8 Mar 2012

Corporate Skills Development In India Is Required

Corporates across the world are struggling to hire skilled and knowledgeable workforce. Surprisingly, only 20 to 25% of graduates and professionals are worth employment in these corporates. Educational institutions producing these graduates are not only outdated but are also academic in nature. They do not provide practical trainings and workable experience to these graduates.

India is no different in this regard and Indian government has a tremendous job in hand to change this situation. Skills developments in India are urgently required to change this position. Further keeping in mind the techno legal requirements of present times, techno legal skills development in India are also required.

Techno legal areas like cyber law, cyber security, cyber forensics, ethical hacking, etc are worst affected. In the name of technical education mere academic diplomas and degrees are provided that are not helping the students in any manner whatsoever.

Perry4Law, Perry4Law Techno Legal Base (PTLB) and Perry4Law Techno Legal ICT Training Centre (PTLITC) believe that information and communication technology (ICT) can help Indian government in achieving the goals set by it regarding skills development. For instance, use of e-learning, online education and distance learning education system can not only ease the pressure from traditional universities and educational institutions but would also help in providing technical and practical education to masses across India.

Perry4Law, PTLB and PTLITC are providing exclusive techno legal e-learning courses in India and techno legal skills development trainings and courses in India. PTLB is providing various techno legal courses for corporate executives, CEOs, CIOs, etc.

Companies and CEOs are required to follow cyber law due diligence in India and must comply with the requirements of Internet intermediaries to get the safe harbour protection under Indian laws. PTLB is providing exclusive techno legal cyber law trainings for corporate executives and CEOs in India.

These trainings have been specifically designed so that corporate executives and CEOs can successfully comply with Indian laws, especially information technology act, 2000 (IT Act 2000) that is the cyber law of India. If you are interested in our techno legal trainings, kindly enroll with us in this regard.

We are committed to improve the techno legal skills developments in India are looking forward for suitable partners and associates in this regard. Read our e-learning blog for regular updates in this regard.

5 Mar 2012

E-Commerce Regulations And Laws In India

Electronic commerce is an area whose legal formalities cannot be taken lightly. Electronic commerce involves multiple jurisdictions and at times multiple laws of different countries are applicable to a single electronic commerce website.

Further, the landscape for electronic commerce dispute resolution in India is also fast changing. With more and more stress upon online disputes resolution (ODR) in India electronic commerce disputants now prefer ODR as a mechanism for dispute resolution. Corporate disputes resolution through ODR in India is also being explored. E-courts and ODR have also added their own valued to electronic commerce and corporate dispute resolutions in India.

Electronic commerce in India is witnessing a good growth due to progressive policies and liberal foreign direct investments (FDIs). E-commerce uses information and communication technology (ICT) to operate. Although many technological aspects are also taken care of by an e-commerce platform, yet establishment and running of an e-commerce website is the most important requirement.

Internet is boundary less and a website hosted in a particular country can be accessed from any part of the world. Further, there may be cases where a websites located in a particular country may attract legal jurisdictions of multiple countries. Thus, compliance with the laws of the principal country as well as those countries where such e-commerce websites targets audience and customers is of prime importance.

There have been instances where e-commerce websites located in India failed to observe cyber law due diligence in India and e-commerce regulations and laws in India. Criminal trials and criminal liabilities have been imposed by Indian legal system upon such websites. The bazee.com case and the criminal and civil trials against companies like Google, Yahoo, Facebook, Microsoft, etc are few examples of the same. Such cases against e-commerce websites and foreign companies would further increase and e-commerce players must appoint nodal officers in India to comply with Indian laws.

Thus, not only legal requirements for undertaking e-commerce in India are stringent but even Internet intermediaries liability in India must be taken seriously by companies engaged in online transactions and businesses. We have no dedicated e-commerce laws in India but the information technology act 2000 (IT Act 2000) covers basic level e-commerce legal framework in India. The IT Act 2000 also prescribes cyber due diligence for foreign websites in India.

E-commerce due diligence in India is a much needed requirement that all e-commerce players, whether Indians or foreign, must undertake as soon as possible. Non observation of local and foreign laws can tarnish the image and brand of a company that cannot be regained again. It is better to err on the side of precaution rather than caught on the wrong side of the law.

