Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

Rite Aid Corporation

Volume 150 · 150 F.T.C. 694

Citation
150 F.T.C. 694
Docket
C-4308
Complaint
2010-11-12
Decision
2010-11-12
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
retail pharmacy stores
Outcome
consent order entered
Relief
recordkeeping; compliance_reporting; notice_to_customers; other
Order term (years)
20
Commission counsel
The Respondent, its attorney, and counsel
Source
Original volume PDF
Original PDF
This decision as a PDF

privacy data security

Cite this decision

Rite Aid Corporation, 150 F.T.C. 694 (2010). Consumer Law Library, https://consumerlawlibrary.org/decisions/v150-0013

Report an error in this record (decision id v150-0013)

Order status: active_until:2030-11-12. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF RITE AID CORPORATION CONSENT ORDER, ETC., INREGARD TO ALLEGED VIOLATION OF SEC. 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4308; File No. 072 3121 Complaint, November 12, 2010 — Decision, November 12, 2010 The consent order addresses allegations that Rite Aid Corporation (“Rite Aid”) failed to protect the sensitive financial and medical information of its customers and employees, in violation of federal law. Specifically, the complaint alleged that Rite Aid failed to properly dispose of personal information, train employees, assess compliance with disposal policies and procedures, or establish procedures for discovering and resolving risks to _ personal information. The consent order requires Rite Aid to establish a comprehensive information security program to ensure the security, confidentiality, and integrity of personal information it collects from consumers and employees. The consent order further requires Rite Aid to have its security program independently audited by a third party every two years for the next 20 years to ensure compliance.

Participants For the Commission: Kristin Krause Cohen, Loretta H. Garrison, and Alain Sheer.

For the Respondent: Stephen Paul Mahinka, Morgan Lewis & Bockius.

COMPLAINT The Federal Trade Commission (“Commission”), having reason to believe that Rite Aid Corporation (“Respondent” or “Rite Aid”) has violated the provisions of the Federal Trade Commission Act, and it appearing to the Commission that this proceeding is in the public interest, alleges: 1. Respondent Rite Aid is a Delaware corporation with its principal office or place of business at 30 Hunter Lane, Camp Hill, PA 17011. It conducts business through several whollyowned subsidiaries and limited liability companies. RITE AID CORPORATION 695 Complaint 2. The acts and practices of Respondent as alleged in this complaint are in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act. RESPONDENT’S BUSINESS 3. At all relevant times, Respondent has been in the business of selling prescription and non-prescription medicines and supplies, as well as other products. It operates, among other things, approximately 4,900 retail pharmacy stores in the United States (collectively, “Rite Aid pharmacies”) and an online pharmacy business. Respondent allows consumers to pay for their purchases with credit, debit and electronic benefit transfer cards (collectively, “payment cards”); insurance cards; personal checks; or cash.

4. In conducting its business, Respondent routinely obtains information from or about its customers, including, but not limited to, name; telephone number; address; date of birth; bank account number; payment card account number and expiration date; prescription information, such as medication and dosage, prescribing physician name, address, and telephone number, health insurer name, and insurance account number and policy number; and Social Security number (collectively, “personal information”). Respondent also collects personal information from or about employees and job applicants, including, but not limited to, Social Security number.

5. Respondent operates computer networks in its pharmacies, corporate headquarters, and distribution centers. Among other things, Respondent uses the networks to fill orders for prescription medicines and supplies; process sales, including to obtain authorization for payment card and insurance card transactions; and aggregate, store, and transmit personal information.

