Posted by Mark Brousseau
An interesting article from The Philadelphia Inquirer:
Social Security offering a debit-card option
By Harold Brubaker
Inquirer Staff Writer
Social Security recipients who receive paper checks because they do not use banks have a new way to get their money.
The U.S. Treasury Department said yesterday that it would begin pitching its new Direct Express debit card to 2.4 million beneficiaries from Maine to Virginia. Information about the card will come with this month's checks.
These recipients include nearly 250,000 people in Philadelphia and surrounding counties in Pennsylvania and about the same number in New Jersey.
"You can easily use this card to manage your money every month with no fees," said Judith R. Tillman, the commissioner of the department's Financial Management Service.
The card is designed to prevent lost checks, thwart check thieves, and save cashing fees that average $6 per check, she said.
Most Social Security recipients receive benefits by direct deposit into their bank accounts. Those without bank accounts typically use check-cashing firms.
The debit cards, issued by Comerica Bank of Dallas, allow users to track their spending at no charge on a Web site or through an automated telephone line. It costs 75 cents a month to get a paper statement. The system will not allow a card user to withdraw more than the available balance. That means there are no overdraft fees, which bedevil many elderly bank customers.
"It seems like a pretty good product," said Leslie Parrish, a senior researcher in the Washington office of the nonprofit Center for Responsible Lending.
"It eliminates the need to go to a check casher, but it also has a leg up on regular bank accounts if people are worried about overdrafting through a debit transaction," she said.
Tillman said her agency sends 489,000 Social Security and Supplemental Security Income checks to Pennsylvania every month, including 241,000 to Philadelphia and the surrounding area. In New Jersey, the figure is 263,000. She did not have a breakout for South Jersey.
If all four million people nationwide who receive Social Security or disability benefits but do not have bank accounts were to sign up for the debit card, taxpayers would save $42 million a year, said Tillman, a graduate of Glassboro State College, now called Rowan University.
The Treasury sent 59.1 million Social Security and disability payments in May. All but 10.5 million of them were deposited directly into bank accounts. The debit card is available to anyone who receives those benefits.
Social Security and Supplemental Security Income recipients may sign up for the card by calling toll-free 1-877-212-9991 or visiting www.USDirectExpress.com.
Monday, July 7, 2008
Wednesday, July 2, 2008
IRS Wants Payment Information
Posted by Mark Brousseau
An interesting article from the Washington Business Journal:
IRS may get reports on credit card payments
Kent Hoover, Washington Bureau Chief
Congress is on the verge of requiring payment card processors to tell the Internal Revenue Service how much money merchants receive through credit card and debit card transactions.
The Bush administration thinks this kind of third-party reporting of revenue would encourage more businesses to report their income accurately.
This could help close the tax gap -- the difference between what the government is owed in taxes and what it actually collects.
Congress views the requirement as an easy way of raising revenue to pay for other tax cuts or additional government spending. It estimates the proposal could raise nearly $10 billion over 10 years.
Under pending legislation:
... Financial institutions that reimburse merchants for credit card or debit card purchases would report annual payments for each merchant to the IRS
... These payment processors would be required to validate the Taxpayer Identification Number (TIN) for each merchant
... If the TIN couldn't be validated, the payment processors would be required to withhold taxes from the merchant
... These requirements also would apply to third-party organizations, such as PayPal, that serve as intermediaries for purchases. In this case, reports would not have to filed for merchants who have $10,000 or less in transactions or 200 or fewer transactions.
Both the House and the Senate included the reporting requirement as a revenue raiser in separate bills that appear headed for passage: House legislation to shield 21 million taxpayers from the alternative minimum tax (H.R. 6275) and Senate legislation to help homeowners and the housing industry (H.R. 3221).
The new requirement, however, couldn't help fund both bills, so the House and Senate would have to resolve this issue before the reporting rule could become law.
This gives small business groups and credit card processors more time to fight the requirement. They contend the proposal would be costly to implement and lead to unfair audits of small businesses that report their income accurately.
It may be too late to stop the requirement, however.
"This becomes very difficult to defeat because of the fact it's become an item that's accepted as a valid revenue raiser that can be used," said Giovanni Coratolo, director of small business policy for the U.S. Chamber of Commerce.
The appeal of the reporting requirement was summed up by Sen. Max Baucus, D-Mont.
"This proposal does not raise taxes on anyone," said Baucus, who chairs the Senate Finance Committee. "These information reports would just cause people to file more accurate returns."
Proposal costly for businesses
Opponents of the proposal doubt it would raise much revenue, however. Credit card receipts already show up on a merchant's bank statement, so tax cheats aren't likely to underreport this income, said Kristie Darien, executive director of the National Association of the Self-Employed.
