Mr. President, I rise today along with my colleague Senator Coleman to introduce the Internet Pharmacy Consumer Protection Act also called the ``Ryan Haight Act'', a bill which is vital to protect the safety of Americans who choose to…
Mr. President, I rise today along with my colleague Senator Coleman to introduce the Internet Pharmacy Consumer Protection Act also called the ``Ryan Haight Act'', a bill which is vital to protect the safety of Americans who choose to purchase their prescription drugs legally over the Internet.
This legislation is necessary because of a growing problem of illegal prescription drug diversion and abuse of prescription drugs. Coupled with the ease of access to the Internet, it has led to an environment where illegitimate pharmacy websites can bypass traditional regulations and established safeguards for the sale of prescription drugs. Internet websites that allow consumers to obtain prescription drugs without the existence of a bona fide physician-patient relationship pose an immediate threat to public health and safety.
To address this problem, the Internet Pharmacy Consumer Protection Act makes several critical steps to ensure safety and to assist regulatory authorities in shutting down ``rogue'' Internet pharmacies.
First, this bill establishes disclosure standards for Internet pharmacies.
Second, this bill prohibits the dispensing or sale of a prescription drug based solely on communications via the Internet such as the completion of an online medical questionnaire.
Third, it allows a State Attorney General to bring a civil action in a federal district court to enjoin a pharmacy operation and to enforce compliance with the provisions of this law.
Under this bill, for a domestic website to sell prescription drugs legally, the website would have to display identifying information such as the names, addresses, and medical licensing information for pharmacists and physicians associated with the website.
In addition, if a person wants to use the Internet to purchase their prescription drugs he or she will not be prohibited from doing so under this bill but, in order to do so, must already have a prescription for the drug that is valid in the United States prior to making the Internet purchase.
Reliance on the Internet for public health purposes and the expansion of telemedicine, particularly in rural areas, make it essential that there be at the very least a minimum standard for what qualifies as an acceptable medical relationship between patients and their physicians.
According to the American Medical Association, a health care practitioner who offers a prescription for a patient he or she has never seen before, based solely on an online questionnaire, generally does not meet the appropriate medical standard of care.
Let me illustrate the situation facing our country today. If a physician's office prescribed and dispensed prescription drugs the same way Internet pharmacies currently can and do, it would look something like this: A physician opens a physical office, asks a patient to fill out a medical history questionnaire in the lobby and give his or her credit card information to the office manager. There is no nurse, and therefore no one to take the patients' height, weight, blood pressure, verify his or her medical history, and so forth and no one to answer the patient's questions regarding their health.
The questionnaire is then slipped through a hole in the window; the office manager takes it to the physician, or person acting as the physician, who then writes the prescription and hands it to the pharmacist, or person acting as the pharmacist, in the next room. Once the patient signs his credit card, he is on his way out the door, drugs in hand.
No examination is performed, no questions asked, and no verification or clarification of the answers provided on the medical history questionnaire.
This illustration is not an exaggeration. It occurs every day all across the United States. The National Association of Boards of Pharmacy estimates
that there are around 500 identifiable rogue pharmacy websites operating on the Internet.
According to the Federation of State Medical Boards, approximately 29 states and the District of Columbia either have laws or medical board initiatives addressing Internet medical practice. Of the other 21 States, 13 have medical or osteopathic medical boards that have taken disciplinary action against a physician for prescribing medication online.
Many States have already enacted laws defining acceptable practices for qualifying medical relationships between doctors and patients and this bill would not affect any existing State laws.
For example, California law was changed in 2000 to say:
No person or entity may prescribe, dispense, or furnish, or
cause to be prescribed, dispensed, or furnished dangerous
drugs or dangerous devices [defined as any drug or device
unsafe for self-use] on the Internet for delivery to any
person in this state, without a good faith prior examination
and medical indication . . .
I believe California's law is a perfect example of why this legislation is needed. The law only applies to persons living in California. As we all know, however, the Internet is not bound by State or even country borders.
