to answer questions regarding how little they are doing to protect Mordecai Alpert&#8217;s privacy.</p>
<div>
<div>
<blockquote>
<div>Thank You</div>
<div>Hello MORDECAI ALPERT,</p>
<p>Your payment has been received and will be applied to your wireless account.</p>
<ul>
<li>Amount: 142.49</li>
<li>Date: 01/22/2010</li>
<li>Confirmation number: QPCODT618700871</li>
</ul>
<p>We appreciate your business.</p>
<p>Thank you,<br />
AT&amp;T</p>
</div>
<div>This e-mail was auto generated. Please do not respond.</div>
</blockquote>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2010/01/15/att-and-mordecai-alpert-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AT&amp;T sends us Mordecai Alpert&#8217;s information again</title>
		<link>http://www.rights.com/2010/01/08/att-sends-us-mordecai-alperts-information-again/</link>
		<comments>http://www.rights.com/2010/01/08/att-sends-us-mordecai-alperts-information-again/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 15:08:09 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=831</guid>
		<description><![CDATA[Great privacy on AT&#38;T&#8217;s part.  So, Mordecai Alpert, please call AT&#38;T.  The AT&#38;T representative said they didn&#8217;t care if the information was posted and that they couldn&#8217;t do anything to correct the problem without talking to Mordecai Alpert (in Delray, FL) since he is the account owner.  So, Mordecai, please call AT&#38;T and ask them [...]]]></description>
			<content:encoded><![CDATA[<p>Great privacy on AT&amp;T&#8217;s part.  So, Mordecai Alpert, please call AT&amp;T.  The AT&amp;T representative said they didn&#8217;t care if the information was posted and that they couldn&#8217;t do anything to correct the problem without talking to Mordecai Alpert (in Delray, FL) since he is the account owner.  So, Mordecai, please call AT&amp;T and ask them (a) why they do NOT verify email addresses, and (b) do not provide a link to let them know they are sending it to the wrong address.  Most importantly, ask them why they don&#8217;t follow their own privacy policy better.</p>
<blockquote><p>Hello MORDECAI ALPERT:</p>
<p>Please contact AT&amp;T Wireless regarding account number 523024065xxx at 1-800-947-5096. Thank You.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<div id="_mcePaste">Your Wireless Bill is Ready Online</div>
<div id="_mcePaste">Hello MORDECAI ALPERT,</div>
<div id="_mcePaste">Your monthly wireless bill (for account 523024065xxx ) is now available for review online.</div>
<div id="_mcePaste">Log in today to view your bill and make a payment.</div>
<div id="_mcePaste">Thank You,</div>
<div id="_mcePaste">AT&amp;T</div>
<p>Your Wireless Bill is Ready Online</p>
<p>Hello MORDECAI ALPERT,<br />
Your monthly wireless bill (for account 523024065xxx ) is now available for review online.Log in today to view your bill and make a payment.<br />
Thank You,AT&amp;T</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;Update, January 11, 2010:</p>
<p><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"> </span></p>
<div style="width: 760px; border: initial none initial;">
<div style="width: 746px; border-right-width: 2px; border-bottom-width: 2px; border-left-width: 2px; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-right-color: #cccccc; border-bottom-color: #cccccc; border-left-color: #cccccc; border-top-style: none; border-top-width: initial; border-top-color: initial; background-color: #ffffff;">
<div style="width: 700px;">
<div>Thank You</div>
<div style="width: 445px;">Hello MORDECAI ALPERT,</p>
<p>Your payment has been received and will be applied to your wireless account.</p>
<ul>
<li style="margin-left: 15px;">Amount: 142.49</li>
<li style="margin-left: 15px;">Date: 01/11/2010</li>
<li style="margin-left: 15px;">Confirmation number: QPCODT613957xxx</li>
</ul>
<p>We appreciate your business.</p>
<p>Thank you,<br />
AT&amp;T</p>
</div>
</div>
<div style="padding-left: 15px;">This e-mail was auto generated. Please do not respond.</div>
</div>
</div>
<div style="width: 340px; text-align: left;">
<div><a style="color: #0000cc;" href="http://click.wireless.att.com:8080/83616104.108580.835370972.542" target="_blank">Privacy Policy</a> | <a style="color: #0000cc;" href="http://click.wireless.att.com:8080/83616104.108580.835370972.242" target="_blank">Terms of Use</a></div>
</div>
<div style="width: 380px; text-align: right;">
<div>©2009 AT&amp;T Intellectual Property. All rights reserved. AT&amp;T and the AT&amp;T logo are trademarks of AT&amp;T Intellectual Property.</div>
</div>
<p><img alt="" width="1" height="1" /></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2010/01/08/att-sends-us-mordecai-alperts-information-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AirTran A+ Visa card from Barclay Card for Burton Stevens!</title>
		<link>http://www.rights.com/2009/12/24/airtran-a-visa-card-from-barclay-card-for-burton-stevens/</link>