VOLUME 150 Complaint RESPONDENT’S REPRESENTATIONS 6. Respondent has disseminated or caused to be disseminated statements and privacy policies to consumers regarding the privacy and confidentiality of personal information, including, but not limited to:

a. From at least 2003, the following statement in its Notice of Privacy Practices:

Rite Aid takes its responsibility for maintaining your protected health information in confidence very seriously. Protected health information means information about you that may identify you and that relates to your past, present or future physical or mental health or condition and related health care services. It also includes basic demographic information. We are required by law to maintain the privacy of protected health information and to provide you with a Notice of Privacy Practices including our legal duties with respect to protected health information. (See Exhibit A).

b. From at least 2004, the following statement in a brochure seeking its customers’ medical history: Although you have the right not to disclose your medical history, Rite Aid would like to assure you that we respect and protect your privacy. (See Exhibit B.) RESPONDENT’S SECURITY PRACTICES 7. Respondent has engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for personal information. Among other things, Respondent has failed to: (1) implement policies and procedures to dispose securely of such information, including, but not limited to, policies and procedures to render the information unreadable in the course of disposal; (2) adequately train employees to dispose securely of such information; (3) use reasonable measures to assess compliance with its established policies and procedures RITE AID CORPORATION 697 Complaint for the disposal of such information; and (4) employ a reasonable process for discovering and remedying risks to such information. 8. As a result of the failures set forth in Paragraph 7, Respondent discarded materials containing personal information in clear readable text (such as pharmacy labels and employment applications) in unsecured, publicly-accessible trash dumpsters used by Rite Aid pharmacies on numerous occasions. For example, in late 2006 and continuing into 2007 and 2008, television stations and other media outlets reported finding personal information in unsecured dumpsters used by Rite Aid pharmacies in at least 7 cities throughout the United States. The personal information found in the dumpsters included information about Respondent’s customers and job applicants. Information discarded in publicly-accessible dumpsters could be misused to commit identity theft or to steal prescription medicines. VIOLATIONS OF THE FTC ACT 9. Through the means described in Paragraph 6, Respondent represented, expressly or by implication, that it implemented reasonable and appropriate measures to protect personal information against unauthorized access. 10.In truth and in fact, Respondent did not implement reasonable and appropriate measures to protect personal information against unauthorized access. Therefore, the representation set forth in Paragraph 9 was, and is, false or misleading.

11. As set forth in Paragraph 7, Respondent failed to employ reasonable and appropriate measures to prevent unauthorized access to personal information. Respondent’s practices caused, or are likely to cause, substantial injury to consumers that is not offset by countervailing benefits to consumers or competition and is not reasonably avoidable by consumers. This practice was, and is, an unfair act or practice.

12. The acts and practices of Respondent as alleged in this complaint constitute unfair or deceptive acts or practices, in or VOLUME 150 Complaint affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this twelfth day of November, 2010 has issued this complaint against Respondent.

By the Commission.

'ANOD Dear Valeo Customer TWILN3Q! Your Mite Aud Pharmacist «5 committed to proxiding you with the most aduarced pharmacy care possible The information that yeu fil out In this brochure 1s vital Ip pahance your health The more you tell us, the better we car serve you Thes information is the fourcanen of a personal health profile we maintain fur you, so our LifeCneck™ Computer can help or event haemiy! drug lateractions wth prescriptions oF STC smedicatinns you may he taking Youre amenated to staying healthy, and Mite Aid wants te tbe there watts you every step of the way. Wo want te give you the bett care you can get and we're continually working to make this possitnie, Seno ongnang training progeams for our pharmacists th U-hour comrehent service, we are abways quing aut of our way to mabe yan Me easaer Aithaugit you have the nght not te disclase your medical history, Rite Alc would ke to assure you that wet respect and protect your privacy. We encourage you tt Completely All out thes farm and retunn it to your p nacist so that we can give you the kind of perenna! (ate Uset wou! and your Famuly deserve, Your heath yamporiant ta you andi Wa us We hope to earn vour ust and 1a became wour pharmacy for He Because with us it's personal Suacorely Your Fite Aid Pharmacist 2Sb000Ve RITE AID CORPORATION Complaint EXHIBIT B EE SE A TY STE Rite Aid Pharmacy Rite Aid is always investing in new technology and pharmacist training to deliver the outstanding pharmacy care that you deserve, Rite Advice® Written information om dosage, side effects and potential drug interactions is included with every prescription. Convenient Refills Refills are just a call or a click away, Use Refills by Phone or Internet Refills 24 hours a day and know exactly what time your refill will be ready.

