Showing posts with label Privacy Commissioner. Show all posts
Showing posts with label Privacy Commissioner. Show all posts

30 August 2014

Complaint turns up heat on Collins

An article from the Dominion Post by Phil Kitchin
An ACC whistleblower has complained to the privacy commissioner alleging Cabinet minister Judith Collins leaked confidential but false details to WhaleOil blogger Cameron Slater. Bronwyn Pullar filed her complaint after reading in Nicky Hager's Dirty Politics claims of Slater giving a friend - a former sex worker - false details about Pullar that the blogger said he got after speaking to Collins.
Privacy Commissioner John Edwards, whose office is overseen by Collins as the justice minister, said yesterday that he was assessing the complaint. The complaint heaps more pressure on the embattled Collins, who is on a "final final warning" from Prime Minister John Key after admitting she passed details about public servant Simon Pleasants to Slater, who then published material on his blog, prompting death threats against the bureaucrat.
Pullar caused severe embarrassment for Collins, who is also ACC minister, when she blew the whistle in 2012 on a massive ACC privacy breach involving her being sent confidential details on 6500 claimants, including sexual abuse victims.
Dirty Politics claims the day the story broke, Slater told the former prostitute - who was concerned her details were part of the ACC breach - that he would talk to Collins for "the real story". In two sets of messages between Slater and the ex-prostitute, Slater said he had spoken to Collins, and he provided his friend with then-unknown information about the whistleblower, the book claims.
Particularly damaging for Collins are the book's claims that Slater's statements show that he knew who Pullar was, that she had tried to extort ACC and that she was likely to be prosecuted. At the time Dirty Politics claims he was stating this to the ex-sex worker, ACC had not laid any extortion complaint to police and Pullar's request for anonymity had been respected by ACC.
If Slater's statements to the former prostitute as detailed in the book are correct, Collins could face serious trouble for leaking Pullar's name and false allegations of extortion against her before the minister had received any final written reports from her ministry.
However, Slater now insists the key details were not leaked by Collins.
Slater yesterday confirmed he spoke to Collins but said she only provided him with details about the privacy breach to allay his ex-sex worker friend's fears. He said Collins gave him no information about Pullar and allegations of extortion, and that he got that information from other sources.
Collins side-stepped questions about what she told Slater and said she was unaware of any complaint to the privacy commissioner against her by Pullar.
"If there is one, I would be unable to comment," Collins said.
"There are complaints about the Hager book and stolen emails before the police and the privacy commissioner and it would be inappropriate to comment further."
When Pullar first blew the whistle on ACC she was not identified, and the corporation was told she wished to remain anonymous so she was not deluged with calls from ACC clients asking if they were part of the privacy breach. The scandal forced ACC into making thousands of apologies and Collins faced snap debates in Parliament.
Three days after the story broke and after crisis meetings involving Collins, then chairman John Judge and then chief executive Ralph Stewart, ACC hit back at Pullar.
ACC published a report claiming Pullar tried to extort the corporation at a December 2011 meeting held between Pullar, her support person and former National Party president Michelle Boag, and two senior ACC managers. ACC did not ask Pullar for her side of the story before making the allegations public and then repeating them to police, who launched an inquiry.
Slater was then fed a memo from Boag to Collins which he gave to a Sunday newspaper reporter and Pullar's name became public knowledge. Slater went on the attack on his blog, falsely accusing Pullar and Boag of blackmail.
But ACC and Slater did not know Pullar had a tape recording of the meeting that showed the allegations were false.
Correspondence with the privacy commissioner's office obtained by The Dominion Post shows the commissioner admitting his office initially "overlooked" Pullar's complaint made on August 15.
The commissioner last week ruled out investigating a Green Party complaint that Collins leaked Pleasants' name to Slater. He said he would need a complaint from Pleasants, who has declined to lodge one.
Edwards' assistant commissioner of investigations, Mike Flahive, told Pullar on Wednesday he was "assessing" her complaint to consider what action to take.
"Your patience would be appreciated," Flahive said.

NEW COMPLAINT
The latest complaint that ACC and Justice Minister Judith Collins breached ACC whistleblower Bronwyn Pullar's privacy is different to one that dragged Collins into an earlier investigation by the privacy commissioner. That investigation was launched when a memo from former National Party president Michelle Boag to Collins clarifying Puller's reasons for blowing the whistle was leaked to a reporter. The leak led to Pullar - who has a brain injury - coming under siege from media as ACC simultaneously falsely claimed she'd tried to extort the corporation.
Investigators trawled through Collins' office and computer and questioned ACC chairman John Judge and then chief executive Ralph Stewart to try to find the source of the leak. Collins was accused of being the leaker, which she correctly denied.
The investigation failed to find the leak but informed sources have confirmed to The Dominion Post that the leak was from one senior board member to another, who gave it to a blogger, who passed it to Slater, who gave it to the reporter.

HOW IT UNFOLDED
March 13, 2012 - The Dominion Post reveals ACC breached the privacy of 6500 ACC clients, including rape victims, by sending their details to an unnamed ACC client.
March 13 - According to Dirty Politics, WhaleOil blogger Cameron Slater tells an ex-prostitute friend he would ring ACC Minister Judith Collins to "get the real story".
March 14 - Slater tells the ex-prostitute the whistleblower was a woman who tried to blackmail ACC and was likely to be prosecuted for extortion, Dirty Politics claims. That afternoon, minister Collins attends a meeting with ACC chief executive Ralph Stewart and chairman John Judge. In an affidavit later, Judge said Collins "very strongly" pushed for police to be told about threats allegedly made by Pullar at a meeting with ACC on December 2011.
March 15 - The word "blackmail" is first publicly discussed. Collins tells Radio Live she had oral reports on the December meeting but wanted written reports.
March 15 - Two ACC managers from the December meeting provide their official account, which contains no allegations of blackmail or extortion.
March 16 - A "situation report" is published on ACC's website accusing the whistleblower of extortion.
March 17 - The book claims Slater tells the ex-prostitute he knows who the whistleblower is and that she will get "rat f...ed hard."
March 18 - A Sunday newspaper names the whistleblower, Bronwyn Pullar, after Slater provides a leaked email from ACC.
March 19 - ACC makes a written complaint to police about alleged extortion.
April 30 - The Dominion Post reveals Pullar recorded the critical meeting at which ACC claimed she'd tried to extort the corporation. The recording showed ACC had made false allegations. Police swiftly shut down their investigation.
© 2014 Fairfax New Zealand Ltd

http://www.stuff.co.nz/national/politics/10440930/Complaint-turns-up-heat-on-Collins

