FTC Alert
Client Alert | 1 min read | 06.06.05
On June 1, 2005, new FTC regulations became effective which outline the duties of persons and companies when disposing of consumer credit reports and information derived from consumer credit reports. Although the new regulations stem from the Fair and Accurate Credit Transactions Act (FACTA), the ramifications are broader because the regulations apply beyond credit reporting agencies and lenders traditionally covered by FACTA, and require that virtually any business that uses consumer credit information take more rigorous measures in handling that information.
The language of the regulations is surprisingly straightforward. The disposal regulations apply to “consumer information,” which is defined as “any record about an individual, whether in paper, electronic, or other form, that is a consumer report or is derived from a consumer report.” This would include any company that uses credit reports for background checks in hiring decisions, credit checks on customers or vendors, or other business investigations which utilize consumer reports. Any person or entity that maintains this consumer information must properly dispose of it by taking “reasonable measures” to protect against unauthorized access or use of the information. Examples given are burning, pulverizing or shredding such information, and destroying or erasing electronic media containing such information. Given the prevalence of identity theft and the prominence of identity theft in the media, aggressive FTC enforcement is likely. In addition, and perhaps more importantly, private civil liability is a potential danger for violations. Although it is not clear whether a private consumer harmed by identity theft could sue directly for a violation of the new regulations, state laws, such as California's unfair business practices law, allow private consumers to “piggyback” on other laws, even laws that do not justify individual lawsuits. It is therefore in the best interest of any company that uses credit information to take a close look at the new regulations and develop a compliance program.
Contacts
Insights
Client Alert | 2 min read | 03.27.26
CMS Releases PY 2020 RADV Audit Methods and Instructions: Key Takeaways for Health Plans
On March 20, 2026, the Centers for Medicare and Medicaid Services (CMS) released new guidance outlining the agency’s audit methods and instructions for Medicare Advantage (MA) plans subject to upcoming risk adjustment data validation (RADV) audits for payment year (PY) 2020. In addition to providing necessary context for MA plans selected for auditing, this resource clarifies CMS’s methodological and procedural expectations. While the high-level takeaways are recapped below for convenience, we strongly recommend that MA organizations selected for PY 2020 audits closely review the guidance to understand what may be involved — or required — during the agency’s review.
Client Alert | 4 min read | 03.25.26
NAIC Intensifies AI Regulatory Focus: What Health Insurance Payors Need to Know
Client Alert | 11 min read | 03.25.26
White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children
Client Alert | 3 min read | 03.24.26
California Considering A Massive Expansion of Its Antitrust Laws