* Refills by Phone ~ call the phone number located on your prescription bottle and follow the automated instructions.

+ Internet Refills ~ log on to riteaid.com powered by drugstore.com and click “refill now”

a With us, it’s personal forest PATIENT INFORMATION & HEALTH CARE SOLUTIONS OU:FESeHOUS about yourhealthn Ful out this brochure with your macical history to eid your pharmacist prowde sau ve th the most complete, persoralized servi Patient Name JWILN3OISNOD Last Street or PO Bow leieprane E-mail Agkdrest Gate at Birth (Month/Day/Year) Genter tcrcie one! MALE FEMALE Wf you have children in your household, to prevent accidental drug poisoning, please specify child resistant packaging.

Would you like us to dispense your medications in child resistant packaging? AYES ONO Prescription Insurance YES QNO If es rame cordnolder Cardholder's Name Kelativerstup 10 cardhoua cle one! (Cardhoidles, spoune. chitd dependent parent ivabled Uependers, ull came student, other! gisLooov"d Please check the appropriate box(es) KNOWN ALLERGIES AND DRUG REACTIONS QO No known aliergies/drug reactions J Aspirin O Cephalosporins (ex. Ceclor, Keflex) O Codeine O Erythromycin O Penicillins O Sulfa drugs U Tetracyctines QO Xanthines jex. Theophylline) Other allergres and drug reactions __ List of prescriptions you are currently taking which were NOT purchased in this store _ PHARMACISTS COMMENTS rs unbeaten in requested by vue Fone A Piva ansehen by Cane rapa 4 Tea rharration wil be kept combos Srce heath mormatcn ray change pencAaly Cnr ow pentcnoscn anc ror saevcigond ahergan drug macs ona cr neath cordare Signature = Patient Information == Medical Information ee Ie HEALTH CONDITIONS U Angina 2 Diabetes U Anemia O Heart conditions G Aniritis O Kidney disease O Asthma O Liver disease D Blood clotting disorders S Blood pressure, high U Breast feeding U Cancer 2 Lung disease O Parkinson's disease U Pregnancy a Ulcers On List of non-prescription medications you are currently taking sore paca we Pravracie 3 any charges © mecaabes Signature QONDI Wish TO COMPLETE Tras FORM ate VOLUME 150 Decision and Order DECISION AND ORDER The Federal Trade Commission having initiated an investigation of certain acts and practices of the Respondent named in the caption hereof, and the Respondent having been furnished thereafter with a copy of a draft Complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge the Respondent with violation of the Federal Trade Commission Act, 15 U.S.C. § 45 et seq; The Respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement’), an admission by the Respondent of all the jurisdictional facts set forth in the aforesaid draft Complaint, a statement that the signing of said Consent Agreement is for settlement purposes only and does not constitute an admission by Respondent that the law has been violated as alleged in such Complaint, or that the facts as alleged in such Complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission's Rules; and The Commission having thereafter considered the matter and having determined that it has reason to believe that the Respondent has violated the said Act, and that a Complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such Consent Agreement on the public record for a period of thirty (30) days, and having duly considered the comments filed thereafter by interested persons pursuant to Section 2.34 of its Rules, now in further conformity with the procedure described in Section 2.34 of its Rules, the Commission hereby issues its Complaint, makes the following jurisdictional findings and enters the following Order: 1. Respondent Rite Aid Corporation is a Delaware corporation with its principal office or place of business at 30 Hunter Lane, Camp Hill, Pennsylvania 17011.

2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the RITE AID CORPORATION 705 Decision and Order Respondent, and the proceeding is in the public interest.

ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:

1.