National Cyber Coordination Centre (NCCC) Of India

India has too many agencies and authorities and they are scattered all over India. For practical reasons, there are no centralised agency that can manage law and order and cyberspace related issues. This is resulting in increased cyber attacks and cyber crimes committed against India and Indian citizens.

Cyber law issues, cyber security and national security are on agenda of Indian government these days. However, till now cyber security in India is not upto the mark and cyber law of India requires an urgent repeal. This is because the entire approach and attitude of India government is defective.

Indian government has failed to understand that e-surveillance is not a substitute for cyber security capabilities. Instead of developing cyber security capabilities of India, the Indian government is stressing upon growing use of e-surveillance in India and Internet censorship in India.

All these exercises of India government have been done without any legal framework supporting these initiatives of Indian government. Phones are tapped in India without a constitutionally valid phone tapping laws in India. The central monitoring system project of India (CMS Project of India) is also not supported by any legal framework. Surveillance of Internet traffic in India is also another area that requires a sound legal framework. Various authorities with far reaching powers have been created without any legal backing.

Now the government has proposed setting up of National Cyber Coordination Centre (NCCC) of India. The NCCC would provide actionable alerts to government departments in cases of perceived security threats. It is hoped that this would help in fighting terrorists and other cyber criminals.

The NCCC will scan whole cyber traffic flowing at the point of entry and exit at India's international Internet gateways. The web scanning centre will provide actionable alerts for proactive actions to be taken by government departments. All government departments will now talk to the Internet Service Providers (ISPs) through NCCC for real time information and data on threats. Presently, the monitoring of web traffic is done by Centre for Development of Telematics (C-DoT) which has installed its equipments at the premises of ISPs and gateways.

All tweets, messages, emails, status updates and even email drafts will now pass through the new scanning centre. The centre may probe further into any email or social media account if it finds a perceived threat.

India's National Security Council Secretariat (NCSC) has asked various departments to assess their needs for officials, who will coordinate with the scanning agency. The National Security Council handles the political, nuclear, energy and strategic security concerns of the country.

This can be another agency without a legal framework. Creating agencies without legal framework is counter productive as it violates civil liberties and human rights. Parliamentary oversight of intelligence agencies of India and proposed NCCC is absolutely required. The Indian government must keep this in mind while creating NCCC.

Mobile Phone Laws In India Required

With the active use of mobile phones in India, dedicated cell phone laws in India and mobile phone laws in India are urgently required. Further, we must also ensure mobile cyber security in India and mobile banking cyber security in India. Even Reserve Bank of India (RBI) has warned Indian banks for inadequate cyber security adoption. Despites these pressing requirements neither mobile phone laws nor mobile phone security has been ensured in India.

Mobile phones are increasingly being used for multi purpose in India. However, legal framework for mobile phones in India is still missing. Some provisions can be made applicable to mobiles in India through the information technology act 2000 (IT Act 2000) but we still do not have a dedicated mobile phone laws in India.

The Department of Telecommunication (DoT) has proposed a new national telecom policy of India 2011 that would be operational very soon. The new telecom policies as well as other projects of Indian government and DoT are excessively favouring e-surveillance in India and surveillance of Internet traffic in India. We need a legally valid e-surveillance policy of India to address these issues. Otherwise, it would violate human rights protection in cyberspace.

The proposal to allow DoT to monitor cell phone locations in India is also a controversial issue. Big brother must not overstep its limits in India. The proposed cell site based e-surveillance in India has crossed this limit well beyond those permitted by Indian Constitution.

We must have well defined procedure and cell site data location laws in India. As we have no dedicated privacy laws, data protection laws, data security laws, anti telemarketing laws, anti spam laws, etc, mobile phones monitoring in India is not legally sustainable.

Even the proposed central monitoring system (CMS) project of India is not legitimate and legally sustainable as there is no legal framework that justifies its operation in India. Currently there is no phone tapping law in India that is constitutionally sound and we urgently need a lawful interception law in India. Similarly, the colonial phone tapping laws of India must be repealed and new and constitutionally sound phone tapping laws in India must be formulated.