24 April 2014

Bronwyn Puller: ACC abused claimants' rights with consent form

A report from 3 News by Melanie Reid for Third Degree
Bronwyn Puller blew the whistle on ACC in 2012. She was sent nearly 7000 personal files in one of New Zealand’s worst privacy breaches.
Two years later ACC has been found to be involved in another massive privacy scandal. This time it potentially affects three-quarters of a million Kiwis.
"There’s no limitation on it [ACC form 167]," says Ms Puller. "So it’s as wild as your imagination. They could go to your bank and obtain all your banking financial records. They could go to your telecommunications provider and obtain access to your emails. They could go to your gym, look at your gym attendance. They could go to your neighbours, talk to your neighbours. But it’s not just what they can collect; this actually also gives ACC unlimited powers of disclosure."
ACC was forcing clients to sign a consent form that was well beyond ACC’s legal mandate. This gave ACC powers – way beyond what they have under the legislation. This gives them the ability, and the Government, to intrude in every aspect of your life. It gives them the ability to release any information about you to any third party.
Here are just a few examples from our ACC files:
  • A male freezing worker's sexual abuse history was shared with his employer.
  • A claimant who had suffered mental health issues had her highly sensitive files released to her employer.
  • A victim of a brutal assault also had confidential files released to his employer – files about his nightmares, medication and counselling sessions.
"This is the consequence of this form," says Ms Puller. "I don’t think anyone in their right mind would want their employer, or a potential employer, or a headhunting agency, having complete access to their medical records. They are the most highly sensitive private information."
The problem for claimants is if they didn’t sign the 167 consent form allowing ACC wide-ranging collection of their private information, they faced being cut off.
So last week a judge ruled ACC’s use of the consent form unlawful. But there are allegations that for years and years ACC has known this.
Ms Puller had raised the issue of the 167 form with the former minister, the board, the State Services Commission, the Privacy Commissioner, Department of Labour and Ombudsman.
"[Current ACC Minister] Judith Collins was given the list of 45 issues, which I took to the meeting in December, that we asked ACC to address," she says. "The ACC 167 was listed on that as one of the concerns we had about the unlawful approach to the way ACC was operating its business. That list was given to the minister on March 14, 2012.
"I know that she received my list of 45 issues. I also know that she received a copy of the independent report that was commissioned by ACC and the Privacy Commissioner, which raised concerns about ACC’s consent form, because it was the major bugbear that most claimants had with ACC."
So going by the judge's ruling, potentially there are hundreds of thousands of files sitting in an ACC database containing private information that has been obtained in an illegally manner.
"At the end of the day, ACC have created their own administrative nightmare, through the way that they’ve acted. They’ve acted unlawfully. They’ve acted irresponsibly. They’ve acted in a way that basically totally abuses the claimants' rights and the right to informed consent, and to control of their personal information. It’s that simple."
Click here to see the response from ACC.
For anyone with concerns about their claim in relation to their signing the ACC 167 consent form, please call 0800 745 254.
© 2013 MediaWorks TV

http://www.3news.co.nz/Bronwyn-Puller-ACC-abused-claimants-rights-with-consent-form/tabid/1771/articleID/341271/Default.aspx#ixzz2zkDroQnw

16 April 2014

Question to Minister

10. KEVIN HAGUE (Green) to the Minister for ACC: Have all of the recommendations of the 2012 Independent Review of ACC’s Privacy and Security of Information been implemented; if not, why not?



Hon JUDITH COLLINS (Minister for ACC): ACC advised that it has implemented 37 of the 44 recommendations. A number have ongoing activity associated with them. Of the remaining seven, two are under active management, which relate to information governance and the implementation of data loss protection software. The other five involve a fundamental review of ACC’s end-to-end claims process activity. Accordingly, ACC advised that it has taken a deliberate decision to complete the end-to-end process review of claims management as part of its work around improving trust and confidence. This is to ensure all processes and information technology changes required under these five recommendations comprehensively meet the intent of the report.
Kevin Hague: Is she confident that the recommendations to ensure that consent forms follow the law and are best practice have been properly implemented, given that the court has just found that the way that ACC was using its ACC167 form was actually illegal?
Hon JUDITH COLLINS: I do not want to argue with the member, but, strictly speaking, the form was not held to be illegal, but the way in which it was used was outside of the statutory requirements. I agree with the member that the form must be changed to comply with the latest decision. I have also been advised by ACC that this form has in the past been approved by the Privacy Commissioner, by the Human Rights Commission, and, I have been told, by six different District Court decisions. So the fact that this latest decision has said that it has been wrongly used is something that ACC is taking very seriously, as am I.
Kevin Hague: How does she reconcile ACC’s illegal use of this form with the privacy review’s findings that stakeholders’ single-biggest concern was the attitude and culture of the organisation in dealing with their personal information, and the report’s finding that a consistent theme was that information not relevant to the claim was held on file?
Hon JUDITH COLLINS: I also recall that the review said that the form itself was able to be used. So I think the problem is that the past decisions of the courts and of other agencies, like the Human Rights Commission, the Privacy Commissioner, and also the review, have not actually said that the form has been misused. But I believe that the member is right that the form should be changed. ACC told me on Monday this week that it was not going to appeal the decision and that it would abide by it. I think that is the right outcome.
Kevin Hague: How do revelations today that ACC has been handing people’s full ACC files—including information on sensitive claims—over to prospective employers stack up against the recommendations of the privacy review?
Hon JUDITH COLLINS: I am sorry, I have not heard that claim, but if the member would like to provide me with the information, I will be happy to take some action. I seek leave to assist the member with the summary—
Mr SPEAKER: You are seeking leave to table a document?
Hon JUDITH COLLINS: It is a document that is the independent review recommendations and summary of actions as at 24 January this year, and I think that might help the member.
Mr SPEAKER: Leave is sought to table that summary of actions. Is there any objection to that being tabled? It can be tabled.
    Document, by leave, laid on the Table of the House.
Kevin Hague: How does the Minister reconcile the responsibility she took as Minister in 2012 and her comment that “I’m not going to sit back and let one of the most important Government entities we have let people down time and time again around things such as privacy. They have to act in the way that I expect them to act.” with her comments over the past several days that the implications of the court decision are an operational matter?
Hon JUDITH COLLINS: Well, strictly speaking, forms are an operational matter, but if the member is going to come to see the progress that has been made and what actions I have taken, I think that I have been very strong on this issue relating to ACC. I can look at the proof of just how successful that has been. In August 2012 there were 80 privacy breaches from ACC. A year later, in August 2013, that was down to 28. In March 2014—the month just past—it was down to 19. There are significant improvements in the ability of ACC to protect people’s privacy, and at the same time, to comply with its obligations under its own Act.

