Tuesday, February 24, 2009

Stimulus Bill COBRA Amendments Require Immediate Action

by Cynthia M. Stamer 

About the writer: 

cindy stamer

Cynthia Marcotte Stamer, is nationally and internationally recognized for her work assisting businesses, governments, and other entities to develop creative strategies for dealing with employee benefit and related human resources, insurance, health care and finance concerns. Ms. Stamer helps businesses design, administer and defend cost-effective employee benefit other human resources programs, policies and procedures to meet their budgetary and other business objectives.

Email Cynthia

Line
The American Recovery and Reinvestment Act of 2009 (the "Stimulus Bill") immediately expanded the group health plan coverage continuation obligations applicable to group health plans covered by the Consolidated Omnibus Budget Reconciliation Act (COBRA) a series of complicated temporary COBRA mandates that became immediately effective when President Obama signed the Stimulus Bill into law on February 17, 2009.

The COBRA amendments in the Stimulus Bill are the latest list in a series of new laws and regulations requiring changes in health plan eligibility rules, notices, administrative forms and practices. Employers, group health plan administrators and insurers must act quickly to review and update their COBRA and other health plan eligibility practices in response to these developments.

The COBRA Amendments enacted under the Stimulus Bill require that employers sponsoring group health plans and group health plan administrators take immediate steps to comply with a series of special temporary mandates applicable to certain individuals experiencing a loss of group health plan coverage due to the involuntary termination of an employee between September 1, 2008 and December 31, 2009 ("assistance-eligible individuals").

Highlights of the new COBRA mandates affecting group health plans enacted as part of the Stimulus Bill include the following:

  • Group health plans must notify assistance eligible individuals of the special COBRA rights granted under the Stimulus Bill. Although regulators are required to publish a model notice for this purpose by April 15, 2009, many group health plan sponsors and administrators will not want to delay providing required notifications until that time, as delay in notification extends the period that assistance-eligible individuals have to elect COBRA coverage.
  • The COBRA premium that a group health plans can charge an assistance-eligible individual for COBRA coverage is limited to 35 percent of the otherwise applicable COBRA premium for a period of up to 9 months.
  • Group health plans must offer assistance eligible individuals who previously did not elect COBRA coverage before February 17, 2009 a second chance to enroll in COBRA coverage within the 60-day period beginning on the date the group health plan provides the required notice of the Stimulus Bill COBRA rights. COBRA coverage for assistance eligible individuals making these second chance elections must begin with the first period of coverage beginning after February 16, 2009 (March 1, 2009 for most plans) and ends when COBRA coverage.
  • Group health plans offering participants different coverage options are required to allow assistance eligible individuals the opportunity to change their coverage elections under certain circumstances.
  • Employers may seek to recoup COBRA premiums paid by the employer to maintain COBRA coverage for assistance-eligible individuals in excess of reduced COBRA premium amounts paid by assistance-eligible individuals filing the necessary claims and reports to qualify to claim a payroll

    tax credit equal to those additional amounts. This payroll tax credit is the mechanism through which Congress sought under the Stimulus Bill to subsidize temporarily 65% of the COBRA premiums of assistance-eligible individuals.

In addition to these special COBRA Rules for assistance eligible individuals, the Stimulus Bill also amends extends COBRA benefits for certain employees and dependents whose qualifying event is a reduction in hours or termination of employment  where either:

  • The employee is eligible for certain Trade Adjustment Assistance; or
  • The covered employee had a non-forfeitable right to a benefit under a defined benefit plan which will be paid by the Pension Benefit Guaranty Corporation (PBGC) forfeitable right to a benefit.

For assistance in evaluating and responding to these and other employee benefit or human resources developments under the Stimulus Bill, contact Cynthia Marcotte Stamer at cstamer@solutionslawyer.net.

FTC – The Federal Trade Commission Obtains Court Order Halting Internet Payday Lenders Who Failed to Disclose Key Loan Terms and Used Abusive and Deceptive Collection Tactics

by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT® 

SUMMARY

The FTC and the State of Nevada are investigating 7 US-based companies and 1 international individual  operating Internet Payday Lending sites.  The FTC charges the companies with violating the FTC Act by using unfair and deceptive collection tactics, including falsely threatening consumers with arrest or imprisonment, falsely claiming that consumers are legally obligated to pay the debts, threatening to take legal action they cannot take, repeatedly calling consumers at work and using abusive and profane language, and disclosing consumers’ purported debts to co-workers, employers, and other third parties.  Read more …

News Item:  From The Federal Trade Commission (02/23/2009)

In a case filed by the Federal Trade Commission and the State of Nevada, a federal court has ordered a halt to certain practices by seven U.S.-based companies and an individual operating as part of an international Internet payday lending operation. They were charged with failing to disclose key loan terms and using abusive and deceptive collection tactics in violation of federal and state laws. The U.S.-based companies and their principal agreed to the court order, which will remain in effect pending trial. The FTC and Nevada seek to permanently bar the defendants from future violations and make them give up the money they obtained using the allegedly illegal collection tactics.

