Loading...
HomeMy WebLinkAboutAdmin Order 21-09-06ADMINISTRATIVE ORDER NO.21-09-06 of the City Manager City of Eugene, Oregon AMENDING THE EUGENE IDENTITY THEFT PROTECTION PROGRAM POLICIES PURSUANT TO THE FAIR AND ACCURATE CREDIT TRANSACTIONS ACT OF 2003, AND REPEAL OF ADMINISTRATIVE ORDER N0.21-08-07. The City Manager of the City of Eugene finds that: A. Under the provisions of Chapter IV, Section 16 of the Eugene Charter of 2002, the City Manager is designated as the administrative head of the City and specifically authorized to assign the duties of all administrative employees. B. The Fair and Accurate Credit Transactions (FACT) Act of 2003, Pub. Law 108- 159, and rules promulgated by the Federal Trade Commission (FTC) pursuant to the FACT Act, 16 C.F.R. 681, require the City to implement identity theft protection policies. In addition, the Oregon Consumer Identity Theft Protection Act, ORS 646A.600 through ORS 646A.628, requires the City to develop identity theft protection policies. C. The FTC had previously required that identity theft protection policies be implemented by November 1, 2008. Consequently, the City Manager issued Administrative Order No. 21-08-07 establishing the Eugene Identity Theft Protection Program Policies Pursuant to the Fair and Accurate Credit Transactions (FACT) Act of 2003, effective November 1, 2008. D. At the request of Members of Congress, the FTC is delaying enforcement of the identity theft protection policies until June 1, 2010. Therefore, it is necessary that the City delay the implementation date of its identity theft protection policies until June 1, 2010. As a result of the implementation delay, Section 5(d) of the Policies should be amended to revise the date on which department heads begin reporting to the City Manager to December 31, 2010. Based upon the above findings, Administrative Order No. 21-08-07 is repealed and the City of Eugene Identity Theft Protection Program Policies set out below are adopted effective June 1, 2010. The City of Eugene Identity Theft Protection Program Policies are designed to detect, prevent and mitigate identity theft and are appropriate to the size and complexity of the City and the nature and scope of the City's activities. CITY OF EUGENE IDENTITY THEFT PROTECTION PROGRAM POLICIES (1) Definitions. (a) "Account" means a continuing relationship established by a person with the City to obtain a product or service for personal, family, household or business purposes. Account includes: Administrative Order -- Page 1 of 7 1. An extension of credit, such as the purchase of property or services involving a deferred payment; and 2. A deposit account. (b) "Covered account" means: 1. An account that the City offers or maintains, primarily for personal, family, or household purposes, that involves or is designed to permit multiple payments or transactions, such as a mortgage loan or utility account; and 2. Any other account that the City offers or maintains for which there is a reasonably foreseeable risk to customers or to the safety and soundness of the City from identity theft, including financial, operational, compliance, reputation, or litigation risks. (c) "Customer" means a person that has a covered account with the City. (d) "Identity theft" means a fraud committed or attempted using the identifying information of another person without authority. (e) "Notice of address discrepancy" means a notice sent to the City by a consumer reporting agency that informs the City of a substantial difference between the address for the consumer that the City provided to request the consumer report and address(es) in the consumer reporting agency's file for the consumer. (f) "Personal information" means a person's name in combination with the following information: a Social Security Number; Oregon driver's license or Oregon identification card number; passport number; or financial, credit, or debit card numbers along with a security or access code or password; when the information is not rendered unusable through encryption, redaction or other methods. (g) "Red Flag" means a pattern, practice, or specific activity that indicates the possible existence of identity theft. (h) "Service provider" means a person that provides a service directly to the City. (2) Periodic Identification of Covered Accounts. Each City department must conduct an annual risk assessment to determine whether it offers or maintains covered accounts. The department shall take into consideration: (a) The methods it provides to open its accounts; (b) The methods it provides to access its accounts; and (c) Its previous experiences with identity theft. (3) Identification of Relevant Red Flays. After considering the types of covered accounts the City offers and maintains, the methods the City provides to open its covered accounts, _ the methods the City provides to access its covered accounts and the City's previous i3. ft rf .. )4 Administrative Order -- Page 2 of 7 a ~~~ experience with identity theft, the City Manager has identified the following categories and types of Red Flags: (a) Alerts, Notifications or Warnings from a Consumer Reporting Agency. 1. A fraud or active duty alert is included with a consumer report provided to the City; 2. A consumer reporting agency provides a notice of credit freeze in response to a request for a consumer report by the City; 3. A consumer reporting agency provides a notice of address discrepancy to the City; 4. A consumer report indicates a pattern of activity that is inconsistent with the history and usual pattern of activity of an applicant or customer, such as: a. A recent and significant increase in the volume of inquiries; b. An unusual number of recently established credit relationships; c. A material change in the use of credit, especially with respect to recently established credit relationships; or d. An account that was closed for cause or identified for abuse of account privileges by a financial institution or creditor. (b) Suspicious Documents. 