Monday, January 12, 2015

Training & Education : 4 Common Mistakes in Government Social Media Policies

These best practices are commonly overlooked in the development of government social media policies.

Twitter birds on telephone line
You probably know that developing a good social media policy for your agency is important. A solid policy guides staff, minimizes risk and helps citizens understand your approach to social. However, there are a few best practices that are commonly overlooked in the development of government social media policies.
 

Tone Deaf


Have you thought about the tone of your social media policy? It might seem trivial, but your policy should strive to be helpful, encouraging and optimistic. You want to send a message that your agency is not against social media — instead you recognize the tremendous value in these tools and want to be consistent and treat everyone fairly.   

Social media still tends to make some people uncomfortable, whether due to lack of familiarity or concern about its application. Having a positive tone in your policy can go a long way toward acceptance for both internal staff and the public.  
 

Excluding Elected Officials


Many policies cover employee use of social media, but leave out language pertaining to elected officials. Many elected officials want to embrace social media to better communicate with constituents, but some have indeed exercised bad social media judgment.

Your policy should include electeds in the “Responsibilities” section, which defines who is responsible for what. Department heads are responsible for assigning social media leads for their department, elected officials are responsible for abiding by laws pertaining to campaigning and open meetings as they relate to social media, etc. This language is especially important to employees who report directly to an elected official and may be asked to post on social networks on his or her behalf.
 

Dated Upon Rollout


A sure way to ensure your social media policy is outdated almost immediately upon rolling it out is to specifically reference platforms and strategies.   

While it’s important to broadly define social media terminology to ensure that everyone reading the policy is speaking the same language, the fact is that platforms change all the time. You do not want your policy to require updating and the lengthy approval process that can come along with it, every time a new Snapchat or Vine is introduced. Instead, define broad terms such as microblog, social network, video sharing platform, etc. 

Social Media Policy Framework

References References overlap with other policies Definitions Broadly define social media terminology Responsibilities Who is responsible for what ProceduresTypically the lengthiest section
  • Account creation
  • Logins and passwords
  • Elected officials
  • Comment policy
  • Monitoring
  • Archival
  • Employee use
Where do you get specific about the approach to particular platforms such as Facebook, Twitter and YouTube? That magic is going to happen in your social media strategy document. One benefit of including this level of specificity in your strategy document is avoiding the delays that typically go along with pushing a policy update through the system. Just be sure to make a reference to the strategy document within your official policy.   
 

Keeping it Under Wraps


Many public agencies do not typically make their internal policies available to the public. But make an exception for the social media policy and publish it in its entirety on your official government website. Going further, extract the portion of the policy that deals with comments and monitoring and publish a hyperlink to this section on key public areas like social media profile descriptions. This simplifies your policy for citizens because they will be able to easily find the portion that pertains to them.

There are several other important components to a good social media policy, but these four approaches should not be overlooked.
This article was originally published by Government Technology.
www.emergencymgmt.com 

Homeland Security and Public Safety : Keeping Hackers Out of Hospitals: Examining Cybervulnerabilities and Health Care

What if hackers could hijack a pump on a hospital’s information network and use it to eavesdrop on sensitive data?

Hospital technology
(TNS) — The humble infusion pump: It stands sentinel in the hospital room, injecting patients with measured doses of drugs and writing information to their electronic medical records.

But what if hackers and identity thieves could hijack a pump on a hospital’s information network and use it to eavesdrop on sensitive data like patient identity and billing data for the entire hospital?

It is not a far-fetched scenario. Though it hasn’t happened yet, the hacking of wireless infusion pumps is considered a critical cybersecurity vulnerability in hospitals — so much so that federal authorities are focusing on the pumps as part of a wide-ranging effort to develop guidelines to prevent cyberattacks against medical devices.

Pumps with Wi-Fi were selected to kick off the new effort because their individual vulnerabilities are magnified by their sheer numbers inside hospitals and clinics.