		<comments>http://www.rights.com/2009/12/24/airtran-a-visa-card-from-barclay-card-for-burton-stevens/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 17:08:30 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=814</guid>
		<description><![CDATA[Yet again a credit card company notifies us of someone else&#8217;s new Visa.   AirTran A+ Visa card from Barclay Card (barclaycardus.com, of the Barclay&#8217;s Group) notified us today of someone else&#8217;s Visa approval.  While Barclays claims to have a privacy policy, they don&#8217;t seem to follow it nor do they give links [...]]]></description>
			<content:encoded><![CDATA[<p>Yet again a credit card company notifies us of someone else&#8217;s new Visa.   AirTran A+ Visa card from Barclay Card (barclaycardus.com, of the Barclay&#8217;s Group) notified us today of someone else&#8217;s Visa approval.  While Barclays claims to have a privacy policy, they don&#8217;t seem to follow it nor do they give links to notify them of the problem.</p>
<p>Humorously enough BarclayCardus.com has this message on it today:</p>
<blockquote><p>&#8220;At Barclaycard, we never stop envisioning new ways to help our partners cultivate customer loyalty.&#8221;  </p></blockquote>
<p><span id="more-814"></span></p>
<p>We don&#8217;t suppose that includes protecting AirTran&#8217;s customers privacy.</p>
<p>This is the email they sent:</p>
<blockquote><p>Dear BURTON,</p>
<p>Welcome! You&#8217;ve been approved for the AirTran Airways A+ Visa Signature card, brought to you by Barclays.</p>
<p>Use your AirTran Airways A+ Visa Signature card to earn points* toward travel on AirTran Airways. Earn one AirTran Credit for every 1,000 points. Soon you&#8217;ll be flying for free by earning:</p>
<p>Bonus Credits when you use your card**<br />
Points toward travel with every purchase you make<br />
Double points on your AirTran Airways travel purchases<br />
In the next few days, we&#8217;ll be sending you everything you need to start using your AirTran Airways A+ Visa Signature card. In the meantime, please register online at www.BarclaycardUS.com. Once you&#8217;ve set up your username and password, simply log in to:</p>
<p>View your account balance and transaction summary<br />
Check the status of any balance transfer(s) you may have requested or submit a new balance transfer after you have received and activated your card<br />
If you have any questions regarding your AirTran Airways A+ Visa Signature card, please visit www.BarclaycardUS.com to send us a secure email. Or, visit www.airtran.com to purchase tickets, redeem Credits or sign-up to receive AirTran Airways Net Escapes airfare offers via email.</p>
<p>Thanks for choosing the AirTran Airways A+ Visa Signature card.<br />
Chris Reitnour<br />
Director, Marketing<br />
Barclays</p>
<p>You received this email because you have been approved for the AirTran Airways A+ Visa Signature card.</p>
<p>We&#8217;re happy to send you occasional emails about Barclays features and benefits, but if you&#8217;d prefer not to receive them, please login to www.BarclaycardUS.com and select ALERTS/PROFILE. From the PROFILE screen you can update your PRIVACY OPTIONS. You will continue to receive any Account Alerts that have been set up and any email updates about your account.</p>
<p>* The AirTran Airways A+ Visa Signature card program is sponsored by AirTran Airways.<br />
** Points will be credited to your account at the close of your first billing cycle after use of the AirTran Airways A+ Visa Signature account. Your annual fee must be paid and your account must be in good standing in order to earn points.</p>
<p>Please Do Not Reply to this Email<br />
This is a notification-only email that cannot accept incoming replies. To send us an email, simply log in to www.BarclaycardUS.com, click on CUSTOMER SERVICE and then select EMAIL to send your message securely.</p>
<p>The AirTran Airways A+ Visa Signature card is issued by Barclays Bank Delaware, Attn: Gates &#8211; IS, 100 S. West Street, Wilmington, DE 19801, Member FDIC.</p>
<p>BRD-EM-14466051
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/12/24/airtran-a-visa-card-from-barclay-card-for-burton-stevens/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon keeps sending someone else&#8217;s account information</title>
		<link>http://www.rights.com/2009/12/09/verizon-keeps-sending-someone-elses-account-information/</link>
		<comments>http://www.rights.com/2009/12/09/verizon-keeps-sending-someone-elses-account-information/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 10:54:45 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=791</guid>
		<description><![CDATA[Verizon keeps sending someone else&#8217;s account information and still pays only lip service to privacy and providing a method to letting them know they are doing so.  Perhaps they should have a coverage map that shows where they are leaking private information.  &#8221;Can you see my account information now?&#8221;  &#8221;Can you see it now?&#8221;



Your Verizon [...]]]></description>
