By Lauren E. Douglas

The year 2021 marks the forty-eighth anniversary of the mobile phone[1] and the eighty-third anniversary of the programmable computer.[2]  It is no secret that mobile devices are significantly more powerful than their inventors could have ever predicted.[3]  What started as clunky, cumbersome machinery has transformed into the backbone of society as we know it.[4]

Many aspects of corporate success are rooted in the evolution of the mobile device.[5]  To aid in their success, the majority of employers now permit the cross-use of electronic devices for personal and professional purposes—a movement known as “Bring Your Own Device” and lovingly referred to as “BYOD” for short.[6]  More specifically, the BYOD phenomenon is a practice whereby employees[7] use their own electronic devices[8] to do their jobs on the employers’ platforms.[9]  The BYOD practice is loved by employees and employers alike[10] and drives corporate activity in ways nearly unimaginable even ten years ago.[11]  In fact, in 2018, the BYOD market was predicted to reach nearly $367 billion by 2022.[12]  In the wake of the COVID-19 pandemic, the true number is likely even higher.[13]  Pandemic or no pandemic, it is clear that the BYOD era is here to stay.[14]

Despite the rising popularity of the BYOD workstyle, very few businesses actually enforce formal BYOD policies and instead simply allow employees to access corporate data on their own devices free of internal regulation.[15]  A study conducted in 2016 revealed that, even though roughly 70 percent of employees conduct work-related activities on their personal devices, only 39 percent of companies have a formal BYOD policy in place.[16]  This is dangerous; if companies do not regulate their BYOD practices, they risk breaches of sensitive corporate data and violations of federal privacy laws.[17]

The Tension Between Privacy Interests and Data Protection

Perhaps the most problematic issue that comes with implementing a BYOD policy is determining to what extent an employer can legally monitor and access its employee’s personal devices.[18]  The American Bar Association describes balancing the employers’ interests in data security with the employees’ rights of privacy as “the single greatest challenge” to a successful BYOD program.[19]  With that said, it must be recognized that employees enjoy a heightened right to privacy regarding information stored on their own personal devices as compared to employer-provided devices.[20]  Such protection may be found in both statutory and common law.

Specifically, the Computer Fraud and Abuse Act of 1986 (“CFAA”)[21] imposes criminal and civil penalties on individuals and companies that “intentionally access a computer without authorization or exceeds authorized access” to obtain “information from any protected computer.”[22]  The CFAA began as a means to protect government computers from hackers, but today the law reaches every computer connected to the internet.[23]  Of course, in 2021, computers are not the only devices used to conduct work.  Luckily, federal case law establishes that, in addition to desktop and laptop computers, the CFAA protects devices such as cell phones,[24] tablet devices, and even videogame systems.[25]  To supplement the CFAA, employees might also claim a violation of the Electronic Communications Privacy Act (“ECPA”), a subsection of the Stored Communications Act (“SCA”) that protects the privacy of electronic communications in electronic storage.[26]

So far, courts addressing the new BYOD privacy dichotomy seem reluctant to construe statutory protection broadly in favor of plaintiff-employees who had their personal devices wiped clean of all information.  For instance, in Rajaee v. Design Tech Homes, Ltd.,[27] a company remotely deleted all of an employee’s work and personal files from his mobile device after he resigned.[28]  The device was connected to the employer’s data server, allowing for remote access to email and calendar platforms.[29]  The employee sued for damages under the ECPA and the CFAA, but the court rejected both claims, reasoning that the personal data lost was not “electronic storage” as defined under the ECPA and was not a qualified “loss” under the CFAA.[30]  Such stringent readings of these statutes makes asserting a viable claim for lost personal data caused by the employer a very difficult feat for employees.[31]

Because technology moves light-years faster than the development of law,[32] the CFAA and ECPA are two of the closest statutes to the BYOD issue; there is currently no federal or state legislation directly addressing BYOD policies.[33]  Similarly, the relevant case law is negligible.[34]  It is thus vital for employers to create and implement comprehensive, transparent, and officially documented BYOD programs.  Thorough BYOD policies are important because, with the lack of statutory law on point, courts in many cases will look directly to the provisions in the BYOD policy to “determine the bounds of permissible employer conduct.”[35]

Private employees generally retain privacy interests in common law so long as their expectations are “reasonable.”[36]  When considering whether an employee has a reasonable expectation of privacy in electronic communications, courts tend to balance the following factors: (1) account ownership;[37] (2) device ownership;[38] (3) the security level of the communication;[39] and (4) published employer policies and whether they were routinely enforced.[40]  No one factor is dispositive and different courts may weigh factors differently.[41]  Because two of the four factors essentially look for whether a BYOD program exists, employers can cover a significant number of bases simply by drafting a formal policy.[42]

Best Practices for Employers

Despite the lack of concrete legal guidelines surrounding the BYOD phenomenon, an employer can mitigate the majority of its concerns by implementing a formal BYOD policy.  An effective policy should “emphasize security and contain clear instructions” regarding acceptable and unacceptable activities on personally owned devices that have access to corporate information systems.[43]  Additionally, an employer’s BYOD policy should make clear that “any and all company information and emails” on all personal devices remain “the sole property” of the company, and that the employer “in its sole discretion” may access and delete any company data that “may be in jeopardy.”[44]  No threat is too small when it comes to business use of personal devices, and providing express notice to employees is the very best way to mitigate legal liability surrounding BYOD policies.[45]

In addition to implementing a comprehensive, written BYOD policy, many companies—especially those that handle sensitive information—are utilizing Mobile Device Management (“MDM”) service providers to help mitigate the technical risks associated with allowing employees to access company data on their own devices.[46]  In essence, MDM broadens the scope of BYOD protection and is “designed to fill security gaps” in employee use of personal devices.[47]  MDM allows employers to exercise control over the device, monitor applications, and remotely wipe the device if it is lost or stolen—clearly a worthwhile addition to any BYOD policy.[48]

The Bottom Line

An astonishing number of employees and employers engage in the BYOD workstyle.  While BYOD practices often increase employee satisfaction and performance, and decrease employer costs, they come with inherent risks that cannot be ignored, such as data breaches and violations of federal privacy law.  Employers can mitigate many of these risks by implementing a strong written BYOD policy that clearly delineates the employers’ rights of access to each device.  Now more than ever, actively and uniformly enforcing a BYOD policy is the best mechanism to alleviate legal risks while the law plays catch-up with the modern technological workplace.

By Mary Catherine Young

Last month, an Azerbaijani journalist was forced to deactivate her social media accounts after receiving sexually explicit and violent threats in response to a piece she wrote about Azerbaijan’s cease-fire with Armenia.[1] Some online users called for the Azerbaijan government to revoke columnist Arzu Geybulla’s citizenship—others called for her death.[2] Days later, an Irish man, Brendan Doolin, was criminally charged for online harassment of four female journalists.[3] The charges came on the heels of a three-year jail sentence rendered in 2019 based on charges for stalking six female writers and journalists online, one of whom reported receiving over 450 messages from Doolin.[4] Online harassment of journalists is palpable on an international scale.

