HomeMy WebLinkAboutAdmin Order 21-09-06ADMINISTRATIVE ORDER NO.21-09-06
of the
City Manager
City of Eugene, Oregon
AMENDING THE EUGENE IDENTITY THEFT PROTECTION
PROGRAM POLICIES PURSUANT TO THE FAIR AND ACCURATE
CREDIT TRANSACTIONS ACT OF 2003, AND REPEAL OF
ADMINISTRATIVE ORDER N0.21-08-07.
The City Manager of the City of Eugene finds that:
A. Under the provisions of Chapter IV, Section 16 of the Eugene Charter of 2002,
the City Manager is designated as the administrative head of the City and specifically authorized
to assign the duties of all administrative employees.
B. The Fair and Accurate Credit Transactions (FACT) Act of 2003, Pub. Law 108-
159, and rules promulgated by the Federal Trade Commission (FTC) pursuant to the FACT Act,
16 C.F.R. 681, require the City to implement identity theft protection policies. In addition, the
Oregon Consumer Identity Theft Protection Act, ORS 646A.600 through ORS 646A.628,
requires the City to develop identity theft protection policies.
C. The FTC had previously required that identity theft protection policies be
implemented by November 1, 2008. Consequently, the City Manager issued Administrative
Order No. 21-08-07 establishing the Eugene Identity Theft Protection Program Policies Pursuant
to the Fair and Accurate Credit Transactions (FACT) Act of 2003, effective November 1, 2008.
D. At the request of Members of Congress, the FTC is delaying enforcement of the
identity theft protection policies until June 1, 2010. Therefore, it is necessary that the City delay
the implementation date of its identity theft protection policies until June 1, 2010. As a result of
the implementation delay, Section 5(d) of the Policies should be amended to revise the date on
which department heads begin reporting to the City Manager to December 31, 2010.
Based upon the above findings, Administrative Order No. 21-08-07 is repealed and the
City of Eugene Identity Theft Protection Program Policies set out below are adopted effective
June 1, 2010. The City of Eugene Identity Theft Protection Program Policies are designed to
detect, prevent and mitigate identity theft and are appropriate to the size and complexity of the
City and the nature and scope of the City's activities.
CITY OF EUGENE IDENTITY THEFT PROTECTION PROGRAM POLICIES
(1) Definitions.
(a) "Account" means a continuing relationship established by a person with the City
to obtain a product or service for personal, family, household or business
purposes. Account includes:
Administrative Order -- Page 1 of 7
1. An extension of credit, such as the purchase of property or services
involving a deferred payment; and
2. A deposit account.
(b) "Covered account" means:
1. An account that the City offers or maintains, primarily for personal,
family, or household purposes, that involves or is designed to permit
multiple payments or transactions, such as a mortgage loan or utility
account; and
2. Any other account that the City offers or maintains for which there is a
reasonably foreseeable risk to customers or to the safety and soundness of
the City from identity theft, including financial, operational, compliance,
reputation, or litigation risks.
(c) "Customer" means a person that has a covered account with the City.
(d) "Identity theft" means a fraud committed or attempted using the identifying
information of another person without authority.
(e) "Notice of address discrepancy" means a notice sent to the City by a consumer
reporting agency that informs the City of a substantial difference between the
address for the consumer that the City provided to request the consumer report
and address(es) in the consumer reporting agency's file for the consumer.
(f) "Personal information" means a person's name in combination with the following
information: a Social Security Number; Oregon driver's license or Oregon
identification card number; passport number; or financial, credit, or debit card
numbers along with a security or access code or password; when the information
is not rendered unusable through encryption, redaction or other methods.
(g) "Red Flag" means a pattern, practice, or specific activity that indicates the
possible existence of identity theft.
(h) "Service provider" means a person that provides a service directly to the City.
(2) Periodic Identification of Covered Accounts. Each City department must conduct an
annual risk assessment to determine whether it offers or maintains covered accounts. The
department shall take into consideration:
(a) The methods it provides to open its accounts;
(b) The methods it provides to access its accounts; and
(c) Its previous experiences with identity theft.
(3) Identification of Relevant Red Flays. After considering the types of covered accounts
the City offers and maintains, the methods the City provides to open its covered accounts, _
the methods the City provides to access its covered accounts and the City's previous
i3.
ft
rf ..
)4
Administrative Order -- Page 2 of 7
a
~~~
experience with identity theft, the City Manager has identified the following categories
and types of Red Flags:
(a) Alerts, Notifications or Warnings from a Consumer Reporting Agency.
