Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Thursday, November 6, 2014

Public Service Announcement: "Combatting Financial Exploitation: A New Tool"

Regular readers of this blog know that preventing the financial exploitation of older or disabled folks is something that I am passionate about.  I've written and spoken on the topic frequently over the past couple of years.

This week, I had the privilege to join a distinguished panel of experts for a series of training webinars on combatting financial exploitation of the elderly and disabled.  The webinar was coordinated by the NC Administrative Office of the Courts (specifically, the inimitable Lori Cole), and included representatives of the NC Department of Justice (the ever-risible Raj Premakumar), UNC School of Government (the erudite Aimee Wall), NC Bankers Association (the staid Jan Dillon), and NC Department of Health and Human Services (the passionate triumverate of Nancy Warren, Renae Minor and LeShana Baldwin).  More than 300 participants registered, most of whom were lawyers, judges, clerks of court, financial professionals, and social services officials from all across North Carolina.

Here are a few quotes from participants who contacted us after the webinar to profide feedback:

"Thank you so much for all the great information I received with the combatting financial exploitation webinar class. This will help me to stay up to date with the new change." - an Assistant Clerk of Court

 "Thank you for an informative CLE!" - a County Attorney

 "Thanks for the program and the info!" - a County Attorney

 "The webinar today was a very good introduction." - an Assistant Clerk of Court

 "It was a very good program." - a Social Services Attorney

"The information was very helpful." - an Assistant Clerk of Court
For those who were unable to join us, a copy of the materials from the presentation is available here.

A video of the presentation will be available soon, and I will update this post to include it.

If you encounter circumstances that lead you to suspect the financial exploitation of an older or disabled person, whether in your professional life or your personal life, please report your suspicions appropriately. 

 
 

Tuesday, September 9, 2014

Social Media: Maximizing the Rewards while Minimizing the Risks

(This article was published in the Carolina Banker magazine by the North Carolina Bankers Association in the Fall 2014 issue.)


Social Media for Financial Institutions: Maximizing the Rewards while Minimizing the Risks



By now almost everyone knows that social media has tremendous potential for businesses of all kinds to connect with important constituent groups.  The average American spends 37 minutes per day on social media.  Facebook alone has more than 1.2 billion users, and a quarter of them log in more than five times per day.  Twitter has twice as many users as the United States has citizens.  In addition to marketing products and services to customers and prospects, banks now use social media to obtain feedback and market intelligence, recruit and engage employees, and enhance shareholder relationships.  These attractive opportunities do not come without risk; fortunately, however, these can be mitigated by an effective social media compliance and risk management program. 

Regulatory Attention

A few months ago, the Federal Financial Institutions Examination Council ("FFIEC"), which includes representatives from federal and state regulators, issued guidance for banks regarding the legal, operational and reputational risks associated with social media.  Soon, examiners will likely expect banks to have written risk assessments and social media policies and procedures.

The FFIEC guidance addressed many — but not all — of the outstanding banking law questions about social media.  Most of the regulations the guidance discusses involves the nature and placement of consumer disclosures, recordkeeping, and other straightforward issues.  The guidance also raised more complex issues, however, such as the risk of disparate impact, an anti-discrimination legal theory favored by the Consumer Financial Protection Bureau.  Not all of the outstanding questions were addressed by the guidance, however, so good, practical judgment will be needed to apply existing regulations in a new environment.  For example, customer privacy issues can arise in social media that require banks to respond to customer communications differently than other businesses might.

Importantly, the guidance states that even banks that do not have any official social media accounts should still consider the risks posed by social media, document the risk assessment, and adopt any policy needed to address identified risks.  Risks faced by banks that do not have an official social media account include reputational risks of negative comments and complaints by customers, as well as risks posed by employees' use of social media.  The regulators have made clear that a bank may be held responsible for an employee's social media use if it appears the employee is acting on behalf of the bank and the bank has not taken adequate steps to address the risk.  (How certain are you that none of your bank's employees are talking about the bank's products and services on their own social media accounts?)

Reputation Management

A widespread concerns among bankers about social media is the potentially damaging effects of publicly-aired customer complaints.  This is a real risk, but it is important to note that it is present whether or not a bank has a social media presence.  Disgruntled customers can — and do — air grievances on social media and customer review websites whether or not you have a Facebook page or Twitter profile.  If your bank has a presence on social media, however, you may have a better opportunity to identify and address those grievances. 

