HomeMy WebLinkAboutRESOLUTION NO. 2020-105 RESOLUTION NO. 2020-105
A RESOLUTION TO APPROVE AN IDENTITY THEFT PREVENTION
POLICY
WHEREAS,the City of Fairfax,Iowa has a need to receive federal grants and other federal
monies; and
WHEREAS, the federal regulations require the City of Fairfax to have certain policies in
place, which include an Identity Theft Prevention Policy.
NOW, THEREFORE, BE IT RESOLVED, by the City Council of the City of Fairfax,
Fairfax, Iowa, that they adopt the attached Identity Theft Prevention Policy; and
BE IT FURTHER RESOLVED,by the Fairfax City Council of the City of Fairfax, Iowa,
that the Mayor and City Clerk are hereby directed to certify this resolution of approval.
Passed and approved this 10th day of November, 2020.
AYES: Otto, Daly, Pacha, Volk, and Wainwright
NAYS: None
ti
Burnell G. Frieden, Mayor
ATTEST:
{a
i fr.
1 +y
C ' thia K. Stimson, City Ierk/Treasurer
C:w
CITY OF FAIRFAX
Identity Theft Prevention Policy
November 10, 2020
I. INTRODUCTION
The City of Fairfax developed this Identity Theft Prevention Policy ("Policy")pursuant to
the Federal Trade Commission's ("FTC") Red Flag Rule, which implements Section 114 of the
Fair and Accurate Credit Transaction Act of 2003. 16 C. F. R. § 681.2. This Policy is designed
to detect, prevent and mitigate identity theft in connection with the opening and maintenance of
certain City of Fairfax accounts. For purposes of this policy, "identity theft" is considered to be
"fraud committed using the identifying information of another person." The accounts addressed
by this policy are City of Fairfax accounts defined as:
1. An account the City offers or maintains primarily for personal, family or household
purposes, that involves multiple payments or transactions; and
2. Any other account the City offers or maintains for which there is a reasonably
foreseeable risk to customers or to the safety and soundness of the utility from
identity theft.
This policy was developed with oversight and approval of the Fairfax City Council.
After consideration of the size and complexity of the City's operations and account systems, and
the nature and scope of the City's activities, the City Council determined that this policy was
appropriate for the City of Fairfax and therefore approved this policy on November 10, 2020.
II. IDENTIFICATION OF RED FLAGS.
A"Red Flag" is a pattern, practice, or specific activity that indicates the possible
existence of identity theft. In order to identify relevant Red Flags, the City considered the types
of accounts that it offers and maintains, the methods it provides to open its accounts, the methods
it provides to access its accounts, and its previous experiences with identity theft. The City
identifies the following Red Flags, in each of the listed categories:
A. Suspicious Documents.
1. Receiving documents that are provided for identification that appear to
be forged or altered.
2. Receiving documentation on which a person's photograph or physical
description is not consistent with the person presenting the
documentation.
3. Receiving other documentation with information that is not consistent
with existing customer information(such as if a person's signature on
a check appears forged.)
4. Receiving an application for service that appears to have been altered
or forged.
B. Suspicious Personal Identifying Information.
1. A person's identifying information is inconsistent with other
sources of information(such as an address not matching
an address on a consumer report or a SSN that was never issued.)
2. A person's identifying information is inconsistent with other
information the customer provides (such as inconsistent SSNs or
birth dates).
2
3. A person's identifying information is the same as shown on other
applications found to be fraudulent.
4. A person's identifying information is consistent with fraudulent
activity (such as an invalid phone number or fictitious billing
address).
5. A person's SSN is the same as another customer's SSN.
6. A person's address or phone number is the same as that of another
person.
7. A person fails to provide complete personal identifying
information on an application when reminded to do so.
8. A person's identifying information is not consistent with the
information that is on file for the customer.
C. Unusual Use of or Suspicious Activity Related to an Account.
1. A change of address for an account followed by a request to
change the account holder's name.
2. An account being used in a way that is not consistent with prior
use (such as late or no payments when the account has been
timely in the past).
3. Mail sent to the account holder is repeatedly returned as
undeliverable.
4. The City receives notice that a customer is not receiving his
paper statements.
5. The City receives notice that an account has unauthorized
activity.
Other Red Flags in this category may include breaches in a City's computer system,
unauthorized access to or use of customer account information, and a City's plans to take steps
with certain data it maintains that contains customer information(i.e. destroying computer files).
