GMR Transcription Services, Inc.
Volume 158 · 158 F.T.C. 90
privacy data securityonline internet
Cite this decision
GMR Transcription Services, Inc., 158 F.T.C. 90 (2014). Consumer Law Library, https://consumerlawlibrary.org/decisions/v158-0006
Report an error in this record (decision id v158-0006)
Cited by 0 later FTC decisions
Cites
Text (OCR of the scan at left; may contain errors)
IN THE MATTER OF GMR TRANSCRIPTION SERVICES, INC.;
AJAY PRASAD;
AND SHREEKANT SRIVASTAVA CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4482; File No. 122 3095 Complaint, August 14, 2014 – Decision, August 14, 2014 This consent order GMR Transcription Services, Inc.’s practices to protect consumers’ personal information from unauthorized access. The complaint alleges that engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumers’ personal information. The complaint further alleges that as a result of these security failures files were publicly available, and were accessed, using a major search engine. The consent order requires respondents to establish and maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. The order also prohibits respondents from misrepresenting the extent to which respondents use, maintain, and protect the privacy, confidentiality, security, or integrity of personal information collected from or about consumers.
Participants For the Commission: Kandi Parsons and Alain Sheer. For the Respondents: Barry Coburn, Kimberly Jandrain, Lloyd Lui, and Monica Seaman, Coburn & Greenbaum PLLC. COMPLAINT The Federal Trade Commission, having reason to believe that GMR Transcription Services, Inc., Ajay Prasad, and Shreekant Srivastava have violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges: GMR TRANSCRIPTION SERVICES, INC. 91 Complaint 1. GMR Transcription Services, Inc. (“GMR”), is a California corporation with its principal office at 2512 Chambers Road, Suite 206, Tustin, CA 92780.
2. Respondent Ajay Prasad is president of respondent GMR and owns 80% of the company. He has authority to control the conduct of respondent GMR. Individually or in concert with others he formulates, directs, or controls the policies, acts, or practices of respondent GMR, including the acts or practices alleged in this complaint. His principal office or place of business is the same as respondent GMR.
3. Respondent Shreekant Srivastava is vice president of respondent GMR and owns 20% of the company. He has authority to control the conduct of respondent GMR. Individually or in concert with others he formulates, directs, or controls the policies, acts, or practices of respondent GMR, including the acts or practices alleged in this complaint. His principal office or place of business is the same as respondent GMR. 4. The acts and practices of respondents alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.
5. At all relevant times, respondents have been in the business of transcribing digital audio files (“audio files”) for individuals and businesses in a variety of professions and industries. Respondents’ customers include: university students and faculty; well-known corporations (including retailers, insurers, and telecom and financial service providers); government agencies; and health care providers and hospitals. 6. Respondents conduct their transcription business almost entirely online using: respondents’ own computers and devices; various websites; and computers and devices leased from thirdparty service providers that are operated by or for respondents (collectively, “respondents’ computer network”). 7. In conducting business, respondents rely almost exclusively on independent service providers to transcribe audio files that respondents assign to them. Respondents: VOLUME 158 Complaint a. assign non-medical audio file transcriptions to at least 100 independent typists located in North America; and b. automatically assigned all medical audio file transcriptions to Fedtrans Transcription Services, Inc. (“Fedtrans”), between at least January 1, 2009, and May 1, 2012. Fedtrans, which is located in India, assigned respondents’ files to independent typists to transcribe.
8. At all relevant times, respondents’ transcription process began when a customer logged in to one of respondents’ websites and uploaded an audio file to a leased server located on respondents’ computer network. Based on the type of file, respondents assigned the audio file to one of their independent typists or Fedtrans. After being notified of the assignment, the typist or Fedtrans logged in to the website and downloaded the file. Fedtrans followed a similar process through which an independent typist downloaded the file from Fedtrans’ computer network. After downloading it, the typist converted the audio file into a Microsoft Word file (“transcript file”) and then followed the reverse process to upload it back to respondents’ computer network. Afterwards, respondents either emailed the transcript file to the customer or notified the customer to retrieve the file from respondents’ computer network.
