further down in the computerworld HIPPA article they have an example (examples seem to be everywhere) of some master file harvesting that includes credit card numbers ... and the resulting fraud and identity theft.
one of the issues is that if privacy related vulnerabilities continue to occur, there will continue to be additional regulatory and legislative actions. and from some other report: "ID theft is growing at 300% per year. The Aberdeen Group estimates that the Global Economy will sustain $221 Billion in losses related to Identity Theft by the end of 2003." and of course, some x9.59 standards objectives: 1) authenticated transactions, 2) cc# by itself is no longer sufficient for fraud and therefor doesn't have to be treated as a shared-secret or privacy issue, and 3) with strongly authentication transactions .... weaker authentication forms involving indentity information (like name, address, zip-code, etc) can be eliminated as part of the financial transaction. past postings related to x9.59 &/or privacy: http://www.garlic.com/~lynn/subpubkey.html#x959 past postings related to vulnerabilities, exploits, and/or fraud: http://www.garlic.com/~lynn/subpubkey.html#fraud -- Internet trivia, 20th anv: http://www.garlic.com/~lynn/rfcietff.htm
