DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

LabMD Responds to FTC Complaint: Claims Agency Lacks Enforcement Jurisdiction

Posted on September 19, 2013 by Dissent

Just received this press release from Cause of Action with LabMD’s response to FTC’s complaint:

Cause of Action (CoA), a government accountability organization, filed an answer to an aggressive and arbitrary enforcement action brought by the Federal Trade Commission (FTC) against LabMD, a small cancer diagnosis company.

CoA is defending LabMD against a complaint brought by the FTC in August, based, in part, on allegations that a third party was able to obtain data from LabMD’s computers through the peer-to-peer (P2P) file sharing program LimeWire. LabMD denies the FTC’s allegations of violations of Section 5 of the FTC Act as well as allegations that LabMD failed to provide reasonable and appropriate security for personal information on its computer networks. The filed answer also explains that the FTC may lack the statutory authority to regulate data-security practices as “unfair acts or practices” under Section 5.

“The FTC admitted in 2000 that it ‘lacks the authority to require firms to adopt information practice policies,’ and while they have wanted Congressional approval for that authority, Congress has said no,” explained Reed Rubinstein, Cause of Action’s senior vice president of litigation. “This is why we are asking the Administrative Law Judge to deny the Commission’s requested relief and dismiss the Complaint in its entirety.”

Cause of Action’s Executive Director, Dan Epstein explained, “Cause of Action is taking up this fight because the FTC’s attempt to exert authority that it does not have on a business that engaged in no wrongdoing is an abuse of agency authority that threatens American jobs.”

Key evidence of this lack of FTC authority includes:

  • Notwithstanding the FTC’s repeated requests that Congress confer upon it the authority to regulate data-security, Congress has refused to grant the FTC this authority.
    • In a 2000 report to Congress, Privacy Online: Fair Information Practices in the Electronic Marketplace: A Report to Congress, for example, the FTC admitted that it “lacks the authority to require firms to adopt information practice policies” and requested Congress enact legislation providing a federal agency with the authority to regulate data security. Since then, Congress has not passed any such law.
  • The FTC cannot rely on any judicial precedent for the proposition that the FTC has the authority to regulate data-security practices under Section 5.
  • Federal District Judge William Duffy recently noted that “there is significant merit to [LabMD’s] argument that Section 5 [of the Federal Trade Commission Act] does not justify an [FTC] investigation into data security practices and consumer privacy issues….”
  • Even if the Commission did have jurisdiction over the claims in the Complaint, which it does not, because the Commission has not published any rules, regulations, or other guidelines clarifying and providing any notice, let alone constitutionally adequate notice, of what data-security practices the Commission interprets Section 5 to prohibit or require, this administrative enforcement action against LabMD violates due process requirements guaranteed and protected by the Fifth Amendment to the U.S. Constitution.

CoA states in LabMD’s answer that “Section 5 of the FTC Act does not give the Commission the statutory authority to regulate the acts or practices alleged in the Complaint and therefore the Commission’s actions are arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law; contrary to constitutional right, power, privilege, or immunity; in excess of statutory jurisdiction, authority, or limitations, or short of statutory right; or without observance of procedure required by law.”

A hearing on the matter is scheduled for April 28, 2014 before Chief Administrative Law Judge Michael Chappell.

The FTC complaint can be found here  and the answer filed by CoA can be found here.

Category: Breach IncidentsCommentaries and AnalysesExposureHealth DataOf NoteU.S.

Post navigation

← Kaiser Permanente lawsuit against former business associate dismissed, but are patient data still at risk?
HHS: Statement of Delay in Enforcement of HIPAA Requirement for Certain CLIA and CLIA-Exempt Laboratories to Revise their Notices of Privacy Practices (NPP) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
  • Call for Public Input: Essential Cybersecurity Protections for K-12 Schools (2025-26 SY)
  • Cyberattack puts healthcare on hold for hundreds in St. Louis metro
  • Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.