“Infusion pumps are ubiquitous. At Allina, we have over 3,000 infusion pumps across the system,” said Linda Zdon, director of information security and compliance at the 12-hospital Twin Cities health system. “Almost every hospital patient at some point has an infusion pump. So it certainly strikes at an area that has a broad application for most patients, and therefore has a significant impact on health systems.”

Allina is one of several Twin Cities health care players that has been working with the National Institute of Standards and Technology since the spring to develop a type of technical analysis known as a “use case” for wireless pumps. The companies’ goal is to speed along the development of new standards to harden medical devices against cyberattacks and computer viruses.

Devicemakers say they’re already hard at work improving security, but hospitals complain that the companies have been moving too slowly on a vulnerability that puts hospitals’ information systems at risk.

In a Nov. 21 letter to the Food and Drug Administration, the American Hospital Association urged the federal government to “hold device manufacturers accountable for cybersecurity.” The Homeland Security Department, meanwhile, is reportedly investigating suspected cybersecurity flaws in one model of infusion pump.

Patients tend to fear a malicious person would try to steal data or even scramble the dosing instructions for an individual pump. While those risks are real, security experts say they’re far less likely than a hack to gain access to a hospital’s wider network traffic. For one thing, attacking an individual through their pump would draw attention and close off what could be a potentially lucrative entry point to many patients’ data.

Minnesota companies like Allina, Fairview Health Services and HealthPartners are playing a central role in the development of the new federal guidelines through early collaboration with researchers. The NIST project was unveiled in December in a presentation before the University of Minnesota’s Technological Leadership Institute. NIST hopes to publish this first set of recommendations as soon as next fall, and then move on to security vulnerabilities in implantable medical devices and large equipment like magnetic-resonance imaging scanners.

Cyber-vulnerabilities are a top-of-mind concern in health care these days. In July, the 200-hospital Community Health Systems revealed in securities filings that a group from China hacked its files and stole information including names, addresses, birth dates and Social Security numbers for about 4.5 million patients. Company officials haven’t said how the hackers got into the system.

Recent headlines have been dominated by the international intrigue surrounding the massive hack at Sony Pictures Entertainment, but several people at the NIST meeting in Minneapolis compared hospitals’ infusion pump vulnerability to what happened at Target Corp. Last year hackers accessed personal data on more than 70 million customers after breaching the retailer’s computer system through a digital side-door created for a heating, ventilating and air-conditioning contractor. The retailer’s sales immediately slumped and its CEO resigned a few months after the company revealed the breach.

“The infusion pump is to the hospital what the HVAC system was to Target. That is, it becomes the vector to get in,” said Ken Hoyme, a computer-security scientist at Minneapolis’ Adventium Labs.

The risk, as described in a Dec. 18 draft of the NIST infusion-pump study, is that a hacker could write malware to compromise a pump, and then use the pump’s network access to plant malicious computer code in the hospital’s central systems. Hoyme said specialized code could be written that would cause the network to send sensitive information outside the hospital to an anonymous network of other infected computers, where it could be sold to identity thieves or used to generate negative publicity about the target.

Although it’s a common fear that talking openly about cybersecurity vulnerabilities will give hackers ideas, experts note that attackers would still need an extraordinary amount of skill and access to a device to pull off an attack.

Gavin O’Brien, one of the lead authors of the NIST report, said public discussion will cause consumers of health-information technology to become better-informed and start demanding more security features.

“Educating enterprises on how to improve their security will benefit the industry,” O’Brien said in an email. “To ignore these issues or just talk about them in small circles may not be enough to push the market into building the security into the products.”

The FDA — working independently from the NIST study — has been concerned with infusion pumps since it launched a 2010 review of software defects and related issues in response to 56,000 reports of adverse events.

Separately, the FDA last fall convened its first-ever cybersecurity conference for medical devices, including infusion-pump makers. That work is ongoing. Following the FDA meeting, Reuters reported that Homeland Security officials have opened investigations into suspected cybersecurity flaws in medical devices, including an infusion pump sold by Chicago-based supplier Hospira.

