360° Coverage : When The Government Closes Your Business

2 Updates
When The Government Closes Your Business

When The Government Closes Your Business

Feb 1 2014, 6:04pm CST | by

“The rules are the rules.”  Health Department Official in Madison County, Ill., after forcing the closure of 11-year-old Chloe Stirling’s cupcake business this week. This week I interviewed Michael...

Filed under: news


37 weeks ago

When The Government Closes Your Business

Feb 1 2014, 6:04pm CST | by

“The rules are the rules.”  Health Department Official in Madison County, Ill., after forcing the closure of 11-year-old Chloe Stirling’s cupcake business this week.

This week I interviewed Michael J. Daugherty, author of “The Devil Inside The Beltway ,” an expose on federal government overreach into cybersecurity and small business.

For those unaware of the case, Daugherty is the founder of LabMD, an Atlanta-based medical testing laboratory that has been caught up in a four-year-long battle with the FTC. Days ago, the company issued a press release: Following a 4:0 vote by the FTC on January 16 to reject LabMD’s motion to dismiss an August 2013 complaint against the facility, the company announced that it has begun the process of winding down. The book documents the company’s saga. While it’s highly specific to the FTC battle, Daugherty’s experience as a founder is also a sobering story for any business owner to read.

Daugherty opened LabMD 18 years ago, in 1996. The lab operated as a small business of 20-some employees and analyzed blood, urine and tissue samples for cancer, micro-organisms and tumor markers. The nightmare began like most any misadventure in business: a company spreadsheet showed up in a research project on accidental data leakage.  Somehow, the company’s database of private client information had escaped the firewall boundary. Upon investigation, the company discovered the unwitting culprit: an employee had downloaded LimeWire, a peer-to-peer sharing program, onto a company workstation to listen to music files during work. The peer sharing protocol, of course, created the means for sensitive client data to leave the network as well.

Yes, it was a serious issue and one that required corrective action. New security measures. Stronger employee procedures. Penalties, perhaps. Even fines.

But LabMD’s nightmare had only begun. What makes the LabMD story interesting is that the company has actually never been charged with a HIPAA violation (the federal government’s privacy regulation that governs who can look at and receive an individual’s private health information.) Instead, LabMD became one of a set of companies aggressively pursued by the Federal Trade Commission (FTC) for allegations of failure to protect sensitive client information, not as a HIPAA violation, but as a “deceptive and unfair trade practice.”

The difference is monumental, Daugherty says: “The IRS has rules. The SEC has regulations that a company must follow. But with the FTC—we’re dealing with a requirement to somehow ‘meet regulation’ in an arena where no clear rules or regulations exist.”

Two years of aggressive discovery ensued. The FTC issued a 12-page Civil Investigative Demand (CID) letter that required LabMD and several other companies affected to provide detailed information on every aspect of their computer systems and organization practice: What data was stored on each computer? What were the personal firewalls and routers used? How did a peer-to-peer program get onto the network? When did executives discover the P2P program? How did they inform their clients when the discovery was made? Mountains of depositions were conducted, with both current and former employees required to fly to Washington, D.C. to respond.

Finally, in August 2013, the FTC filed a formal complaint against LabMD, requiring, among other things, that the company institute a comprehensive information security program and submit to third party security audits twice yearly for the next 20 years. In other data breach cases, the FTC has targeted dozens of companies and almost all have taken the path of least resistance and settled charges rather than fighting in court, said Craig A. Newman, Managing Partner of the New York law firm Richards Kibbe & Orbe LLP and a cybersecurity expert.   (Newman does not represent Daugherty or LabMD, but discussed the case earlier this week with The Wall Street Journal).  Newman noted that the terms of FTC consent decrees have included requiring companies to adopt revised privacy and data security policies as well as data monitoring for up to 20 years.

Through a private watchdog group, Cause of Action (CoA), Daugherty and LabMD attempted to fight the FTC’s authority to regulate data security practices. In most cases, Daugherty notes, larger organizations have simply conceded and succumbed to fines as a means to survive. In a notable exception, hotel chain Wyndham Worldwide Corp is engaged in litigation in federal court, also challenging the FTC’s authority to regulate data security, according to Newman.  “These challenges to the FTC’s jurisdiction will not be resolved anytime soon and are destined for future appeals.”