The legislation, however, would require credit card processors to withhold taxes on payments to a merchant whose taxpayer identification number (TIN) couldn't be verified. But there are bound to be errors in the TIN verification process, Darien said, meaning some small businesses could have 28 percent of their credit card reimbursements withheld until the errors are corrected.
That could "put a severe strain on millions of American families counting on a self-employed breadwinner," she said.
Credit card processors said the proposal would cost them millions of dollars as well.
"Our systems do not currently track merchant payment transaction to TINs, and it will be extremely expensive and time-consuming to reprogram our systems to comply with the new mandates," said Kim Stubna, director of public policy for First Data Corp., a Denver-based processor of electronic payment transactions.
Small businesses fear these costs would be passed on to them through higher fees.
Donald Boeding, general manager of merchant services for Fifth Third Processing Services in Cincinnati, said the requirement "will likely strain the relationship between payment processors and merchant customers." Some merchants might decide that accepting credit cards is no longer worth the hassle. A move to cash would make it "less likely that the IRS will be able to track taxable income," he said.
IRS to profile businesses?
Small business lobbyists fear the IRS would use the reports to create industry profiles and audit small businesses whose credit card usage deviated from the norm.
That is "enormously concerning to us" because of "the great diversity" among small businesses, said Todd McCracken, president of the National Small Business Association. A difference in credit card usage "doesn't mean anything funny is going on," he said.
Plus, a company's actual revenue from credit card transactions would differ from what is reported because of chargebacks, returns, refunds, deposits and cash back on debit card purchases.
Yet small businesses could be audited "for no good reason" on the basis of these reports, McCracken said.
Coratolo said Congress would reject this type of profiling if individuals, not businesses, were being targeted.
"This is the camel's nose under the tent," he said.
Treasury Department spokesman Andrew DeSouza said he "wouldn't speculate" on what the IRS would do with this credit card data. But he said businesses also would get a copy of the reports, which would help them file accurate tax returns.
An interesting article from the Washington Business Journal:
IRS may get reports on credit card payments
Kent Hoover, Washington Bureau Chief
Congress is on the verge of requiring payment card processors to tell the Internal Revenue Service how much money merchants receive through credit card and debit card transactions.
The Bush administration thinks this kind of third-party reporting of revenue would encourage more businesses to report their income accurately.
This could help close the tax gap -- the difference between what the government is owed in taxes and what it actually collects.
Congress views the requirement as an easy way of raising revenue to pay for other tax cuts or additional government spending. It estimates the proposal could raise nearly $10 billion over 10 years.
Under pending legislation:
... Financial institutions that reimburse merchants for credit card or debit card purchases would report annual payments for each merchant to the IRS
... These payment processors would be required to validate the Taxpayer Identification Number (TIN) for each merchant
... If the TIN couldn't be validated, the payment processors would be required to withhold taxes from the merchant
... These requirements also would apply to third-party organizations, such as PayPal, that serve as intermediaries for purchases. In this case, reports would not have to filed for merchants who have $10,000 or less in transactions or 200 or fewer transactions.
Both the House and the Senate included the reporting requirement as a revenue raiser in separate bills that appear headed for passage: House legislation to shield 21 million taxpayers from the alternative minimum tax (H.R. 6275) and Senate legislation to help homeowners and the housing industry (H.R. 3221).
The new requirement, however, couldn't help fund both bills, so the House and Senate would have to resolve this issue before the reporting rule could become law.
This gives small business groups and credit card processors more time to fight the requirement. They contend the proposal would be costly to implement and lead to unfair audits of small businesses that report their income accurately.
It may be too late to stop the requirement, however.
"This becomes very difficult to defeat because of the fact it's become an item that's accepted as a valid revenue raiser that can be used," said Giovanni Coratolo, director of small business policy for the U.S. Chamber of Commerce.
The appeal of the reporting requirement was summed up by Sen. Max Baucus, D-Mont.
"This proposal does not raise taxes on anyone," said Baucus, who chairs the Senate Finance Committee. "These information reports would just cause people to file more accurate returns."
Proposal costly for businesses
Opponents of the proposal doubt it would raise much revenue, however. Credit card receipts already show up on a merchant's bank statement, so tax cheats aren't likely to underreport this income, said Kristie Darien, executive director of the National Association of the Self-Employed.
The legislation, however, would require credit card processors to withhold taxes on payments to a merchant whose taxpayer identification number (TIN) couldn't be verified. But there are bound to be errors in the TIN verification process, Darien said, meaning some small businesses could have 28 percent of their credit card reimbursements withheld until the errors are corrected.