http://www.parliament.nz/en-nz/pb/business/qoa/50HansQ_20140416_00000010/10-accident-compensation-corporation%E2%80%94privacy-and-security

22 December 2012

Privacy the year's big trivial story

An article from the New Zealand Herald by John Roughan
ACC data leak turned out to contain nothing personal.
Among the Christmas cards I get at work there is always one from the Privacy Commissioner, Marie Shroff. Invariably it contains a good visual gag. This year's features a Slane cartoon of a boy stuck with his head and upper body in a Dutch dyke and a passer-by explains to another, "The leak was worse than first thought".
I hope the irony was intended, because it's time to acknowledge that the biggest leak of the year, the one that the news kept calling a "massive privacy breach" which the commissioner had to investigate, turned out not to be very big at all.
It sounded serious when it was first reported that the personal details of thousands of ACC claimants had been accidentally emailed to one unnamed claimant.Among them were said to be victims of sexual offences.
Then someone on the side of ACC leaked back, naming the recipient and letting it be known she had turned up with a supporter, none other than National insider Michelle Boag, for a meeting where it was pointedly mentioned to her claim handlers that she was holding information she shouldn't have.
After that, the story took off in all directions, not all of them connected to the email accident. Nick Smith had to resign, there was palace intrigue over who leaked a memo from Boag to ACC minister, Judith Collins, who sued two MPs for suggesting it was her.
Grimly, she replaced ACC's chairman, deputy chairman, four board members and the chief executive.
Meanwhile, Labour and the Greens made a sustained attack on ACC's "culture", not just its carelessness with email but its determination to check all claims rigorously and get the injured back to work quickly. The story took on so many dimensions and ran for so long that the Privacy Commissioner's investigation of the original data leak became little more than a footnote.
But there was nothing minimal about her investigation. She appointed an independent review team of KPMG business consultants and a Melbourne company, Information Integrity Solutions Ltd, who together really went to town. From April to August they travelled the country, conducting by their own account more than 150 interviews at ACC's head office, its sensitive claims unit, six branch offices and two service centres.
They went far beyond "client facing" staff to talk to the myriad sections of the corporation that have to see claimants' confidential information: researchers, lawyers, risk assessors, injury prevention officers, assurance services, business intelligence, actuarial people, plus the complaints investigation team.
They talked to "external stakeholders": claimants, their advocates and associates, holding a workshop with some of them. They performed "walk-throughs" of the corporation's email handling habits, compared its information security practices with those of some other organisations, and much, much more.
By the time they presented the Privacy Commissioner with their report, the country was sick of the subject and hardly anybody read it.
It ran to 102 pages. You had to read to page 99 to discover exactly what sort of confidential client information had escaped.
But finally, in the fifth appendix, there it was: a sample of the fabled spreadsheet of "personal" data. It consisted of four tables listing claimants' names (removed for the report), their claim numbers, review numbers, branch, lodgement dates, issue codes, decision dates and the like.
That was it. That is all there was.
There was nothing that could be of the slightest use or interest to anyone outside ACC. No personal details alongside the names, no injury information, nothing.
That is what all the fuss had been about.
The thing that disappointed me was that so many people had known all along that the "massive privacy breach" amounted to nothing more than this. Investigative reporters, the Privacy Commissioner, her Independent Review Team, all would have discovered the contents of the spreadsheet very quickly.
None blew the whistle. No reports that I saw looked critically at the facts at the heart of a story that kept on growing and giving. The Privacy Commissioner did not say something to restore a sense of proportion. The review team, no doubt well paid, went about its investigation as though there was a serious problem.
An accident had happened. An ACC rehabilitation officer had a monthly sheet of case reviews on his screen when he decided to respond to an email. He dragged the data aside, clicked a wrong button and unwittingly attached it to the return email.
Computers are a minefield for privacy. Accidents will happen, despite all the procedures the commissioner's expert team has laid down. It happened to Social Welfare kiosks a short time later. If the data is as indecipherable as that ACC released, it won't matter in the slightest. It was the trivial story of the year.
© 2012 APN Holdings NZ Ltd

http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&objectid=10855584

05 October 2012

ACC reined in over waiver

An article from Stuff
The Privacy Commissioner's office has again reined in ACC after it asked clients to sign a form accepting their personal files may be lost, then claimed such a form gave it indemnity.
The waiver forms were introduced after a series of client privacy breaches, including emailing of the personal details of more than 6700 clients to claimant Bronwyn Pullar.
ACC used to send sensitive files to claimants' houses via courier. It has now asked clients to sign a contract accepting the files may not reach their destination. The form states the client accepts risks, including "non-delivery, delivery to an unauthorised person, or interception by an unauthorised person".
Outgoing ACC chief executive Ralph Stewart told TVNZ: "They need to indemnify us, just in case it does go to the wrong place and they haven't used the options we've offered them."
But the Privacy Commissioner's office contacted ACC to put him right after TVNZ approached it about the comments. Mr Stewart later said the corporation would take responsibility for its mistakes.
© 2012 Fairfax NZ News

http://www.stuff.co.nz/national/politics/7772012/ACC-reined-in-over-waiver

06 September 2012

Not cute

A blog post from Off the Couch by Kyle MacDonald
I think that politics and psychotherapy are worlds apart, and largely in the different ways they approach the truth. Psychotherapy is largely the search for the truth along with understanding and validating one persons experience of it.
Politics these days seems to be largely about the manipulation of the truth, to most closely match whatever agenda is being pushed. In some ways I can live with that, it’s what I expect from politicians and a healthy news media can assist us to dive into the debate and decide who and what we want to believe. But it’s much harder to take from a public organization charged with the care and treatment of all New Zealanders.
Both of the recent reports into the ACC by the Auditor General and the Office of the Privacy Commissioner  point to “culture problems” within the ACC.  (See: “Dual investigations shows culture problems at the ACC“). In my view this starts to get us to the heart of the problems that have plagued the Sensitive Claims Unit for a number of years. I believe the culture problem that exists within the ACC’s Senior Management is an ongoing pattern of cynical manipulation of the truth for financial and political gain. And sometimes blatant self-preservation...
Click here to read the rest of this post.