Hospira, which is listed as the lone devicemaker company working with NIST on the infusion pump guidelines, declined to comment for this story. CareFusion, a major infusion-pump devicemaker based in San Diego, listed several specific steps it takes to secure its devices, including working with third-party experts to test and validate product security and using strong data encryption.

It remains to be seen whether the news about hacks at Sony and Target or the NIST will spur more rapid action by devicemakers. But it if doesn’t, the companies won’t be able to say they weren’t warned.

After the Sony hack, Homeland Security Secretary Jeh Johnson issued a statement saying, “This event underscores the importance of good cybersecurity practices to rapidly detect cyber intrusions and promote resilience throughout all of our networks. Every CEO should take this opportunity to assess their company’s cybersecurity.”

©2015 Star Tribune (Minneapolis). Distributed by Tribune Content Agency, LLC.
www.emergencymgmt.com 

Homeland Security and Public Safety : Drones Do Not Create a More Secure Border, DHS Official Says

Drones patrolling the U.S. border are poorly managed and ineffective at stopping illegal immigration, reports the DHS inspector general.

Drone patrolling the U.S. border
(TNS) — Drones patrolling the U.S. border are poorly managed and ineffective at stopping illegal immigration, and the government should abandon a $400 million plan to expand their use, according to an internal watchdog report released Tuesday.

The 8-year-old drone program has cost more than expected, according to a report by the Department of Homeland Security’s inspector general, John Roth.

Rather than spend more on drones, the department should “put those funds to better use,” Roth recommended. He described the Predator B drones flown along the border by U.S. Customs and Border Protection as “dubious achievers.”

“Notwithstanding the significant investment, we see no evidence that the drones contribute to a more secure border, and there is no reason to invest additional taxpayer funds at this time,” Roth said in a statement.

The audit concluded that Customs and Border Protection could better use the funds on manned aircraft and ground surveillance technology.

The drones were designed to fly over the border to spot smugglers and illegal border crossers. But auditors found that 78 percent of the time that agents had planned to use the craft, they were grounded due to bad weather, budget constraints or maintenance problems.

Even when aloft, auditors found, the drones contributed little. Three drones flying around the Tucson, Ariz., area helped apprehend about 2,200 people illegally crossing the border in 2013, fewer than 2 percent of the 120,939 apprehended that year in the area.

Border Patrol supervisors had planned on using drones to inspect ground-sensor alerts. But a drone was used in that scenario only six times in 2013.

Auditors found that officials underestimated the cost of the drones by leaving out operating costs such as pilot salaries, equipment and overhead. Adding such items increased the flying cost nearly fivefold, to $12,255 per hour.

“It really doesn’t feel like (Customs and Border Protection) has a good handle on how it is using its drones, how much it costs to operate the drones, where that money is coming from or whether it is meeting any of its performance metrics,” said Jennifer Lynch, a lawyer for the Electronic Frontier Foundation, a San Francisco-based privacy and digital rights group.

The report’s conclusions will make it harder for officials to justify further investment in the border surveillance drones, especially at a time when Homeland Security’s budget is at the center of the battle over President Barack Obama’s program to give work permits to millions of immigrants in the country illegally. Each Predator B system costs about $20 million.

“People think these kinds of surveillance technologies will be a silver bullet,” said Jay Stanley, a privacy expert at the American Civil Liberties Union. “Time after time, we see the practical realities of these systems don’t live up to the hype.”

Customs and Border Protection, which is part of Homeland Security, operates the fleet of nine long-range Predator B drones from bases in Arizona, Texas and North Dakota.

The agency purchased 11 drones, but one crashed in Arizona in 2006 and another fell into the Pacific Ocean off San Diego after a mechanical failure last year.

Agency officials said in response to the audit that they had no plans to expand the fleet aside from replacing the Predator that crashed last year. The agency is authorized to spend an additional $433 million to buy up to 14 more drones.