That could "put a severe strain on millions of American families counting on a self-employed breadwinner," she said.
Credit card processors said the proposal would cost them millions of dollars as well.
"Our systems do not currently track merchant payment transaction to TINs, and it will be extremely expensive and time-consuming to reprogram our systems to comply with the new mandates," said Kim Stubna, director of public policy for First Data Corp., a Denver-based processor of electronic payment transactions.
Small businesses fear these costs would be passed on to them through higher fees.
Donald Boeding, general manager of merchant services for Fifth Third Processing Services in Cincinnati, said the requirement "will likely strain the relationship between payment processors and merchant customers." Some merchants might decide that accepting credit cards is no longer worth the hassle. A move to cash would make it "less likely that the IRS will be able to track taxable income," he said.
IRS to profile businesses?
Small business lobbyists fear the IRS would use the reports to create industry profiles and audit small businesses whose credit card usage deviated from the norm.
That is "enormously concerning to us" because of "the great diversity" among small businesses, said Todd McCracken, president of the National Small Business Association. A difference in credit card usage "doesn't mean anything funny is going on," he said.
Plus, a company's actual revenue from credit card transactions would differ from what is reported because of chargebacks, returns, refunds, deposits and cash back on debit card purchases.
Yet small businesses could be audited "for no good reason" on the basis of these reports, McCracken said.
Coratolo said Congress would reject this type of profiling if individuals, not businesses, were being targeted.
"This is the camel's nose under the tent," he said.
Treasury Department spokesman Andrew DeSouza said he "wouldn't speculate" on what the IRS would do with this credit card data. But he said businesses also would get a copy of the reports, which would help them file accurate tax returns.
Data Breaches Rising
Posted by Mark Brousseau
An interesting article from the Washington Post on the rising number of data breaches:
Data Breach Reports Up 69 Percent in 2008
By Brian Krebs
Businesses, governments and universities reported a record number of data breaches in the first half of this year, a 69 percent increase over the same period in 2007 driven by a spike in data thefts attributed to employees and contractors, according to an analysis by identity theft experts.
The San Diego-based Identity Theft Resource Center tracked 342 data breach reports from Jan. 1 to June 27. Nearly 37 percent of reports came from businesses -- an increase from almost 29 percent last year.
Data breach reports from health care providers (14.9 percent of the total) and banks (10 percent) continued to rise, while the share of breaches from educational institutions (21.3 percent of the total) government entities and the military (17 percent) declined for the third year in a row, the ITRC found.
Hacking was the least-cited cause of data breaches in the first six months of 2008 (11.7 percent of the total). Instead, lost or stolen laptops and other digital storage media remain the most frequently cited cause of data breaches, accounting for more than 20 percent of all reported cases, the ITRC found. The inadvertent posting of personal and financial data online prompted roughly 15 percent of the data breach disclosures.
While the share of breaches due to data on the move fell nearly eight percent from last year, that slack was picked up by insider theft. Data breaches due to information stolen by someone inside the company increased from just six percent of the total in 2007 to nearly 16 percent so far this year. Another 13.5 percent of breaches came from subcontractors who lost or stole their clients' customer data.
The 342 breaches the ITRC studied from this year involved almost 17 million consumer records. But ITRC founder Linda Foley said the true number of records jeopardized by those breaches is likely far higher, because in nearly 40 percent of the breaches the affected entity has not yet disclosed how many consumer records were lost or stolen.
Some 44 states and the District of Columbia now have laws requiring entities that suffer a data loss or breach to alert affected consumers (according to the ITRC, the states without data breach notification laws are Alaska, Alabama, Iowa, Kentucky, Mississippi and South Dakota). But Foley said only three states -- Maryland, New Hampshire and Wisconsin - require reporting to state officials and routinely publish that information online.
Breach notices filed with those three states have in many cases amounted to the first public disclosure of data breaches, but they also expose the gaps in those disclosure laws, Foley said.
On June 9, for example, the United Transportation Union Insurance Association notified the Maryland Attorney General that the loss of an undisclosed number of laptops jeopardized the names and Social Security numbers of 394 Maryland residents. However, the association has not yet said how many consumer records from all states were included on the missing laptops.
On May 8, Saks Inc. notified Maryland that the theft of four laptops had resulted in the loss of the name, address and Saks Fifth Avenue credit card numbers belonging to 2,391 Maryland residents. Saks similarly told the New Hampshire Attorney General's office that the breach affected 163 of that state's residents. Saks has not yet said how many customers nationwide may have been impacted by the lost laptops.