9. Audio files and transcript files can include sensitive information from or about consumers, including children. This information can include, but is not limited to: names, dates of birth, addresses, email addresses, telephone numbers, Social Security numbers, driver’s license numbers, tax information, medical histories, health care providers’ examination notes, medications, and psychiatric notes (collectively, “personal information”).
10. Since at least 2006, respondents have disseminated or caused to be disseminated privacy policies and statements, including, but not necessarily limited to, the following statements regarding the privacy and security of personal information: Why GMR Transcription Services? . . . Security Measures to Protect Your Confidentiality. GMR TRANSCRIPTION SERVICES, INC. 93 Complaint Each transcriptionist within the GMR community is required to sign a Confidentiality Agreement prior to working for us. This is kept on file. You can be assured that the materials going through our system are highly secure and are never divulged to anyone. (Exhibit A: www.gmrtranscription.com (from 2006 through 2013)).
HIPAA Compliant Medical Transcription Service (Exhibit B: www.gmrmedicaltranscription.com (from 2006 through May 2012)).
It is often asked what one needs to be careful while choosing an outsourcing transcription company. In the medical industry, security and privacy are extremely important. In outsourcing arrangements with services and healthcare vendors, you can check the vendor’s expertise and credibility by HIPAA compliance. Amongst all the rules that are stipulated by HIPAA, ones concerned with security, health care compliance and privacy are deemed to be important by outsourcing experts. The benefits include giving greater accuracy, data security, and absolute privacy for all of their patient’s (sic) records and documents. Look for a company that is HIPAA compliant and takes proper measures to ensure security, health care compliance and privacy. A good company will make sure that the sensitive information related to patients is handled with great care. From compliance training and secure systems to the confidentiality agreements, Transcription Companies cover all the aspects involved in the HIPAA regulations.
(Exhibit C: GMR Blog, http://blog.gmrtranscription.com /securing-medical-transcription-data-with-hipaa/ (posted Feb. 23, 2010 through present)).
VOLUME 158 Complaint HIPAA compliant medical transcription is the basic need of any medical professionals and hospitals. (Exhibit D: Twitter (Sept. 19, 2010) @gmrtranscript). 11. Respondents have engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security to protect personal information in audio and transcript files. Among other things, respondents failed to: a. require typists to adopt and implement security measures, such as installing anti-virus applications, or confirm that they had done so;
b. adequately verify that their service provider, Fedtrans, implemented reasonable and appropriate security measures to protect personal information in audio and transcript files on Fedtrans’ network and computers used by Fedtrans’ typists. For example, respondents did not:
i. require Fedtrans by contract to adopt and implement appropriate security measures to protect personal information in medical audio and transcript files, such as by requiring that files be securely stored and securely transmitted to typists (e.g., through encryption) and authenticating typists (e.g., through unique user credentials) before granting them access to such files; and ii. take adequate measures to monitor and assess whether Fedtrans employed measures to appropriately protect personal information under the circumstances. Respondents did not request or review relevant information about Fedtrans’ security practices, such as, for example, Fedtrans’ written information security program or audits or assessments Fedtrans may have had of its computer network.
12. As a result of these security failures, respondents were unaware that Fedtrans used a File Transfer Protocol (“FTP”) GMR TRANSCRIPTION SERVICES, INC. 95 Complaint application to both store medical audio and transcript files on its computer network and transmit the files between the network and its typists. The application stored and transmitted files in clear readable text and was configured so that the files could be accessed online by anyone without authentication. A major search engine therefore was able to reach the Fedtrans FTP application and index thousands of medical transcript files that respondents had assigned to Fedtrans (collectively, the “Fedtrans files”). The files were publicly available, and were accessed, using the search engine.