			<content:encoded><![CDATA[<p>Verizon keeps sending someone else&#8217;s account information and still pays only lip service to privacy and providing a method to letting them know they are doing so.  Perhaps they should have a coverage map that shows where they are leaking private information.  &#8221;Can you see my account information now?&#8221;  &#8221;Can you see it now?&#8221;</p>
<table border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="font-family: arial, sans-serif; font: normal normal normal 16px/normal Arial; color: #d6001c; text-align: left; font-weight: bold; padding-top: 17px; padding-left: 20px; padding-right: 40px; margin: 0px;">Your Verizon Wireless Account Number ending with 1772-00001</td>
</tr>
<tr>
<td style="font-family: arial, sans-serif; font: normal normal normal 12px/normal Arial; color: #000000; text-align: left; padding-top: 17px; padding-left: 20px; padding-right: 20px; margin: 0px;">Your current Verizon Wireless bill statement is now available for online viewing. The current balance due is $193.79.You can conveniently view your bill statement at<a style="color: #0000cc;" href="http://www.verizonwireless.com/" target="_blank">www.verizonwireless.com</a>. The online bill is a restatement of your paper bill.</p>
<p>It&#8217;s easy to pay your Verizon Wireless bill. On the web, go to My Verizon at <a style="color: #0000cc;" href="http://www.verizonwireless.com/" target="_blank">www.verizonwireless.com</a>. On your cellular phone, you can access account information by dialing #PMT (airtime free).</p>
<p>Auto Bill Pay is Available!</p>
<ul>
<li style="margin-left: 15px;">Automatically pay your bill, in full, each month by signing up for Auto Bill Pay using your checking account or debit/credit card. For more information or to change your current payment method, go to My Verizon at<a style="color: #0000cc;" href="http://www.verizonwireless.com/" target="_blank">www.verizonwireless.com</a> and select Auto Bill Pay.</li>
<li style="margin-left: 15px;">Or, call us at 1-866-868-3882 to enroll.</li>
</ul>
<p>Thank you for using Verizon Wireless.</td>
</tr>
</tbody>
</table>
<p><span style="line-height: normal; font-size: x-small;">&#8230;To review our Privacy Policy, <a style="color: #000000;" href="http://www.verizonwireless.com/b2c/footer/privacy.jsp" target="_blank">click here</a>.</span></p>
<p><span style="line-height: normal; font-size: x-small;"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/12/09/verizon-keeps-sending-someone-elses-account-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smith Barney, Intuit Payroll, and Amex update</title>
		<link>http://www.rights.com/2009/11/24/smith-barney-and-amex-update/</link>
		<comments>http://www.rights.com/2009/11/24/smith-barney-and-amex-update/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 00:15:02 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=749</guid>
		<description><![CDATA[Smith Barney sent a welcome message to Harold Bxxxxx, welcoming Harold B to Smith Barney online and another for account number ###-##099 being enrolled in E-Delivery with the last 3 SSN ending in 040.  Smith Barney, like others, links to their privacy policy, and does a wonderful job following it.  They do give an 800 [...]]]></description>
			<content:encoded><![CDATA[<p>Smith Barney sent a welcome message to Harold Bxxxxx, welcoming Harold B to Smith Barney online and another for account number ###-##099 being enrolled in E-Delivery with the last 3 SSN ending in 040.  Smith Barney, like others, links to their privacy policy, and does a <em>wonderful</em> job following it.  They do give an 800 number (800-221-3636) to call, but no link or email address to notify them.</p>
<p>Next we have Intuit QB Basic Payroll sending order # SBL36468501 for 243.89 to me for Grant Kxxxxx in Boca Raton, Florida with no reply address and no way to notify them that they are sending information to someone else.</p>
<p>An update on the American Express &#8220;Settlement and Payment Advice Report for SE No: 9740108691.&#8221;  American Express is still sending them.  While asking to be notified by email, but messages to their notification email address still bounce.</p>
<p>How about companies adopt a standard link at the end of their emails to notify them to review the address?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/11/24/smith-barney-and-amex-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Best Buy sends credit card info!</title>
		<link>http://www.rights.com/2009/11/16/best-buy-sends-credit-card-info/</link>
		<comments>http://www.rights.com/2009/11/16/best-buy-sends-credit-card-info/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 01:01:52 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=740</guid>
		<description><![CDATA[Following in the footsteps of others, Best Buy and HSBC Bank send private information without a method of notifying them of their mistake.  They obviously do not bother to verify email addresses.   So, Tom H***** is getting information from Best Buy about his account ending in 8954 sent to us.