The drones — unarmed versions of the MQ-9 Reaper drone flown by the Air Force to hunt targets in Pakistan, Somalia and elsewhere — fly the vast majority of their missions in narrowly defined sections of the Southwest border, the audit found.

They spent most of their time along 100 miles of border in Arizona near Tucson and 70 miles of border in Texas.

Rep. Henry Cuellar, D-Texas, has promoted the use of drones along the border but believes the agency should improve how it measures their effectiveness.

Homeland Security “can’t prove the program is effective because they don’t have the right measures,” Cuellar said in an interview. “The technology is good, but how you implement and use it — that is another question.”

The audit also said that drones had been flown to help the FBI, the Texas Department of Public Safety and the Minnesota Department of Natural Resources.

Such missions have long frustrated Border Patrol agents, who complain that drones and other aircraft aren’t available when they need them, said Shawn Moran, vice president of the Border Patrol agents’ union.

“We saw the drones were being lent out to many entities for nonborder-related operations and we said, ‘These drones, if they belong to (Customs and Border Protection), should be used to support (its) operations primarily,’ ” Moran said.

©2015 Tribune Co. Distributed by Tribune Content Agency, LLC.
www.emergencymgmt.com 

Public Health : Using Social Media Data to Identify Outbreaks and Control Disease

Could infectious disease surveillance systems that accurately track social media data inform early warning systems and outbreak response?

The HealthMap tool uses informal online sources to monitor public health trends. HealthMap
The recent Ebola outbreak unearthed an interesting phenomenon. A “mystery hemorrhagic fever” was identified byHealthMap — software that mines government websites, social networks and local news reports to map potential disease outbreaks — a full nine days before the World Health Organization declared the Ebola epidemic. This raised the question: What potential do the vast amounts of data shared through social media hold in identifying outbreaks and controlling disease?

Ming-Hsiang Tsou, a professor at San Diego State University and an author of a recent study titled The Complex Relationship of Realspace Events and Messages in Cyberspace: Case Study of Influenza and Pertussis Using Tweets, believes algorithms that map social media posts and mobile phone data hold enormous potential for helping researchers track epidemics.

“Traditional methods of collecting patient data, reporting to health officials and compiling reports are costly and time consuming,” Tsou said. “In recent years, syndromic surveillance tools have expanded and researchers are able to exploit the vast amount of data available in real time on the Internet at minimal cost.”

Given the popularity of social media, infectious disease surveillance systems that use data-sharing technologies to accurately track social media data could potentially inform early warning systems and outbreak response, and facilitate communication between health-care providers and local, national and international health authorities.
 

A Shifting Approach


Indicator-based methods that rely on the collection and analyses of data based on protocols tailored to each disease are the most common method of disease tracking today. But such methods can’t detect potential threats quickly. In addition, they are poorly equipped to detect new diseases. Given such facts, some health agencies have begun to consider new ways to monitor symptoms in order to speed detection.

Additionally people do not always visit a doctor when they feel sick, making data collected from doctors and hospitals less useful. Yet people who stay home sick are likely to use social media to discuss their illness or search websites like Google to investigate their symptoms. 

Currently there are no official national programs for disease surveillance via social media, but several systems are being used as complementary sources of information.

For example, disease detection app Flu Near You helps predict outbreaks of the flu in real time. Users self-report symptoms in a weekly survey, which the app then analyzes and maps to show where pockets of influenza-like illness are located. Flu Near You is administered by HealthMap in partnership with the American Public Health Association and the Skoll Global Threats Fund. The effort is supported with private funds to demonstrate its utility for multiple sectors that work together on pandemic preparedness. The information on the site is available to public health officials, researchers, disaster planning organizations and anyone else who may find the information useful.

“There are real opportunities for using this data that is scattered across the Web in news, blogs, chat rooms and social media,” said John Brownstein, HealthMap co-founder and associate professor of pediatrics at Harvard Medical School. “We’re focused on collecting all that information using data scraping, machine learning and other processes and combining it into one platform that will enable clinicians, public health practitioners and consumers to see what’s happening.”