13. The Fedtrans files were prepared between March 2011 and October 2011. They included personal information, such as names, dates of birth, health care provider names, examination notes, medical histories, medications, and, in some cases, employment histories and marital status. Some of the files contained children’s examination notes and highly sensitive medical information, such as information about psychiatric disorders, alcohol use, drug abuse, and pregnancy loss. Such information can easily be misused to cause substantial consumer injury, such as identity theft, and unauthorized access can cause harm by disclosing sensitive private medical information. 14. Respondents could have corrected their security failures using readily available, low-cost security measures. 15. Consumers have no way of independently knowing about respondents’ security failures and could not reasonably avoid possible harms from such failures.
16. After being informed that the Fedtrans files were available online in clear readable text, respondents notified Fedtrans and asked the search engine that had indexed the files to remove the files from its cache.
VIOLATIONS OF THE FTC ACT COUNT I 17. Through the means described in Paragraph 10, respondents represented, expressly or by implication, that they implemented reasonable and appropriate security measures to VOLUME 158 Complaint prevent unauthorized access to the personal information in audio and transcript files.
18. In truth and in fact, as described in Paragraphs 11-14, respondents did not implement reasonable and appropriate security measures to prevent unauthorized access to personal information in audio and transcript files. Therefore, the representation set forth in Paragraph 17 was false or misleading and constitutes a deceptive act or practice. COUNT II 19. Through the means described in Paragraph 10, respondents represented, expressly or by implication, that they took reasonable measures to oversee their service providers to ensure such service provider implemented reasonable and appropriate security measures.
20. In truth and in fact, as described in Paragraphs 11-14, respondents did not take reasonable measures to oversee their service providers to oversee ensure such service providers implemented reasonable and appropriate security measures. Therefore, the representation set forth in Paragraph 19 was false or misleading and constitutes a deceptive act or practice. COUNT III 21. As set forth in Paragraphs 11-15, respondents failed to employ reasonable and appropriate measures to prevent unauthorized access to personal information in audio and transcript files. Respondents’ practices caused, or are likely to cause, substantial injury to consumers that is not outweighed by countervailing benefits to consumers or competition and is not reasonably avoidable by consumers. This practice was, and is, an unfair act or practice.
22. The acts and practices of respondents as alleged in this complaint constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.
GMR TRANSCRIPTION SERVICES, INC. 97 Complaint THEREFORE, the Federal Trade Commission this fourteenth day of August, 2014, has issued this complaint against respondents.
By the Commission, Commissioner McSweeny not participating.
VOLUME 158 Complaint Exhibit A GMR TRANSCRIPTION SERVICES, INC.
Transcriptan Sanne ee La Rusinest Trarecision Cael Cal Traracsgees Ticisige Traspergion focus group Treeacoior Dewenmernwionganizalion here Thinncipht heumncn Trerecrpion Prat pitied TAenonen Lege! Trargotpiar:
Mariet eseeect Poaeiipten Werdicn! Transcriotion Wieeing Trees oro Microcanpate Tranuctpion (Poccia! Tratserube demon Taesergton Tartintart Tearteroben Nantaraon Treecigon Video Tankian Langengs Tranzerpticn Spenian Trang cayioa Marden Tremctcton uae Ta Engith aciiratrin Trrtion Manager ts Engien Translation Engiht oe Spanish Troniton Seerin Eegee Ture ece Theo ot Ponto Wasiow Files Acedia &aaa B32 a oe oh Tent Files Accepted a = 5 2 oe oe Other cations V1 Peochiews Stem WI, Sete 300 Agorca, GAMO CTP nL Mier aavtrees, Complaint Gmr Transcription -Confidential Non-Disclosure Tot Free: 1-800-F21-74i2 Gall Us: 714-202-8653 2612 Chawrbers Roend, Sulte 286.