http://psychotherapy.org.nz/not-cute/

03 September 2012

Minister fumes as ACC fails yet again

An article from the Dominion Post by Shane Cowlishaw
ACC'S privacy practices have again been exposed after it sent information about an elderly client to the wrong person, and then took six weeks to tell her about it.
The corporation also failed to inform ACC Minister Judith Collins about the breach. She was unaware of it until told on Friday by The Dominion Post.
Mrs Collins has weekly meetings with the organisation and has demanded a zero-tolerance approach to privacy violations. She said the latest breach was "totally unacceptable" and called for a full explanation from outgoing chief executive Ralph Stewart.
The information, which included details about Auckland resident Diane Hawke's injury, compensation and complaints about ACC, was sent to a client in the corporation's sensitive claims unit in a bundle of documents at the end of March - just weeks after the privacy breach involving whistleblower Bronwyn Pullar was revealed.
All correspondence with sensitive claims unit clients is supposed to go through more thorough security checks.
The mistake was not discovered until July, when the recipient, who has had her own privacy breached by ACC several times, finally found time to look at all the information she was sent. Incensed, she emailed and called ACC several times. She was shocked to discover six weeks later that Mrs Hawke had still not been told of the breach.
Both Mrs Hawke and the sensitive claims unit client were among the 7000 people whose details were inadvertently sent to Ms Pullar.
The fallout from Ms Pullar's revelations claimed the scalps of Cabinet minister Nick Smith, ACC chairman John Judge and several board members.
Last week a damning independent report into the breach vindicated Ms Pullar and highlighted a poor privacy culture at ACC.
The sensitive claimant said she was "mortified" at receiving Mrs Hawke's details, but her shock quickly turned to anger when she learnt how ACC had handled it.
"Look, I was just shattered that their strategy in the media is ‘We take it seriously'. This took them six weeks to get serious about. It's a bad, sick joke, and it's simply not good enough."
The breach raised several issues, including how historical information from a standard ACC claimant had been mixed up in current documents prepared for one handled by the sensitive claims unit, she said.
Mrs Hawke, who has been sent another person's details in the past, said she was angry to learn about the delay in informing her. "I thought ... here we go again, because I have no confidence in their privacy or anything else."
Ms Collins said Mr Stewart would report on how the breach happened and what was done to ensure it never happens again.
ACC spokeswoman Stephanie Melville said the six-week delay was too long, and ACC apologised. An inquiry was under way and no decision had been made on possible compensation. The findings of the privacy commissioner's report had been accepted and all recommendations would be implemented in full, she said.

TIMELINE
March 29: ACC sends the sensitive claimant a bundle of documents relating to her case.
July 11: Claimant, who regularly receives large volumes of documents from ACC, notices the March package contains nine pages of Diane Hawke's information, dated 2008.
July 11: Sensitive claimant emails her case manager over breach.
July 12, 16: Claimant rings ACC complaints office and customer support service manager Kerry Dow over breach.
July 18-22: She and Mr Dow exchange emails about breach and whether the documents have been destroyed.
August 15: After speaking to Mrs Hawke, sensitive claimant learns ACC has yet to tell her of the breach. She calls ACC again.
August 16: Mr Dow calls Mrs Hawke to tell her of the breach and emails sensitive claimant, informing her he has done so.
http://www.stuff.co.nz/national/7597898/Minister-fumes-as-ACC-fails-yet-again

© 2012 Fairfax NZ News

24 August 2012

Claimants shouldn’t be forgotten in ACC fallout

A press release from the Labour Party by Andrew Little
ACC must take the concerns of sensitive claims unit claimants seriously, and set up a high level unit to deal with the outstanding complaints around breaches of privacy and misuse of information, Labour’s ACC spokesperson Andrew Little says.
Two independent reports yesterday highlighted the "cavalier" nature of information management and called for a change in culture within the Corporation.
"While the work of the two review teams will be helpful in moving to a healthier culture at ACC, it is still surprising little was said by either review team about the fate of nearly 200 sensitive claims unit claimants who had some of their details released in the mass privacy breach that was the subject of the investigation.
"The Privacy Commissioner's review treated the SCU claimants too lightly when it implied not much identifying information was disclosed, but the report shows there was an identifying code for the issues under appeal, so unauthorized ACC staff would know exactly what those claims were about.
"A couple of months ago Labour called for a high level independent review team to be set up straight away to deal with all existing complaints about misuse of information.
"If ACC and Judith Collins are serious about restoring confidence, then this is an initiative that could go a long way to doing so as well as exorcising some difficult demons that will only hold the Corporation back if they are not dealt with.
"ACC really needs to accept that an entirely new approach is required. All of the difficult files of recent years need to be reviewed with a fresh pair of eyes so everyone can move on with the confidence that they have been treated fairly,” said Andrew Little.
http://www.scoop.co.nz/stories/PA1208/S00370/claimants-shouldnt-be-forgotten-in-acc-fallout.htm

Privacy breach a warning for others

An article from the Nelson Mail by Laura Basham
In a chilling revelation, an inquiry into the case of ACC emailing sensitive details about more than 6000 claimants to the wrong person reveals it could have happened to any big government agency.
A spreadsheet containing details of the 6000-plus claimants - including more than 200 handled by the ACC's sensitive claims unit dealing with rape and sexual abuse victims - was emailed to Auckland woman Bronwyn Pullar after an ACC staffer mistakenly clicked on it and sent it as an attachment without noticing.
An inquiry yesterday found simple human error was to blame for the breach, which has so far claimed the scalps of a government minister, the chairman and chief executive of ACC and could yet claim further victims as the hunt continues for the person who leaked an email from Pullar support person, former National Party president Michelle Boag, to ACC Minister Judith Collins.
Former ACC minister and Nelson MP Nick Smith said today he was pleased that the reports concluded that Ms Pullar did not receive any extra entitlements or benefits as a consequence of her friendship with him or that she was known through the pipfruit industry and to former ACC director John McCliskie. The inquiries were initiated out of allegations that because Ms Pullar had been involved with the National Party, she had received entitlements, he said.
"These reports show that is not true and that both myself and the board were very clear Bronwyn Pullar should not be treated in any way differently from any other claimant," said Dr Smith.
However, he said he still regretted writing the letter attesting to Ms Pullar's health prior to her accident, that ultimately triggered his resignation from his ministerial portfolios in March.
Dr Smith also noted that the system issue that led to the accidental email of a large file of client information could happen to other government agencies, and said there needed to be a broader review of systems to ensure that did not happen.
The release of the reports concludes the investigations on the ACC issues, but Dr Smith would not be drawn on the issue of his potential return to Cabinet, saying it was up to Prime Minister John Key. "We'll just have to see how it goes."
The report released yesterday remains silent on whether ACC was justified in going to police over claims that Ms Pullar tried to use the data breach to guarantee her benefit for two years - despite four members of the independent review team listening to a tape recording of the meeting where the blackmail threat was alleged to have been made. Police later tossed out the complaint because of a lack of evidence but ACC has so far refused to apologise to Ms Pullar over the claim.
The head of the review team, former Australian privacy commissioner Malcolm Crompton, said the blackmail allegation was outside the inquiry's terms of reference.
The inquiry, commissioned by the Privacy Commissioner and ACC, was one of two reports released yesterday into the mass privacy breach. The second was by Auditor General Lyn Provost. Both reports call for a culture change at ACC, which acting chairwoman Paula Rebstock promised yesterday would occur after the privacy breach raised "profound questions about our management of private information".
Privacy Commissioner Marie Shroff said the breach threw the spotlight on the use of personal information by government agencies.
"Public sector agencies collect information from us on a very large scale, often by compulsion, in a situation where we really have no alternative but to provide it. The information is held these days in vast electronic databases. That information is the necessary lifeblood of those agencies and a major business asset for those agencies. But the bargain for us, the citizens, the clients, is we need to be able to trust those agencies to protect our information and not to misuse it or lose it."
Both reports released yesterday raise questions not just about the privacy breach, but also over the treatment received by Ms Pullar, who was a former high-flying business woman and moved in National Party circles. Mrs Provost found Ms Pullar received special treatment after she approached a former business associate, Mr McCliskie, who was on the ACC board, over her case and he set up a meeting with senior managers.
"Although meetings with such senior ACC officials are not without precedent, few claimants have that opportunity," she noted.
© 2012 Fairfax NZ News