Online harassment of journalists abounds in the United States as well, with females receiving the brunt of the persecution.[5] According to a 2019 survey conducted by the Committee to Protect Journalists, 90 percent of female or gender nonconforming American journalists said that online harassment is “the biggest threat facing journalists today.”[6] Fifty percent of those surveyed reported that they have been threatened online.[7] While online harassment plagues journalists around the world, the legal ramifications of such harassment are far from uniform.[8] Before diving into how the law can protect journalists from this abuse, it is necessary to expound on what online harassment actually looks like in the United States.

In a survey conducted in 2017 by the Pew Research Center, 41 percent of 4,248 American adults reported that they had personally experienced harassing behavior online.[9] The same study found that 66 percent of Americans said that they have witnessed harassment targeted at others.[10] Online harassment, however, takes many shapes.[11] For example, people may experience “doxing” which occurs when one’s personal information is revealed on the internet.[12] Or, they may experience a “technical attack,” which includes harassers hacking an email account or preventing traffic to a particular webpage.[13] Much of online harassment takes the form of “trolling,” which occurs when “a perpetrator seeks to elicit anger, annoyance or other negative emotions, often by posting inflammatory messages.”[14] Trolling can encompass situations in which harassers intend to silence women with sexualized threats.[15]

The consequences of online harassment of internet users can be significant, invoking mental distress and sometimes fear for one’s physical safety.[16] In the context of journalists, however, the implications of harassment commonly affect more than the individual journalist themselves—free flow of information in the media is frequently disrupted due to journalists’ fear of cyberbullying.[17] How legal systems punish those who harass journalists online varies greatly both internationally and domestically.[18]

For example, the United States provides several federal criminal and civil paths to recourse for victims of online harassment, though not specifically geared toward journalists.[19] In terms of criminal law, provisions protecting individuals against cyber-stalking are included in 18 U.S.C. § 2261A, which criminalizes stalking in general.[20] According to this statute, “[w]hoever . . . with the intent to kill, injure, harass, intimidate, or place under surveillance with intent to . . . harass, or intimidate another person, uses . . . any interactive computer service . . . [and] causes, attempts to cause, or would be reasonably expected to cause substantial emotional distress to a person . . .” may be imprisoned.[21] In terms of civil law, plaintiffs may be able to allege defamation or copyright infringement claims.[22] For example, when the harassment takes the form of sharing an individuals’ self-taken photographs without the photographer’s consent, whether they are explicit or not, the circumstances may allow the victim to pursue a claim under the Digital Millennium Copyright Act.[23]

Some states provide their own online harassment criminal laws, though states differ in whether the provisions are included in anti-harassment legislation or in their anti-stalking laws.[24] For example, Alabama,[25] Arizona,[26] and Hawaii[27] all provide for criminal prosecution for cyberbullying in their laws against harassment, whereas Wyoming,[28] California,[29] and North Carolina[30] include anti-online harassment provisions in their laws against stalking.[31] North Carolina’s stalking statute, however, was recently held unconstitutional as applied under the First Amendment after a defendant was charged for posting a slew of Google Plus posts about his bizarre wishes to marry the victim.[32] The North Carolina Court of Appeals decision in Shackelford seems to reflect a distinctly American general reluctance to interfere with individuals’ ability to freely post online out of extreme deference to First Amendment rights.

Other countries have taken more targeted approaches to legally protecting journalists from online harassment.[33] France, in particular, has several laws pertaining to cyberbullying and online harassment in general, and these laws have recently provided relief for journalists.[34] For example, in July 2018, two perpetrators were given six-month suspended prison sentences after targeting a journalist online.[35] The defendants subjected Nadia Daam, a French journalist and radio broadcaster, to months of online harassment after she condemned users of an online platform for harassing feminist activists.[36] Scholars who examine France’s willingness to prosecute perpetrators of online harassment against journalists and non-journalists alike point to the fact that while the country certainly holds freedom of expression in high regard, this freedom is held in check against other rights, including individuals’ right to privacy and “right to human dignity.”[37]

Some call for more rigorous criminalization of online harassment in the United States, particularly against journalists, to reduce the potential for online harassment to create a “crowding-out effect” that prevents actually helpful online speech from being heard.[38] It seems, however, that First Amendment interests may prevent many journalists from finding relief—at least for now.

[1] Aneeta Mathur-Ashton, Campaign of Hate Forces Azeri Journalist Offline, VOA (Jan. 8, 2021),

[2] Id.

[3] Tom Tuite, Dubliner Charged with Harassing Journalists Remanded in Custody, The Irish Times (Jan. 18, 2021),

[4] Brion Hoban & Sonya McLean, ‘Internet Troll’ Jailed for Sending Hundreds of Abusive Messages to Six Women, The (Nov. 14, 2019),

[5] Lucy Westcott & James W. Foley, Why Newsrooms Need a Solution to End Online Harassment of Reporters, Comm. to Protect Journalists (Sept. 4, 2019),

[6] Id.

[7] Id.

[8] See Anya Schiffrin, How to Protect Journalists from Online Harassment, Project Syndicate (July 1, 2020),

[9] Maeve Duggan, Online Harassment in 2017, Pew Rsch. Ctr. (July 11, 2017),

[10] Id.

[11] Autumn Slaughter & Elana Newman, Journalists and Online Harassment, Dart Ctr. for Journalism & Trauma (Jan. 14, 2020),

[12] Id.

[13] Id.

[14] Id.

[15] Id.

[16] Duggan, supra note 9.

[17] Law Libr. of Cong., Laws Protecting Journalists from Online Harassment 1 (2019),

[18] See id. at 3–4; Marlisse Silver Sweeney, What the Law Can (and Can’t) Do About Online Harassment, The Atl. (Nov. 12, 2014),

[19] Hollaback!, Online Harassment: A Comparative Policy Analysis for Hollaback! 37 (2016),

[20] 18 U.S.C. § 2261A.

[21] § 2261A(2)(b).

[22] Hollaback!, supra note 19, at 38.

[23] Id.; see also 17 U.S.C. §§ 1201–1332.

[24] Hollaback!, supra note 19, at 38–39.

[25] Ala. Code § 13A-11-8.

[26] Ariz. Rev. Stat. Ann. § 13-2916.

[27] Haw. Rev. Stat. § 711-1106.

[28] Wyo. Stat. Ann. § 6-2-506.

[29] Cal. Penal Code § 646.9.

[30] N.C. Gen. Stat. § 14-277.3A.

[31] Hollaback!, supra note 19, at 39 (providing more states that cover online harassment in their penal codes).

[32] State v. Shackelford, 825 S.E.2d 689, 701 (N.C. Ct. App. 2019), After meeting the victim once at a church service, the defendant promptly made four separate Google Plus posts in which he referenced the victim by name. Id. at 692. In one post, the defendant stated that “God chose [the victim]” to be his “soul mate,” and in a separate post wrote that he “freely chose [the victim] as his wife.” Id. After nearly a year of increasingly invasive posts in which he repeatedly referred to the victim as his wife, defendant was indicted by a grand jury on eight counts of felony stalking. Id. at 693–94.

