WHEREAS, The Fair and Accurate Credit Transactions Act of 2003, an amendment to the
Fair Credit Reporting Act, requires rules regarding identity theft protection to be
promulgated and adopted jointly by the Office of the Comptroller of the Currency,
Treasury; the Board of Governors of the Federal Reserve System; the Federal Deposit
Insurance Corporation; the Office of Thrift Supervision, Treasury; the National Credit
Union Administration; and the Federal Trade Commission; and
WHEREAS, Those rules become effective November 1, 2008, and require certain financial
institutions and creditors to implement an identity theft prevention program; and
WHEREAS, The Federal Trade Commission suspended enforcement of the new "Red Flags
Rule" until May 1, 2009; and
WHEREAS, The Federal Trade Commission delayed enforcement of the new "Red Flags Rule"
until August 1, 2009; and
WHEREAS, The risk to the University, and its students, faculty, staff, and other constituents
from data loss and identity theft is of significant concern to the University and
the Board of Trustees has determined that the University should make reasonable efforts
to detect, prevent, and mitigate identify theft; and
WHEREAS, The Board of Trustees has determined that the proposed Red Flags Rule Identity
Theft Prevention Program is in the best interest of the University and its students,
faculty, staff, and other constituents;
THEREFORE, LET IT BE RESOLVED by the Board of Trustees for Winthrop University meeting in Rock Hill, South Carolina on June 5, 2009 that:
1. the "Red Flags Rule Identity Theft Prevention Program" attached hereto as Exhibit
A is hereby approved; and
2. the Vice President for Finance and Business of the University is hereby delegated
operational responsibility of the Program, including but not limited to oversight,
development, implementation, and administration of the Program; approval of needed
changes to the Program; and implementation of needed changes to the Program.
EXHIBIT A
RED FLAGS RULE
IDENTITY THEFT PREVENTION PROGRAM
Purpose
The purpose of this policy is to establish a Red Flags Rule Identity Theft Prevention Program designed to detect, prevent and mitigate identity theft in connection with the opening of a covered account or an existing covered account and to provide for continued administration of the Program. The Program shall include reasonable policies and procedures to:
Existing Policies and Practices
The University has policies to ensure compliance with Gramm-Leach-Bliley Act (GLB), Family Educational Rights and Privacy Act (FERPA), system and application security, and internal control procedures which provide an environment where identity theft opportunities are mitigated. Records are safeguarded to ensure the privacy and confidentiality of student and borrower records.
In addition, the University adheres to the following practices:
Definitions
Covered Accounts
Identifying Relevant Red Flags
Detecting Red Flag Activity
Covered accounts are opened as follows:
Federal Perkins Loan Program
South Carolina Teaching Fellows Program
Student Payment Plans
Students must call, e-mail or come into the Controller's Office to request their account be placed on a tuition payment plan.
Responding to Red Flags
The Program shall provide for appropriate responses to detected red flags to prevent and mitigate identity theft. The appropriate responses to the relevant red flags are as follows:
Updating the Program
The University will update the Program annually in December, to reflect changes in risks to students or borrowers or to the safety and soundness of the University from identity theft, based on factors such as:
Oversight of Service Provider Arrangements
The University shall take steps to ensure that the activity of a service provider is conducted in accordance with reasonable policies and procedures designed to detect, prevent and mitigate the risk of identity theft whenever the University engages a service provider to perform an activity in connection with one or more covered accounts.
Currently the University uses UAS to administer the Perkins Loan Program. Students contact UAS directly through its website or by telephone and provide personal identifying information to be matched to the records that the University has provided to UAS.