This legislation makes a critical step forward by providing additional authority for State Attorneys General to file an injunction in Federal court to shut down an Internet site operating in another State that violates the provisions in the bill.
Under current law, in order to close down an Internet website selling prescription drugs prosecutors must take enforcement actions in every State where the Internet pharmacy operates, requiring a tremendous amount of resources in an environment where the location of the website is difficult, if not impossible, to determine or keep track of.
This bill will allow a State Attorney General to bring a civil action in a Federal district court to enjoin a pharmacy operation and to enforce compliance with the provisions of the law in every jurisdiction where the pharmacy is operating.
While this legislation pertains to domestic Internet pharmacies, the practice of international pharmacies selling low-cost drugs to U.S. consumers who have valid prescriptions from their doctors deserves to be discussed and debated on the Senate floor. It is my hope that the Senate will act this year on prescription drug importation legislation.
In closing, I want to share with you the story of Ryan T. Haight of La Mesa, CA in whose memory this bill is named.
Ryan was an 18-year old honor student from La Mesa, CA, when he died in his home on February 12, 2001. His parents found a bottle of Vicodin in his room with a label from an out-of-state pharmacy.
It turns out that Ryan had been ordering addictive drugs online and paying with a debit card his parents gave him to buy baseball cards on eBay.
Without a physical exam or his parents' consent, Ryan had been obtaining controlled substances, some from an Internet site in Oklahoma. It only took a few months before Ryan's life was ended by an overdose on a cocktail of painkillers.
Ryan's story and others like it force us to ask why anyone in the U.S. would be able to access such highly addictive and dangerous drugs over the Internet with such ease?
Why was there no physician or pharmacist on the other end of this teenager's computer verifying his age, his medical history and that there was a valid prescription?
That is why I support this legislation. It makes sensible requirements of Internet pharmacy websites that will not impact access to convenient, oftentimes cost-saving drugs.
With simple disclosure requirements for Internet sites such as names, addresses and medical or pharmacy licensing information, patients will be better off and state medical and pharmacy boards can ensure that pharmacists and doctors are properly licensed.
Lastly, this bill will give State Attorneys General the authority they need to shut down rogue Internet pharmacies operating in other States. I urge my colleagues to support this bill.
Mr. President, I rise to introduce, along with my colleague, Senator Bill Nelson, the Increasing Notice of Foreign Outsourcing Act, or the INFO Act. This legislation will help safeguard Americans' most important and sensitive personal information when it is sent abroad for processing to countries that may have lax security and privacy standards.
The bill will ensure that American companies notify consumers of a business's outsourcing practices. It will require American companies to certify the adequacy of their outsourcing protections. And it will require American companies to hold their foreign business partners accountable for protecting Americans' data.
In order to protect the information of Americans that is now vulnerable abroad, this bill calls for the following key safeguards:
First, the bill requires American health and financial companies to notify consumers when sending their information abroad, and to certify the safety of the overseas processing. We drafted provisions carefully to minimize the burden on businesses, so they will expand on privacy disclosures that companies already make under Federal law.
Second, American companies processing health or financial data must include clauses in contracts with their foreign partners to allow audits of their foreign information processors and to enforce American privacy standards.
Third, the bill creates a system to inform American companies and Federal regulators of any security breaches involving American health or financial information at facilities operated outside the United States.
And fourth, the bill gives Americans the right to have workers at foreign call centers disclose where they are calling from.
The bill also gives Federal agencies the power to enforce these provisions. It is important to emphasize that this bill is drafted to minimize the burdens on businesses, by expanding on existing privacy data and security laws.
While many are concerned about how outsourcing abroad hurts American workers, outsourcing also poses risks to the security and privacy of American consumers' personal data. The recent wave of international outsourcing means that we are flooding the entire world with our most sensitive information.
Once sent abroad, the information is at risk because our Federal laws do not apply to foreign companies operating overseas. Another reason is because many foreign countries have far weaker security laws than our own. For instance, India still has no laws to protect personal and private data. And still another reason is because it is extremely difficult for Americans to use foreign courts to sue foreign companies that misuse American data.
