Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Vague FTC Order Addressing Data Security Struck Down by Federal Appellate Court

By Jeffrey M. Schlossberg on June 21, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

In a significant ruling that calls into question the Federal Trade Commission’s (“FTC”) authority to regulate a private company’s data security program, a federal appellate court of appeals ruled that the agency’s cease and desist order directing implementation of a data security program should be vacated as unenforceable. LabMD, Inc. v. Federal Trade Commission, No. 16-16270 (11th Cir. June 6, 2018).

In 2005, a billing manager of LabMD installed a peer-to-peer file sharing system that exposed to users a file containing personal information of 9,300 consumers. The information included names, dates of birth, social security numbers, and medical information. The file was accessed by a data security firm which brought the issue to LabMD’s attention in the hope that LabMD would retain the firm to correct the problem. When LabMD declined the offer, the security firm reported LabMD to the FTC. Notably, no other third parties accessed the files and there were no reports of identity theft.

In 2013, the FTC initiated its enforcement action alleging that LabMD had failed to use reasonable data security measures. Following a hearing before an Administrative Law Judge, the full Commission ruled that LabMD’s inadequate measures led to substantial injury to consumers and, thus, constituted an unfair practice under Section 5(a) of the FTC Act. As a remedy, the FTC ordered that LabMD implement a data security program reasonably designed to protect consumer information.

LabMD appealed claiming that the order was not enforceable because it was too vague. Notably, the appellate court did not review the Commission’s finding of liability. The Court assumed that “LabMD’s failure to design and maintain a reasonable data security program invaded consumers’ right of privacy and thus constituted an unfair act or practice.”

Despite this conclusion, the Court noted that a remedy from the Commission must meet the requirement of “reasonable definiteness.” Therefore, the Court ruled that the order was unenforceable because it contained no prohibitions or directives as to how to stop committing any specific acts.

Looking forward, the court’s holding leaves open the ability of the FTC to continue monitoring data security. At the same time, the court’s ruling does not detail the specific practices a company must adopt in order to meet the FTC’s definition of reasonableness. Continued enforcement from the FTC can be expected as it goes back to the drawing board to determine if it can more clearly identify specifics to include in its data security orders. Only through continued monitoring of future FTC orders will companies learn what these standards are.

Below are some of our helpful resources on the FTC’s data security activity:

  • The FTC Announces a National Cybersecurity Education Campaign for Small Businesses
  • New FTC Report Makes Security Recommendations to the Mobile Device Industry 
  • Lenovo-FTC Consent Order Calls for 20-Year Monitoring Period 
  • FTC Joins Other Agencies in Warning About Ransomware 
Photo of Jeffrey M. Schlossberg Jeffrey M. Schlossberg

Jeffrey M. Schlossberg is a Principal in the Long Island, New York, Office of Jackson Lewis P.C. Mr. Schlossberg has devoted his entire career to the employment law field. He is a Certified Information Privacy Professional (CIPP/US) with the International Association of Privacy…

Jeffrey M. Schlossberg is a Principal in the Long Island, New York, Office of Jackson Lewis P.C. Mr. Schlossberg has devoted his entire career to the employment law field. He is a Certified Information Privacy Professional (CIPP/US) with the International Association of Privacy Professionals and is an editor of the firm’s EPL Risk Mitigation Blog.

Mr. Schlossberg has extensive experience in handling all aspects of the employer-employee relationship. Areas of concentration include: employment discrimination prevention and litigation; workplace harassment policy development and compliance; social media and information privacy in the workplace; family and medical leave; disability matters; wage and hour investigations and litigation; non-competition agreements; and corporate mergers and acquisitions.

Mr. Schlossberg has defended against claims such as sexual harassment, age, race, national origin and disability discrimination for public and private companies in industries such as media, technology, airline, aircraft components, restaurants, supermarkets, securities, medical, manufacturing, cosmetics, food processing, software, clothing, vitamins and nutritional products, and many other employers of varying size throughout the metropolitan area and across the country.

Mr. Schlossberg lectures frequently about various topics to trade and professional associations, such as the Hauppauge Industrial Association. Mr. Schlossberg is also an active member of the Nassau County Bar Association and is a Past Chair of the Nassau County Bar Association Labor & Employment Law Committee.

Mr. Schlossberg is an appointed member of the Employment Law Panel of arbitrators for National Arbitration and Mediation.

Read more about Jeffrey M. SchlossbergEmail
Show more Show less
  • Posted in:
    Administrative and Regulatory, Privacy and Cybersecurity
  • Blog:
    Workplace Privacy, Data Management & Security Report
  • Organization:
    Jackson Lewis P.C.
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo