Tag Archives: CFPB

ALTA Best Practice #3: Protecting NPI

This particular Best Practice seems to be creating the most buzz. What exactly is NPI? What is the best way to protect it? What is it going to take to be compliant? What are your thoughts.

Non-public Personal Information (NPI)

Personally identifiable data, for example: information provided by a customer on a form or application, information about a customer’s transactions, or any other information about a customer which is otherwise unavailable to the general public. NPI includes first name or first initial and last name coupled with any of the following: Social Security Number, driver’s license number, state-issued ID number, credit card number, debit card number, or other financial account numbers.

Best Practice

Adopt and maintain a written privacy and information security program to protect NPI as required by law.

Reason

Federal and state laws require title companies to develop a written information security program that explains how NPI is protected.

For more information about all the ALTA Best Practices and also 1 credit of title insurance continuing education, enroll in the ALTA Best Practice course at Learntitle. Click Here to Enroll

CFPB continues RESPA enforcement with action against nonbank lender – Lexology

On February 24, the CFPB announced that a nonbank mortgage lender agreed to pay an $83,000 penalty to resolve violations of RESPA’s Section 8. The lender primarily offers loss-mitigation refinance mortgage loans to distressed borrowers. According to the consent order, after the lender ceased obtaining funding for its loans from two subsidiaries of a hedge fund, the lender continued to split loss-mitigation and origination fees with the subsidiaries on 83 additional loans originated over an eight-month period, even though neither subsidiary provided financing or any other service in any of those transactions

Read the full article here

CFPB continues RESPA enforcement with action against nonbank lender – Lexology.

How to create a strong password

ALTA Best practices encourages the use of strong passwords for your computer systems. Passwords provide the first line of defense against unauthorized access to your computer. The stronger your password, the more protected your computer will be from hackers and malicious software. You should make sure you have strong passwords for all accounts on your computer. If you’re using a corporate network, your network administrator might require you to use a strong password.

Check the strength of your password here

What makes a password strong (or weak)?

A strong password:

  • Is at least eight characters long.

  • Does not contain your user name, real name, or company name.

  • Does not contain a complete word.

  • Is significantly different from previous passwords.

  • Contains Uppercase letters, Lowercase letters, numbers and symbols

A password might meet all the criteria above and still be a weak password. For example, No1password! meets all the criteria for a strong password listed above, but is still weak because it contains a complete word. N01 p@ssw0rd! is a stronger alternative because it replaces some of the letters in the complete word with numbers and also includes spaces.

Help yourself remember your strong password by following these tips:

  • Create an acronym from an easy-to-remember piece of information. For example, pick a phrase that is meaningful to you, such as My daughter’s birthday is 28 October, 1974. Using that phrase as your guide, you might use Mdbi28/Oct,74 for your password.

  • Substitute numbers, symbols, and misspellings for letters or words in an easy-to-remember phrase. For example, My daughter’s birthday is 28 October, 1974 could become MiDauBrthd8iz 281074 (it’s OK to use spaces in your password).

  • Relate your password to a favorite hobby or sport. For example, I love to play basketball could become ILuv2PlayB@sk3tb@ll.

If you feel you must write down your password in order to remember it, make sure you don’t label it as your password, and keep it in a safe place.

Check the strength of your password here