How New Regulations for Small Business Owners

Time passed, you could just close the shingle and call it business. As long as you did not shoot anyone, you shot yourself. Not anymore. There have been a number of state and provincial laws, many of them over the past few years, and many of them operate in small businesses.

These regulations are intended to fulfill any of the few public assets, such as protecting individual privacy and preventing identity theft, preventing corporate financial scandals, or lastly, or, more likely, annoying small business owners by increasing their paper load. Fortunately, if you understand these rules, compliance does not have to be too complicated or too expensive.

If you own a company owned by the public, you must comply with the Sarbanes-Oxley Act, which sets out the technical standards and reporting requirements of how companies handle their financial reporting. Approved due to the recent wave of corporate scandals, financial mismanagement and direct theft, Sarbanes-Oxley sets a set of requirements to establish internal controls that ensure the integrity of the company's financial data.

Although requirements are generally the same for companies of all sizes, small companies are given some flexibility over long periods of time to comply.

The Act requires, among other things, security measures to be taken to regulate access to financial data, to provide audit information, and to provide detailed government reporting. The good news is that, if you already follow the best security practices, you are already more than half there.

If you are in the healthcare industry, whether you are a health care provider, pharmacist, or data processing agency working for the healthcare industry, you will need to comply with the Health Insurance and Accountability Management Act (HIPAA). HIPAA calls on any company that handles personal patient data to ensure that it is secure and secure from unauthorized access.

If your company has health care information of any kind, for whatever reason, you will need to take technical steps to ensure it is protected by measures such as encryption, two-factor authentication, and adequate fire extinguishers.

And if you are in California, or if any of your customers are in California, you will need to comply with SB 1386 (California Information Practice Act). This law requires that your company provide notification to customers whenever a technical or other technical breach occurs, causing personal information to be identified and risked theft.

Aimed at preventing identity theft, this law of the country also applies to any subcontractors of companies that hold information about California citizens. This law is important, because even though it is as legal as California law, it has, in effect, become an organization law.

California is the largest, most populous state, in the U.S., and any medium and small company has at least a few customers in California, no matter where the company really is. If, for example, your company is in Maine, but part of your mail order sells certain products to someone in California, you must comply.

Compliance means that if your network is attacked, you must notify your customers. While this can be done individually, many companies actually make an announcement on their websites, or by publishing a report to the media.

The Visa Cardholder Information Security Program (CISP) is not a national or corporate law, but a mandate from VISA USA designed to protect cardholder data. It calls on all merchants who accept credit card payments to adhere to a high level of information security in order to monitor identity theft.

CISP urges retailers to use common security measures such as fire shortcuts, antivirus software, and robust authentication to control who can access customer credit card data. Visa also sets a set of the best ways.

Compliance is easy, and involves adhering to the Payment Card Industry Data Protection Standard which includes an application to implement standard security technologies, limit access, and encryption the transfer of any cardholder data.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author