Unless otherwise specified, “store” shall mean each pharmacy entity or store location that sells prescription medicines, drugs, devices, supplies, or services and/or non-prescription products and services. Unless otherwise specified, “LLC” shall mean a limited liability company: (a) that owns, controls, or operates one or more stores (including, but not limited to, the companies identified in attached Exhibit A), and (b) in which Rite Aid Corporation is a member, directly or indirectly.

Unless otherwise specified, “Respondent” shall mean Rite Aid Corporation, its subsidiaries, divisions, affiliates, and LLCs, and its successors and assigns. “Personal information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license number or other government-issued identification number; (g) prescription information, such as medication and dosage, and prescribing physician name, address, and telephone number, health insurer name, insurance account number, or insurance policy number; (h) a bank account, debit card, or credit card account VOLUME 150 Decision and Order number; (i) a persistent identifier, such as a customer number held in a “cookie” or processor serial number, that is combined with other available data that identifies an individual consumer; (j) a biometric record; or (k) any information that is combined with any of (a) through (j) above. For the purpose of this provision, a “consumer” shall include an “employee,” and an individual seeking to become an employee, where “employee” shall mean an agent, servant, salesperson, associate, independent contractor, and other person directly or indirectly under the control of Respondent.

5. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. I.

IT IS ORDERED that Respondent, and its officers, agents, representatives, and employees, directly or through any corporation, subsidiary, limited liability company, division, or other device, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall not misrepresent in any manner, expressly or by implication, the extent to which it maintains and protects the privacy, confidentiality, security, or integrity of personal information collected from or about consumers. I.

IT IS FURTHER ORDERED that Respondent, and its officers, agents, representatives, and employees, directly or through any corporation, subsidiary, limited liability company, division, or other device, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall, no later than the date of service of this order, establish and implement, and thereafter maintain, a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. Such program, the content and implementation of which must be fully documented in writing, shall contain RITE AID CORPORATION 707 Decision and Order administrative, technical, and physical safeguards appropriate to Respondent’s size and complexity, the nature and scope of Respondent’s activities, and the sensitivity of the personal information collected from or about consumers, including: A.

the designation of an employee or employees to coordinate and be accountable for the information security program.

the identification of material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assessment of the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment should include consideration of risks in each area of relevant operation, including, but not limited to: (1) employee training and management; (2) information systems, including network and software design, information processing, storage, transmission, and disposal; and (3) prevention, detection, and response to attacks, intrusions, or other systems failures.

the design and implementation of reasonable safeguards to control the risks identified through risk assessment, and regular testing or monitoring of the effectiveness of the safeguards’ key controls, systems, and procedures.

the development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from Respondent, and requiring service providers by contract to implement and maintain appropriate safeguards.

the evaluation and adjustment of Respondent’s information security program in light of the results of the testing and monitoring required by subpart C, any VOLUME 150 Decision and Order material changes to Respondent’s operations or business arrangements, or any other circumstances that Respondent knows or has reason to know may have a material impact on the effectiveness of its information security program.

Il.

IT IS FURTHER ORDERED that, in connection with their compliance with Part II of this order, Respondent, and its officers, agents, representatives, and employees, shall obtain initial and biennial assessments and reports (“Assessments”) from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession. The reporting period for the Assessments shall cover: (1) the first year after service of the order for the initial Assessment, and (2) each two (2) year period thereafter for twenty (20) years after service of the order for the biennial Assessments. Each Assessment shall:

A. set forth the specific administrative, technical, and physical safeguards that Respondent has implemented and maintained during the reporting period; B. explain how such safeguards are appropriate to Respondent’s size and complexity, the nature and scope of Respondent’s activities, and the sensitivity of the personal information collected from or about consumers;

C. explain how the safeguards that have been implemented meet or exceed the protections required by the Part II of this order; and D. certify that Respondent’s security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period. Each Assessment shall be prepared and completed within sixty (60) days after the end of the reporting period to which the RITE AID CORPORATION 709 Decision and Order Assessment applies by a person qualified as a Certified Information System Security Professional (CISSP) or as a Certified Information Systems Auditor (CISA); a person holding Global Information Assurance Certification (GIAC) from the SysAdmin, Audit, Network, Security (SANS) Institute; or a qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580. Respondent shall provide the initial Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been prepared. All subsequent biennial Assessments shall be retained by Respondent until the order is terminated and provided to the Associate Director for Enforcement within ten (10) days of request. IV.