The kicker is that Best Buy [...]]]></description>
			<content:encoded><![CDATA[<p>Following in the footsteps of others, Best Buy and HSBC Bank send private information without a method of notifying them of their mistake.  They obviously do not bother to verify email addresses.   So, Tom H***** is getting information from Best Buy about his account ending in 8954 sent to us.</p>
<p>The kicker is that Best Buy and HSBC included the statement that  &#8221;We maintain strict security standards and procedures to prevent unauthorized access to information about you.&#8221;  I guess that is, unless of course HSBC and Best Buy send it to the wrong email address they do not bother to verify them.</p>
<p>After speaking with a supervisor, they intended to &#8220;try to find the account number&#8221; and delete it, but apparently there is no method for them to look up an account number by email address, name or last four digits.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/11/16/best-buy-sends-credit-card-info/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Continental Sends someone else&#8217;s Flight check-in information</title>
		<link>http://www.rights.com/2009/11/13/continental-sends-someone-elses-flight-check-in-information/</link>
		<comments>http://www.rights.com/2009/11/13/continental-sends-someone-elses-flight-check-in-information/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 01:37:14 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=723</guid>
		<description><![CDATA[And yet another example for poor privacy practices by Continental Airlines sending me flight check-in information for &#8220;Annmrs Zgonena&#8221;.  Now it seems a bit strange that someone would be using an email address that does not belong to them to book a flight and the airlines wouldn&#8217;t know it.  But it is also amazing the [...]]]></description>
			<content:encoded><![CDATA[<p>And yet another example for poor privacy practices by Continental Airlines sending me flight check-in information for &#8220;Annmrs Zgonena&#8221;.  Now it seems a bit strange that someone would be using an email address that does not belong to them to book a flight and the airlines wouldn&#8217;t know it.  But it is also amazing the amount of information they share including the confirmation number, complete itinerary and the food selection with a complete stranger.</p>
<p><span style="font-family: Verdana, Arial, Helvetica, sans-serif;"><span style="line-height: normal;">To make matters worse, Continental provides no method to notify them that someone is not using their own email address to book a flight. </span></span></p>
<p><span style="font-family: Verdana, Arial, Helvetica, sans-serif;"><span style="line-height: normal;"><br />
</span></span></p>
<p><span style="font-family: Verdana, Arial, Helvetica, sans-serif;"><span style="line-height: normal;"><br />
</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/11/13/continental-sends-someone-elses-flight-check-in-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HomeDepot and private information</title>
		<link>http://www.rights.com/2009/11/13/homedepot-and-private-information/</link>
		<comments>http://www.rights.com/2009/11/13/homedepot-and-private-information/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 15:17:53 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=718</guid>
		<description><![CDATA[As a follow-up, HomeDepot is yet another company that plays fast and lose with your privacy.  Check the email out below.