The mobile phone laws of India must cover all these issues that are presently left unaddressed. In the absence of such laws, mobile phone data analysis, mobile phone location tracking, mobile phone tapping in India, etc are illegal and unconstitutional.

E-Health Laws And Regulations In India

Information and communication technology (ICT) has streamlined the way medical services and para medical services are provided world over. E-health and telemedicine are examples of use of ICT for medical purposes.

However, when technology is used for medical purposes, it gives rise to medico legal and techno legal issues. In United States, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Health Information Technology for Economic and Clinical Health Act (HITECH Act), etc are some of the laws that take care of medico legal and techno legal issues of e-health and telemedicine.

On the contrary, we have no dedicated e-health and telemedicine laws in India. Even essential attributes of these laws like privacy protection, data protection, data security, cyber security, confidentiality maintenance, etc are not governed by much needed dedicated laws.

However, numerous statues carry individual provisions that may be applicable to e-health and telemedicine activities in India. For instance, the e-governance and e-commerce related aspects of e-health and tele medicine may be governed by the Information Technology Act, 2000 (IT Act 2000) that is the cyber law of India. All electronic contraventions and violations pertaining to e-health and tele medicine can be regulated b the IT Act 2000.

Similarly, privacy and data protection aspects in cyberspace pertaining to e-health are also governed by the IT Act 20000. Further, the Supreme Court of India has interpreted Article 21 of Indian Constitution as conferring a right to privacy upon all persons in India. Even in some cases the Supreme Court of India has held that patients have a right to privacy to protect their health related information except where non disclosure of such information is violating fundamental rights of others and is against public interest and public policy.

Even data security and cyber security aspects have been covered by the IT Act 2000 to some extent. The real problem is that these provisions that protect privacy, data protection, data security, etc are piecemeal efforts and they are not serving the purposes as required.

We need to have dedicated e-health laws and regulations in India that are presently missing. The sooner these e-health laws and regulations are formulated in India the better it would be for the larger interest of medical community and patients in India.

4 Mar 2012

Health Insurance Portability and Accountability Act of 1996

Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a comprehensive Federal legislation of United States (US) that ensures health care coverage, privacy protection, electronic information security, and fraud prevention regarding health care related issues.

Before the enactment of HIPAA there was no centralised legislation that covered the entire US. Even regarding privacy issues, there were numerous uncoordinated Federal legislations which addressed privacy in some form. Prior to HIPAA, there was no standard authority for enforcement of fraud and abuse that applied to State and Federal health care programs.

HIPAA “consolidated” all these issues at a single place and made it much easier and effective to implement health insurance related matters in US. Further, HIPAA also ensured cyber security and data security for electronic patient and health related information.

The Preamble to HIPAA says that it is an Act to amend the Internal Revenue Code of 1986 to improve portability and continuity of health insurance coverage in the group and individual markets, to combat waste, fraud, and abuse in health insurance and health care delivery, to promote the use of medical savings accounts, to improve access to long-term care services and coverage, to simplify the administration of health insurance, and for other purposes.

Title II of HIPAA, deals with prevention of health care frauds and abuse, administrative simplification and medical liability reform. It defines numerous offenses relating to health care and sets civil and criminal penalties for them. It also creates several programs to control fraud and abuse within the health care system.

The Department of Health and Human Services (HHS) has promulgated five rules regarding Administrative Simplification: the Privacy Rule, the Transactions and Code Sets Rule, the Security Rule, the Unique Identifiers Rule, and the Enforcement Rule.

(1) Privacy Rule: The HIPAA Privacy Rule regulates the use and disclosure of Protected Health Information (PHI) held by "covered entities" (generally, health care clearinghouses, employer sponsored health plans, health insurers, and medical service providers that engage in certain transactions.) By regulation, the Department of Health and Human Services extended the HIPAA privacy rule to independent contractors of covered entities who fit within the definition of "business associates". PHI is any information held by a covered entity which concerns health status, provision of health care, or payment for health care that can be linked to an individual. This is interpreted rather broadly and includes any part of an individual's medical record or payment history. Covered entities must disclose PHI to the individual within 30 days upon request. They also must disclose PHI when required to do so by law, such as reporting suspected child abuse to state child welfare agencies.