IT IS FURTHER ORDERED that Respondent shall maintain and, upon request, make available to the Federal Trade Commission for inspection and copying: A. for a period of five (5) years, a print or electronic copy of each document relating to compliance, including, but not limited to, documents, prepared by or on behalf of Respondent, that contradict, qualify, or call into question Respondent’s compliance with this order; and B. for a period of three (3) years after the date of preparation of each Assessment required under Part II of this order, all materials relied upon to prepare the Assessment, whether prepared by or on behalf of Respondent, including, but not limited to, all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, and any other materials relating to Respondent’s compliance with Parts II and III of this order, for the compliance period covered by such Assessment.

VOLUME 150 Decision and Order V.

IT IS FURTHER ORDERED that Respondent Rite Aid Corporation shall deliver a copy of this order to all its current and future subsidiaries (including LLCs and each store that is owned, controlled, or operated by Respondent or an LLC), current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order. Respondent shall deliver this order to such current subsidiaries and personnel within sixty (60) days after service of this order, and to such future subsidiaries and personnel within sixty (60) days after the Respondent acquires the subsidiary or the person assumes such position or responsibilities. VI.

IT IS FURTHER ORDERED that Respondent shall notify the Commission at least thirty (30) days prior to any change in Respondent that may affect compliance obligations arising under this order, including, but not limited to, a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor company; the creation or dissolution of a subsidiary (including an LLC), parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in Respondent’s name or address. Provided, however, that, with respect to any proposed change in Respondent about which Respondent learns less than thirty (30) days prior to the date such action is to take place, Respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. All notices required by this Part shall be sent by certified mail to the Associate Director, Division of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580.

VII.

IT IS FURTHER ORDERED that Respondent, and its successors and assigns, within sixty (60) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of RITE AID CORPORATION 711 Decision and Order receipt of written notice from a representative of the Commission, it shall submit additional true and accurate written reports. VIII.

This order will terminate on November 12, 2030, or twenty (20) years from the most recent date that the United States or the Federal Trade Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part in this order that terminates in less than twenty (20) years;

B. This order’s application to any Respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that Respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission.

VOLUME 150 EXHIBIT A Decision and Order ieee Te) Za) OVMELO Fy a MOS dal aim; ebey PIA Foe ods Ay ayy RITE AID CORPORATION 713 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, a consent agreement from Rite Aid Corporation (“Rite Aid’).

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. The Commission’s proposed complaint alleges that Rite Aid is in the business of selling prescription and non-prescription medicines and supplies, as well as other products. It operates, among other things, approximately 4,900 retail pharmacy stores in the United States (collectively, “Rite Aid pharmacies”) and an online pharmacy business. The company allows consumers buying products in Rite Aid pharmacies to pay for their purchases with credit, debit and electronic benefit transfer cards; insurance cards; personal checks; or cash.

The complaint alleges that in conducting its business, Rite Aid routinely obtains information from or about its customers, including, but not limited to, name; telephone number; address; date of birth; bank account number; payment card account number and expiration date; prescription information, such as medication and dosage, prescribing physician name, address, and telephone number, health insurer name, and insurance account number and policy number; and Social Security number. The company also collects and maintains sensitive information from or about its employees and job applicants, which includes, among other things, Social Security numbers.

