X hits on this document

16 views

0 shares

0 downloads

0 comments

5 / 9

  • -

    ,p

1

2

required to be authorized, or licensed or required to be licensed, pursuant to the Insurance Code.

3

4

5

6

7

12. Spruill discarded over 1,000 insurance business records containing or bearing "personal information" as defined in ORS 646A.602(11) in that the documents contained business client names associated with unredacted Social Security numbers, driver license numbers, bank account numbers, and/or credit card numbers with card expiration dates.

8

9

10

11

13. Spruill failed to develop a comprehensive written information security plan with reasonable safeguards to protect the security, confidentiality and integrity of the personal information he collected or acquired in his insurance business in violation of ORS 646A.622(1) and OAR 836-081-0111(1).

12

13

14

15

16

17

14. By discarding over 1,000 insurance business records containing or bearing "personal information" into an unlocked trash container open to the public, Spruill failed to implement or maintain reasonable safeguards to protect the security, confidentiality and integrity of the personal information he collected or acquired in the course of conducting his business, including disposal of the data, as required by ORS 646A.622(1).

15.

By discarding over 1,000 insurance business records and other

19

documents related to insurance transactions into an unlocked trash container open to

20

21

22

the public, Spruill failed to implement a comprehensive written information security program that includes administrative, technical and physical safeguards for the protection of customer information as required by OAR 836-081-0111(1).

23

16.

Pursuant to ORS 646A.624(4)(a), a person who violates or who procures,

24

25

aids or abets in the violation of the Oregon Consumer Identity Theft Protection Act may be subject to a civil penalty of not more than $1,000 for every violation.

26

17.

Pursuant to ORS 731.988(1), an individual insurance producer, adjuster

Page 5-CEASE AND DESIST ORDER - Robert Warren Spruill (ID-09-0027)

Document info
Document views16
Page views16
Page last viewedSat Dec 03 19:45:24 UTC 2016
Pages9
Paragraphs369
Words2720

Comments