[33] Law Libr. of Cong., supra note 17, at 1–2.

[34] Id. at 78–83.

[35] Id. at 83.

[36] Id.

[37] Id. at 78.

[38] Schiffrin, supra note 8.

9 Wake Forest L. Rev. Online 21

Alexander W. Prunka*

I. Introduction

In the era of the #MeToo movement, there has been a dramatic push to name names and expose individuals accused of sexual misconduct and harassment across the world.[1] Before Harvey Weinstein was first accused and the #MeToo movement stormed onto the scene, though, college campuses were already predicting what was to come.[2]

For example, in 2014, on the heels of recent changes to the federal government’s interpretation of Title IX as it relates to peer-to-peer sexual misconduct, advocates founded the It’s On Us campaign to end sexual assault.[3] In 2015, a shocking documentary premiered detailing the prevalence of sexual assault on college campuses and institutional failure to address the issue.[4] The documentary featured prestigious universities, including the University of North Carolina at Chapel Hill ( “UNC”).

The Daily Tar Heel ( “DTH”), UNC’s campus newspaper, has long argued that UNC should disclose the names of individuals found responsible for sexual misconduct by University.[5] DTH has a history of seeking access to student disciplinary records: it took its 1996 attempt to publicize Honor Court proceedings and declassify their records to the North Carolina Court of Appeals.[6] DTH has been so dedicated to exposing UNC’s shortcomings in addressing sexual misconduct, it once published the details of victims’ complaints to the Department of Education against the victims’ wishes and without their consent.[7] So what happens when a student news organization allows its desire to spite its university and publicly shame those accused of sexual misconduct to drive its reporting agenda? Groundbreaking litigation, apparently.[8]

The Federal Educational Rights and Privacy Act of 1974[9] (“FERPA”) is a comprehensive statute protecting the privacy of student records.[10] With its broad protections, FERPA can be seen as a shield: protecting students from unwarranted invasions of privacy at all educational levels.[11] FERPA does, however, have some narrow exceptions.[12] The North Carolina Public Records Act[13] (“Public Records Act”), on the other hand, requires disclosure of a broadly defined class of public records and exceptions or exemptions are narrowly construed.[14]

On April 17, 2018, the North Carolina Court of Appeals issued a landmark decision in a lawsuit brought by DTH against UNC.[15] Reversing the superior court’s judgment in favor of UNC, the court of appeals’ decision compels UNC to disclose records identifying students found responsible by the University for virtually any violation of sexual misconduct policies over a nearly ten-year period. Thus, the court of appeals effectively endorsed DTH’s attempt to weaponize FERPA—a protective statute—through a misleading interpretation of a particular FERPA exception read in conjunction with the Public Records Act.

Part II discusses the history and background of FERPA, the Public Records Act, and Title IX of the Education Amendments of 1974 (“Title IX”). Part III discusses the case of DTH Media Corp. v. Folt[16] and the decision by the North Carolina Court of Appeals. Finally, Part IV argues the court of appeals was fundamentally incorrect in deciding for DTH. This Note concludes the North Carolina Supreme Court should properly determine that FERPA grants UNC discretion in determining whether to release the records in question, the Public Records Act is in conflict with that discretion, and FERPA preempts the Public Records Act to the extent it conflicts with the discretion given by FERPA. Further, this Note analyzes some of the public policy implications of the court of appeals decision to illustrate the need to reverse.

II. Background

FERPA and the Public Records Act form the basis of the legal question before the North Carolina Supreme Court in DTH Media Corp. v. Folt.[17] However, without recent interpretations of Title IX and subsequent changes to universities’ Title IX enforcement policies regarding peer-to-peer sexual misconduct,[18] the push to expose inadequacies in institutional responses to sexual misconduct may not have materialized. Thus, Title IX is indirectly at the heart of the litigation as well.

A. Student Disciplinary Records and FERPA

FERPA has two major purposes: to ensure access to student records for parents and students and “to protect [students’ and families’] right to privacy by limiting the transferability of their [educational] records without their consent.”[19] Educational records are “those records, files, documents, and other materials which contain information directly related to a student and are maintained by an educational agency or institution or by a person acting for such agency or institution.”[20] The statue provides only a handful of narrow exceptions.[21]

FERPA protects student privacy through an exercise of Congress’ spending power.[22] However, because FERPA’s statutory scheme and enforcement mechanisms do not confer a private right of action for violations,[23] the only avenue for enforcement is for aggrieved students to file a complaint with the Department of Education.[24] While the Department of Education has broad authority to withhold funding from institutions in violation of FERPA,[25] no school has ever lost funding.[26]

FERPA has been substantively amended several times.[27] In 1990, a section of the Student Right to Know, Crime Awareness, and Campus Security Act modified FERPA by inserting a provision which permits institutions of higher education to disclose the outcome of disciplinary proceedings to the victims of crimes of violence.[28] The Higher Education Amendments Act of 1998 amended FERPA further, creating an exception and giving institutions of higher education the authority to disclose to anyone the final result of a disciplinary proceeding conducted against a student who was alleged to have committed a crime of violence or nonforcible sex offense and has been determined to have violated the institutions rules pertaining to such offenses (hereinafter the “final result exception”).[29] The final result exception, while narrow and limited in scope, includes a broad list of crimes.[30]

The day after the House of Representatives voted in favor of the final result exception, Representative Thomas Foley, the amendment’s primary sponsor, made a statement on the floor of the House,[31] claiming the amendment was designed to provide balance “between one student’s right of privacy to another student’s right to know about a serious crime in his or her college community,”[32] and that it would make reporting on such records “subject to the State laws that apply.”[33] Representative Foley discussed the allegation that schools were using student disciplinary hearings to conceal crime issues on campuses.[34] He stated the amendment was important “[b]ecause . . . parents and community leaders and others deserve to know the statistical problems that are being experienced on our Nation’s campuses.”[35]

In the mid-1990’s, a years-long battle between news media and Miami University began over student disciplinary records.[36] After the Miami Student successfully convinced the Ohio Supreme Court that student disciplinary records were not student records protected by FERPA, The Chronicle of Higher Education sought the disclosure of disciplinary records, “fraught with personally identifiable information and virtually untainted by redaction.”[37] In 2002, the Sixth Circuit held student disciplinary records were protected under FERPA, in part because of the final result exception.[38] Because Ohio’s public records law did not apply to federally-protected records, disclosure was prohibited.[39] In its decision, the Sixth Circuit opined about the significant weight Congress has placed on student privacy rights through its creation of FERPA.[40]

B. North Carolina’s Public Records Law

Until 1935, North Carolina had no public records statute and relied on common law principles to govern citizen access to public records.[41] The statute enacted in 1935 contained significantly more access rights, but it was primarily enacted for historical preservation purposes and citizen access was an afterthought.[42]