Pantin Caldeerde - 12P0E Conidany Kondiiscissire Tech banecplionia witvn fre CMM cores ob recone ba alge Corfetndiaity Agreenen| prior ip sorting fpr us. Thad aap! on te. Piau cirt ee ainieared that ie Pasig going among? ger syringe Ughiy mecug and oa cae deaged to dfyere ORSe aaron! fas Bee COMMMET Sed cuberimes, i118 Comm aletely asleted Perna haeoigbore's computer That a legely feet agrenant petesen Gai Trereccatcr ard ach eivdusl horsersboel We ee etirg lpg ty pecs once Agroceiest eth dey Gaia ato raquecz one Pegge infor ua of ha reed in do gy peor is registering, or et erry tine, by conisctieg ua ai: eingacerecmts com hitps..wwew.gmrtransen pion com/eentidential. aspx ificas Page | of 2 Cares | Fath | Blog Glen Area aah cena ere Kobe og Fort ypt Paonia + Pasured on PAW & BAM Chews parva ATS Foam haport 11 MuwbHovs's Te Lenk For ‘hee Hirieg © Trarnecristion Company Enter hire Greer Gaal unm oP” IPE Ne MIELE PASE: on aewetaerar ened UPLOAD TOUR FILES.
fret WAI VOLUME 158 Complaint Exhibit B GMR TRANSCRIPTION SERVICES, INC. 101 Complaint Exhibit C Securing Medical Transcription Data With HIPAA | GME Transenption Page | of 4 GMR Transcription Toll Free: 1-80(- 731-7412 | Call Us: (714) 202-9653 2312 Chambers Road, Suite 206 Tustin, California - 92780 Contact Ls Securing Medical Transcription Data With HIPAA 0 | Like 0 Tweet oO Itis often asked what one needs to be careful while choosing an outsourcing transcription company, In the medical industry, security and privacy are extremely important, In outsourcing arrangements with services and healthcare vendors, you can cheek the vendor's expertise and credibility by HIPAA compliance. Amongst all the rules that are stipulated by HIPAA, ones concemed with security, health cure compliance and privacy are deemed to be important by outsourcing experts. The benefits include giving greater accuracy, data security, and absolute privacy for all of their patient's records and documents.
Look for a company that is HIPAA compliant and takes proper measures to ensure security, health care compliance and privacy. A good company will make sure that the sensitive information related to patients is handled with great care, From compliance training and secure systems to the confidentiality agreements, Transcription Companies cover all the aspects invelved in the HIPAA regulations. Transferred medical files should always be encrypted while moving between transcriptionists and medical providers. This will help to ensure absolute safety and privacy of the data. Use of logged systems and high secunty firewalls restrict movernent of information while locking it down to the system on which personnel works. You can also request the transeription company to work on your company’s servers too, They operate remotely through your computers, nullifying data theft risks. Email access is also banned or restricted for process managers working on healthcare projects while handling customer data. Access to USB and floppy drives is banned so that there is no privacy breach.
[tis important to know that those who work for the company are qualified to work in the medical transcription industry. They must have knowledge of medical terms, procedures, and need to have completed traning on initenational coding standards. Coders have various levels of expertise and experience. These coders are regularly updated with contemporary methodologies that work in the best interest of your company.
While hiring a transcription company, one of the mest important things to look at isto ensure that the company has effective safeguards to keep private information secure, Also find our if the company does http. blog. pmirtransenption.com/securing-medical-transeripeion—lata-with-hipaas 27013 VOLUME 158 Complaint Securing Medical Transenption Data With HIPAA | GMR Transenption Page 2 of 4 check backgrounds of their employees. They should have strict rules to find out the credibility of new employees; after all you do not want your company's sensitive work to be handled by unreliable personnel.
About Mail Web Mare Poors (42 Sj transcription | admin February 23, 2010 RSS feed for comments on this post. TrackBack URI Leave a Reply You must be logged in to post a comment. * Search for: | Search « = Enter your email address:
Subsaribe Delivered by FeedBumer GMR Transcription, & Scholarship for »~ College Students $500 Cash and More...
APPLY NOW « BLOGGERS https ‘blog. errtranseription,com/securing-medical-transeri ption-data-with-hipaa! W2W2013 GMR TRANSCRIPTION SERVICES, INC.
Complaint Exhibit D Twitter / gmrtranscript: HIPAA compliant medical .. since GMR Transcription Follow Worertranscrpt HIPAA compliant medical transcription is the basic need of any medical professionals and hospitals.