Brownstein said the volume of data that can be collected today is what predicates the value. “One individual on social media talking about their illness is not going to be that useful,” he said. “But in aggregate, that information can tell us really useful things about epidemics. It can even tell us about new things, like the Enterovirus epidemic that we recently experienced. So we are developing systems that are much more crowdsourcing in nature. We are trying to better engage the public, to put the ‘public’ back in public health. That provides us some really exciting opportunities to understand what’s happening on the ground level.”

Understanding the accuracy of such information is also important, said Tsou, whose recent study explored the interaction between cyberspace message activity (measured by keyword-specific tweets) and real-world occurrences of influenza and pertussis. Tweets were collected within a 17-mile radius of 11 U.S. cities chosen on the basis of population and the availability of disease data. Tweets were then aggregated by week and compared to weekly influenza-like illness and pertussis incidence. The correlation coefficients between tweets or subgroups of tweets and disease occurrence were then calculated and trends were presented graphically.

“The correlation between the weekly flu tweets versus the national flu data was almost 86 percent,” said Tsou. “It was a very high correlation. Even more interesting is that when we compared our data to data from the San Diego County Health and Human Services Agency, who we partner with, we received even more precise data on weekly flu cases reported through their lab testing. The correlation was 93 percent — even higher than the national level. That was a very encouraging finding.”

But utilizing social media data in this manner also presents challenges, such as correlating a social media post with a specific disease or condition. 

“A lot of people tweet that they have a fever or have the flu, but sometimes that information isn’t specific enough for us to connect it with a disease like whooping cough,” Tsou said. “That’s one of the limitations we are dealing with.”

“There’s both a blessing and a curse to using social media in that it’s super rapid, but it also generates huge amounts of noise,” Brownstein said. “Dealing with all the noise and trying to pick out the signals that have meaning is definitely a challenge.”
 

Public Health Possibilities


Some public health agencies are already beginning to rely on social media data to investigate health issues. 

For example, last year the Chicago Department of Public Health began using Twitter to identify cases of foodborne outbreaks. The department teamed up with a group called Smart Chicago to develop an app that analyzes tweets that reference food poisoning, leading the city to step up inspections and enforcement on offending establishments. 

The New York City Department of Health and Mental Hygiene is taking a similar approach. It recently worked with Columbia University and Yelp on a pilot to prospectively identify restaurant reviews on Yelp that referred to foodborne illness.

“These systems are operational, and they are being used by government entities to provide situational awareness,” Brownstein said. “They’re not necessarily the only sources of information, but they are an important source of information.”

But it may still be a while before public health departments officially adopt social media data as a significant element of their regular investigations. 

“Public health officials tend to be very conservative,” Tsou said. “They want to make sure social media can really demonstrate a value for predicted disease outbreak. There is still a long way to go in terms of communication and education. But I think there is great promise and potential for using social media as a public health tool.”

“The use of social media for public health surveillance and disease detection is an evolving work nationwide,” said Jeffrey Johnson, a senior epidemiologist for the San Diego County Health and Human Services Agency. “Most of the work is still within the realm of research and academics, some of whom are validating their work with real events detected through different systems and reporting channels.”

Johnson added that while San Diego County Public Health Services does use social media quite a bit as a media and communication tool, the county is not currently using social media for surveillance and disease case finding.
 

Going Mainstream


The Milbank Quarterly recently published a study on the challenges facing practitioners as they consider ways to integrate social media and Internet data into the detection and management of disease outbreaks. Researchers involved in the Social Media and Internet-Based Data in Global Systems for Public Health Surveillance study found some of the limitations of event-based surveillance: Information isn’t always moderated by professionals or interpreted for relevance before it’s disseminated to epidemiologists; there’s no standardized system for updates; algorithms and statistical baselines aren’t well developed; and new information about health events isn’t disseminated efficiently. 

On the positive side, because it occurs in real time, event-based surveillance can identify events faster than indicator-based surveillance. Ultimately the authors concluded that event-based surveillance could improve surveillance activities, but not without systematic evaluation within a public health agency. 