In 1975, North Carolina passed a new public records law providing for much broader access to state and local government records.[43] The law as it is now is incredibly broad.[44] Any document created by a public agency constitutes a public record, with the main limitation being specific statutory exceptions.[45] While the General Assembly has provided broad protection to the educational records of elementary and secondary students,[46] no similar provision exempting records of students within the UNC system or the North Carolina Community College system exists.[47]

It is difficult to imagine that this lack of exception was anything other than deference to FERPA[48] or a mere oversight. As Ryan Fairchild explained, the wording of the Public Records Act is so breadth and liberal that application could conceivably require absurd disclosures.[49] Despite the potential for absurdity, the North Carolina Supreme Court has been clear that “whether [exceptions] should be made is a question for the legislature, not the Court.”[50]

The North Carolina Court of Appeals first addressed FERPA’s protection of student disciplinary records in the UNC system twenty years ago in DTH Publishing Corp. v. University of North Carolina.[51] There, it held that student disciplinary proceedings were validly held in closed session under the state open meetings law because the proceedings required divulging student records.[52] The court reasoned that “FERPA was adopted to address systematic . . . violations of students’ privacy and confidentiality rights through unauthorized releases of sensitive educational records,”[53] and FERPA’s conditional funding therefore rendered the records “privileged or confidential.”[54] The court held that the minutes of disciplinary proceedings were exempt from the Public Records Act because release would “frustrate the purpose” of a closed session.[55] While DTH Publishing dealt broadly with student disciplinary records,[56] the issue of records falling under the final result exception has not been addressed by North Carolina courts until now.

C. Title IX and Sexual Misconduct

Title IX declares: “No person in the United States shall, on the basis of sex, be excluded from participation in, be denied the benefits of, or be subjected to discrimination under any education program or activity receiving Federal financial assistance . . .”[57] On April 4, 2011, in response to a growing epidemic of sexual misconduct on college campuses,[58] Vice President Joe Biden and Secretary of Education Arne Duncan announced a “Dear Colleague” letter outlining the Department of Education’s interpretations of how peer-to-peer sexual misconduct relates to Title IX.[59] The significant policy pivots in the letter were not subject to notice and comment rulemaking procedures.[60]

In response, universities refined how they addressed peer-to-peer sexual misconduct.[61] Along with new policies came a substantial increase in disciplinary enforcement of sexual misconduct policies.[62] Since the release of the Dear Colleague Letter, complaints of noncompliance to the Office for Civil Rights have increased exponentially each year,[63] and to date, the Office has opened more than 500 investigations into universities’ handling of sexual misconduct allegations.[64]

Accompanying these changes has been a host of litigation against universities by students accused or disciplined in Title IX sexual misconduct proceedings.[65] Doe v. The Ohio State University,[66] claimed that The Ohio State University’s disciplinary procedures relating to Title IX sexual misconduct allegations would violate an accused student’s right to privacy.[67] The district court, noting that such a claim would not be ripe without disclosure, concluded the claim was without merit because all parties, the district court, and the Sixth Circuit Court of Appeals were in agreement that student disciplinary records produced in Title IX disciplinary proceedings were protected under FERPA.[68] The court noted that there was no concern about disclosure under the final result exception because the records in question did not constitute a final result of a disciplinary proceeding.[69]

Since the beginning of President Donald Trump’s term, the Department of Education has rolled back the clock on the interpretation of how Title IX applies to peer-to-peer sexual misconduct. In September 2017, the administration rescinded the Dear Colleague Letter and subsequent clarifying guidance,[70] issuing interim guidance that gives colleges and universities more flexibility in crafting peer-to-peer sexual misconduct policies and allows the use of the more stringent clear and convincing standard in disciplinary proceedings.[71] These changes were implemented in hopes of making the process more fair for all parties and with the intention that official rules would be promulgated in the future.[72]

In November 2018, the Department of Education proposed new rules.[73] The proposed rule features more protections for the accused and narrows the definition of actionable sexual misconduct.[74] Further, universities would have discretion in determining whether to investigate allegations of off-campus sexual misconduct.[75] While the exact impact these changes will have is unclear,[76] it is plain that Title IX will remain the driving force behind universities enforcing peer-to-peer sexual misconduct policies.

III. The Case: DTH Media Corp. v. Folt

On September 30, 2016, DTH sent a letter to UNC requesting “copies of all public records made or received by [UNC] in connection with a person having been found responsible for rape, sexual assault or any related or lesser included sexual misconduct.”[77] In a column days later, DTH Editor-in-Chief Jane Wester argued disclosure of names was necessary because she “badly want[ed] to know” how many people UNC has found responsible for sexual assault and what sanctions were being imposed.[78]

UNC denied the request, and DTH filed a declaratory judgment action on November 21, 2016.[79] Eventually, the Superior Court entered judgment in favor of UNC, concluding that FERPA grants universities discretion in determining whether to release records to the public under the final result exception and that this grant of discretion preempted required disclosure under the Public Records Act.[80] DTH appealed, and the North Carolina Court of Appeals issued its shocking decision on April 17, 2018.[81] The court reasoned that under proper canons of statutory interpretation, FERPA and the Public Records Act should be read to avoid conflict.[82] Reading the statutes in such a way, the court concluded the final result exception did not grant public universities absolute discretion in making disclosures.[83] The court determined that DTH was entitled to the records to the fullest extent they fell under the § 1232g(b)(6)(B) exception, fully granting the request except as to the date of the offenses.[84] Finally, the court explained its belief that FERPA did not preempt the Public Records Act in this case.[85]

IV. FERPA Preempts the Public Records Act

The North Carolina Supreme Court should first determine that the final result exception is a grant of discretionary power to universities to disclose particular records. Next, it should determine that the Public Records Act does not yield to the final result exception because the exception does not serve as an express statutory exemption which prohibits disclosure of the records in question. Finally, the court should conclude that FERPA and the Public Records Act conflict, and FERPA’s grant of discretion preempts the Public Records Act through implicit conflict preemption.

The court of appeals’ interpretation of the final result exception is based on the exception’s plain language.[86] However, the reasoning suggests the court’s interpretation of FERPA’s text relies on the conclusion that FERPA is in pari materia with the Public Records Act, and that they must be read in context with one another.[87] Statutes are considered in pari materia when they share a common aim or purpose or when they speak on the same subject.[88] When the text of a statute under consideration is clear, though, statutes in pari materia should not control construction.[89]

Even assuming, arguendo, the court of appeals read the statutes in pari materia to resolve ambiguity, such a reading would be improper because FERPA and the Public Records Act cannot reasonably be considered in pari materia. FERPA is a shield providing comprehensive protections to students by preventing disclosure of student records.[90] The Public Records Act, on the other hand, is a sword, broadly requiring disclosure of a vast array of records.[91] No matter how the subjects, purposes, and aims of the statutes are framed they will never be in pari materia.[92] Since much of the court’s analysis of the final result exception rests upon the faulty notion that it must be read in context with the Public Records Act,[93] it is a fair assumption that the mistake substantially and fatally flawed the court’s entire analysis.