A covered entity may disclose PHI to facilitate treatment, payment, or health care operations, or if the covered entity has obtained authorisation from the individual. However, when a covered entity discloses any PHI, it must make a reasonable effort to disclose only the minimum necessary information required to achieve its purpose.

The Privacy Rule gives individuals the right to request that a covered entity correct any inaccurate PHI. It also requires covered entities to take reasonable steps to ensure the confidentiality of communications with individuals. The Privacy Rule requires covered entities to notify individuals of uses of their PHI. Covered entities must also keep track of disclosures of PHI and document privacy policies and procedures. They must appoint a Privacy Official and a contact person responsible for receiving complaints and train all members of their workforce in procedures regarding PHI.

An individual who believes that the Privacy Rule is not being upheld can file a complaint with the Department of Health and Human Services Office for Civil Rights (OCR).

(2) Transactions and Code Sets Rule: HIPAA was intended to make the health care system in the United States more efficient by standardising health care transactions. Under HIPAA, HIPAA-covered health plans are now required to use standardised HIPAA electronic transactions.

(3) Security Rule: The Security Rule complements the Privacy Rule. While the Privacy Rule pertains to all Protected Health Information (PHI) including paper and electronic, the Security Rule deals specifically with Electronic Protected Health Information (EPHI). It lays out three types of security safeguards required for compliance: administrative, physical, and technical. For each of these types, the Rule identifies various security standards, and for each standard, it names both required and addressable implementation specifications. Required specifications must be adopted and administered as dictated by the Rule. Addressable specifications are more flexible. Individual covered entities can evaluate their own situation and determine the best way to implement addressable specifications.

The standards and specifications are as follows:

(a) Administrative Safeguards – policies and procedures designed to clearly show how the entity will comply with the act

(i) Covered entities (entities that must comply with HIPAA requirements) must adopt a written set of privacy procedures and designate a privacy officer to be responsible for developing and implementing all required policies and procedures.
(ii) The policies and procedures must reference management oversight and organisational buy-in to compliance with the documented security controls.
(iii) Procedures should clearly identify employees or classes of employees who will have access to electronic protected health information (EPHI). Access to EPHI must be restricted to only those employees who have a need for it to complete their job function.
(iv) The procedures must address access authorization, establishment, modification, and termination.
(v) Entities must show that an appropriate ongoing training program regarding the handling of PHI is provided to employees performing health plan administrative functions.
(vi) Covered entities that out-source some of their business processes to a third party must ensure that their vendors also have a framework in place to comply with HIPAA requirements. Companies typically gain this assurance through clauses in the contracts stating that the vendor will meet the same data protection requirements that apply to the covered entity. Care must be taken to determine if the vendor further out-sources any data handling functions to other vendors and monitor whether appropriate contracts and controls are in place.
(vii) A contingency plan should be in place for responding to emergencies. Covered entities are responsible for backing up their data and having disaster recovery procedures in place. The plan should document data priority and failure analysis, testing activities, and change control procedures.
(viii) Internal audits play a key role in HIPAA compliance by reviewing operations with the goal of identifying potential security violations. Policies and procedures should specifically document the scope, frequency, and procedures of audits. Audits should be both routine and event-based.
(ix) Procedures should document instructions for addressing and responding to security breaches that are identified either during the audit or the normal course of operations.

(b) Physical Safeguards – controlling physical access to protect against inappropriate access to protected data

(i) Controls must govern the introduction and removal of hardware and software from the network. (When equipment is retired it must be disposed of properly to ensure that PHI is not compromised.)
(ii) Access to equipment containing health information should be carefully controlled and monitored.
(iii) Access to hardware and software must be limited to properly authorized individuals.
(iv) Required access controls consist of facility security plans, maintenance records, and visitor sign-in and escorts.
(v) Policies are required to address proper workstation use. Workstations should be removed from high traffic areas and monitor screens should not be in direct view of the public.
(vi) If the covered entities utilise contractors or agents, they too must be fully trained on their physical access responsibilities.

(c) Technical Safeguards – controlling access to computer systems and enabling covered entities to protect communications containing PHI transmitted electronically over open networks from being intercepted by anyone other than the intended recipient.

