Loading...
HomeMy WebLinkAboutRESOLUTION NO. 2020-105 RESOLUTION NO. 2020-105 A RESOLUTION TO APPROVE AN IDENTITY THEFT PREVENTION POLICY WHEREAS,the City of Fairfax,Iowa has a need to receive federal grants and other federal monies; and WHEREAS, the federal regulations require the City of Fairfax to have certain policies in place, which include an Identity Theft Prevention Policy. NOW, THEREFORE, BE IT RESOLVED, by the City Council of the City of Fairfax, Fairfax, Iowa, that they adopt the attached Identity Theft Prevention Policy; and BE IT FURTHER RESOLVED,by the Fairfax City Council of the City of Fairfax, Iowa, that the Mayor and City Clerk are hereby directed to certify this resolution of approval. Passed and approved this 10th day of November, 2020. AYES: Otto, Daly, Pacha, Volk, and Wainwright NAYS: None ti Burnell G. Frieden, Mayor ATTEST: {a i fr. 1 +y C ' thia K. Stimson, City Ierk/Treasurer C:w CITY OF FAIRFAX Identity Theft Prevention Policy November 10, 2020 I. INTRODUCTION The City of Fairfax developed this Identity Theft Prevention Policy ("Policy")pursuant to the Federal Trade Commission's ("FTC") Red Flag Rule, which implements Section 114 of the Fair and Accurate Credit Transaction Act of 2003. 16 C. F. R. § 681.2. This Policy is designed to detect, prevent and mitigate identity theft in connection with the opening and maintenance of certain City of Fairfax accounts. For purposes of this policy, "identity theft" is considered to be "fraud committed using the identifying information of another person." The accounts addressed by this policy are City of Fairfax accounts defined as: 1. An account the City offers or maintains primarily for personal, family or household purposes, that involves multiple payments or transactions; and 2. Any other account the City offers or maintains for which there is a reasonably foreseeable risk to customers or to the safety and soundness of the utility from identity theft. This policy was developed with oversight and approval of the Fairfax City Council. After consideration of the size and complexity of the City's operations and account systems, and the nature and scope of the City's activities, the City Council determined that this policy was appropriate for the City of Fairfax and therefore approved this policy on November 10, 2020. II. IDENTIFICATION OF RED FLAGS. A"Red Flag" is a pattern, practice, or specific activity that indicates the possible existence of identity theft. In order to identify relevant Red Flags, the City considered the types of accounts that it offers and maintains, the methods it provides to open its accounts, the methods it provides to access its accounts, and its previous experiences with identity theft. The City identifies the following Red Flags, in each of the listed categories: A. Suspicious Documents. 1. Receiving documents that are provided for identification that appear to be forged or altered. 2. Receiving documentation on which a person's photograph or physical description is not consistent with the person presenting the documentation. 3. Receiving other documentation with information that is not consistent with existing customer information(such as if a person's signature on a check appears forged.) 4. Receiving an application for service that appears to have been altered or forged. B. Suspicious Personal Identifying Information. 1. A person's identifying information is inconsistent with other sources of information(such as an address not matching an address on a consumer report or a SSN that was never issued.) 2. A person's identifying information is inconsistent with other information the customer provides (such as inconsistent SSNs or birth dates). 2 3. A person's identifying information is the same as shown on other applications found to be fraudulent. 4. A person's identifying information is consistent with fraudulent activity (such as an invalid phone number or fictitious billing address). 5. A person's SSN is the same as another customer's SSN. 6. A person's address or phone number is the same as that of another person. 7. A person fails to provide complete personal identifying information on an application when reminded to do so. 8. A person's identifying information is not consistent with the information that is on file for the customer. C. Unusual Use of or Suspicious Activity Related to an Account. 1. A change of address for an account followed by a request to change the account holder's name. 2. An account being used in a way that is not consistent with prior use (such as late or no payments when the account has been timely in the past). 3. Mail sent to the account holder is repeatedly returned as undeliverable. 4. The City receives notice that a customer is not receiving his paper statements. 5. The City receives notice that an account has unauthorized activity. Other Red Flags in this category may include breaches in a City's computer system, unauthorized access to or use of customer account information, and a City's plans to take steps with certain data it maintains that contains customer information(i.e. destroying computer files). D. Notice Regarding Possible Identity Theft. 