Reply Revues Favorite More Ti AM - 19 Sep 10 Don't miss any updates from GMR Transcription Join Twitter today and foSow what interests you! Full name Email Password Slqai-ap.
Téat Pollow gmintranseript te 40404 in the United States &2013 Twitter About Hee https: twitter.com) pmirtranscriptstamis 2495682 53807 Page | of 2 272014 VOLUME 158 Decision and Order DECISION AND ORDER The Federal Trade Commission having initiated an investigation of certain acts and practices of the Respondents named in the caption hereof, and the Respondents having been furnished thereafter with a copy of a draft Complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge the Respondents with violation of the Federal Trade Commission Act, 15 U.S.C. § 45 et seq; The Respondents, their attorneys, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), an admission by the Respondents of all the jurisdictional facts set forth in the aforesaid draft Complaint, a statement that the signing of said Consent Agreement is for settlement purposes only and does not constitute an admission by Respondents that the law has been violated as alleged in such Complaint, or that the facts as alleged in such Complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it has reason to believe that the Respondents have violated the said Act, and that a Complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such Consent Agreement on the public record for a period of thirty (30) days, and having duly considered the comments filed thereafter by interested persons pursuant to Commission Rule 2.34, 16 C.F.R. § 2.34, now in further conformity with the procedure described in Commission Rule 2.34, the Commission hereby issues its Complaint, makes the following jurisdictional findings and enters the following Order: 1. Respondent GMR is a California corporation with its principal office or place of business at 2512 Chambers Road, Suite 206, Tustin, CA 92780.
2. Respondents Ajay Prasad (“Prasad”) and Shreekant Srivastava (“Srivastava”) are co-owners of GMR and President and Vice President of the company, GMR TRANSCRIPTION SERVICES, INC. 105 Decision and Order respectively. Individually or in concert with others, they formulate, direct, or control the policies, acts, or practices of respondent GMR. Their principal place of business is the same as GMR’s.
ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:
A. Unless otherwise specified, “respondents” shall mean GMR Transcription Services, Inc., and its successors and assigns, and Ajay Prasad and Shreekant Srivastava.
B. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. C. “Personal information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license number or other government-issued identification number; (g) a bank account, debit card, or credit card account number; (h) a persistent identifier, such as a customer number held in a “cookie” or processor serial number; and (i) medical information about a consumer including, but not limited to, prescription information, clinical laboratory testing information, health insurance information, physician examination notes, and medical history. For the purpose of this provision, a “consumer” shall mean any person, including, but not limited to, any user of respondents’ services, any person whose information is contained in the files of a VOLUME 158 Decision and Order user of respondents’ services, and respondents’ employees and service providers.
I.
IT IS ORDERED that respondents and their officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device or affiliate owned or controlled by respondents, shall not misrepresent in any manner, expressly or by implication, the extent to which respondents use, maintain, and protect the privacy, confidentiality, security, or integrity of personal information collected from or about consumers. II.
IT IS FURTHER ORDERED that respondent GMR Transcription Services, Inc., its successors and assigns, and any business entity that respondent Ajay Prasad or Shreekant Srivastava controls, directly or indirectly, that collects, maintains, or stores personal information from or about consumers, shall, no later than the date of service of this order, establish and implement, and thereafter maintain, a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. Such program, the content and implementation of which must be fully documented in writing, shall contain administrative, technical, and physical safeguards appropriate to respondents’ or the business entity’s size and complexity, the nature and scope of respondents’ or the business entity’s activities, and the sensitivity of the personal information collected from or about consumers, including: A. the designation of an employee or employees to coordinate and be accountable for the information security program;
B. the identification of material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, GMR TRANSCRIPTION SERVICES, INC. 107 Decision and Order and assessment of the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment should include consideration of risks in each area of relevant operation, including, but not limited to: (1) employee training and management; (2) information systems, including network and software design, information processing, storage, transmission, and disposal; and (3) prevention, detection, and response to attacks, intrusions, or other systems failures;
C. the design and implementation of reasonable safeguards to control the risks identified through risk assessment, and regular testing or monitoring of the effectiveness of the safeguards’ key controls, systems, and procedures;
D. the development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from respondents, and requiring service providers by contract to implement and maintain appropriate safeguards; and E. the evaluation and adjustment of the information security program in light of the results of the testing and monitoring required by subpart C, any material changes to any operations or business arrangements, or any other circumstances that respondents know or have reason to know may have a material impact on the effectiveness of the information security program. III.