(i) Information systems housing PHI must be protected from intrusion. When information flows over open networks, some form of encryption must be utilised. If closed systems/networks are utilized, existing access controls are considered sufficient and encryption is optional.
(ii) Each covered entity is responsible for ensuring that the data within its systems has not been changed or erased in an unauthorized manner.
(iii) Data corroboration, including the use of check sum, double-keying, message authentication, and digital signature may be used to ensure data integrity.
(iv) Covered entities must also authenticate entities with which they communicate. Authentication consists of corroborating that an entity is who it claims to be. Examples of corroboration include: password systems, two or three-way handshakes, telephone callback, and token systems.
(v) Covered entities must make documentation of their HIPAA practices available to the government to determine compliance.
(vi) In addition to policies and procedures and access records, information technology documentation should also include a written record of all configuration settings on the components of the network because these components are complex, configurable, and always changing.
(vii) Documented risk analysis and risk management programs are required. Covered entities must carefully consider the risks of their operations as they implement systems to comply with the act. (The requirement of risk analysis and risk management implies that the act’s security requirements are a minimum standard and places responsibility on covered entities to take all reasonable precautions necessary to prevent PHI from being used for non-health purposes.)

(4) Unique Identifiers Rule (National Provider Identifier): HIPAA covered entities such as providers completing electronic transactions, healthcare clearinghouses, and large health plans, must use only the National Provider Identifier (NPI) to identify covered healthcare providers in standard transactions.

All covered entities using electronic communications (e.g., physicians, hospitals, health insurance companies, and so forth) must use a single new NPI. The NPI replaces all other identifiers used by health plans, Medicare, Medicaid, and other government programs. However, the NPI does not replace a provider's DEA number, state license number, or tax identification number. The NPI is 10 digits (may be alphanumeric), with the last digit being a checksum. The NPI cannot contain any embedded intelligence; in other words, the NPI is simply a number that does not itself have any additional meaning. The NPI is unique and national, never re-used, and except for institutions, a provider usually can have only one. An institution may obtain multiple NPIs for different "subparts" such as a free-standing cancer center or rehab facility.

(5) Enforcement Rule: The Enforcement Rule sets civil money penalties for violating HIPAA rules and establishes procedures for investigations and hearings for HIPAA violations.

American Recovery and Reinvestment Act of 2009/Division A/Title XIII/Subtitle D: HITECH Act: Privacy Requirements

Subtitle D of the Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment Act of 2009, addresses the privacy and security concerns associated with the electronic transmission of health information.

This subtitle extends the complete Privacy and Security Provisions of HIPAA to business associates of covered entities. This includes the extension of newly updated civil and criminal penalties to business associates. These changes are also required to be included in any business associate agreements with covered entities. On November 30, 2009, the regulations associated with the new enhancements to HIPAA enforcement took effect.

Another significant change brought about in Subtitle D of the HITECH Act, is the new breach notification requirements. This imposes new notification requirements on covered entities, business associates, vendors of personal health records (PHR) and related entities if a breach of unsecured protected health information (PHI) occurs. On April 27, 2009, the Department of Health and Human Services (HHS) issued guidance on how to secure protected health information appropriately. Both HHS and the Federal Trade Commission (FTC) were required under the HITECH Act to issue regulations associated with the new breach notification requirements. The HHS rule was published in the Federal Register on August 24, 2009 and the FTC rule was published on August 25, 2009.

The final significant change made in Subtitle D of the HITECH Act, implements new rules for the accounting of disclosures of a patient's health information. It extends the current accounting for disclosure requirements to information that is used to carry out treatment, payment and health care operations when an organisation is using an electronic health record (EHR). This new requirement also limits the timeframe for the accounting to three years instead of six as it currently stands. These changes won't take effect until January 1, 2011, for organizations implementing EHRs between January 1, 2009 and January 1, 2011, and January 1, 2013, for organisations who had implemented an EHR prior to January 1, 2009.

Effects on Research and Clinical Care

The enactment of the Privacy and Security Rules has caused major changes in the way physicians and medical centers operate. The complex legalities and potentially stiff penalties associated with HIPAA, as well as the increase in paperwork and the cost of its implementation, were causes for concern among physicians and medical centers.