1. A fraud or active duty alert is included with a consumer report provided to
the City;
2. A consumer reporting agency provides a notice of credit freeze in
response to a request for a consumer report by the City;
3. A consumer reporting agency provides a notice of address discrepancy to
the City;
4. A consumer report indicates a pattern of activity that is inconsistent with
the history and usual pattern of activity of an applicant or customer, such
as:
a. A recent and significant increase in the volume of inquiries;
b. An unusual number of recently established credit relationships;
c. A material change in the use of credit, especially with respect to
recently established credit relationships; or
d. An account that was closed for cause or identified for abuse of
account privileges by a financial institution or creditor.
(b) Suspicious Documents.
1. An identification document that appears altered, forged or inauthentic;
2. For an identification document that includes a photograph or physical
description, the photograph or physical description on the identification is
inconsistent with the appearance of the applicant or customer presenting
the identification;
3. An identification document that includes information which is inconsistent
with information provided by the person opening a new covered account
or by the customer presenting the identification;
4. An identification document that includes information that is inconsistent
with readily accessible information on file with the City, such as a
signature card or a recent check;
5. An application that appears to have been altered or forged, or destroyed
and reassembled.
(c) Suspicious Identification Information.
1. Identification information that is inconsistent with external information
sources used by the City. For example:
a. The address provided to the City does not match any address in the
consumer report; or
b. The Social Security Number (SSN) provided to the City has not
been issued, or is listed on the Social Security Administration's
Death Master File.
2. Identification information provided by the customer is inconsistent with
other identification information provided by the customer. For example,
there is a lack of correlation between the SSN range and date of birth.
3. Identification information provided by the customer is associated with
known fraudulent activity as indicated by internal or third-party sources
used by the City. For example:
Administrative Order -- Page 3 of 7
a. The address on an application is the same as the address provided
on a fraudulent application; or
b. The phone number on an application is the same as the number
provided on a fraudulent application.
4. Identification information provided is of a type commonly associated with
fraudulent activity as indicated by internal or third-party sources used by
the City. For example:
a. The address on an application is fictitious, a mail drop, or a prison;
(d)
or
b. The phone number is invalid, or is associated with a pager or
answering service.
5. The SSN provided is the same as that submitted by other persons opening
an account or by other customers.
6. The address or telephone number provided is the same as or similar to the
account- number or telephone number submitted by an unusually large
number of other persons opening accounts or by other customers.
7. The person opening the covered account or the customer fails to provide
all required identification information on an application or in response to
notification that the application is incomplete.
8. Identification information provided is not consistent with identification
information that is on file with the City.
Unusual Use of, or Suspicious Activity Related to, the Covered Account.
1. Shortly following the notice of a change of address for a covered account,
the City receives a request for the addition of authorized users on the
account.
2. Anew revolving credit account is used in a manner commonly associated
with known fraud patterns. For example:
a. The majority of available credit is used for cash advances or
merchandise that is easily convertible to cash (e.g., electronics
equipment or jewelry); or
b. The customer fails to make the first payment or makes an initial
payment but no subsequent payments.
3. A covered account is used in a manner that is not consistent with
established patterns of activity on the account. There is, for example:
a. Nonpayment when there is no history of late or missed payments;
b. A material increase in the use of available credit; or
c. A material change in purchasing or spending patterns.
4. A covered account that has been inactive for a reasonably lengthy period
of time is used (taking into consideration the type of account, the expected
pattern of usage and other relevant factors).
5. Mail sent to the customer is returned repeatedly as undeliverable although
transactions continue to be conducted in connection with the customer's
covered account.
6. The City is notified that the customer is not receiving paper account
statements.
Administrative Order -- Page 4 of 7
7. The City is notified of unauthorized charges or transactions in connection
with a customer's covered account.
(e) Notice from Customers Victims of Identity Theft, Law Enforcement Authorities,
or Other Persons Regarding Possible Identity Theft in Connection With Covered
Accounts Held by the Financial Institution or Creditor. The City is notified by a
customer, a victim of identity theft, a law enforcement authority, or any other
person that the City has opened a fraudulent account for a person engaged in
identity theft.
(4) Detection of Red Flays.
(a) To facilitate detection of the Red Flags noted in section 3 of this program in
connection with the opening of a new covered account, city staff will take the
following steps to attempt to verify the identity of the person opening the covered
account:
1. Request certain identifying information such as:
a. .Name, date of birth, social security number, drivers license
number, residential or business address (current and/or previous),
documentation showing the existence of a business entity and
address of principal place of business, or other similar
identification;
b. Review the documentation provided for Red Flags.