Both legal and practical considerations in determining whether, and how, to respond to a public complaint.  Well-crafted social media policies and procedures, coupled with a well-trained and savvy team, can effectively handle most public complaints, and may achieve net-positive outcomes.  When the commenter can be identified, the recommended approach is usually to simply ask the customer to remove the offending post.  If a commenter refuses to remove a false, misleading, or abusive comment voluntarily, you may resort to dealing with platform provider (e.g., Facebook, Twitter, Google, Yelp, etc.).  Each platform has terms and conditions that establish unique criteria for removing posts.  Understanding these criteria can help you draft a request to the platform that is more likely to result in the removal of an offending comment.  A letter sent from a knowledgeable lawyer on behalf of the bank is often helpful.

Spoofing

Social media presents opportunities for others to impersonate or "spoof" the bank.  However, this can happen whether or not a bank is active on social media, and in fact, by being active in social media, a bank can actually reduce the likelihood and effectiveness of these nefarious efforts.  Fortunately, most social media platforms are generally quick to shut down fraudulent accounts.

Promotions

Social media and promotional contests seem to go together like peanut butter and jelly.  They can be useful tools to encourage social sharing of your bank's content.  As with any promotional contest, various state and federal laws must be observed, and liability and reputational risks must be mitigated.  Also, some social media platforms restrict certain types of promotions.  It may be worthwhile to consult a knowledgeable lawyer before beginning any contest or drawing.

Developing a Policy, Procedures, and Implementation Team

The size and complexity of a social media program should be commensurate with the degree of the bank's involvement in social media.  For example, a bank that uses only one platform (e.g. Facebook) should have a more focused program.  A bank using several media (e.g., Facebook, LinkedIn, Twitter, Yelp, Google +, and YouTube) should have more comprehensive procedures.

The FFIEC advises that a social media program should be designed with participation from specialists in compliance, technology, information security, legal issues, human resources, and marketing.  Ideally, a team will be small, with individuals whose expertise spans more than one of these categories.  After a program is crafted, it can be implemented by a smaller team or an individual, with support from specialists as necessary. 

A recent survey revealed that banks in the southeastern United States  have the lowest rates of social media participation in the nation.  In some other regions of the country, banks are more than three times as likely to have a social media presence.  Given the size of the potential audiences and the high level of user engagement, it seems likely that more banks in our region will implement or expand social media strategies soon.  Though all risks cannot be eliminated, a well-crafted plan can manage the risks while maximizing the rewards. 


Friday, November 22, 2013

More on Elder Financial Abuse

I've written an article about North Carolina's new law designed to further protect older adults from financial exploitation, and it was published in Gray Matters (the official newsletter of the Elder & Special Needs Law Section of the North Carolina Bar Association) this week.  You can read it here or here.

http://elderlaw.ncbar.org/media/29919677/elnovember2013.pdf

You might also be interested to read the first column in the newsletter, the Chair's Comments, in which Bob Mason and I discuss the effects of the new statute on estate and Medicaid planning.

My friend and law school classmate Mike Anderson has written a more technical piece about the new law for the Estate Planning & Fiduciary Law Section's newsletter, The Will and The Way, focusing on criminal liability and the ability of agencies to obtain a subpoena.  (Mike's practice includes fiduciary litigation.)

If you read the North Carolina Business & Banking Law Blog regularly, you may recall that I first wrote about the new law in August, with related posts in September (addressing federal agency guidance for financial institutions) and October (sharing a PowerPoint presentation from a speech I gave on the topic at a joint seminar of the NC Bankers Association and the NC Credit Union League).

Wednesday, October 16, 2013

More on Protecting Older North Carolinians from Financial Exploitation

I had the honor of speaking today about the new law designed to help protect older North Carolinians from financial exploitation at the Elder Financial Abuse Summit co-sponsored by the North Carolina Bankers Association and the North Carolina Credit Union League. 

We had a great turnout of financial services professionals from banks and credit unions across the state.  If you were not able to attend, I am sharing my handouts here.
 

Please feel free to share these materials with anyone associated with a financial institution so that they will be aware of the tools and protections financial institutions now have to combate elder financial exploitation.

Sunday, August 4, 2013

New Law Helps Protect Older Adults and Disabled Persons from Financial Exploitation



Older North Carolinians will soon have a new source of protection from financial exploitation, and financial institutions will soon have a new customer protection law to observe.  

Just a couple of weeks ago, Governor Pat McCrory signed into law a bipartisan bill designed to protect older adults and disabled adults from financial exploitation.  The actual title of the bill is "AN ACT TO INCREASE THE RECOGNITION, REPORTING, AND PROSECUTION OF THOSE WHO WOULD DEFRAUD OR FINANCIALLY EXPLOIT DISABLED OR OLDER ADULTS and to CONTINUE THE TASK FORCE ON FRAUD AGAINST OLDER ADULTS, as recommended by THE TASK FORCE ON FRAUD AGAINST OLDER ADULTS."  If ever there was a bill that could benefit from a short title, this is it!  Alas, the General Assembly did not include a short title.  