Brownstein agreed. “There needs to be a way for representing that data in a way that’s useful for decision-makers,” he said. 

Yet the combination of indicator-based and event-based surveillance has potential for improved overall “epidemic intelligence” that could help monitor outbreaks and disease risk. And it may have other benefits.

“Even more important is the situational awareness that can be derived from the mining of social media data,” said Brownstein. “What are the impacts of outbreak events at the societal level? We can pick up these kinds of things through these channels. There’s value in understanding the public perception and communication and how government can refine its communications based on the response of the population. Using social media to understand people’s attitudes and beliefs in that way is extraordinarily powerful.”
This article was originally published by Government Technology.

Justine Brown  |  Contributing Writer
Justine Brown is a veteran journalist who specializes in technology and education. Email her at justinebrown@comcast.net.
www.emergencymgmt.com 

Homeland Security and Public Safety : Paris Attack Has Parallels to Boston Marathon Bombings

Both attacks have been blamed on homegrown terrorist brothers and provide lessons for law enforcement.

People gather around the Republique Plaza statue during the solidarity demonstration in Paris
People gather around and on top of the Republique Plaza statue during the solidarity demonstration in Paris, Thursday, Jan. 8, 2015. Scattered gunfire and explosions shook France on Thursday as its frightened yet defiant citizens held a day of mourning for 12 people slain at a Paris newspaper. (AP Photo/Francois Mori)

(TNS) — There are chilling similarities between the deadly Charlie Hebdo attack in Paris and the Boston Marathon bombings, with lessons to be drawn for law enforcement, terrorism experts say.

Both attacks have been blamed on homegrown terrorist brothers — in each case with a brother who had drawn law enforcement attention for Islamic radical ties before. In both cases, both police and citizens were targeted with equal cold-blooded vigor.

“I think what you’re going to see is governments going through their watch lists to see how many names appear identical. They should have added worry when you have two or three members of the same family giving prior warning, governments should be taking a second and third look at them,” said Victor David Hanson of the Hoover Institution. “When you are dealing with familial relations, it means there are fewer people who have privileged information about the ongoing plotting and the secret is reinforced by family ties ... it’s going to be much harder for Western intelligence to break into them.”

French police yesterday were searching for the Kouachi brothers — Cherif and Said, the Paris-born sons of Algerian parents — for the attack Wednesday that killed 12 people at Charlie Hebdo, a satirical weekly that lampooned radical Muslims and the Prophet Muhammad.

Cherif Kouachi appeared in a 2005 documentary on Islamic extremism and was sentenced to 18 months in prison in 2008 for trying to join up with jihadis in Iraq. Said Kouachi is believed to have trained with al-Qaeda in Yemen. Both brothers were known to U.S. authorities and were on the U.S. no-fly list.

Tamerlan Tsarnaev, killed in a shootout with police four days after the 2013 marathon bombings, had been flagged in 2011 to the FBI by Russian intelligence because of links to Islamic extremists in Dagestan. The FBI questioned and cleared him. His younger brother Dzhokhar survived the shootout and is now on trial for murder.

Former terrorist hunter Fred Burton, now with Stratfor, a global intelligence firm, said as in Boston French authorities are tracking the two fugitive siblings through their personal histories, places they’ve lived, relatives, places they’ve visited, as well as chasing down tips.

“They’re breaking down grids based upon intelligence and the likelihood of them being in a specific area,” Burton said. “You have to hope you’re ready for them, when they make a move. I really don’t think this is going to end well. Much like what we saw in Boston. These folks are cop killers. They also killed some of their own.”

©2015 the Boston Herald. Distributed by Tribune Content Agency, LLC.
www.emergencymgmt.com 

Disaster Preparedness & Recovery FEMA Mishandled Florida Hurricane Payments, Audit Reports

Some 10 years after the winds died down, federal officials are still cleaning up after a flurry of hurricanes hit Florida in 2004 and 2005.