Now in this same email, the Subject says &#8220;DO NOT REPLY.&#8221;  In the text HomeDepot says &#8220;This is an unmonitored mailbox; please do not reply directly to this e-mail.&#8221;  Then a few sentences further, it says [...]]]></description>
			<content:encoded><![CDATA[<p>As a follow-up, HomeDepot is yet another company that plays fast and lose with your privacy.  Check the email out below.</p>
<p>Now in this same email, the Subject says &#8220;DO NOT REPLY.&#8221;  In the text HomeDepot says &#8220;This is an unmonitored mailbox; please do not reply directly to this e-mail.&#8221;  Then a few sentences further, it says &#8220;if this message has been sent to you in error, please immediately alert the sender by reply e-mail.&#8221;  The do include a link to their privacy policy (<a href="http://www.homedepot.com/privacy">http://www.homedepot.com/privacy</a>).  Fortunately OUR terms of service that apply to email sent to us, is that we may quote it here. Otherwise, emailing us is strictly forbidden.</p>
<p>HomeDepot should be including a link to report problems that are either fraud or honest errors.  Likewise, HomeDepot should take the time to proofread their emails in order to ensure that they make sense.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Fri, Nov 13, 2009 at 9:54 AM<br />
subject	DO NOT REPLY: The Home Depot Home Services Appointment Details [47638xx]<br />
Dear: Paul Jxxxxxx,<br />
Thank you for submitting your information with The Home Depot&#8217;s Installation Services:</p>
<p>Home Insulation</p>
<p>Our representatives will contact you within 24 to 48 hours.<br />
&#8230;<br />
This is an unmonitored mailbox; please do not reply directly to this e-mail.<br />
&#8230;<br />
If you are not the intended recipient of this message, or if this message has been sent to you in error, please immediately alert the sender by reply e-mail and then delete this message, including any attachments.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/11/13/homedepot-and-private-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Corporations that play fast and loose with individuals private information</title>
		<link>http://www.rights.com/2009/11/10/corporations-that-play-fast-and-loose-with-individuals-private-information/</link>
		<comments>http://www.rights.com/2009/11/10/corporations-that-play-fast-and-loose-with-individuals-private-information/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 14:50:10 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=696</guid>
		<description><![CDATA[In a recent investigation Rights.com has discovered many large companies who should be protecting your privacy are not doing so.  Companies that are large enough to have good privacy policies either are ignoring them or not doing a good enough job in doing so.  Ironically, most of the companies include links to their privacy policies [...]]]></description>
			<content:encoded><![CDATA[<p>In a recent investigation Rights.com has discovered many large companies who should be protecting your privacy are not doing so.  Companies that are large enough to have good privacy policies either are ignoring them or not doing a good enough job in doing so.  Ironically, most of the companies include links to their privacy policies that include the terms that they will share personal information with 3rd parties.</p>
<p>First up on our list of companies that do not verify where they are sending your private information is BMW Financial Services disclosed Sandra A&#8217;s name (last name included in the email but not included here to protect her privacy), her presumed nickname &#8211; Sandy-, and the BMW car she has 2006, 325xi.  BMW attempted to look up the account by email and said they would attempt to remove it [Update: a week later they were still sending us email].  Most people would not have called them though in order to correct their error.  The email also included the line &#8220;we diligently safeguard your privacy&#8221; with a link to their privacy policy (<a href="http://www.bmwusa.com/About/privacy.htm?panelid=3">http://www.bmwusa.com/About/privacy.htm?panelid=3</a>), none of which did BMW follow by sending us Ms. A&#8217;s personal information.  BMW provided no method to let them know that they had made a mistake, and in fact made it extremely difficult to speak with a human in order to even get a comment requesting account numbers or social security number repeatedly.</p>
<p>AT&amp;T Wireless was even worse.  The first woman I spoke too transferred me to a different department where I was rudely told I &#8220;didn&#8217;t understand the Internet&#8221; and that the fact that they were sending me information about Crystal R&#8217;s account meant that my own email account had been stolen and that I had to talk to my ISP about how to remedy the problem.  AT&amp;T could not believe that they had entered an email address in error and would not even pull up the account to remove the email address &#8211; AT&amp;T had helpfully sent me the phone number. Of course, it had NOTHING to do with the fact that it turned out that her email account was the same as mine except with an &#8220;i&#8221; at the end which AT&amp;T had neglected to enter.  I called the person to let them know that AT&amp;T was sending me her account information and she and I figured out the problem while on hold with AT&amp;T.  It is funny that after calling back 3 more times I finally spoke with someone who understood the problem and decided to actually call the account holder and fix the email address in the AT&amp;T Wireless computer system.  AT&amp;T should train its employees better to be more polite, and to be receptive to good Samaritans who are try to report a problem to AT&amp;T.  Likewise, AT&amp;T Wireless also has been sending me updates for MORDECAI ALPERT about his A-List Feature or Call-list.</p>