When the government comes knocking at small business’ door, is throwing in the towel the only alternative? In his interview with me, Daugherty offered the following words of advice:

  1. As a small company, especially, document everything. Bear in mind, Daugherty cautions, that small businesses are informal environments where decisions tend to be made by “conversations as you walk down the hall.” But to increase your safety in an environment of regulation you should document every step and every decision to a degree that it would be understandable to even a stranger. Every operational procedure. Every technology purchase. The blueprint of the network. This is an arena where electronic alternatives or reliable services that specialize in governance can be especially helpful in keeping any potential for exposure (to theft or to liability) to the greatest minimum that you can.
  2. Get a comprehensive data security program in place. Unfortunately, Daughetry acknowledges, while alternatives such as Websense are suitable for mid to large organizations, very few truly comprehensive data security alternatives for smaller organizations exist. This means, however, an opportunity for aspiring entrepreneurs to develop increasingly better security alternatives that can keep a smaller organization compliant and safe where issues such as HIPAA regulation are concerned. However, as I have previously reported, cyber theft of every kind is an increasingly prevalent risk for small business, who can do much to increase their safety through even the small and straightforward steps such as applying malware and security software and putting sufficient physical access and password protection in place.
  3. Consider the implications – all of the implications – of staffing and outsourcing. How does a company’s liability shift when it employs directly versus work fulfillment through an external agency? In addition to macro issues such as FTC and SEC regulations, companies need to consider the implications of decisions such as whether they store client data (and particularly data such as medical records) on site or whether they outsource to the cloud. If you outsource, where is the cloud located? What is your company’s liability? Likewise, what is your liability for the actions of employees who are under your employ as opposed to those you engage through outside services? You should research these alternatives with care in advance.
  4. Be a savvy business “consumer”.  Every business owner must stay abreast of the changing regulatory climates that affect their industries and business, Daugherty says. A rapidly evolving environment presents a need (and also the opportunity) to stay nimble in working not only to keep your organization as safe as possible, but to capitalize on the opportunities to meet new market needs. For example, for better or worse, changing or increasing regulation creates a greater need and demand for services that can help other businesses to stay educated and to remain abreast and compliant in conjunction with change.

Most importantly of all, in Daugherty’s opinion, is the need for small businesses in the U.S. to get involved in the regulatory issues that affect them directly. As an immediate step, work with your local Chamber of Commerce, he recommends. (Nationally, the Chamber of Commerce is one of the organizations getting strongly involved in the issue of overreach by the FTC.) Contact your congressional leaders and let them know your feelings about the undue (and even unfair) restrictions the current regulatory environment is forcing your business to face. In all, a heavy regulatory environment enforces scenarios on small business that by anybody’s estimations are unjust. However, companies must be extremely careful of their responsibility to every restriction—as frustrating as it is to be felled by an unclear or an unfair environment, an entrepreneur should be doubly careful to avoid tripping in the regulatory arenas where specific rules exist.

For example, I mentioned to Daugherty the experience of a former close associate whose tangle with the IRS effectively felled his first business. As notices arrived that claimed he’d under-withheld on employee taxes he gamely tried to comply. Ultimately, convinced he was correct and had done all he could do to serve the complaint he began to ignore the notices. It was a bad plan: some time later he walked into the business one day to find the company’s accounts had been frozen. His operation had been forced to a halt. In the denouement, he recalls the ultimate agony: “When they had eventually combed through every detail of my business, I found out the last thing I wanted to hear. Turns out they were right.” The system was cumbersome, but his nightmare was an outcome that could have been avoided.

In other cases, it’s attention in the press (ironically) that can kick off a fledgling company’s woes: Consider the case in this week’s news of 11-year-old Chloe Stirling, of Illinois. This aspiring young girl recently started a cupcake business in the family kitchen with the goal of earning enough money to eventually purchase a car and perhaps to ultimately open a bakery. Her family was careful to ensure all license and compliance issues were covered, even purchasing a small refrigerator for Chloe where her ingredients and batter are kept. The trouble began when a local news agency, inspired by her story, ran a news segment to highlight her efforts to contribute her wares to fundraising efforts for cancer. The story caught the eye of the local Madison County Health department officials who ruled that unless the family builds a separate kitchen that it dedicates entirely to the business or purchases a commercial bakery, the venture must stop. (This story is still in progress as Chloe’s plight is now making headlines in the national news.)

In Daugherty’s case, after 25 years in the medical industry, his work at LabMD is winding down to a close. His disappointment in the system is palpable and the weariness of the “uphill fight” is clear in his voice. However, in the aftermath of his battle he is discovering a new career. He is increasingly involving himself in public activism, particularly as it pertains to the FTC. The Devil Inside The Beltway is premiering to positive reviews. For now, at least, Daugherty’s story is making national headlines (for an ongoing look at his progress, readers can visit www.michaeljdaugherty.com). He is also in demand as a keynote speaker.

Do you agree or disagree with Michael Daugherty’s approach to his battle with the FTC? What are your own experiences with business survival in in environment of heavy and unclear regulation? I look forward to hearing your thoughts.