(b) To facilitate the detection of Red Flags in connection with an existing account,
city staff will take the following steps:
1. Attempt to verify the identity of customers if they request information
related to the covered account;
2. Attempt to verify the validity of requests for address changes or other
information related to the covered account;
3. Attempt to verify changes in information for payment purposes.
(5) Prevention and Mitigation of Identity Theft.
(a) The City Manager or designee will take the following steps to protect personal
information:
1. Require that any website or computer program used for storing or
processing personal information is secure or provide clear and obvious
notice that the website or program is not secure;
2. Require that office computers are password protected;
3. Require that when not needed for work purposes, documents containing
personal information be stored in a secure location;
4. Require that computer virus protection is up to date;
5. Provide training for employees on identity theft protection issues; and
6. Dispose of personal information once it is no longer needed by redacting
or destroying any physical records and by erasing electronic media so that
the personal information cannot be read or reconstructed. Any document
redaction or destruction shall be undertaken in accordance with state law
and the City's record retention policies.
Administrative Order -- Page 5 of 7
(b) In the event City staff detect one or more Red Flags, staff may take one or more
of the following actions, depending on the degree of risk that the Red Flag
indicates identity theft:
1. Continue to monitor a covered account for evidence of identity theft;
2. Contact the customer;
3. Change any passwords, security codes, or other security devices that
permit access to a covered account;
4. Reopen a covered account with a new account number;
5. Decline to open a new covered account;
6. Close an existing covered account;
7. Not attempt to collect on a covered account or not refer a covered account
to a debt collector;
8. Notify law enforcement; or
9. Determine that no response is warranted under the particular
circumstances.
(c) The head of each department, or the department head's designee, shall be
responsible for implementation of the Program for his or her department. The
City Manager will periodically update the Program (including the Red Flags
determined to be relevant) to reflect changes in risks to customers or the City
from identity theft, based on factors such as:
1. The experiences of the City with identity theft;
2. Changes in methods of identity theft;
3. Changes in methods to detect, prevent, and mitigate identity theft;
4. Changes in the types of accounts that the City offers or maintains; and
5. Changes in the business arrangements of the City, including service
provider arrangements.
(d) Each department head shall report to the City Manager by December 31st of each
year, beginning in 2010, on his or her department's compliance with the Program.
The report should address:
1. The covered accounts overseen or maintained by the department;
2. The effectiveness of the Program in addressing the risk of identity theft in
connection with the opening of covered accounts and with respect to
existing covered accounts;
3. Service provider arrangements;
4. Significant incidents involving identity theft and the department's
response;
. 5. Steps taken by the department to protect personal information; and
6. Recommendations for changes to the Program.
(e) If a department does not oversee any covered accounts, the annual report to the
City Manager may be limited to addressing steps taken by the department to
protect personal information.
(6) Oversight of service provider arrangements. Whenever the City engages a service
provider to perform an activity in connection with one or more covered accounts the City
will take steps to ensure that the activity of the service provider is conducted in
Administrative Order -- Page 6 of 7
accordance with reasonable policies and procedures designed to detect, prevent, and
mitigate the risk of identity theft.
(7) Verifyin~ Information in Consumer Reports.
(a) If the City receives a notice of address discrepancy from a consumer reporting
agency, city staff will take reasonable steps to verify that the consumer report
relates to the consumer about whom the City has requested the report. Those
steps may include:
1. Comparing the information in the consumer report with information the
City:
a. Obtains and uses to verify the consumer's identity;
b. Maintains in its own records, such as applications, change of
address notifications, other customer account records; or
c. Obtains from third-party sources.
2. Verifying the information in the consumer report provided by the
consumer reporting agency with the consumer.
(b) After taking reasonable steps to verify the consumer's address, the City shall
furnish an address for the consumer that the City has reasonably confirmed is
accurate to the consumer reporting agency if city staff:
1. Can form a reasonable belief that the consumer report relates to the
consumer about whom the City requested the report;
2. Have established a continuing relationship with the consumer; and
3. Regularly and in the ordinary course of business furnish information to the
consumer reporting agency from which the notice of address discrepancy
relating to the consumer was obtained.
(c) The City will furnish the consumer's address that city staff have reasonably
confirmed is accurate to the consumer reporting agency as part of the information
it regularly furnishes for the reporting period in which it establishes a relationship
with the consumer.
Dated this ~ g~day of November, 2009.
_____._~r~~
Jon R. Ruiz
City Manager
Administrative Order -- Page 7 of 7