The complaint further alleges that Rite Aid engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for sensitive information from consumers, employees, and job applicants. In particular, Rite Aid VOLUME 150 Analysis to Aid Public Comment failed to: (1) implement policies and procedures to dispose securely of such information, including, but not limited to, policies and procedures to render the information unreadable in the course of disposal; (2) adequately train employees to dispose securely of such information; (3) use reasonable measures to assess compliance with its established policies and procedures for the disposal of such information; or (4) employ a reasonable process for discovering and remedying risks to such information. The complaint alleges that as a result of these failures, Rite Aid pharmacies discarded materials containing — sensitive information in clear readable text (such as pharmacy labels and job applications) in unsecured, publicly-accessible trash dumpsters on numerous occasions. For example, in July 2006 and continuing into 2007 and 2008, television stations and other media outlets reported finding such information in unsecured dumpsters used by Rite Aid pharmacies in at least 7 cities throughout the United States. When discarded in publiclyaccessible dumpsters, such information can be obtained by individuals for purposes of identity theft or the theft of prescription medicines.

The proposed order applies to sensitive information about consumers, employees, and job applicants obtained by Rite Aid. It contains provisions designed to prevent Rite Aid from engaging in the future in practices similar to those alleged in the complaint. Part I of the proposed order prohibits misrepresentations about the security, confidentiality, and integrity of sensitive information. Part II of the order requires Rite Aid to establish and maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of such information (whether in paper or electronic format) about consumers, employees, and those seeking to become employees. The order covers health and other sensitive information obtained by all Rite Aid entities, including, but not limited to, retail pharmacies. The security program must contain administrative, technical, and physical safeguards appropriate to Rite Aid’s size and complexity, the nature and scope of its activities, and the sensitivity of the information collected from or about consumers and employees. Specifically, the order requires Rite Aid to: RITE AID CORPORATION 715 Analysis to Aid Public Comment e Designate an employee or employees to coordinate and be accountable for the information security program. e Identify material internal and external risks to the security, confidentiality, and integrity of sensitive information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks.

¢ Design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards’ key controls, systems, and procedures.

¢ Develop and use reasonable steps to select and retain service providers capable of appropriately safeguarding sensitive information they receive from Rite Aid, and require service providers by contract to implement and maintain appropriate safeguards.

¢ Evaluate and adjust its information security programs in light of the results of testing and monitoring, any material changes to operations or business arrangements, or any other circumstances that it knows or has reason to know may have a material impact on its information security program.

Part HI of the proposed order requires Rite Aid to obtain within one year, and on a biennial basis thereafter for a period of twenty (20) years, an assessment and report from a qualified, objective, independent third-party professional, certifying, among other things, that: (1) it has in place a security program that provides protections that meet or exceed the protections required by Part II of the proposed order; and (2) its security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of sensitive consumer, employee, and job applicant information has been protected.

VOLUME 150 Analysis to Aid Public Comment Parts IV through VIII of the proposed order are reporting and compliance provisions. Part IV requires Rite Aid to retain documents relating to its compliance with the order. For most records, the order requires that the documents be retained for a five-year period. For the third-party assessments and supporting documents, Rite Aid must retain the documents for a period of three years after the date that each assessment is prepared. Part V requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part VI ensures notification to the FTC of changes in corporate status. Part VII mandates that Rite Aid submit a compliance report to the FTC within 60 days, and periodically thereafter as requested. Part VIII is a provision “sunsetting” the order after twenty (20) years, with certain exceptions. The Commission conducted its investigation jointly with the Office for Civil Rights in the Department of Health and Human Services (“OCR-HHS”). Working together, the Commission and OCR-HHS each entered into separate but coordinated agreements with Rite Aid to resolve all the issues of both agencies. This is the Commission’s twenty-ninth case to challenge the failure by a company to implement reasonable information security practices, and the second case: (1) involving a health provider, (2) proceeding jointly with OCR-HHS, and (3) challenging the security of employee data. The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed order or to modify its terms in any way.

PILOT CORPORATION / FLYING J INC. 717 Complaint

← 150 F.T.C. 586 · 150 F.T.C. 717 →