Damage from Hurricane Charley in Punta Gorda, Fla.
A bicycle and home in Punta Gorda, Fla., destroyed by Hurricane Charley in 2004. (FEMA Photo/Mark Wolfe)

(TNS) — Some 10 years after the winds died down, federal officials are still cleaning up after a flurry of hurricanes hit Florida in 2004 and 2005, with a new federal audit saying the Federal Emergency Management Agency might have paid cities for damages that insurance should have covered.

The audit by the inspector general of the Department of Homeland Security, which oversees FEMA, found that the quality of FEMA’s insurance reviews in Florida was so lacking the agency can’t ensure it didn’t pay for damages that a private insurer should have covered.

FEMA also improperly waived the need for communities to buy insurance to protect against future disasters. That means FEMA and federal taxpayers might be on the hook to cover damages from the next hurricanes. According to the audit, FEMA stands to lose up to $1 billion in future Florida disasters because of these improper insurance waivers.

While the payments in question revolve around damages incurred by cities and other government entities, the issue isn’t with them or with the Florida insurance company that handled the claims. The issue is with FEMA.

“FEMA needs to be checking that the communities are allowing the insurance companies to pay for the portion they should be covering,” John Kelly, an inspector general official who oversaw the report on FEMA’s Florida payments, said in an interview. “It is FEMA’s responsibility to make sure tax dollars are being spent properly. It’s critical that FEMA start applying its regulations correctly and consistently.”

That’s doubly important, he said, since some of the FEMA employees involved in Florida reviews have moved on to other disasters, such as the superstorm Sandy that hit New York and New Jersey.

“We need to make sure the same problems don’t perpetuate themselves,” Kelly said.

While up to $177 million in payments are at issue, Kelly said, Florida cities “are not going to lose a penny.” The private insurer, however, could be found to be liable for additional payments, he said.

The 2004-2005 hurricanes — Charley, Frances, Ivan, Jeanne, Dennis, Katrina, Wilma — ravaged the state, resulting in $4.4 billion in what is known as “public assistance funding” to help local governments recover. It covers activities such as debris removal as well as the repair, replacement or restoration of disaster-damaged facilities.

In some cases, FEMA’s insurance specialists determined that insurance was not available to cover specific damages. Some of those cases involved disagreements over what a policy should or shouldn’t cover: If a ball field was damaged, for example, does the insurance cover only damage to the ground — or also to the fences, scoreboard and bleachers? Those are some of the kinds of issues at play in the insurance reviews, Kelly said.

In most cases, however, the inspector general found that FEMA reviewers could not support their “no insurance” decisions. They either incorrectly arrived at the decisions or had no support to justify them — often because paperwork was incomplete or missing.

The inspector general reviewed only a sample of the 2,088 projects at issue; those projects received a total of $177 million from FEMA. But in its review of the projects, the inspector general “concluded that FEMA could not have completed a valid insurance assessment with the documentation available. We conclude that FEMA has little assurance that its insurance specialists properly” handled the $177 million in FEMA-approved damages.

The inspector general is calling on FEMA to conduct a review of all projects — large and small — associated with the insurance company and recover any additional money the insurance company should have covered.

In a statement, FEMA press secretary Susan Hendrick said the agency “is on track to respond to the report’s findings and recommendations in late March of 2015.”

The insurance company was not named in the inspector general’s report, since the report was about FEMA’s actions, not the insurer’s or the cities’. But the company was the Florida Municipal Insurance Trust, which provides insurance services for more than 600 public entities in the state and is part of the Florida League of Cities.

Eric Hartwell, deputy general counsel for the Florida League of Cities, said that federal officials approached them around 2010 to review claims from the 2004-05 hurricanes and that they worked with cities, the state and FEMA to do so.

“When we found something that should have been paid, we paid it,” he said. “But there were cases in which there was no coverage.”

At one time, the trust earmarked $25 million to handle claims stemming from the FEMA review, but that earmark no longer exists, as the trust believes that all legitimate claims against it have been paid, Hartwell said.