http://www.stuff.co.nz/nelson-mail/news/7541881/Privacy-breach-a-warning-for-others

ACC privacy report may lead to wider overhaul

An article from the New Zealand Herald by Adam Bennett
All government agencies' handling of private data may be reviewed after an independent inquiry into the ACC privacy breach found it could have happened in any department.
The report by former Australian Privacy Commissioner Malcolm Crompton and accountancy firm KPMG examined what led to a spreadsheet containing details about 6748 clients being emailed to claimant and former National Party insider Bronwyn Pullar last year, and ACC's response when it learned of the breach in December.
It concluded that the breach, which was disclosed to the public, senior management and ACC Minister Judith Collins only when Ms Pullar went to the media with the information in March, was down to "a genuine human error".
However, "such an error was more likely to occur because of systemic weaknesses within ACC's culture, systems and processes".
The report also found ACC's subsequent response process could have been better "if appropriate policies, practices, escalation protocols and the right culture were in place".
It made a series of recommendations to improve privacy handling at the corporation.
Acting ACC chairwoman Paula Rebstock said the corporation would be implementing the review's recommendations in full.
Speaking to reporters, Mr Crompton said Ms Pullar had done the public "a service by making sure that we pay attention to the proper governance of personal information".
"Most organisations should be taking great note of the fact that it could have been them."
State Services Commissioner Ian Rennie said the report was "a dramatic reminder of the need for all government agencies to treat private information with the utmost care and respect".
"To this end, I am considering that state sector chief executives review their systems for handling private information. Any stocktake would initially be targeted on areas of greatest potential risk."
But Labour's ACC spokesman, Andrew Little, said he did not believe Mr Crompton's claim it was bad luck that the breach occurred at ACC rather than another department.
"There is nowhere else in the Government where there has been the apparent sloppiness in the approach to managing that information as at ACC."
Mr Little said the National Government on coming to power had painted a picture of an organisation in financial crisis that therefore needed to focus on cutting costs.
"That is at least one explanation for the more cavalier attitude towards claimants, their issues and their privacy. I don't think the Government can disown responsibility for it having got to this point."
Privacy Commissioner Marie Shroff, who commissioned yesterday's report, said it appeared ACC staff had been under pressure and "a failure in systems processes and perhaps leadership has led to them developing a somewhat cavalier attitude towards people's information and that needs to change".
Mr Little called for Ms Collins to be replaced as ACC Minister to allow the culture change required. Ms Collins dismissed that call, and Mr Little, as "silly".
A report by Auditor-General Lyn Provost into whether Ms Pullar gained any advantage in the way her claim was treated because of her connections with former board member John McCliskie, which was also released yesterday, found no evidence that was the case.
But the report did raise concerns Mr McCliskie and then-chairman John Judge failed to recognise wider allegations of illegality and fraud at the corporation brought to their attention by Ms Pullar late last year.
© 2012 APN Holdings NZ Ltd

http://www.nzherald.co.nz/nz/news/article.cfm?c_id=1&objectid=10829060

23 August 2012

Coalition welcomes opportunity provided by reports

A press release from the ACC Futures Coalition
The two reports on ACC commissioned by the Privacy Commissioner and the Office of the Auditor-General may highlight failures but they also provide an opportunity to rethink the direction of the scheme, according to the ACC Futures Coalition.
“We welcome these reports,” said ACC Futures Coalition spokesperson Hazel Armstrong. “They confirm that there were problems at the governance and senior levels of the corporation with regard to the management of risk and claimants’ information.”
The report of the Privacy Commissioner (conducted by KPMG) found that the release of claimants’ details to Bronwyn Pullar, which occurred in August 2011, was a genuine error but occurred because of systemic weaknesses within ACC's culture, systems and processes.
“There is much to like about the KPMG report,” said Ms. Armstrong, “for example, we are pleased to see the emphasis that the report places on organisational culture. The report emphasises the need for a balance between ‘privacy, customer service and efficient and effective management so that “firm is also seen as fair” by ACC and its external clients and stakeholders.’ The report also stresses the importance of a culture of respect for claimant privacy which will lead to the wellbeing of clients and to achieving community trust in ACC.”
“We see these points as recognition of the link between the problems with the culture around the protection of information and the wider culture of the corporation,” said Ms. Armstrong.
“When discussing the culture of corporation the report raises the challenge arising from conflicting political views on the role of ACC and the resulting fluctuations in scheme performance, stating that this has resulted in ambiguity for staff in terms of customer service and managing claimant entitlements. There is a need for multi-party agreement on the future of the scheme,” said Ms. Armstrong, “something which the ACC Futures Coalition has been calling for since its inception.”
“These reports represent an opportunity to achieve a consensus on the future direction of the scheme,” said Ms. Armstrong. “We have begun the process of developing our own manifesto for ACC and are organising a one-day seminar in late October to assist us with that process. We want to contribute to a debate about how we can restore the scheme to its original founding values and we hope that all the parties and the Minister, will join us.”
“Both of the reports also identify failings at governance level around management of risk,” said Ms. Armstrong.
http://www.scoop.co.nz/stories/PO1208/S00364/coalition-welcomes-opportunity-provided-by-reports.htm

Question to Minister

4. DAVID BENNETT (National—Hamilton East) to the Minister for ACC: What are the findings of reports released today by the Privacy Commissioner and the Auditor-General about a privacy breach and governance at ACC?