1. An identification document that appears altered, forged or inauthentic; 2. For an identification document that includes a photograph or physical description, the photograph or physical description on the identification is inconsistent with the appearance of the applicant or customer presenting the identification; 3. An identification document that includes information which is inconsistent with information provided by the person opening a new covered account or by the customer presenting the identification; 4. An identification document that includes information that is inconsistent with readily accessible information on file with the City, such as a signature card or a recent check; 5. An application that appears to have been altered or forged, or destroyed and reassembled. (c) Suspicious Identification Information. 1. Identification information that is inconsistent with external information sources used by the City. For example: a. The address provided to the City does not match any address in the consumer report; or b. The Social Security Number (SSN) provided to the City has not been issued, or is listed on the Social Security Administration's Death Master File. 2. Identification information provided by the customer is inconsistent with other identification information provided by the customer. For example, there is a lack of correlation between the SSN range and date of birth. 3. Identification information provided by the customer is associated with known fraudulent activity as indicated by internal or third-party sources used by the City. For example: Administrative Order -- Page 3 of 7 a. The address on an application is the same as the address provided on a fraudulent application; or b. The phone number on an application is the same as the number provided on a fraudulent application. 4. Identification information provided is of a type commonly associated with fraudulent activity as indicated by internal or third-party sources used by the City. For example: a. The address on an application is fictitious, a mail drop, or a prison; (d) or b. The phone number is invalid, or is associated with a pager or answering service. 5. The SSN provided is the same as that submitted by other persons opening an account or by other customers. 6. The address or telephone number provided is the same as or similar to the account- number or telephone number submitted by an unusually large number of other persons opening accounts or by other customers. 7. The person opening the covered account or the customer fails to provide all required identification information on an application or in response to notification that the application is incomplete. 8. Identification information provided is not consistent with identification information that is on file with the City. Unusual Use of, or Suspicious Activity Related to, the Covered Account. 1. Shortly following the notice of a change of address for a covered account, the City receives a request for the addition of authorized users on the account. 2. Anew revolving credit account is used in a manner commonly associated with known fraud patterns. For example: a. The majority of available credit is used for cash advances or merchandise that is easily convertible to cash (e.g., electronics equipment or jewelry); or b. The customer fails to make the first payment or makes an initial payment but no subsequent payments. 3. A covered account is used in a manner that is not consistent with established patterns of activity on the account. There is, for example: a. Nonpayment when there is no history of late or missed payments; b. A material increase in the use of available credit; or c. A material change in purchasing or spending patterns. 4. A covered account that has been inactive for a reasonably lengthy period of time is used (taking into consideration the type of account, the expected pattern of usage and other relevant factors). 5. Mail sent to the customer is returned repeatedly as undeliverable although transactions continue to be conducted in connection with the customer's covered account. 6. The City is notified that the customer is not receiving paper account statements. Administrative Order -- Page 4 of 7 7. The City is notified of unauthorized charges or transactions in connection with a customer's covered account. (e) Notice from Customers Victims of Identity Theft, Law Enforcement Authorities, or Other Persons Regarding Possible Identity Theft in Connection With Covered Accounts Held by the Financial Institution or Creditor. The City is notified by a customer, a victim of identity theft, a law enforcement authority, or any other person that the City has opened a fraudulent account for a person engaged in identity theft. (4) Detection of Red Flays. (a) To facilitate detection of the Red Flags noted in section 3 of this program in connection with the opening of a new covered account, city staff will take the following steps to attempt to verify the identity of the person opening the covered account: 1. Request certain identifying information such as: a. .Name, date of birth, social security number, drivers license number, residential or business address (current and/or previous), documentation showing the existence of a business entity and address of principal place of business, or other similar identification; b. Review the documentation provided for Red Flags. (b) To facilitate the detection of Red Flags in connection with an existing