FTC Delays ‘Red Flags’ Rule Deadline
WASHINGTON — For the third time, the Federal Trade
Commission has put off compliance with the “Red Flags” rule,
postponing
its Aug. 1 deadline until Nov. 1.
Developed as a result of the Fair and Accurate Credit
Transactions Act of 2003, the anti-fraud regulation requires
financial institutions and other “creditors” to implement written
programs to identify the warning signs, or “red flags,” that could
indicate identity theft. Under the rule, HME providers who accept
deferred payment for equipment or services are considered
creditors.
In a news release issued today, the FTC said it would delay
enforcement of the rule to give covered companies more time to
review the guidance and get prevention programs in place to track
and respond to indicators of identify theft.
The rule was originally set to take effect Nov. 1, 2008, but
because of widespread confusion — notably whether the rule
applies to some companies — the FTC put off its deadline
until May 1, 2009. At the end of April, the agency pushed the deadline out to Aug. 1 and
set up an educational Web site about the rule.
According to the FTC release, the site now will be beefed up
with additional compliance guidance, including a special link for
“small and low-risk entities” about whether they are covered under
the rule and, if so, how they must comply.
The agency has posted FAQs that address how it intends to enforce the
rule, noting the FTC “would be unlikely to recommend bringing a law
enforcement action if entities know their customers or clients
individually, or if they perform services in or around their
customers’ homes, or if they operate in sectors where identity
theft is rare and they have not themselves been the target of
identity theft.”
See “Are You
Ready for the Red Flags Rule?” for a comprehensive Q&A on
the rule’s basics from health care attorney Jeff Baird of Brown
& Fortunato.
Read the full
text of the rule.
Post navigation
OUR DIGITAL PARTNERS