IT IS FURTHER ORDERED that, in connection with its compliance with Part II of this order, respondents shall obtain initial and biennial assessments and reports (“Assessments”) from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession. Professionals qualified to prepare such assessments shall be: a person qualified as a Certified Information System Security Professional (CISSP) or as a Certified Information VOLUME 158 Decision and Order Systems Auditor (CISA); a person holding Global Information Assurance Certification (GIAC) from the SANS Institute; or a qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580. The reporting period for the Assessments shall cover: (1) the first one hundred and eighty (180) days after service of the order for the initial Assessment, and (2) each two (2) year period thereafter for twenty (20) years after service of the order for the biennial Assessments. Each Assessment shall:
A. set forth the specific administrative, technical, and physical safeguards that respondents have implemented and maintained during the reporting period;
B. explain how such safeguards are appropriate to respondents’ or the business entity’s size and complexity, the nature and scope of respondents’ or the business entity’s activities, and the sensitivity of the personal information collected from or about consumers;
C. explain how the safeguards that have been implemented meet or exceed the protections required by Part II of this order; and D. certify that the security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period. Each Assessment shall be prepared and completed within sixty (60) days after the end of the reporting period to which the Assessment applies. Respondents shall provide the initial Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been completed. All subsequent biennial Assessments shall be retained by respondents until the order is terminated and provided to the Associate Director for Enforcement within ten (10) days of GMR TRANSCRIPTION SERVICES, INC. 109 Decision and Order request. Unless otherwise directed by a representative of the Commission, the initial Assessment, and any subsequent Assessments requested, shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, D.C. 20580, with the subject line In the matter of GMR Transcription Services, Inc., FTC File No. 1123120. Provided, however, that in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of any such notice is contemporaneously sent to the Commission at [email protected]. IV.
IT IS FURTHER ORDERED that respondents shall maintain and, upon request, make available to the Federal Trade Commission for inspection and copying:
A. for a period of three (3) years after the date of preparation of each Assessment required under Part III of this order, all materials relied upon to prepare the Assessment, whether prepared by or on behalf of respondents, including but not limited to, all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, and any other materials relating to respondents’ compliance with Parts II and III of this order, for the compliance period covered by such Assessment;
B. unless covered by IV.A, for a period of five (5) years from the date of preparation or dissemination, whichever is later, a print or electronic copy of each document relating to compliance with this order, including but not limited to:
1. all advertisements and promotional materials containing any representations covered by this order, with all materials used or relied upon in making or disseminating the representation; and VOLUME 158 Decision and Order 2. any documents, whether prepared by or on behalf of respondents, that contradict, qualify, or call into question compliance with this order.
V.
IT IS FURTHER ORDERED that respondents shall deliver copies of the order as directed below:
A. Respondents shall deliver a copy of this order to (1) all current and future principals, officers, directors, and managers, (2) all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order, and (3) any business entity resulting from any change in structure set forth in Part VI. Respondents shall deliver this order to such current personnel within thirty (30) days after service of this order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities. For any business entity resulting from any change in structure set forth in Part VI, delivery shall be at least ten (10) days prior to the change in structure.
B. Respondents shall secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section.
VI.