The legislation was supported by the North Carolina Bankers Association, the North Carolina Credit Union Association, and the North Carolina Attorney General's office.  It passed almost unanimously: 111 to 1 in the House and 47 to 0 in the Senate.  (The lone objector was Rep. Speciale, who told me that he was concerned about the regulatory burden created.)

Photo credit: Ed Yourdon / Foter
The Act gives financial institutions permission to solicit a list of trusted individuals from older and disabled adults to notify in case of suspected exploitation.  Institutions are not required to ask for a list, nor are customers required to provide any names. 
 
If a financial institution, or an officer or employee of a financial institution, has "reasonable cause to believe that a disabled adult or older adult [customer] is the victim or target of financial exploitation," they must report the information.  (The term "disabled adult" means anyone who is physically or mentally incapacitated as defined in N.C.G.S. 108A-101(d). The term "older adult" means anyone age 65 or older.)  Note the use of the word "target," which, although not defined, implies that financial institutions should be somewhat proactive in reporting before a customer is victimized. It is also interesting that the term "financial exploitation" is defined as "the illegal or improper use of a disabled adult's or older adult's financial resources for another's profit or pecuniary advantage."  The use of the term "improper" indicates that the acts in question need not necessarily be illegal.
 
A financial institution must report suspected exploitation to the following:
  •  Persons on the list provided by the customer, if such a list has been provided by the customer (unless a person on the list is suspected);
  • The appropriate local law enforcement agency; and
  • The appropriate county department of social services, if the customer is a disabled adult.
The report may be verbal, but I would suggest documenting it in writing. The report must include the name and address of the customer, the nature of the suspected exploitation, and any other relevant information.  The Act provides that no financial institution, officer, or employee who reports this sort of information in good faith can be held liable for doing so.

The Act enables a law enforcement agency or a social services department investigating alleged financial exploitation to seek a  subpoena for the financial records of the disabled or older adult.  A customer whose information is turned over pursuant to a subpoena of this type cannot be penalized or prosecuted for anything obtained by a law enforcement agency using this type of subpoena, with the exception of a joint account holder accused of exploiting the other account holder.
 
The agency is required to notify the customer when the subpoena is issued, unless there is a risk that a customer notice could hamper an investigation, in which case the judge may order that the customer not be notified until later.  In that event, the judge's order will also direct the financial institution not to disclose the existence of the subpoena or investigation to the customer. 

Action Items for Financial Institutions:  The law becomes effective December 1, 2013.  Financial institutions should begin updating their subpoena response policies to address the new law, decide whether they will solicit lists of trusted individuals from their older or disabled customers, and update privacy policies to comport with the new law and policy.

You can read the full text of the new law here.



Monday, July 8, 2013

What Must a Business Do to Protect Customers from Identity Theft?



Don Hankins / Foter.com / CC BY
Despite growing awareness of the problem, identity theft continues to occur with increasing frequency and losses continue to rise.  For years, identity theft has been the most common complaint received by the Federal Trade Commission ("FTC").  The FTC recently reported that it received more than 400,000 complaints related to identity theft in 2012, including the misuse of personal information such as a social security, credit, or bank account number to commit fraud or theft. 
Clearly this is bad news for individual victims, but does your business have any legal obligation to combat identity theft?  The answer may be "yes." 

Under a smattering of state and federal statutes and regulations, businesses are increasingly being drafted by the government to fight in the war against identity theft. 

WRAL TechWire has recently published an article I wrote on this topic.  You can read more about identity theft and how businesses are required to address it here.  In the article, I cover the Federal Trade Commission's rules regarding the "red flags" of identity theft, address discrepancies, the North Carolina Identity Theft Protection Act, as well as California law.   The article also lays out the components of a suitable identity theft plan.

One of the best steps a company can take to protect itself prior to a problem arising is to create, adopt, and implement a well-conceived identity theft plan.  Not only will such a plan prevent potential identity theft, it may also help limit a company's losses in the event a problem does occur.  A business is well-advised to act promptly to protect its customers—and therefore itself—from the growing threat of identity theft.
 
(WRAL TechWire is an online news source for technology and business news and analysis for the Research Triangle Park and the Raleigh/Durham/Chapel Hill business and technology communities.  It is owned by Capitol Broadcasting Company, Inc., which operates the WRAL broadcast television station in the Triangle.)