(a) Effects on Research: HIPAA restrictions on researchers have affected their ability to perform retrospective, chart-based research as well as their ability to prospectively evaluate patients by contacting them for follow-up. In addition, informed consent forms for research studies now are required to include extensive detail on how the participant's protected health information will be kept private. While such information is important, the addition of a lengthy, legalistic section on privacy may make these already complex documents even less user-friendly for patients who are asked to read and sign them.

(b) Effects on Clinical Care: The complexity of HIPAA, combined with potentially stiff penalties for violators, can lead physicians and medical centers to withhold information from those who may have a right to it. A review of the implementation of the HIPAA Privacy Rule by the U.S. Government Accountability Office found that health care providers were "uncertain about their legal privacy responsibilities and often responded with an overly guarded approach to disclosing information than necessary to ensure compliance with the Privacy rule".

Costs of Implementation

In the period immediately prior to the enactment of the HIPAA Privacy and Security Acts, medical centers and medical practices were charged with getting "into compliance". With an early emphasis on the potentially severe penalties associated with violation, many practices and centers turned to private, for-profit "HIPAA consultants" who were intimately familiar with the details of the legislation and offered their services to ensure that physicians and medical centers were fully "in compliance". In addition to the costs of developing and revamping systems and practices, the increase in paperwork and staff time necessary to meet the legal requirements of HIPAA may impact the finances of medical centers and practices at a time when insurance companies and Medicare reimbursement is also declining.

3 Mar 2012

Legal And Regulatory Issues Of Cloud Computing In India

Use of cloud computing in India is still not very liberal. There are many policy and law related issues that are responsible for slow growth and adoption of cloud computing in India. Absence of an effective cloud computing policy of India is responsible for limited utilisation of cloud computing in India. However, legal issues of cloud computing in India are the main reason for cautious adoption of cloud computing in India.

We have no dedicated regulatory framework for cloud computing in India. In fact, we have no legal framework for cloud computing in India at all. Even as per the research and studies of Perry4Law and Perry4Law Techno Legal Base (PTLB), cloud computing in India is risky and India is not ready for cloud computing. This conclusion of Perry4Law and PTLB has been endorsed by other companies and it has been reported that chief information officers (CIOs) in India are not comfortable using cloud computing in India.

In short, cloud computing in India is still not trusted. The primary reasons for this situation is absence of legal framework for cloud computing in India, missing privacy laws, absence of data protection laws in India, inadequate data security in India, etc.

Even the cloud computing due diligence in India is missing and companies and individuals are using the same in great disregard of the various laws of India. Cloud computing service providers in India are required to follow cyber law due diligence in India. The cyber law due diligence for Indian companies is now well established but cloud computing and e-commerce service providers are not taking it seriously.

We believe that India must not use software as a service (SaaS), cloud computing, m-governance, etc till proper legal frameworks and procedural safeguards are at place. This has also been accepted by the CIOs community and it is now for the Indian government to do the needful. Similarly, cloud computing security in India is also required to be strengthened. As on date, use of cloud computing in India is not a viable solution as we are ignoring legal and security concerns. Cloud computing in India must be techno legal in nature and till it meets the techno legal requirements, it should not be used in India.

Besides regulatory framework for cloud computing in India we must also ensure high availability levels, appropriate data erasing mechanisms, data privacy at the service provider’s level, export restrictions upon data, data handling monitoring mechanisms, jurisdictional issues, cloud computing security issues, licensing issues for cloud computing, etc.

Privacy violations, data breaches, data thefts, cyber crimes, etc would definitely arise in cases of use of cloud computing in India. Even if a company or individual offers cloud computing services in India, it/he has to comply with many legal provisions and cyber due diligence requirements. The information technology act 2000 (IT Act 2000) has prescribed due diligence requirements for various business organisations and stakeholders. These due diligence requirements equally apply to cloud computing service providers in India.

These due diligence requirements are very stringent and cloud computing providers can find themselves in legal hassles if they ignore the same. Managing sensitive and personal data and information in India is no more a causal approach but it has become very stringent.

With the proposal to codify law of torts in India, more and more civil proceeding for violation of privacy rights may be initiated against the cloud computing service providers. It would be a wise option to establish best practices and cloud computing policy by all stakeholders in their own larger interests.