Hon JUDITH COLLINS (Minister for ACC): The independent report released by the Privacy Commissioner focused on ACC’s culture, policies, and practices around privacy and security of information. It found that these were not up to 21st century standards. The Auditor-General focused on governance of the corporation, and found that senior board members involved and management failed to recognise the systems of systemic failure around privacy and security information, and did not take the appropriate steps. I agree with all the findings.
David Bennett: What specific concerns did the independent report and the Auditor-General raise, and what is ACC doing to address these?
Hon JUDITH COLLINS: The independent report released by the Privacy Commissioner noted systemic weaknesses, including a variable culture around the importance of handling private information carefully and a lack of accountability for addressing privacy issues. ACC will undertake a significant programme of work to address concerns raised by both the independent report and the Auditor-General. A timetable for this programme of work is included in the report from the Privacy Commissioner, and I expect ACC to make the required changes as a priority.
Andrew Little: In view of the findings in today’s reports, both released at 2 p.m., that ACC board members, which her Government appointed, were too inexperienced to appreciate the gravity of Bronwyn Pullar’s complaints, and that the corporation took a cavalier attitude to protecting claimant privacy, what steps is she taking to fill the multiple board and senior management vacancies with people who understand ACC and the importance of utmost public confidence in it?
Hon JUDITH COLLINS: The question is not quite correct in one of the assumptions. I will deal with that first and then deal with the substance of the question. In fact, the board members who were named in the reports as having not appreciated the seriousness of the situation were its longest-serving board members—the chair and deputy chair. In relation to the filling of the board positions, I can tell the member that there is a very thorough process that is ongoing. Interviews are being undertaken and I am putting a great deal of thought into making sure we get the right combination of board members with the right skills, the right character, and the right experience.
David Bennett: What expectations has she set for ACC to improve public trust and confidence in how it operates?
Hon JUDITH COLLINS: Earlier this year I signed a letter of expectations and a service and purchase agreement with ACC outlining my priorities for the board. I expect the ACC board to improve public trust and confidence, improve the management and security of private information, maintain a focus on levy stability and financial sustainability, ensure early resolution of disputes, and provide high-quality service for clients. The Auditor-General noted that “this approach will lead to a more balanced and comprehensive approach to the governance and operation of ACC.”
Hon Trevor Mallard: In light of the Privacy Commissioner’s comment that the ACC culture change has to start at the top, what action has she taken to plug the leaks from her office?
Hon JUDITH COLLINS: There are no leaks from my office, as that member well knows.

http://www.scoop.co.nz/stories/PA1208/S00350/questions-and-answers-august-23.htm

ACC fiasco starts and stops with the Minister

A press release from the New Zealand Labour Party by Andrew Little
The Privacy Commissioner’s report into the ACC leaks is a litany of leadership gone wrong, Labour’s ACC spokesperson Andrew Little says.
“In slamming the culture at ACC, the Commissioner says it is ‘vital’ for a change starting at the top.
“So let’s start with Judith Collins. This whole fiasco is a direct consequence of the Government clearing out experienced board members, putting in their own, overseeing strategies aimed at cost cutting rather than treatment and rehabilitation – which a more experienced board member might have expressed caution about – and then not recognising they were facing allegations of serious problems with the Corporation’s conduct.
“It is not good enough to name and blame others. The Cabinet that Ms Collins is part of has driven the agenda on this and she must take responsibility for the fallout.
“It’s not enough for ACC to be a clip-on to a senior Minister’s other roles.
“If the Government is serious about change from the top then it should start by having a dedicated minister in the role who can work closely with the board and senior management to bring about the necessary changes.
“We will only know the government has taken the reports of both the Privacy Commissioner and the Auditor-General seriously when it appoints a minister who can win public confidence.
“It is essential, too, that the recommendations are put into effect as soon as possible, so that ACC can once again stand by its reputation as a world-class insurance agency,” said Andrew Little.
http://www.scoop.co.nz/stories/PA1208/S00340/acc-fiasco-starts-and-stops-with-the-minister.htm

Privacy Commissioner urges ACC culture change

A press release from the Office of the Privacy Commissioner
The Privacy Commissioner says a culture change starting at the top of ACC is vital if further data security breaches are to be prevented.
Marie Shroff is commenting on the findings and recommendations of the Independent Review of ACC Privacy and Security of Information that were released today.
The report was commissioned jointly by the Office of the Privacy Commissioner (OPC) and the ACC Board following the unauthorized disclosure of details of 6,748 clients.
"The review has found the breach was a genuine error and I accept that. But it also shows the error happened because of systemic weaknesses within ACC's culture, systems and processes," says Ms Shroff.
"The reviewers noted a good level of privacy awareness especially at branch level. But the review also highlights a culture that, according to stakeholder feedback to the reviewers, has at times "an almost cavalier" attitude towards its clients and to the protection of their private information.
"The review shows that information stewardship is low level and defensive and focuses on breaches and complaints rather than taking strong leadership that emphasises respect for clients and their information.
"That is not good enough particularly in this digital age. Personal information is the lifeblood of ACC and it is vital that ACC treats that information with respect - the trust of its clients and, in many respects, the success of its operations depends on it."
Ms Shroff says the report shows that ACC lacks a comprehensive strategy for protecting and managing its client information.
"This sort of data is a major business asset with associated risks that have to be managed.
"While ACC has elements of privacy protection and security, these are not up to the standard expected of a responsible public sector agency that holds highly sensitive information on a large number of people.
"Changing that is essential. And the changes, which must include a culture change, have to start right at the top."
The review recommends that an independent audit of how ACC has implemented the changes is undertaken every two years and provided to the Privacy Commissioner.
Marie Shroff welcomes the recommendation.
"It's evident from the report that a lot needs to change before public confidence in ACC can be restored. I believe it can be done, but only if ACC takes the review's findings and recommendations seriously and gives its many good and committed staff the support they need to implement the necessary changes.
"The review provides a strong set of proposals. I will closely monitor ACC's progress as it implements these changes."
Ms Shroff says the data security breach at ACC has provided a timely warning to both public and private sector organisations.
"Agencies that hold large amounts of personal information should be taking note of what has happened at ACC and learn from its mistakes. Many organisations will recognise it could just as easily be them in the headlines."
http://www.scoop.co.nz/stories/PO1208/S00359/privacy-commissioner-urges-acc-culture-change.htm