account, city staff will take the following steps: 1. Attempt to verify the identity of customers if they request information related to the covered account; 2. Attempt to verify the validity of requests for address changes or other information related to the covered account; 3. Attempt to verify changes in information for payment purposes. (5) Prevention and Mitigation of Identity Theft. (a) The City Manager or designee will take the following steps to protect personal information: 1. Require that any website or computer program used for storing or processing personal information is secure or provide clear and obvious notice that the website or program is not secure; 2. Require that office computers are password protected; 3. Require that when not needed for work purposes, documents containing personal information be stored in a secure location; 4. Require that computer virus protection is up to date; 5. Provide training for employees on identity theft protection issues; and 6. Dispose of personal information once it is no longer needed by redacting or destroying any physical records and by erasing electronic media so that the personal information cannot be read or reconstructed. Any document redaction or destruction shall be undertaken in accordance with state law and the City's record retention policies. Administrative Order -- Page 5 of 7 (b) In the event City staff detect one or more Red Flags, staff may take one or more of the following actions, depending on the degree of risk that the Red Flag indicates identity theft: 1. Continue to monitor a covered account for evidence of identity theft; 2. Contact the customer; 3. Change any passwords, security codes, or other security devices that permit access to a covered account; 4. Reopen a covered account with a new account number; 5. Decline to open a new covered account; 6. Close an existing covered account; 7. Not attempt to collect on a covered account or not refer a covered account to a debt collector; 8. Notify law enforcement; or 9. Determine that no response is warranted under the particular circumstances. (c) The head of each department, or the department head's designee, shall be responsible for implementation of the Program for his or her department. The City Manager will periodically update the Program (including the Red Flags determined to be relevant) to reflect changes in risks to customers or the City from identity theft, based on factors such as: 1. The experiences of the City with identity theft; 2. Changes in methods of identity theft; 3. Changes in methods to detect, prevent, and mitigate identity theft; 4. Changes in the types of accounts that the City offers or maintains; and 5. Changes in the business arrangements of the City, including service provider arrangements. (d) Each department head shall report to the City Manager by December 31st of each year, beginning in 2010, on his or her department's compliance with the Program. The report should address: 1. The covered accounts overseen or maintained by the department; 2. The effectiveness of the Program in addressing the risk of identity theft in connection with the opening of covered accounts and with respect to existing covered accounts; 3. Service provider arrangements; 4. Significant incidents involving identity theft and the department's response; . 5. Steps taken by the department to protect personal information; and 6. Recommendations for changes to the Program. (e) If a department does not oversee any covered accounts, the annual report to the City Manager may be limited to addressing steps taken by the department to protect personal information. (6) Oversight of service provider arrangements. Whenever the City engages a service provider to perform an activity in connection with one or more covered accounts the City will take steps to ensure that the activity of the service provider is conducted in Administrative Order -- Page 6 of 7 accordance with reasonable policies and procedures designed to detect, prevent, and mitigate the risk of identity theft. (7) Verifyin~ Information in Consumer Reports. (a) If the City receives a notice of address discrepancy from a consumer reporting agency, city staff will take reasonable steps to verify that the consumer report relates to the consumer about whom the City has requested the report. Those steps may include: 1. Comparing the information in the consumer report with information the City: a. Obtains and uses to verify the consumer's identity; b. Maintains in its own records, such as applications, change of address notifications, other customer account records; or c. Obtains from third-party sources. 2. Verifying the information in the consumer report provided by the consumer reporting agency with the consumer. (b) After taking reasonable steps to verify the consumer's address, the City shall furnish an address for the consumer that the City has reasonably confirmed is accurate to the consumer reporting agency if city staff: 1. Can form a reasonable belief that the consumer report relates to the consumer about whom the City requested the report; 2. Have established a continuing relationship with the consumer; and 3. Regularly and in the ordinary course of business furnish information to the consumer reporting agency from which the notice of address discrepancy relating to the consumer was obtained. (c) The City will furnish the consumer's address that city staff have reasonably confirmed is accurate to the consumer reporting agency as part of the information it regularly furnishes for the reporting period in which it establishes a relationship with the consumer. Dated this ~ g~day of November, 2009. _____._~r~~ Jon R. Ruiz City Manager Administrative Order -- Page 7 of 7