IT IS FURTHER ORDERED that respondents Prasad and Srivastava, for a period of ten (10) years after the date of issuance of the order, shall notify the Commission of the following: (a) Any changes to respondent Prasad’s or respondent Srivastava’s residence, mailing addresses and/or telephone numbers, within ten (l0) days of the date of such change; (b) Any changes in respondent Prasad’s or respondent Srivastava’s employment status (including self-employment), and any changes in ownership in any business entity, within ten (10) days of the date of such change. Such notice shall include: the name and address of each business that respondent Prasad or respondent Srivastava is GMR TRANSCRIPTION SERVICES, INC. 111 Decision and Order affiliated with, employed by, creates or forms, incorporates, or performs services for; a detailed description of the nature of the business; and a detailed description of respondent Prasad’s or respondent Srivastava’s duties and responsibilities in connection with the business or employment; and (c) Any changes in respondent Prasad’s or respondent Srivastava’s name or use of any aliases or fictitious names, including “doing business as” names. All notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, D.C. 20580, with the subject line In the matter of GMR Transcription Services, Inc., FTC File No.1123120. Provided, however, that in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of any such notice is contemporaneously sent to the Commission at [email protected]. VII.
IT IS FURTHER ORDERED respondents shall notify the Commission at least thirty (30) days prior to any change in respondents that may affect compliance obligations arising under this order, including, but not limited to, a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor company; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in either corporate name or address. Provided, however, that, with respect to any proposed change in the corporation about which respondents learn less than thirty (30) days prior to the date such action is to take place, respondents shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission, all notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, D.C. 20580, with the subject line In the matter of GMR Transcription Services, Inc., FTC File No.1123120. Provided, however, that in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of any such VOLUME 158 Decision and Order notice is contemporaneously sent to the Commission at [email protected].
VIII.
IT IS FURTHER ORDERED that respondents, within sixty (60) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, it shall submit additional true and accurate written reports.
IX.
This order will terminate on August 14, 2034, or twenty (20) years from the most recent date that the United States or the Federal Trade Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part in this order that terminates in less than twenty (20) years;
B. This order’s application to any respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.
Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission, Commissioner McSweeny not participating.
GMR TRANSCRIPTION SERVICES, INC. 113 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, a consent agreement from GMR Transcription Services, Inc. (“GMR”), Ajay Prasad (“Prasad”), and Shreekant Srivastava (“Srivastava”) (taken together, “respondents”) The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. Respondents are in the business of transcribing digital audio files for individuals and businesses in a variety of professions and industries. Respondents conduct their transcription business almost entirely online, where customers can upload audio files for transcription. Respondents rely almost exclusively on independent service providers to transcribe audio files that respondents assign to them. Respondents assign non-medical audio file transcriptions to at least 100 independent typists located in North America, and, between at least January 1, 2009, and May 1, 2012, automatically assigned all medical audio file transcriptions to Fedtrans Transcription Services, Inc. (“Fedtrans”). Fedtrans, which is located in India, assigned respondents’ files to independent typists to transcribe. After being notified of the assignment, the typist or Fedtrans logged in to the website and downloaded the file. Fedtrans followed a similar process through which an independent typist downloaded the file from Fedtrans’ computer network. Following the transcription, respondents either emailed the transcript file to the customer or notified the customer to retrieve the file from respondents’ computer network. Audio files and transcript files can include sensitive information from or about consumers, including children, such as: names, dates of birth, addresses, email addresses, telephone numbers, Social Security numbers, driver’s license numbers, tax information, medical histories, health care providers’ examination notes, medications, and psychiatric notes (collectively, “personal information”). VOLUME 158 Analysis to Aid Public Comment The Commission’s complaint alleges that respondents misrepresented that they maintained reasonable and appropriate practices to protect consumers’ personal information from unauthorized access and that respondents took reasonable steps to ensure that those engaged in transcribing medical files complied with applicable security and privacy requirements. Respondents engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumers’ personal information. Among other things, respondents failed to: a. require typists to adopt and implement security measures, such as installing anti-virus applications, or confirm that they had done so;
b. adequately verify that their service provider, Fedtrans, implemented reasonable and appropriate security measures to protect personal information in audio and transcript files on Fedtrans’s network and computers used by Fedtrans’s typists. For example, respondents did not: i. require Fedtrans by contract to adopt and implement appropriate security measures to protect personal information in medical audio and transcript files, such as by requiring that files be securely stored and securely transmitted to typists (e.g., through encryption) and authenticating typists (e.g., through unique user credentials) before granting them access to such files; and ii. take adequate measures to monitor and assess whether Fedtrans employed measures to appropriately protect personal information under the circumstances. Respondents did not request or review relevant information about Fedtrans’s security practices, such as, for example, Fedtrans’s written information security program or audits or assessments Fedtrans may have had of its computer network.
