|
CONSUMER NEWS RECALLS COMPLAINT FORM SCAM ALERTS |
| Small Claims Guide | Class Actions | Lemon Law | FAQ | Resources | Newsletters | Spanish | |
|
|
![]() |
Texas Sues CVS for Dumping Customer Records |
|||||
|
By Martin H. Bosworth April 19, 2007
Abbott's office posted redacted scans of the recovered information on its Web site, displaying receipts and forms full of personal information. Abbott's office is investigating if any of the information may have been used for identity theft or fraud. "Identity theft is one of the fastest growing crimes in the United States," Abbott said in a statement. "Texans can rest assured that we will continue aggressively cracking down on vendors who jeopardize the confidentiality of their clients' sensitive information." CVS is charged with violating Texas' "Identity Theft Enforcement and Protection Act" of 2005, under which businesses can be charged $50,000 for each potential violation. In addition, Abbott accused CVS of violating Chapter 35 of the state's Business and Commerce code, which requires businesses operating in Texas to develop and maintain procedures for retaining and disposing of customer data. Each exposed record could cost the drugstore giant $500. Radio Shack employees in Portland, Texas who had dumped thousands of customer records behind their store found themselves hit with a similar lawsuit from Abbott's office on April 3. Abbott had previously campaigned against the posting of Social Security numbers online by Texas county employees, a crusade he lost when Governor Rick Perry signed legislation approving the practice. Abbott was also one of the first state Attorneys General to sue the Sony corporation for selling CDs containing dangerous "rootkit" software that exposed users to potential hacker attacks. What Your Drug Store Knows About YouCVS and many other store chains gather extensive customer information through their "loyalty card" programs, which they will then often sell and resell to partner companies and third-party marketers, often without the customer's knowledge or express consent. The information gathered not only presents the retailers with a thorough profile of the customer, but also constitutes a serious identity theft risk if it is not properly safeguarded. CVS' "ExtraCare" rewards program was at the center of a small privacy breach in 2005 when the anti-loyalty card group CASPIAN (Consumers Against Supermarket Privacy Invasion And Numbering) exposed the ease with which people could obtain a CVS ExtraCare member's shopping history from the company Web site. The breach was shut down after CASPIAN founder Katherine Albrecht documented how someone could get access to any ExtraCare member's buying records just by using their card number, ZIP code, and the first three letters of their last name. Report Your Experience
|
|||||
Back to the top | |
||||||
Advertisement
|
Home |
Complaint Form |
News |
Recalls |
FAQ |
|
Terms of Use Your use of this site constitutes acceptance of the Terms of Use
Copyright © 2003-2008 ConsumerAffairs.com Inc. All Rights Reserved. The contents of this site may not be republished, reprinted, rewritten or recirculated without written permission. |
|