<p>Disney Destinations has sent several emails including confirmation numbers for reservations, full details of the people making the reservation &#8211; name, address, balance due &#8211; where they were staying and the dates.  But not way to notify Disney of the error.  For example, Ms. Jackie G. from West Palm Beach is going to stay at Disney&#8217;s Boardwalk Inn in December.  Kris P is going to be there the same day, perhaps they know each other.</p>
<p>AmericanExpress sent us a &#8220;Settlement and Payment Advice Report&#8221; for &#8220;SE No: 9740108691.&#8221;  With all kinds of merchant details and transactions.  They ask you to reply immediately if you &#8220;receive this message in error.&#8221;  That is the right idea, but the email address gives the message that &#8220;Delivery to the following recipients failed.&#8221;  So, while AmericanExpress did try, they didn&#8217;t succeed.</p>
<p>Verizon  sent us information about the account number ending in 1772-00001 that &#8220;[t]he current balance due is $270.55.You can conveniently view your bill statement.&#8221;  Verizon provides a link that states &#8220;If you are not the intended recipient and feel you have received this email in error, please <a style="color: #0000cc;" href="http://support.vzw.com/" target="_blank">click here</a> to notify us.&#8221;  However, the link takes you to the generic Verizon Wireless website with no link to contact about email addresses that are incorrect.  Verizon seems to have the right idea, but a poor implementation.  Verizon also has a link to their privacy policy, which doesn&#8217;t seem to be being followed.  Beth at Verizon said that Verizon does not verify the email addresses and it is up to the customer to do so.</p>
<p>1800Flowers has sent several emails.  For example, one on November 10th, with a delivery for Edwina L. in North Fort Myers, FL from (presumably) her son, Kevin H.and Dana H. in Geneva IL saying &#8220;Thank you for being such a wonderful Mother, Love, Dana&#8221;.  The email lists the last four digits of the American Express card, the full addresses of both people, order number etc.</p>
<p>Walmart sent us email for JB Hughes with the last 4 digits of his Visa card (aka Walmart MoneyCard) and the balance remaining.  Walmart&#8217;s email is &#8220;an unmonitored email box&#8221; with no way to notify them of the error by phone or email.  They ironically provide a link to their privacy policy. (<a href="http://https://www.walmartmoneycard.com/AcctMgmt/Controls/Walmart/Support/PrivacyPolicy.aspx?siteid=Walmart" target="_blank">See here</a>.)</p>
<p>GE Consumer and Industrial Appliance Parts was even kind enough to send me their eNewsletter with the tag &#8220;CONFIDENTIAL — DO NOT DISTRIBUTE OR PUBLISH TO THIRD PARTY.&#8221;  And no link to let them know that GE itself is &#8220;publish[ing] to a third party.&#8221;</p>
<p>The worst of the bunch though is Hilton Hotels.  After receiving 3 emails from various Hilton Hotels in the last 2 days, none with a link to report their error, I called Hilton to get a comment.  For example, Stephen B will be at the Hilton Garden Inn, Cleveland Downtown Nov 14-15.  Hilton Hotels was happy to send his confirmation number and more, but no link to let them know they&#8217;d made a mistake.  Amauri A will be at the Hilton, Chicago O&#8217;Hare Airport 11/30-12/1 2009.  No link to let them know of the error, but links to &#8220;modify or cancel your reservation.&#8221;  George U stated at the Hilton Garden Inn Pittsburgh/Southpoint 11/5-116 and earned 119 miles for it.  The General Manager of the hotel, Paul Bazzano signed the email, but didn&#8217;t provide details on correcting their error.  The kicker is this: The email states &#8220;<span style="text-decoration: underline;">Please do not reply to this email.</span> Mail sent to this address cannot be answered&#8221; but then states &#8220;I<span style="text-decoration: underline;">f it has been sent to you in error, please reply to advise the sender</span> of the error and then immediately delete this message.&#8221; Hilton, which one is it?  Reply or not?  After replying to the email and receiving no answer after several days, it appears they will not be doing so.</p>
<p>So I decided call Hilton at 877-444-9847. After being on hold for 20 minutes I finally spoke with Bryan Simmons who asked me to forward the email to them so they could investigate.  No reasonable person is going to try to attempt to correct Hilton Hotel&#8217;s errors for that long, but I was hoping to be able to speak with someone there and did so.  Perhaps Hilton will correct the issues in the future.</p>