According to the FTC’s complaint, the companies offered loans of $500 or less within 24 hours without requiring a credit check, proof of income, or documentation. Consumers were told that they qualified for a loan that had to be repaid by their next payday with a fee ranging from $35 to $80, and that if the loan was not repaid by then, it would be extended automatically for an extra fee that would be debited from the consumer’s bank account “until the loan is repaid.”

The FTC charges the companies with violating the FTC Act by using unfair and deceptive collection tactics, including falsely threatening consumers with arrest or imprisonment, falsely claiming that consumers are legally obligated to pay the debts, threatening to take legal action they cannot take, repeatedly calling consumers at work and using abusive and profane language, and disclosing consumers’ purported debts to co-workers, employers, and other third parties. They also allegedly violated the Truth in Lending Act and Regulation Z by failing to make required written disclosures, clearly and conspicuously, before consummating a consumer credit transaction, including the amount financed, itemization of the amount financed, the finance charge, the annual percentage rate, the payment schedule, the total number of payments, and any late payment fees.

Pending trial, the court order bars the U.S.-based companies and their principal from deceptive debt collection practices such as misrepresenting that consumers can be arrested or imprisoned for failing to pay debts, that consumers are legally obligated to pay the full amount of a debt claimed as owed, and that for nonpayment consumers may or will be subject to legal action, such as a lawsuit, seizure of property, or garnishment of wages. The preliminary injunction also prohibits unfair collection practices such as continuously and repeatedly calling consumers and third parties at consumers’ work places, using obscene or threatening language toward consumers and third parties, and disclosing the existence of consumers’ purported debts to third parties.

The U.S.-based companies and their principal also are barred from violating the Truth in Lending Act and Regulation Z, in the extension of closed-end credit, by failing to make the required TILA disclosures as provided by law, and by failing in any other manner to comply with TILA and Regulation Z. They also are prohibited from violating the laws of the State of Nevada by making loans from Nevada or identifying Nevada as the source of a loan or as their principal place of business, unless properly licensed; and by failing to provide notice and disclosure of all material facts as required by state law, including failing to disclose the location, physical address, and non-toll-free telephone number of all of their locations. In addition, the U.S.-based companies and their principal are prohibited from violating any state or federal law regarding the sale or lease of goods or services, including using coercion, duress, or intimidation in any kind of transaction.

The injunction also bars the U.S.-based companies and their principal from disclosing or benefitting from customers’ personally identifiable or financial information, and it contains record-keeping provisions to allow the FTC to monitor compliance with the order.

The defendants named in the court order are Leads Global, Inc., Waterfront Investments, Inc., ACH Cash, Inc., HBS Services, Inc., Lotus Leads, Inc., First4Leads, Inc., and Rovinge International, Inc., and Jim Harris. Also charged in the complaint but not named in the order are four United Kingdom-based companies operating in the U.S. as Cash Today, Route 66 Funding, Global Financial Services International, Ltd., and Interim Cash, Ltd., and their principals, Aaron Gershfield and Ivor Gershfield.

NOTE: The Commission issues a complaint when it has “reason to believe” that the law has been or is being violated, and it appears to the Commission that a proceeding is in the public interest. These complaints are not a finding or ruling that the respondents have actually violated the law.

© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)

Friday, February 20, 2009

Unsafe At Any [Connection] Speed

by Kevin M Nixon, MSA, CISSP®, CISM®, CGEIT®

Introduction

I was surprised and very concerned at the number of responses I received to my article regarding a Blended Hack Attack.  The article was about how Hackers tricked people into going to a website to check to see if they had received a Parking Ticket.

Now, the creativity of combining a Social Engineering attack with a fake website is amazing but what really got me going were the number of people that think that using Apple's Macintosh system is "protection" against an attack.

I also realized that when one can remember the evolution of a hardware platform from an 8-bit processor chip with a dual 8" floppy storage system to the Mega Systems of today; that proves one thing.  I’m getting old!

Yes, A Mac Can Be Hacked and Infected Just Like PCs

Prior to January 1984, Apple had the Apple I, Apple II, and the Apple III.  There were no hard drives they ran on Dual 8" Floppy disks. The Apple I and II were Command Line systems.  No Mouse here.  The motherboard contained a single MOS 6502 8-bit chip! Steve Wozniak modified a version of BASIC and after using the booting with the floppy, the Boot Disk was removed and then the single application floppy was inserted into A: and the ONLY Commercially Off The Shelf application was Visicalc.  Apple-II improved speed by using the memory in the CRT device.  When the Apple III was released it came with Visicalc pre-burned on the chip. 

Then the world changed on January 22, 1984 during the 3rd quarter of Super Bowl XVIII when Apple unveiled the Macintosh 128K. This was the first MAC.  Up till then the devices were all named Apple.

Two days after the 1984 ad aired, the Macintosh went on sale. It came bundled with two applications designed to show off its interface: MacWrite and MacPaint.

>See Timeline of Mac Models

Apple is a vertically integrated product, meaning that Apple controls every aspect of the product including the operating system. The OSX operating system will only work on Apple computers.  