A. The Meaning of the Section 1232g(b)(6)(B) Exception

1. The Plain Text

North Carolina courts have long followed the plain language rule in statutory interpretation: “If the language of the statute is clear and is not ambiguous, we must conclude that the legislature intended the statute to be implemented according to the plain meaning of its terms.”[94]

While the court of appeals concluded that nothing in the text of the final result exception[95] “required” UNC to exercise discretion in determining whether to disclose results within the final result exception,[96] a plain reading of the statute indicates the final result exception grants universities the discretion to determine whether to make such disclosures.

The language “[n]othing in this section shall be construed to prohibit . . .” indicates that the conduct is allowed, but not required.[97] The exception creates a discretionary decision: the university may choose whether to engage in the excepted conduct.[98] Thus, a university clearly has a discretionary choice of whether to disclose the final result of certain disciplinary proceedings.[99]

The court of appeals ignores this common-sense reading, arguing the only hint of discretion within the final result exception is the limiting condition that the exception applies only when “the institution determines as a result of that disciplinary proceeding that the student committed a violation of the institution’s rules or policies with respect to such crime or offense.”[100] Further, the court of appeals insists that FERPA’s judicial order exception demonstrates that the FERPA exception does not grant institutions discretion in determining whether to release records.[101]

The court’s logic misses the mark, ignoring that the judicial order exception is an independent exception.[102] “Just as Congress’ choice of words is presumed to be deliberate, so too are its structural choices.”[103] In 1998, Congress chose to amend FERPA to add the final result exception.[104] The court should have presumed Congress was deliberate in its structural placement and wording of the final result exception, rather than focus on such a circular argument.[105]

2. Legislative Intent Demonstrates That Discretion is Appropriate

Although the meaning of the final result exception is plain on its face, even if the language is ambiguous, FERPA evinces a legislative intent to leave the decision to disclose records under the exception within the discretion of universities. Our supreme court notes that “legislative intent controls the meaning of a statute” and directs that to determine intent, “a court must consider the act as a whole, weighing the language of the statute, its spirit, and that which the statute seeks to accomplish.”[106]

Because we must presume that Congress was deliberate in its wording of the final result exception,[107] it is telling that Congress crafted a permissive exception.[108] Under the court of appeals’ decision and the language of the Public Records Act, virtually any request for disclosure coming within the final result exception would become mandatory for the sixteen constituent universities within the UNC system. For public universities in North Carolina, the final result exception would become a required disclosure. Where Congress did not choose to require disclosure of these records, such a requirement for disclosure is surely inconsistent with the intent of the law.

Requiring disclosures in such a way is grossly inconsistent with the spirit and goals of FERPA. The court of appeals places great emphasis on the statement Representative Foley made the day after the provision was approved by the House of Representatives.[109] In regards to this type of misguided reliance, Justice Scalia said it best: “Arguments based on subsequent legislative history, like arguments based on antecedent futurity, should not be taken seriously, not even in a footnote.”[110] Considering, for the sake of discussion, that Representative Foley’s statement has even a scintilla of importance in determining the intent of Congress, the statement clearly demonstrates that the intent of the amendment was to balance the interest “between one student’s right of privacy to another student’s right to know about a serious crime in his or her college community.”[111] Balance requires the measurement and offsetting of competing interests to achieve the most desirable result,[112] and universities would be in the best position to balance the interests of the community against the privacy interest of the students.[113] It is preposterous to conclude that Congress expected that the law these records would be subject to would require blind disclosure without any balancing of interests.

B. The Public Records Act Does Not Yield to the Discretion Granted by the Final Results Exception

Because the conflicting law exemption found in section 132-1(b) of the Public Records Act is construed so narrowly,[114] our supreme court should not determine that the Public Records Act yields to FERPA. Construing this provision narrowly, the court should note that while FERPA itself would specifically provide a broad exemption for student records under the Public Records Act,[115] the final result exception removes certain records from that category. Thus, the final result exception does not “otherwise provide” that records within the exception may not be disclosed. Instead, because the final result exception permits disclosure the records, they are therefore subject to section 132-1(b)’s disclosure requirements unless preempted by FERPA.

C. FERPA’s Grant of Discretion to Colleges and Universities Preempts the Public Records Act

The supreme court should determine that the Public Records Act is in conflict with the final result exception of FERPA, and therefore FERPA implicitly preempts the Public Records Act to the extent it requires disclosure of records within the final result exception.[116] The court of appeals relies on the notion that it should presume both that the Public Records Act does not conflict with FERPA[117] and that federal preemption does not apply.[118] While it would be logical to presume that two statutes enacted by the same sovereign are not meant to contradict one another, there is little sense in assuming that two unrelated legislatures would avoid conflict to any extent.[119]

Federal preemption may be either express or implied.[120] Courts have taken two avenues of analysis of implicit conflict preemption: “obstacle” preemption occurs when a state statute “stands as an obstacle to the accomplishment and execution of the full purposes and objectives of Congress,”[121] while “impossibility” preemption occurs when compliance with both state and federal law is a “physical impossibility.”[122]

It has been argued that the federal judiciary has grossly misapplied implicit conflict preemption through a broad reading of purposes and objectives preemption.[123] Since at least 2000, Supreme Court justices have warned of such an overwhelming expansion.[124] Advocates for change often argue in favor of a much stronger presumption against preemption and/or an increased reliance on the nuanced and cumbersome “physical impossibility” analysis.[125] In response to the seemingly artificial requirement of choosing between ridiculously broad or the uncompromisingly narrow analyses, analysis of implicit preemption should simply be “an inquiry into whether the ordinary meanings of state and federal law conflict.”[126]

Such a plain text approach to implicit preemption analysis requires a full understanding of the purposes underlying the Supremacy Clause.[127] The Supremacy Clause contains a rule of applicability requiring application of federal law in state courts with equal force as state law[128] and a rule of priority requiring application of federal law over state law when conflict exists.[129] These two rules, without further historical understanding, leave the final phrase of the Supremacy Clause –“anything in the Constitution or laws of any State to the contrary notwithstanding”[130]– seemingly redundant.[131]

Understood in the context of the ratification debates, however, this phrase was critically necessary to the success of the Supremacy Clause.[132] At the time of ratification, there was a judicial presumption against reading statutes in a manner which resulted in conflict, which would result implied repeal.[133]

In response to the presumption against implied repeals, legislatures sometimes include a non obstante provision to indicate to courts that new legislation may indeed contradict other statutes and that possible conflict should not skew the meaning of the statute.[134] The language of such clauses often dictated that the statute would apply “any law to the contrary notwithstanding,” or similar wording to the same effect.[135] Instead of leaving the Supremacy Clause’s rule of priority open to the interpretation of state courts, which might still apply the presumption and stretch the meaning of a federal statute to avoid conflict and implied repeal, the drafters of the Constitution included the phrase “anything in the Constitution or laws of any State to the contrary notwithstanding” as the final phrase of the Supremacy Clause as a universal non obstante clause, applying to all federal laws, and specifically contemplating potential conflict with state law and cautioning interpreting courts not to stretch their interpretation of federal statutes.[136] A plain text approach to implicit preemption, free from judicial policymaking, gives meaning to the framer’s express words and their intent that courts should strain to find harmony between apparently conflicting state and federal statutes.[137]