While a data breach may be reported as a single incident, it often masks the true number of institutions affected by the incident. This is most often the case with contractor breaches, such as one first publicly reported to the Maryland Attorney General's office on June 13. That notification was sent by attorneys for technology news media outlet CNET Networks, who said they were told that computer equipment stolen from Colt Express Outsourcing Services Inc., a California company that administers benefit plans to businesses across the country, resulted in the loss of records bearing the names, dates of birth and Social Security numbers of 6,500 CNET current and former employees and dependents.
Colt officials have declined to say how many total consumer records may have been affected, but several other businesses have reported receiving notifications from Colt over the past few weeks.
"It's a little like if you see a major pileup on the freeway, there's that one car that caused the whole accident, and then there are bunch of other innocent third parties that are affected due to the domino effect," Foley said.
An interesting article from the Washington Post on the rising number of data breaches:
Data Breach Reports Up 69 Percent in 2008
By Brian Krebs
Businesses, governments and universities reported a record number of data breaches in the first half of this year, a 69 percent increase over the same period in 2007 driven by a spike in data thefts attributed to employees and contractors, according to an analysis by identity theft experts.
The San Diego-based Identity Theft Resource Center tracked 342 data breach reports from Jan. 1 to June 27. Nearly 37 percent of reports came from businesses -- an increase from almost 29 percent last year.
Data breach reports from health care providers (14.9 percent of the total) and banks (10 percent) continued to rise, while the share of breaches from educational institutions (21.3 percent of the total) government entities and the military (17 percent) declined for the third year in a row, the ITRC found.
Hacking was the least-cited cause of data breaches in the first six months of 2008 (11.7 percent of the total). Instead, lost or stolen laptops and other digital storage media remain the most frequently cited cause of data breaches, accounting for more than 20 percent of all reported cases, the ITRC found. The inadvertent posting of personal and financial data online prompted roughly 15 percent of the data breach disclosures.
While the share of breaches due to data on the move fell nearly eight percent from last year, that slack was picked up by insider theft. Data breaches due to information stolen by someone inside the company increased from just six percent of the total in 2007 to nearly 16 percent so far this year. Another 13.5 percent of breaches came from subcontractors who lost or stole their clients' customer data.
The 342 breaches the ITRC studied from this year involved almost 17 million consumer records. But ITRC founder Linda Foley said the true number of records jeopardized by those breaches is likely far higher, because in nearly 40 percent of the breaches the affected entity has not yet disclosed how many consumer records were lost or stolen.
Some 44 states and the District of Columbia now have laws requiring entities that suffer a data loss or breach to alert affected consumers (according to the ITRC, the states without data breach notification laws are Alaska, Alabama, Iowa, Kentucky, Mississippi and South Dakota). But Foley said only three states -- Maryland, New Hampshire and Wisconsin - require reporting to state officials and routinely publish that information online.
Breach notices filed with those three states have in many cases amounted to the first public disclosure of data breaches, but they also expose the gaps in those disclosure laws, Foley said.
On June 9, for example, the United Transportation Union Insurance Association notified the Maryland Attorney General that the loss of an undisclosed number of laptops jeopardized the names and Social Security numbers of 394 Maryland residents. However, the association has not yet said how many consumer records from all states were included on the missing laptops.
On May 8, Saks Inc. notified Maryland that the theft of four laptops had resulted in the loss of the name, address and Saks Fifth Avenue credit card numbers belonging to 2,391 Maryland residents. Saks similarly told the New Hampshire Attorney General's office that the breach affected 163 of that state's residents. Saks has not yet said how many customers nationwide may have been impacted by the lost laptops.
While a data breach may be reported as a single incident, it often masks the true number of institutions affected by the incident. This is most often the case with contractor breaches, such as one first publicly reported to the Maryland Attorney General's office on June 13. That notification was sent by attorneys for technology news media outlet CNET Networks, who said they were told that computer equipment stolen from Colt Express Outsourcing Services Inc., a California company that administers benefit plans to businesses across the country, resulted in the loss of records bearing the names, dates of birth and Social Security numbers of 6,500 CNET current and former employees and dependents.
Colt officials have declined to say how many total consumer records may have been affected, but several other businesses have reported receiving notifications from Colt over the past few weeks.
"It's a little like if you see a major pileup on the freeway, there's that one car that caused the whole accident, and then there are bunch of other innocent third parties that are affected due to the domino effect," Foley said.
Labels:
archive,
Brousseau,
data breaches,
data security,
TAWPI
Subscribe to:
Posts (Atom)