Despite the $1.5 Million spent on the Super Bowl Ad plus an additional $2.5 Million spent for a 39 page advertising brochure in Newsweek, Apple continued to struggle, due to various problems, such as lack of OS compatible application software, the monochrome-only display and the closed architecture.

Apple eventually gained success as a result of its introduction of desktop publishing (and later computer animation) through Apple's partnership with Adobe Systems which introduced the laser printer and Adobe PageMaker. Indeed, the Macintosh would become known as the de-facto platform for many industries including cinema, music, publishing and the arts.

Apple did briefly license some of its own application designs, but Apple did not allow other computer makers to "clone" the Mac until the 1990s, long after Microsoft dominated the marketplace with its broad licensing program. By then, it was too late for Apple to reclaim its lost market share.

At the 1997 Macworld Expo, Steve Jobs announced that Apple would be entering into partnership with Microsoft. Included in this was a five-year commitment from Microsoft to release Microsoft Office for Macintosh as well a US$150 million investment in Apple. It was also announced that Internet Explorer would be shipped as the default browser on the Macintosh.

Today, a modern Mac can boot on a Windows operating system with the boot camp utility, which lets you chose between OSX and Windows when starting the computer.

A PC is a generic architecture design of hardware that will allow a Linux or Windows operating system to boot.

PC manufactures' rely on OEM software, and do not vertically integrate their products.

As a result of the interoperability of PC architecture, PC's have around 95% market share, this is good news for the availability of software, and bad news for the availability of viruses.

The 2 Minute Mac-Hack

(source: Mac Hacked In Under 2 Minutes )

Within 2 minutes, of directing a MAC to a Web site that contained exploit code, the computer was under the hacker's control.

The hacker (Charlie Miller) was given a $10,000 cash prize AND was quickly given a nondisclosure agreement to sign, and he's not allowed to discuss particulars of his bug with anyone but Apple.

The Contest rules stated that the hacker could only take advantage of software that was preinstalled on the Mac, so the flaw he exploited must have been accessible by, or possibly inside, Apple's Safari browser.

So is an Apple Mac immune to Hacks, Worms or a Virus?  NO!

Every Mac owner needs to be just as concerned as a PC owner.

If a Mac was not able to be hacked or infected why would the Apple Support Website publish Security Update Patches?  Mac owners should review the following pages at Apple support and update and patch just like 95% of all computer owners!

From the Apple Support Website:
Apple Security Updates
Apple security updates (25-Jan-2005 to 21-Dec-2007)
Apple security updates (03-Oct-2003 to 11-Jan-2005)
Apple security updates (August, 2003 and earlier)
VirusBarrier X5

© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)

 

Parking Ticket Leads to PC Virus Attack

by Kevin M Nixon, MSA, CISSP, CISM, CGEIT

At 11:47 AM CST – 02-20-09 I posted this story on Daily Kos and my comment meter went off the scale.  People just couldn’t believe that something like this could be true.

I have to give a “SHOUT OUT” to my friend “Sparky” (Shannon Myers-Leitz at GotMetrics.com) for sharing this story.

Firewalls. Corrupted files. Spam with bad code.  Those were the traditional vectors hackers used to plant malware on a system or gain access to a workstation. Now they just give you a parking ticket.  

Last week the SANS Internet Storm Center discovered a case in Grand Forks, North Dakota where yellow card-like fliers presumed to be parking  tickets were found on cars in a parking lot.

The would-be tickets read: "PARKING VIOLATION: This vehicle is in violation of standard parking regulations."

The card then instructs the ticket recipient to visit a specified Web Site. From this point, hackers count on law-abiding users to go home and log on where, strangely enough, they'll see a picture the parking lot where their car was. A few clicks later, a fake Internet Explorer security alert pops up asking the user if they'd like to do a quick antivirus scan. The infection starts from there.

Lesson learned:  Go Green! Take Public Transportation.

Forensics of the Hack

With the “Parking Ticket” in hand, lawful citizens went to the website only to discover a photo of their car!

parking1rt5

The picture displayed was of cars in that location (not the ticket holders car) with the prompt to use the Picture Search Tool.  This leads the person to believe that they can search through a series of photos looking for their car.  So CLICK, and then the fun begins.

The Picture Search Tool is know as a Browser Help Object (BHO).  The BHO seemed to wait for the user to browse the Internet a bit, and then brings up a pop-up with a fake security alert:

Error Message

The initial program installed itself as a browser helper object (BHO) for Internet Exploter that downloaded a component from childhe.com and attempted to trick the victim into installing a fake anti-virus scanner from bestantispyware securityscan.com and protectionsoft warecheck.com.

Attackers continue to come up with creative ways of tricking potential victims into installing malicious software. Merging physical and virtual worlds via objects that point to websites is one way to do this. I imagine we'll be seeing such approaches more often.

© Copyright 2009 – Kevin M. Nixon – All Rights Reserved – See: Information Security Resources
(This article may be reprinted in whole or in part only with proper attribution to the author.)

Powered By Blogger