“We have reviewed everything that has been identified,” he said. “For everything that has been identified and everything they brought forward — yes, we did a fair review.”

©2015 McClatchy Washington Bureau. Distributed by Tribune Content Agency, LLC.
www.emergencymgmt.com 

Wednesday, December 17, 2014

Homeland Security and Public Safety : FBI Beefs Up Amid Explosion of Cybercrime

The head of the FBI said cybercrime is "exploding" apace as the influence of the Internet rises meteorically.

FBI Director James Comey
FBI Director James Comey takes questions from members of the media during a news conference on Nov. 18, 2014, in Boston. (AP Photo/Steven Senne)

(TNS) — The head of the FBI said cybercrime is "exploding" apace as the influence of the Internet rises meteorically.

"It (the Internet) is transforming human relationships in ways we've never seen in human history before," FBI Director James Comey said Friday.

Comey said he sees a "tremendous amount of cyberespionage going on — the Chinese being prominent among them, looking to steal our intellectual property."

"I see a whole lot of hacktivists, I see a whole lot of international criminal gangs, very sophisticated thieves," he said. "I see people hurting kids, tons of pedophiles, an explosion of child pornography."

Cybercrime is one of the priorities for the FBI, which has 13,260 special agents across the country, including on Oahu, Maui and Hawaii island, according to the agency. The FBI had an $8.3 billion budget in fiscal 2014.

Comey, the head of the FBI for 15 months, met with law enforcement officials on Oahu on Friday as part of his effort to visit each of the FBI's 56 field offices around the country by the end of the year.

The Honolulu office in Kapolei was No. 56, he said.

Comey met with U.S. Attorney Florence Nakakuni and county police chiefs and introduced Paul Delacourt as the new special agent in charge of the FBI's Honolulu Division.

Comey was asked at the press event about former Oahu resident and NSA whistleblower Edward Snowden and other intelligence breaches in Hawaii in recent years.

He said that foreign intelligence-gathering in Hawaii is "significant."

"Let me say it this way: Our counterintelligence program is one of the most important parts of the FBI and our partnerships here," Comey said. "This (Hawaii) is where a huge part of the nation's military, civilian and intelligence infrastructure is, so it's where foreign nation-states are going to come if they want to steal stuff from us."

Comey said he wouldn't characterize the threat of foreign intelligence-gathering as increasing, but "it is significant and it has remained significant."

As for Snowden, who lives in exile in Russia, Comey said he would "welcome the opportunity to afford him the rights and privileges attendant to anybody who is a defendant" in the U.S. criminal justice system.

The Kapolei field office has about 200 people, including agents and analysts, and those working in computer services and administration, the FBI said.

The agency said it does not reveal how many agents there are within that total.

Comey said he talked with the agents in Hawaii and his law enforcement partners "about ways to work better together and to see if we can't get more technology and more talent here to focus on the cyber threat."

Agency-wide, the FBI is "doing a lot of hiring" to combat cybercrime, Comey said.

"We've hired 100 more computer scientists," he said. "I'm investing in high-speed accesses and all kinds of equipment."

He added, "Congress has given us the resources, because Congress sees the threat."

In an October talk at the Brookings Institution, Comey raised concern about real-time and stored data, including phone calls, live chat sessions and email text messages, that are increasingly being encrypted.

"We call it ‘going dark,' and what it means is this: Those charged with protecting our people aren't always able to access the evidence that we need to prosecute crime and prevent terrorism even with lawful authority," Comey said at the time.

The discussion comes as Snowden's government eavesdropping revelations created a backlash against those far-reaching efforts.

Comey said Friday it's important for the nation to "have a conversation" about giving law enforcement the ability to access real-time and stored data.

"I'm a big fan of privacy," he said. "I don't want anybody rifling through my stuff. But if there's probable cause to believe that the evidence of a serious crime is contained on a device, we need to be able to get access to it."

©2014 The Honolulu Star-Advertiser. Distributed by Tribune Content Agency, LLC.
 www.emergencymgmt.com