In 2011, the Supreme Court came its closest to implementing a plain text approach, guided by the Supremacy Clause’s non obstante provision, to implicit preemption. In PLIVA, Inc. v. Mensing,[138] Justice Thomas delivered the opinion of the court.[139] Although the critical implied preemption analysis was only a plurality portion of the opinion, the time may soon arrive that our nation’s courts finally do away with difficult and nuanced tests for conflict preemption.[140]

Though PLIVA specifically discusses judicial speculation about actions which could reconcile federal and state law under an impossibility preemption analysis,[141] it stands for a broader textualist approach to conflict preemption: “The non obstante provision of the Supremacy Clause indicates that a court need look no further than the ordinary meaning of federal law, and should not distort federal law to accommodate conflicting state law.”[142]

Taking a textual approach to implicit conflict preemption simply requires determining whether the text of the state law conflicts with the text of the federal law.[143] Focusing on the text of statutes would simplify the analysis by removing the need to classify the conflict in terms of obstacle or impossibility. A clear rule based in a textual analysis will remove the need to speculate and stretch meaning, producing more consistent results and comporting more fully with the non obstante provision of the Supremacy Clause.

It is clear that the Public Records Act conflicts with FERPA to the extent that it would require blind disclosure of all records falling within the final result exception. The ordinary language of the exception clearly reveals Congress’ intent to grant universities discretion in disclosing these records.[144] Because the Public Records Act would require UNC to blindly disclose the records, it interferes with UNC’s ability to exercise the discretion the final result exception grants.

D. Policy Implications

North Carolina courts generally defer questions of public policy to the General Assembly.[145] Though the North Carolina Supreme Court need not give much weight to considerations of policy implications, it is important to consider some potential implications of affirming the court of appeals.

The most troubling policy consideration is that the release of records identifying students as responsible for “rape, sexual assault or any related or lesser included sexual misconduct” could create constitutional privacy issues. Doe v. The Ohio State University left open the possibility that if Title IX investigation records were not protected, an accused may have a cognizable substantive due process claim under the United States Constitution.[146] Named students certainly would have a legitimate concern: the Southern District of Ohio framed it as “the interest in avoiding disclosure of highly personal matters.”[147] State run universities would be required to disclose their conclusions, often based on “investigations” with low evidentiary standards and limited due process rights, that individuals committed crimes.

Furthermore, what about the negative effects that required blind disclosure would have upon the goals Title IX’s peer-to-peer sexual misconduct policy enforcement? Confidentiality in the process is at the crux of Title IX and a major reason why victims often prefer reporting to their university rather than the police.[148]

Finally, there are instances where false accusations occur.[149] In a system where for at least the majority of the last ten years the federal government has required adjudication of these allegations by universities using the low standard of preponderance of the evidence,[150] are we ready to risk upending lives by labeling people as predators[151] and rolling back progress made for victims?[152] The Duke Lacrosse and Rolling Stone cases show that such risks should be considered.

These few concerns beg the question: with so much at stake, and a grant of discretion so clear, is there a need to weaponize the final result exception in conjunction with the Public Records Act?

V. Conclusion

In the end, what would truly serve the interests of progress and student welfare would be a release of detailed, non-personally identifiable information about sexual misconduct on campus. Indeed, Wester has gone on the record several times describing the needs allegedly at the heart of DTH’s request.[153] These needs do not require naming names. Even Representative Foley, who sponsored the final result exception, noted the importance of using statistics to inform the community.[154]

It is frustrating that no exception to the Public Records Act is on the books for student records in the University of North Carolina system.[155] The General Assembly could have created such a provision and still could moot this litigation by fixing it now. Perhaps Congress, too, should reconsider the need for the final result exception.

For now, the question is before the North Carolina Supreme Court. With a proper textual approach to statutory construction, our supreme court should conclude that the final result exception does give discretion to universities, and therefore the Public Records Act’s requirement to disclose is in conflict with FERPA. Without acrobatic harmonizing, the supreme court should find that FERPA preempts the Public Records Act to the extent this conflict exists, and reverse the court of appeals.

* J.D. Candidate 2020, Wake Forest University School of Law.

By Dan Menken

Today, in the civil case of Covey v. Assessor of Ohio County, a published opinion, the Fourth Circuit reversed the district court’s dismissal of Christopher and Lela Covey’s suit against government officials for entering the curtilage of their house without a search warrant.

Question of Fourth Amendment Protection From Unreasonable Government Intrusion

The Court was asked to decide whether government officials violated the Coveys’ Fourth Amendment right to protection from unreasonable government intrusion when the government officials entered the curtilage of the Covey’s home in search of marijuana without a warrant.

Government Tax Assessor Relayed Information to Police Regarding Marijuana Plants

On October 21, 2009, a field deputy for the tax assessor of Ohio County, West Virginia, entered the Covey’s property to collect data to assess the value of the property for tax purposes. The tax assessor entered the Covey’s property despite seeing “No Trespassing” signs, which is against West Virginia law. When searching the property, the tax assessor found marijuana in the Covey’s walk-out basement patio. The tax assessor then contacted the police.

When the police arrived, they entered the curtilage of the Covey’s residence and proceeded to the area where the marijuana was located. As they were searching the property they encountered Mr. Covey. The officers detained Mr. Covey and continued their search. The officers then waited several hours to obtain a warrant to search the house. During that time, Mrs. Covey returned home and was warned that she would be arrested if she entered the house, after which she left the premises. Upon returning an hour later, Mrs. Covey was seized and interrogated. After the police received the search warrant, the Coveys were arrested and jailed overnight.

On March 30, 2010, Mr. Covey pleaded guilty in state court to manufacturing marijuana in exchange for the government’s promise that they would not initiate prosecution against Mrs. Covey. He was sentenced to home confinement for a period of not less than one year and not more than five years. On October 20, 2011, the Coveys brought this suit pro se. The claims, brought under 42 U.S.C. § 1983 and Bivens, alleged that several defendants violated the Coveys’ Fourth Amendment rights by conducting an unreasonable search. The district court dismissed the Coveys’ claim concluding that none of the defendants violated the Fourth Amendment. This appeal followed.

Fourth Amendment Protects Curtilage of Home

The Court reviewed the district court’s grant of a motion to dismiss de novo. To prevail on a motion to dismiss, a plaintiff must “state a claim to relief that is plausible on its face.” Ashcroft v. Iqbal. A claim is plausible if “the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id.

According to Oliver v. United States (1984), the Fourth Amendment protects homes and the “land immediately surrounding and associated” with homes, known as curtilage, from unreasonable government intrusions. Probable cause is the appropriate standard for searches of the curtilage and warrantless searches of curtilage is unreasonable.   The knock-and-talk exception to the Fourth Amendment’s warrant requirement allows an officer, without a warrant, to approach a home and knock on the door, just as any ordinary citizen could do. An officer may bypass the front door when circumstances reasonably indicate the officer might find the homeowner elsewhere on the property. The right to knock and talk does not entail a right to conduct a general investigation on a home’s curtilage.