The complaint further alleges that as a result of these security failures, respondents were unaware that Fedtrans used an application on its computer network that stored and transmitted medical audio and transcript files in clear readable text and was GMR TRANSCRIPTION SERVICES, INC. 115 Analysis to Aid Public Comment configured so that the files could be accessed online by anyone without authentication. A major search engine therefore was able to reach the application and index thousands of medical transcript files that respondents had assigned to Fedtrans. The files were publicly available, and were accessed, using the search engine. The Fedtrans files, which were prepared over at least eight months, included personal information such as names, dates of birth, health care provider names, examination notes, medical histories, medications, and, in some cases, employment histories and marital status. Some of the files contained highly sensitive medical information, such as information about psychiatric disorders, alcohol use, drug abuse, and pregnancy loss, and notes of examinations of children.
Information contained in the Fedtrans and other files can easily be misused to cause substantial consumer injury, such as identity theft, and unauthorized access can cause harm by disclosing sensitive private medical information. Respondents could have corrected their security failures using readily available, low-cost security measures. Consumers have no way of independently knowing about respondents’ security failures and could not reasonably avoid possible harms from such failures. Accordingly, the complaint alleges that respondents failed to employ reasonable and appropriate measures to prevent unauthorized access to personal information in audio and transcript files, which caused, or are likely to cause, substantial injury to consumers that is not outweighed by countervailing benefits to consumers or competition and is not reasonably avoidable by consumers. The Commission alleges that this practice was, and is, an unfair act or practice. Part I of the proposed order prohibits respondents from misrepresenting (1) the extent to which respondents use, maintain, and protect the privacy, confidentiality, security, or integrity of personal information collected from or about consumers. Part II of the proposed order requires respondents to establish and maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. The security program must contain administrative, technical, and physical safeguards appropriate to respondents’ size and complexity, nature and scope of their activities, and the VOLUME 158 Analysis to Aid Public Comment sensitivity of the information collected from or about consumers. Specifically, the proposed order requires respondents to: designate an employee or employees to coordinate and be accountable for the information security program; identify material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks; design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards’ key controls, systems, and procedures; develop and use reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from respondents, and require service providers by contract to implement and maintain appropriate safeguards; and evaluate and adjust the information security program in light of the results of testing and monitoring, any material changes to operations or business arrangement, or any other circumstances that they know or have reason to know may have a material impact on its information security program.
Part III of the proposed order requires respondents to obtain within the first one hundred eighty (180) days after service of the order, and on a biennial basis thereafter for a period of twenty (20) years, an assessment and report from a qualified, objective, independent third-party professional, certifying, among other things, that: (1) respondents have in place a security program that provides protections that meet or exceed the protections required by Part II of the proposed order; and (2) respondents’ security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and GMR TRANSCRIPTION SERVICES, INC. 117 Analysis to Aid Public Comment integrity of sensitive consumer, employee, and job applicant information has been protected.
Parts IV through VIII of the proposed order are reporting and compliance provisions.
Part IV requires respondents to retain documents relating to its compliance with the order. Part V requires dissemination of the order to all current and future principals, officers, directors, managers, employees, agents, and representatives having supervisory responsibilities relating to the subject matter of the order. Parts VI and VII ensure notification to the FTC of changes in corporate status and employment status of respondents Prasad and Srivastava. Part VIII mandates that respondents submit reports to the Commission detailing its compliance with the order. Part IX provides that the order expires after twenty (20) years, with certain exceptions.
The purpose of the analysis is to aid public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed order or to modify its terms in any way.
VOLUME 158 Complaint