Damning reports show Government’s role in ACC dysfunction

A press release from the Green Party by Kevin Hague
Reports into ACC provide the most compelling evidence yet that the Government’s focus on saving a buck has caused ACC to lose sight of its role in helping injured and vulnerable New Zealanders, the Green Party said today.
Following requests from the Green Party, reviews into the Bronwyn Pullar Privacy breach and ACC board governance were conducted by the Privacy Commissioner and the Auditor General. Reports on both were released today.
“They reveal a corporation in desperate need of a culture change which the Privacy Commissioner stated must ‘start at the very top’,” Green Party ACC spokesperson Kevin Hague said.
“The reports cite the previous ACC minister’s focus on denying claimants every dollar he could as driving the culture at the corporation.
“And they show that ACC was prepared to sustain human casualties in its drive to achieve the Government’s goal.
“The current minister must now lead the top level change that’s been called for.
“The reports reveal a corporation bumbling along with archaic ideas about communication and responsibility which meant it failed both to treat claimants with decency, and to recognise enormous risks to the organisation even when they hit it in the face,” Mr Hague said.
The Auditor General expresses concern that serous ‘accusations of systemic illegality and fraud were not taken seriously by the corporation’.
And the Privacy Commissioner highlighted ‘an almost cavalier attitude towards its clients and to the protection of their private information’.
“These are two of the most damning reports on a Government entity I’ve ever read.
“It is clear that if board chairman John Judge had not already resigned, he would have been sacked today,” Mr Hague said.
The reports highlight three key issues:
  1. As a result of Nick Smith's direction to prioritise ACC's bottom line, the organisation had inadequate focus on the needs of its clients;
  2. The culture policies and systems of the organisation are a chaotic shambles that are not fit for purpose;
  3. Restoring public trust and confidence is an essential goal and will require very major change starting from the top.
“Given the seriousness of the findings, the Minster must now request that the Auditor General bring forward her review into claims management at ACC. Most of the serious claims Ms Pullar made appear not to have been considered by the board.
“What’s now needed is for visionary leadership to turn this organisation around and focus on the original principals on which it was founded.
“The Minister must ensure that future appointments to the board are up to this task,” Mr Hague said.
http://www.scoop.co.nz/stories/PA1208/S00337/damning-reports-show-governments-role-in-acc-dysfunction.htm

Dual investigations shows culture problems at the ACC

A press release from the New Zealand Association of Psychotherapists by Kyle MacDonald
Today’s dual reports from the Privacy Commisioner and the Office of the Auditor General into the privacy breaches at the ACC show deep concerns about the manner in which privacy is handled, and shows systemic weaknesses within ACC’s culture, systems and processes.
“This report will do little to reassure all those who were effected by the privacy breach and it is very clear that the ACC’s approach to privacy is still of deep concern and clear deficiencies remain,” says Kyle MacDonald of the New Zealand Association of Psychotherapists. “Along with the Auditor General’s report released today, I believe this underlines the fact that there have been, and remain, ongoing problems with the organizations culture.”
“It seems to me that despite ongoing statements by the ACC to the contrary, the blame for this massive breach of privacy and the subsequent frustrations of Ms. Pullar in trying to have her concerns heard, land squarely at the feet of the ACC and senior management. The ACC’s efforts to attack and dis-credit Ms Pullar should now also be called into question.”
The independent report commissioned by the Privacy Commissioner describes an “almost cavalier” approach to the management of private claimant information, and that “the importance of personal information and respecting individual’s personal information is not consistent and is often de-emphasised over dealing with the management of the claim/claimant."
Both reports emphasise the failures of Governance and the systemic and cultural issues that lead to the privacy breach and the way that subsequent events were handled.
http://psychotherapy.org.nz/dual-investigations-shows-culture-problems-at-the-acc/

Reports on ACC privacy, governance welcomed

A press release from the New Zealand Government by Judith Collins
ACC Minister Judith Collins today welcomed the Independent Review of ACC’s Privacy and Security of Information, and the Auditor-General’s Inquiry into aspects of ACC’s Board-level governance.
Ms Collins says ACC must deliver the high level of protection people rightly expect for their personal information and the independent report’s recommendations give clear directions for improvements.



“New Zealanders expect to be able to trust in ACC and be confident their sensitive information will be managed securely, and with care and respect.
“ACC staff have done their best, but they need leadership, tools and processes in place to support them in the important work they do. I am encouraged by the Board’s stated commitment to implementing the report’s recommendations in full.
“I have already put in place a new Service and Purchase Agreement to rebalance ACC’s priorities and set new targets to ensure ACC meets the highest standards of best practice and service for its clients.
“There is a great opportunity now for ACC to restore the public’s trust and confidence. Genuine culture change will take time, but with the right systems and processes, focussed leadership, and commitment to change, ACC can make positive progress.
“I am particularly pleased the authors of the independent review have provided a timeline for improvements in the privacy and security of information. I expect these to be met as a priority,” Ms Collins says.
Also released today, the Auditor-General’s Inquiry into aspects of ACC’s Board-level governance found senior Board members should have managed a client conflict of interest better and failed to recognise and appreciate the risks to ACC of the symptoms of systemic failure.
“The Auditor-General’s report makes it clear that neither the wider Board, nor the Chief Executive were aware of the issues,” Ms Collins says.
In addition, the Board did not have the right protocols to manage risks arising from conflicts of interest with claimants.
“The Auditor-General found the Service and Purchase Agreement the Government has put in place will lead to a more balanced and comprehensive approach to the governance and operation of ACC.
“Building on the strengths of the current four members, I am putting together a reconfigured Board that will have the right experience and the right commitment to leadership to take ACC forward,” Ms Collins says.
http://www.scoop.co.nz/stories/PA1208/S00335/reports-on-acc-privacy-governance-welcomed.htm