1. The City receives notice from a customer, an identity theft victim, law enforcement or any other person that it has opened or is maintaining a fraudulent account for a person engaged in identity theft. III. DETECTION OF RED FLAGS. In order to detect any of the Red Flags identified above with the opening of a new account, City personnel may take the following steps to obtain and verify the identity of the person opening the account: 1. Will require certain identifying information such as name, date of birth, residential or business address, telephone number, place of employment and landlord's name if applicable. May contact landlord to verify information in the case of a tenant. May also request SSN. 3 2. Will verify the customer's identity if unknown to staff, such as by reviewing and photocopying a driver's license or other identification card. 3. May request and review documentation showing the existence of a business entity. In order to detect any of the Red Flags identified above for an existing account, City personnel may take the following steps to monitor transactions with an account: 1. Verifying the identification of customers if they request information (in person, via telephone, via facsimile, via email) 2. Verifying the validity of requests to change billing addresses. 3. Requiring those customers that request a debit to their bank account for payment of their utility bill to appear in person to furnish or change banking information. IV. PREVENTING AND MITIGATING IDENTITY THEFT. In the event City personnel detect any identified Red Flags, such personnel shall take one or more of the following steps, depending on the degree of risk posed by the Red Flag: 1. Continuing to monitor an account for evidence of identity theft. 2. Contacting the customer. 4. Not opening a new account. 5. Notifying law enforcement. 6. Determining that no response is warranted under the particular circumstances. 7. Notifying the Policy Administrator (as defined below) for determination of the appropriate step(s) to take. In order to further prevent the likelihood of identity theft occurring with respect to City accounts, the City will take the following steps with respect to its internal operating procedures: 1. Will provide a secure website or clear notice that a website is not secure if sensitive information is transmitted over the internet. 2. Old and/or obsolete records and handwritten notes that contain SSNs, birth dates and customer bank information will be shredded. 3. Office computers will be password protected. 4. Hard drives will be destroyed or erased on office computers that are no longer used by the utility. 5. Will ensure that sensitive customer information on computer screens is not viewable to the public. 6. Sensitive, identifying customer information such as customer's SSNs, birth dates and bank information will be kept in a locked area. 4 V. UPDATING THE POLICY AND THE RED FLAGS This policy will be periodically reviewed and updated to reflect changes in risks to customers and the soundness of the City from identity theft. At least every year the Policy Administrator will consider the City's experiences with identity theft situations, changes in identity theft methods, changes in identity theft detection and prevention methods, changes in types of accounts the City maintains and changes in the City's business arrangements with other entities. After considering these factors, the Policy Administrator will determine whether changes to the policy, including the listing of Red Flags, are warranted. The Policy Administrator may be authorized to make appropriate changes without City Council approval. If warranted, the Policy Administrator may present the City Council with his or her recommended changes and the City Council may make a determination of whether to accept, modify or reject those changes to the Policy. VI. POLICY ADMINISTRATION. A. Oversight. The City of Fairfax's Policy will be overseen by a Policy Administrator. The Policy Administrator shall be the City Clerk-Treasurer, with the assistance of the Deputy City Clerk. The Policy Administrator will be responsible for the policy's administration, for ensuring appropriate training of City staff on the policy, for reviewing any staff reports regarding the detection of Red Flags and the steps for preventing and mitigating identity theft, determining which steps of prevention and mitigation should be taken in particular circumstances, reviewing and, if necessary, approving changes to the policy. B. Staff Training and Reports. City staff responsible for implementing the policy shall be trained either by or under the direction of the Policy Administrator in the detection of Red Flags, and the responsive steps to be taken when a Red Flag is detected. C. Service Provider Arrangements. In the event the City engages a service provider to perform an activity in connection with one or more accounts, the City will take steps to ensure the service provider performs its activity in accordance with reasonable policies and procedures designed to detect, prevent, and mitigate the risk of identity theft. These steps may include requiring, by contract, that service providers have such policies and procedures in place, and report any Red Flags to the Policy Administrator. Any detection of identity theft will be reported to the Policy Administrator and appropriate steps will be taken to mitigate the risk. 5