The Complaint Presented Plausible Claims For Violations of the Fourth Amendment

Properly construed in the Coveys’ favor, the complaint alleges that the officers saw Mr. Covey only after they entered the curtilage. Thus, applying the Rule 12(b)(6) standard, the Court found that the Coveys plausibly alleged that the officers violated their Fourth Amendment rights by entering and searching the curtilage of their home without warrant. The district court erred by accepting the officers account of events, in which they stated that they saw Mr. Covey prior to entering the curtilage.

Turning to the tax assessor, the Court believed that his entering of the property, although illegal, was not a per se violation of the Fourth Amendment. In this case, the Court believed that the governmental interest in the search for tax purposes was minimal, while the Covey’s privacy interest is significant. Therefore, the Fourth Circuit held that the Coveys pleaded a plausible claim that the tax assessor conducted an unreasonable search of their home and curtilage.

Defendants’ Affirmative Defenses

According to Ashcroft v. al-Kidd (2011) qualified immunity “shields federal and state officials form money damages unless a plaintiff pleads facts showing (1) that the official violated a statutory or constitutional right, and (2) that the right was ‘clearly established’ at the time of the challenged conduct. As to the police officers, the Court stated that they should be aware that a warrantless search of the home, absent consent or exigency, is presumptively unconstitutional. Additionally, the Court noted that Fourth Circuit has, for over a decade, recognized that the curtilage of the home is entitled to Fourth Amendment protection. The Court felt that the tax assessor presented a closer case. Because there was no case law that spoke to a similar set of facts, and the tax assessor should have been aware that he was violating a Constitutional right by searching the property, the Court ruled that the tax assessor was not entitled to qualified immunity.

Finally, the defendants claimed that the Coveys’ § 1983 and Bivens claims are barred by Heck v. Humphrey (1994). There are two requirements for Heck to bar the Coveys’ claims. First, “a judgment in favor of the plaintiff [must] necessarily imply the invalidity of [a plaintiff’s] conviction or sentence.” Second, the claim must be brought by a claimant who is either (i) currently in custody or (ii) no longer in custody because the sentence has been served, but nevertheless could have practicably sought habeas relief while in custody. The court concluded that Mr. Covey’s claims did not necessarily imply the invalidity of his conviction and thus are not necessarily barred by Heck. The Court remanded the district court for further analysis under Heck.

Reversed and Remanded

Thus, the Fourth Circuit reversed the district court’s grant of dismissal and remanded the case for further proceedings.

By Michael Mitchell

Today, in Lynn v. Monarch Recovery Management, Inc., the Fourth Circuit affirmed the summary judgment granted to Kevin Lynn for Monarch Recovery Management’s violation of the Telephone Consumer Protection Act (“TCPA”).   On appeal, the Court rejected Monarch’s argument that it was exempt from the TCPA as a debt collector.

Under 47 U.S.C. § 227, the TCPA prohibits “making any call . . . [using] an artificial or prerecorded voice . . . to any telephone number assigned to a . . . cellular telephone service . . . or any service for which the called party is charged for the call.”   The United States District Court for the District of Maryland, at Baltimore, found that Monarch’s calls to Lynn violated the TCPA because Lynn was individually charged for each call.  Monarch made these calls to Lynn in its capacity as a debt collection company.

Affirming the district court’s grant of summary judgment to Lynn in an unpublished per curiam decision, the Fourth Circuit rejected Monarch’s attempt to avoid liability under the call-charged provision of the TCPA.  Specifically, Monarch argued that the FCC’s regulation excepted debt collectors from the TCPA’s prohibition on “call[s] to any residential telephone line using an artificial or prerecorded voice to deliver a message.”

The Court relied on its review of legislative intent in denying Monarch’s assertion that it was exempt from the call-charged provision of the TCPA.  Citing Clodfelter v. Republic of Sudan, 720 F.3d 199, the Court held that Congress did not intend for companies like Monarch to use the TCPA to limit their liability.  Thus, the Fourth Circuit has maintained civil liability for debt collectors under the call-charged provision of the TCPA.

By Joshua P. Bussen

Today in United States v. Mitchell, the Fourth Circuit, in a per curiam opinion affirmed the conviction of Sidney Mitchell for unlawful possession of a firearm by a felon. Mitchell entered a conditional plea of guilty in the Middle District of North Carolina, reserving his right to appeal the judgment of the district court. Mitchell contends that the district court erred in denying his motion to suppress evidence of a firearm that was found while police were conducting a search of his vehicle. Mitchell was sentenced to twenty-six months in prison.

In the waning hours of sunlight on November 20, 2012, a North Carolina police officer stopped Mitchell’s car on a suspicion that the tint on the vehicle’s windows was darker than allowed under North Carolina law. While performing a test that would gauge the level of tint on Mitchell’s windows—a process that involves placing a device on the inside of the vehicle—the officer claims he noticed the smell of “burnt marijuana.” Though Mitchell denied smoking marijuana, he consented to a search of his person. After searching Mitchell the officer turned to the vehicle, discovering a small amount of marijuana resin and a gun on the driver’s side floorboard.

In the Middle District of North Carolina Mitchell moved to suppress the firearm due to an improper search and seizure. The district court found that the tint on Mitchell’s windows gave the officer reasonable cause to pull the car over, and the smell of burnt marijuana subsequently warranted probable cause to search the vehicle. On appeal Mitchell did not question the officer’s motivation for detaining the vehicle, but disputed “lawfulness of the subsequent search of the [inside of the] car.”

The Fourth Circuit, relying on United States v. Scheetz, 293 F.3d 175, 184 (4th Cir. 2002), held that the odor of marijuana emanating from a car warranted sufficient probable cause to search the vehicle. Mitchell’s final argument that the officer’s credibility should be questioned fell on deaf ears, the Circuit judges were not willing to disturb the factual findings of the district court because “the district court is so much better situated to evaluate these matters.”

By Steven I. Friedland

“The world isn’t run by weapons anymore, or energy, or money.  It’s run by little ones and zeroes, little bits of data.  It’s all just electrons.”[1]

We live in an era of mass surveillance. Advertisers, corporations and the government engage in widespread data collection and analysis, using such avenues as cell phone location information, the Internet, camera observations, and drones.  As technology and analytics advance, mass surveillance opportunities continue to grow.[2]

The growing surveillance society is not necessarily harmful[3] or unconstitutional.  The United States must track people and gather data to defend against enemies and malevolent actors.  Defenses range from stopping attempts to breach government computers and software programs,[4] to identifying and thwarting potential terroristic conduct and threats at an embryonic stage.

Yet, without lines drawn to limit mass data gathering, especially in secret, unchecked government snooping likely will continue to expand.  John Kerry, the sitting Secretary of State, even recently acknowledged that the government has “sometimes reached too far” with its surveillance.[5] The stakes for drawing lines demarcating privacy rights and the government’s security efforts have never been higher or more uncertain.