Best Places On Earth To Run A Business

Source: Forbes Business


8 weeks ago

Khazanah throws MAS RM6b lifeline

Aug 29 2014 5:01pm CDT | Source: Business Times Singapore

August 30, 2014 1:15 AMKHAZANAH Nasional will inject RM6 billion (SS$2.4 billion) over three years to resuscitate loss-making Malaysia Airlines (MAS) under a recovery plan that includes even an Act of Parliament. Other key moves are migrating its operations, assets and liabilities to a new company (NewCo) an ...
Source: Business Times Singapore   Full article at: Business Times Singapore


8 weeks ago

MAS posts loss of RM307m for Q2

Aug 28 2014 5:00pm CDT | Source: Business Times Singapore

August 29, 2014 1:13 AMMALAYSIA Airlines (MAS) registered a loss of RM307 million (S$122 million) for the second quarter to end-June, but warned of worse to come in the second half when the "full financial impact of the double tragedies of MH370 and MH17" hi ...
Source: Business Times Singapore   Full article at: Business Times Singapore


Don't miss ...


<a href="/latest_stories/all/all/30" rel="author">Forbes</a>
Forbes is among the most trusted resources for the world's business and investment leaders, providing them the uncompromising commentary, concise analysis, relevant tools and real-time reporting they need to succeed at work, profit from investing and have fun with the rewards of winning.


blog comments powered by Disqus

Latest stories

India-born Sundar Pichai is Google's new product chief
Washington, Oct 25 (IANS) In a major restructuring of Google management, India-born Sundar Pichai, who is already in-charge of Android, Chrome and Google Apps, has been made the chief of core Google products, according to a technology magazine.
Mali: Country with 300 Indians records first Ebola death
Accra (Ghana), Oct 25 (IANS) The authorities in the West African nation of Mali, where the Indian embassy says there are between 200 and 300 of its nationals, have confirmed the death of the country's first Ebola patient, a two-year-old girl.
Ebola cases exceed 10,000: WHO
London, Oct 25 (IANS) The World Health Organisation (WHO), in its latest report Saturday said the number of Ebola virus cases has exceeded 10,000, with 4,922 deaths.
Sundar Pichai to head key Google products, services
New Delhi, Oct 25 (IANS) Search engine giant Google in a reorganisation of its management has assigned Sundar Pichai the leadership of core Google products, technology magazine Recode reported.

Latest from the Network

Second MERS case reported in Qatar
Doha, Oct 23 (IANS) A 43-year-old man in Qatar has tested positive for Middle East Respiratory Syndrome (MERS) in the second confirmed case of the deadly virus in 10 days, media reported Thursday. The patient had...
Read more on Business Balla
Two people die in Pakistan bomb blast
Islamabad, Oct 23 (IANS) At least two people were killed and 12 others injured in an explosion that took place in Pakistan's Balochistan province Thursday, media reported. The bomb was planted on a motorcycle, Dawn...
Read more on Politics Balla
Trott extends contract with Warwickshire till 2017
London, Oct 23 (IANS) England batsman Jonathan Trott, whose mental issues led to his abrupt departure from last winter's Ashes tour, has confirmed his successful comeback to competitive cricket by signing a new three-...
Read more on Sport Balla
Srikanth, Kashyap big movers in BWF rankings
Kuala Lumpur, Oct 23 (IANS) Indian men shuttlers Kidambi Srikanth and Parupalli Kashyap jumped seven places each in the latest Badminton World Federation (BWF) rankings released Thursday while Olympic bronze medallist...
Read more on Sport Balla
Alvin Stardust dead
London, Oct 23 (IANS) English singer Alvin Stardust died after a short illness. He was 72. Stardust's manager confirmed the news about his demise Thursday, reports mirror.co.uk. He was recently diagnosed with...
Read more on Celebrity Balla
Indian man reunited with family after 40 years
Dubai, Oct 23 (IANS) An Indian man, who had disappeared from his hometown in Kerala nearly 40 years ago, has been found by his family at a hospital in Dubai in the UAE, a newspaper report said. Now in his 60s, Abdulla...
Read more on Politics Balla
Srikanth, Kashyap, Saina rise in world rankings
Kala Lumpur, Oct 23 (IANS) Indian men shuttlers Kidambi Srikanth and Parupalli Kashyap jumped seven places each in the latest released Badminton World Federation (BWF) rankings Thursday while Olympic bronze medallist...
Read more on Sport Balla
Flintoff signs for Big Bash side Brisbane Heat
Brisbane, Oct 23 (IANS) Former England captain and all-rounder Andrew Flintoff, who retired from international cricket in 2009, Wednesday confirmed that he will play for Brisbane Heat in the Big Bash League (BBL) this...
Read more on Sport Balla
OPEC daily basket price falls again
Vienna, Oct 23 (IANS/WAM) The basket of 12 crude oils of the Organization of Petroleum Exporting Countries (OPEC) closed at $81.94 a barrel Wednesday compared to $82.09 Tuesday, the OPEC Secretariat said. The new OPEC...
Read more on Business Balla
Lopez to sign multi-million dollar deal?
Los Angeles, Oct 23 (IANS) Singer-actress Jennifer Lopez is reportedly in the final stages of securing a multi-million dollar deal to perform in Las Vegas. The 45-year-old is being offered $350,000 per show at The...
Read more on Celebrity Balla