D. Notice Regarding Possible Identity Theft.
1. The City receives notice from a customer, an identity theft victim, law
enforcement or any other person that it has opened or is maintaining a
fraudulent account for a person engaged in identity theft.
III. DETECTION OF RED FLAGS.
In order to detect any of the Red Flags identified above with the opening of a new
account, City personnel may take the following steps to obtain and verify the identity of the
person opening the account:
1. Will require certain identifying information such as name, date of birth,
residential or business address, telephone number, place of employment and
landlord's name if applicable. May contact landlord to verify information in
the case of a tenant. May also request SSN.
3
2. Will verify the customer's identity if unknown to staff, such as by reviewing
and photocopying a driver's license or other identification card.
3. May request and review documentation showing the existence of a
business entity.
In order to detect any of the Red Flags identified above for an existing account, City
personnel may take the following steps to monitor transactions with an account:
1. Verifying the identification of customers if they request information (in
person, via telephone, via facsimile, via email)
2. Verifying the validity of requests to change billing addresses.
3. Requiring those customers that request a debit to their bank account for
payment of their utility bill to appear in person to furnish or change
banking information.
IV. PREVENTING AND MITIGATING IDENTITY THEFT.
In the event City personnel detect any identified Red Flags, such personnel shall take one
or more of the following steps, depending on the degree of risk posed by the Red Flag:
1. Continuing to monitor an account for evidence of identity theft.
2. Contacting the customer.
4. Not opening a new account.
5. Notifying law enforcement.
6. Determining that no response is warranted under the particular
circumstances.
7. Notifying the Policy Administrator (as defined below) for
determination of the appropriate step(s) to take.
In order to further prevent the likelihood of identity theft occurring with respect to City
accounts, the City will take the following steps with respect to its internal operating procedures:
1. Will provide a secure website or clear notice that a website is not secure if
sensitive information is transmitted over the internet.
2. Old and/or obsolete records and handwritten notes that contain SSNs, birth
dates and customer bank information will be shredded.
3. Office computers will be password protected.
4. Hard drives will be destroyed or erased on office computers that are no longer
used by the utility.
5. Will ensure that sensitive customer information on computer screens is not
viewable to the public.
6. Sensitive, identifying customer information such as customer's SSNs, birth
dates and bank information will be kept in a locked area.
4
V. UPDATING THE POLICY AND THE RED FLAGS
This policy will be periodically reviewed and updated to reflect changes in risks to
customers and the soundness of the City from identity theft. At least every year the Policy
Administrator will consider the City's experiences with identity theft situations, changes in
identity theft methods, changes in identity theft detection and prevention methods, changes in
types of accounts the City maintains and changes in the City's business arrangements with other
entities. After considering these factors, the Policy Administrator will determine whether
changes to the policy, including the listing of Red Flags, are warranted. The Policy
Administrator may be authorized to make appropriate changes without City Council approval.
If warranted, the Policy Administrator may present the City Council with his or her
recommended changes and the City Council may make a determination of whether to accept,
modify or reject those changes to the Policy.
VI. POLICY ADMINISTRATION.
A. Oversight.
The City of Fairfax's Policy will be overseen by a Policy Administrator. The Policy
Administrator shall be the City Clerk-Treasurer, with the assistance of the Deputy City Clerk.
The Policy Administrator will be responsible for the policy's administration, for ensuring
appropriate training of City staff on the policy, for reviewing any staff reports regarding the
detection of Red Flags and the steps for preventing and mitigating identity theft, determining
which steps of prevention and mitigation should be taken in particular circumstances, reviewing
and, if necessary, approving changes to the policy.
B. Staff Training and Reports.
City staff responsible for implementing the policy shall be trained either by or under the
direction of the Policy Administrator in the detection of Red Flags, and the responsive steps to be
taken when a Red Flag is detected.
C. Service Provider Arrangements.
In the event the City engages a service provider to perform an activity in connection with
one or more accounts, the City will take steps to ensure the service provider performs its activity
in accordance with reasonable policies and procedures designed to detect, prevent, and mitigate
the risk of identity theft. These steps may include requiring, by contract, that service providers
have such policies and procedures in place, and report any Red Flags to the Policy
Administrator. Any detection of identity theft will be reported to the Policy Administrator and
appropriate steps will be taken to mitigate the risk.
5