ACC chair on independent review of ACC privacy

A press release from ACC by Paula Rebstock
ACC and the Board want to thank the authors for the work they have done and the considered way they have presented the findings.
We will be implementing the recommendations made in full.
On behalf of the Board and ACC, I undertake that we will respond to the challenge before us.
ACC has a clear sense of purpose which is to help individuals, communities and businesses return to independence after accidents. The events over the last six months have raised profound questions about our management of information.
ACC must show customers and stakeholders that change is occurring, that we are responding quickly and that we can demonstrate that people’s personal information is being treated with the care and respect it deserves.
We need processes that help minimise errors with safeguards to provide checks and back-ups. If something does go wrong, we must have systems to respond quickly and appropriately, and just as importantly, we need to find out what went wrong so we can try to prevent it happening again.
The responsibility for this sits with the Board and Management of ACC to provide our people with the environment, tools and processes they need to manage information appropriately.
The review outlines seven broad areas for improving systems and processes with a series of detailed recommendations under each. Just as important, we need strong leadership, the right culture and unquestionable commitment to privacy – and that starts with the Board.
I would also like to acknowledge the work of the Auditor General and the Inquiry Report that was released today into aspects of ACC’s Board-level governance following the breach.
The OAG report recognises the critical importance of having clear and detailed protocols for dealing with communication between Board members and clients.
We accept the conclusions and will incorporate all the OAG recommendations to ensure our practices, training and Governance Manual underpin and support sound governance practice. This includes how the Board and management address any allegations of improper conduct.
The Board is clear about its responsibility and has undertaken to implement the measures in the Auditor General’s report.
Both the Independent Review of ACC and the Auditor General’s report will form part of a programme of work against which ACC can be measured.
We have put in place a structure to lead this work, and we will engage external specialist advice to help plan and prioritise the work ahead of us.
ACC will work closely with the Privacy Commissioner to measure and monitor progress on implementing the recommendations which include regular public reporting of results.
http://www.scoop.co.nz/stories/PO1208/S00352/acc-chair-on-independent-review-of-acc-privacy.htm

Independent review of ACC privacy and information security

A press release from KPMG by the Independent Review Team
A review of the Privacy and Security of Information at the Accident Compensation Corporation was released by the Office of the Privacy Commissioner and ACC’s Board today following a comprehensive review by an Independent Review Team comprising KPMG and Information Integrity Solutions Pty Limited.
The review examined the circumstances relating to a major data breach involving the inadvertent release of personal details of 6,748 ACC clients, and the appropriateness and effectiveness of ACC’s privacy and security policies and practices.
“Information is arguably the most critical asset in any organisation today. The challenge of protecting personal information has never been greater.” says Malcolm Crompton, former Australian Privacy Commissioner and Managing Director of Information Integrity Solutions Pty Limited. “While ACC has suffered a significant data breach, other organisations, both public and private, could face the same.”
The Independent Review Team concluded that the breach that occurred was a genuine human error, but that such an error was more likely to occur because of systemic weaknesses within ACC’s culture, systems and processes. ACC’s subsequent response process could also have been better if appropriate policies, practices, escalation protocols and the right culture were in place to allow for transparency of breach handling at the appropriate levels, in an appropriate manner.
The Recommendations of the Review Team are comprehensive:
  • ACC needs to put in place clear policies that create a positive privacy mindset as part of rebuilding customer trust and establishing a ‘firm but also seen as fair’ image in the minds of the public.
  • Strengthen Board governance of personal information management.
  • Strengthen privacy leadership and strategy.
  • Enhance its privacy programme.
  • Strengthen the organisational culture.
  • Strengthen privacy accountability.
  • Review and update business processes and systems.
  • Provide additional resources to clear backlogs on privacy related processes.
KPMG Partner Souella Cumming commented that “An organisation’s data needs to be protected by thorough and effective risk mitigation strategies to the same or higher levels as other vital assets. Without these strategies in place, the organisation is at risk of significant reputational damage.”
Malcolm Crompton and Souella Cumming noted “We emphasise the significance of a culture and environment where personal information is valued. This must be supported by an approach to compliance with the privacy principles that is embedded within governance, leadership, business processes and systems.”
This forms the basis of the recommendations in the report of the Independent Review Team.

Independent_Review_of_ACCs_Privacy_and_Security_of_Information__August_2012.pdf

http://www.scoop.co.nz/stories/PO1208/S00351/independent-review-of-acc-privacy-and-information-security.htm

13 August 2012

Minister furious over ACC's privacy stance

An article from Stuff by John Hartevelt
ACC Minister Judith Collins wants the state insurer to start sacking staff who breach a new "zero tolerance" policy on privacy breaches.
A furious Ms Collins has revealed her astonishment at the failure of ACC to include privacy among nine of its "top priorities".
"I'm not going to sit back and let one of the most important government entities [that] we have let people down time and time again around things such as privacy.
"They have to act in the way that I expect them to act. When I go around the branches, most of the people there absolutely understand it.
"But, actually, a few are letting them down and when we have things like the audit and risk committee having nine priorities for the year and not one of them [being] privacy, how can that be acceptable given everything else that's going on?"
Ms Collins' comments come as figures from ACC show 11 staff members have been reprimanded over "serious misconduct" since 2010. The breaches involved: theft; fraud against ACC or a claimant; serious misuse of ACC property, including information and systems; dishonesty; disobeying a lawful and reasonable instruction from a manager; and any act that had the potential to bring ACC into disrepute. Nine staff were sacked as a result of the breaches and two were given final written warnings.
Ms Collins said while the serious misconduct cases were "a shame", she was pleased they were taken seriously and not covered up. "I think that they need to be - and they are now - taking on a culture of zero tolerance to privacy breaches, in particular," she said.
Police had a "zero tolerance" approach to staff accessing private details about people without good reason.
"People lose their jobs over it, and that's something that I think ACC needs to have, which is that we have people's very personal information, we should treat it with respect and should understand it's a very privileged position."
ACC has been under siege over repeated privacy breaches since March, when it was revealed the private details of 6500 clients were accidentally sent to claimant Bronwyn Pullar. The revelation sparked a string of controversies, culminating in three inquiries and the resignations of Cabinet minister Nick Smith, board chairman John Judge, chief executive Ralph Stewart and three other board members. Separate inquiries by the privacy commissioner and the auditor-general will be released within weeks.
Ms Collins said she expected the new board members, including a new chairperson, to be in place "just after that".
"When I reappoint or appoint people to the board, that has to be someone who is going to be able to spend the time necessary in bringing about the cultural change that I expect from ACC . . . We need to do an awful lot around the culture of customer service and respect towards members of the public that I know most of our staff are providing."
Green MP Kevin Hague said even basic data protection systems at ACC still appeared to be hopeless.
"When every other state agency, let alone private sector organisation, was busily doing its best to protect data and figure out how to keep people's privacy protected, how come ACC, an organisation that was dealing with some of the most sensitive information out there in the state sector, was effectively doing nothing? I suspect that their focus has been not on meeting client needs. I think their focus has been on their financial result . . . thinking about clients as liabilities rather than people to whom they owe service."
© 2012 Fairfax NZ News

http://www.stuff.co.nz/national/politics/7464891/Minister-furious-over-ACCs-privacy-stance