These factors leave the most intimate details of the lives of uncountable Americans vulnerable to lax security and to malicious identity thieves.
And there is even more at stake. Information outsourcing poses a direct risk to national security. We are painfully aware that some people want to steal the identity of individual Americans in order to evade our homeland defenses and harm us all.
International information outsourcing has skyrocketed in recent years. Consider the following:
Tax returns for about 200,000 Americans were prepared in India this year. To put this number in context, India workers processed only about 1,000 U.S. tax returns 2 years ago. Tax returns have Americans' names, Social Security numbers, income, employers, addresses, and other details.
The American Association of Medical Transcription estimates that 10 percent of all medical transcription of doctors' notes is being done abroad.
An executive from Trans Union, one of the major credit agencies in the United States, told The San Francisco Chronicle that:
A hundred percent of our mail regarding customer disputes
is going to go to India at some point.
If anyone doubts the risk that international outsourcing poses to Americans, consider these incidents:
Recently, a low-paid transcriber in Pakistan was working as a subcontractor to the University of California Medical Center in San Francisco. That foreign worker threatened to post confidential patient information on the Internet unless the university coaxed her boss into paying some of her bills.
Three weeks later, a strikingly similar incident occurred with a worker in Bangalore, India.
In another incident, in Noida, India, an employee working at a call center used an American's credit card information to buy electronics equipment from Sony.
Also in India, there is a burgeoning black market in personal identity information. According to one report, stolen names, addresses, phone numbers, the bank a person has an account with, and even bank account numbers are sold on the streets for mere pennies.
These are just a few incidents. No one knows how many other times workers have done similar things. And that is a big part of the problem. It is not merely that Americans' identities are vulnerable when sent abroad. The problem is that American companies obscure how much outsourcing they do, and when they are doing it.
For example, according to the San Jose Mercury News, a worker at a call center dealing with State benefits refused to identify his location. The supervisor, when she picked up the call, refused to say anything more than that she worked for Citicorp.
In essence, the problem of obscurity is so bad that we can list only a few incidents reported by the media. How many security breaches have taken place? Have consumers been informed when their information is abroad and at risk? How much money has this cost consumers? We don't know.
And so far, American regulatory agencies have been unable to say despite their oversight of these industries. And American companies have stayed mum. We need to break the silence.
The fact is, our Government is simply not doing enough to protect consumers. Earlier this month I received a letter from John D. Hawke, Jr., who is the U.S. Comptroller of the Currency. He heads one of the agencies that regulates U.S. financial institutions and banks.
Mr. Hawke wrote to me that the Office of the Comptroller of the Currency, known as the OCC, does not directly regulate foreign contractors that work for U.S. banks. Specifically, he wrote:
[T]he OCC focuses its supervisory reviews regarding foreign
servicing relationships on whether the serviced banks have
adequate procedures in place. . . .
That means the OCC is focusing on the American companies, not the foreign ones.
I also learned from the OCC that it already suggests certain safeguards for American banks to use when they hire foreign information processors. The OCC asks U.S. banks to use contract provisions to make sure that foreign companies use secure methods to process data, and to let the U.S. companies audit the foreign companies.
But the OCC only suggests that companies adopt these safeguards. The legislation we are introducing today would take safeguards like the OCC's a step further, and make them mandatory.
Now is the time to act. We know that there are criminal syndicates, such as in Nigeria, that have fraudulently obtained bank information to steal untold fortunes. We can hardly imagine the damage such organizations can do with a vast new source of sensitive financial data from international information outsourcing.
In short, this bill accomplishes four goals crucial to protecting Americans' sensitive data sent abroad. It requires companies to give notice that they send consumers' sensitive data abroad. It ensures that U.S. companies can audit their foreign partners, and impose U.S. privacy standards on them. It establishes a system to ensure that foreign and U.S. companies will report security breaches to the U.S. Government. And it allows American consumers to demand to know where foreign call centers are located.
This bill helps to protect outsourced information while minimizing burdens on American businesses. I urge my colleagues to join us in this effort.