<p>Then we have Beacon Medical Services for Longs Peak ER Physicians that notified us that Jody J. M.&#8217;s payment was declined on her Mastercard ending in XXXX for $55.00 with 1990534xx as the account number.  After speaking with them, they say they do not email people, so someone must&#8217;ve been pretending to be them and spamming with that information. True?  Perhaps.</p>
<p>Vonage is yet another company that has difficulty protecting individuals private information.  Vonage has been sending me the visual voicemails, with voice-message.wav attached for a Willie T. at 706-955-11xx.  They provide no means of notifying them of problem and are sharing private voicemails with someone who is not their customer.  Calling their toll-free number (which should NOT be required) connects you with someone who is not a native English speaker and who (both times I called) had difficulty in understanding how they could be sending me someone else&#8217;s voice mails.</p>
<p>Sprint (sprint.com) continues the trend with no way to notify them, and no way to remove yourself.  Sprint has been sending us Gary S&#8217;s PIN and security answer with only a part of the account number blocked.  So, there is absolutely no way to notify them that they are sending the information to us.  Amazingly poor privacy protection.</p>
<p>Few of the companies provide the means to correct their mistakes.  Someone who was attempting to steal and identity or commit fraud could use this information to further their cause.  Likewise, any burglar would love to know when a person is going to be out of town in Pittsburgh or Orlando.</p>
<p>Some suggested requirements for companies who send private information to their customers.</p>
<p>(a) Require users to enter email addresses twice.  Require employees to enter email twice and read the email address back to the user.</p>
<p>(b) Verify email addresses prior to sending.  This does not mean just a link to click on, but a code sent via regular mail or text message that is then entered after clicking a link in the email.</p>
<p>(c) Provide a method to report an incorrect address.  Just a link that says &#8220;You have the wrong email address, please delete it&#8221; would be sufficient.</p>
<p>(d) For confidential email, senders should sign and/or encrypt the email with something like PGP.  Sending confidential information by email is just a bad idea all around.  It is like sending private information by postcard and addressing it to the New York Times.</p>
<p>In short, while the companies above are claiming to protect your privacy a combination of mistakes by either their customers or their representatives are failing to do so.  We&#8217;ll be updating this report over time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/11/10/corporations-that-play-fast-and-loose-with-individuals-private-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Insurance penalties</title>
		<link>http://www.rights.com/2009/10/18/health-insurance-penalties/</link>
		<comments>http://www.rights.com/2009/10/18/health-insurance-penalties/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 14:49:26 +0000</pubDate>
		<dc:creator>Christian Riley</dc:creator>
				<category><![CDATA[Abuse of Power]]></category>
		<category><![CDATA[Constitution]]></category>
		<category><![CDATA[Obama-Biden]]></category>
		<category><![CDATA[big government]]></category>
		<category><![CDATA[personal responsibility]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[rights]]></category>

		<guid isPermaLink="false">http://www.rights.com/?p=665</guid>
		<description><![CDATA[In the health care bill passed last Tuesday (10/13/2009) by the Senate Finance Committee, adults who do not purchase health insurance would face an excise-tax penalty of $200 a year starting in 2014 and rising gradually to $750 in 2017.
Let&#8217;s analyze this.  You can pay whatever you are paying per month now for insurance or [...]]]></description>
			<content:encoded><![CDATA[<p>In the health care bill passed last Tuesday (10/13/2009) by the Senate Finance Committee, adults who do not purchase health insurance would face an excise-tax penalty of $200 a year starting in 2014 and rising gradually to $750 in 2017.</p>
<p>Let&#8217;s analyze this.  You can pay whatever you are paying per month now for insurance or you can forgo buying insurance and pay an annual penalty knowing that you can buy insurance later when you need it.  Simple trade-off there.  Pay $500/month for health insurance now or pay $200/year penalty and only pay the $500 when you need it.</p>
<p>If even a percentage of people wait until they are sick to get coverage, costs will go up on the people who do not try to cheat the system.</p>
<p>The Federal government has one method of making a &#8220;universal coverage&#8221; mandate viable:  huge taxes that everyone has to pay followed by jail if they don&#8217;t.  Every other method can, and will, be gamed.  Look at all the other government programs that people cheat on: from military purchases, to food stamps being, to Social Security (relatives of the dead still collecting), to Medicare, to Medicaid (dump your assets so you qualify) to taxes.  Government socialized health care will be no different.</p>
<p>Even ignoring the Constitutionality of it, do we really want jail time for not having health insurance in what is supposed to be free country?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rights.com/2009/10/18/health-insurance-penalties/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