This Article argues that the forgotten Third Amendment, long in desuetude, should be considered to harmonize and intersect with the Fourth Amendment to potentially limit at least some mass government surveillance.  While the Fourth Amendment has been the sole source of search and seizure limitations, the Third Amendment should be added to the privacy calculus,[6] because it provides a clear allocation of power between military and civil authorities and creates a realm of privacy governed by civil law.

Consequently, in today’s digital world it would be improper to read the words of the Third Amendment literally, merely as surplusage. Instead, the Amendment’s check on government tyranny should be viewed as restricting cybersoldiers from focusing surveillance instrumentalities[7] on and around private residences or businesses in an intrusive way—or using proxies to do so—that would serve as the functional equivalent of military quartering in the civil community.

I.  Mass Surveillance

Imagine an America with continual domestic drones, which collected camera and cell phone surveillance of every person in a particular residential subdivision, business headquarters, or city high-rise building.  The surveillance would be mostly secret but “in public,” capturing people sitting on rocking chairs on their front porches, unloading bags of groceries from their cars, opening their wallets to pay bills, and anything visible through windows in private residences and businesses.  People who go to sporting events or the supermarket would have their faces matched to an existing database. The metadata from Internet use, cell phone location data and other sources, including hyper-local observations, would be fed into computers for complex analysis and combined with other surveillance information.[8]  This information, all gathered and utilized outside the private space protected by the physical walls and doors of houses, would present a fairly intimate picture of these individuals over time, creating in essence a virtual window to what is occurring within the house or building, as well as without.[9]

Such a day is not far off. Drones and robots are currently being employed domestically in the skies,[10] on land, and in the seas[11] for various purposes, although apparently not yet on a continual and widespread basis. Yet, expansion of their use seems inevitable.[12] While most unmanned aircraft systems fly high overhead, out of sight, as more information is released and people look more carefully, we will know they are there. The government also is developing the Biometric Optical Surveillance System (“BOSS”), which will have tremendous capabilities for identifying people from distances of up to 100 meters.  This system was scheduled for testing at a public hockey game in the State of Washington in 2013.[13]  To supplement the information acquired directly, the government obtains considerable amounts of information through the consent of third parties.[14]

While surveillance is not overly intrusive when deployed in public places, where being watched can be expected, it still can be dangerous.[15] Surveillance, when taken as a whole with information and data gathering, can form a mosaic of intrusion in a manner similar to that described by Justices Alito and Sotomayor in their concurrences in the GPS tracking device case United States v. Jones.[16]  Pursuant to this “mosaic theory,” a privacy violation does not require a physical trespass.  One commentator noted the following,

Today’s police have to follow hunches, cultivate informants, subpoena ATM camera footage. . . . Tomorrow’s police . . . might sit in an office or vehicle as their metal agents methodically search for interesting behavior to record and relay. Americans can visualize and experience this activity as a physical violation of their privacy.[17]

Significantly, surveillance also is an expression of power—an accumulation of data that can be used against persons, even creating that intimate picture of what occurs inside a house when the cybersleuth never actually sets foot in it. As another commentator has observed about possible power abuses, “We cannot have a system, or even the appearance of a system, where surveillance is secret, or where decisions are made about individuals by a Kafkaesque system of opaque and unreviewable decision makers.” [18]

II.  The Third Amendment’s Place In Constitutional Orthodoxy

“[N]o Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law.”[19]

A.     Origins and Interpretations

The Third Amendment might have an obscure[20] and obsolete[21] place in constitutional law orthodoxy, yet it draws on a rich history. The bright-line Amendment[22] traces its origins to pre-revolutionary war England, where multiple abuses by the king in quartering soldiers, the Royal entourage and their horses in private residences led to laws prohibiting quartering in England.[23]These laws were enacted in part to avoid maintaining a standing army, especially during peacetime.[24]  For example, in 1689,the British Parliament enacted the Mutiny Act, which outlawed the quartering of troops in private homes without the owner’s consent.[25] A standing army was thought to provide a slippery slope to tyranny, and it was the confluence of military with civil authority that was the real problem, not simply the taking of private resources by the King.

Continued quartering abuses in the colonies led to the adoption of the Third Amendment. Patrick Henry argued for the amendment because it offered rule by civil authority, not military force, [26] as did Samuel Adams, who objected to soldiers quartered “in the body of a city” and not just houses.[27]

Perhaps the amendment’s desuetude is attributable in part to the fact that it has only been the subject of Supreme Court cases in passing, such as in Griswold v. Connecticut,[28] and just one significant direct judicial interpretation, Engblom v. Carey,[29] a 1981 Second Circuit Court of Appeals case. In Engblom, the court was confronted with a claim by two correctional officers who claimed their Third Amendment rights were infringed by the State of New York when the state quartered national guardsmen in their dormitory-style residences during a prison strike by the guards in an upstate New York prison.[30]  The guards were renting their rooms from the State.[31]

The court first applied the Third Amendment to the State of New York through the incorporation doctrine of the Fourteenth Amendment.[32]  Significantly, the court viewed several of the key terms in the amendment expansively. The court considered the national guardsmen to be “soldiers” and held that the Third Amendment applied to the guardsmen as “tenants,” even if they did not own their quarters, despite the express language in the amendment.[33]

B.     The Relationship Between the Third and Fourth Amendments

The Second Circuit in Engblom also used an analysis borrowed from the Fourth Amendment, setting forth a standard of a “legitimate expectation of privacy” to determine if Third Amendment rights were triggered.[34] It noted that the amendment’s objective was to protect the fundamental right to privacy in conjunction with the use and enjoyment of property rights.[35]

The Engblom analysis at least implicitly recognized the interlocking nature of the Third and Fourth Amendments and the primary role of the Fourth Amendment as the privacy standard bearer. As one noted commentator observed, “If the Fourth Amendment had never been enacted, the Third Amendment might have provided the raw material for generating something like an anti-search and seizure principle.”[36]

Constitutionally, courts have used the Fourth Amendment to protect against government snooping on others, but the Fourth Amendment has been strapped with textual limits, given its language protecting only against unreasonable, not all, searches and seizures, and interpretive limits authored by a reticent Supreme Court that has stuck by rules created in predigital cases.[37] Also, while the Fourth Amendment protects against United States government spying, it does not apply to such conduct by foreign governments, which can and do swap data with the United States,[38] or apparent swaps of data with thousands of technology, finance, and manufacturing companies.[39]

Preoccupation with the Fourth Amendment doctrine, combined with a Gresham’s Law style of constitutional application suggesting that general principles often end up marginalizing specific provisions, help explain the Third Amendment’s disuse.  A contextual interpretation of this amendment in the digital era could offer a significant link in a system of digital checks and balances.

III.  Interpretation

The Third Amendment’s relevancy to surveillance privacy depends on its interpretation,[40] both in terms of its themes and words. The amendment’s broad themes resonate in the world of “Big Data” and the Internet. The amendment provides a bright line allocation of power, with a clear distinction that limits the military and protects homes from intrusion without consent.  As evidenced by Due Process, Equal Protection, and other constitutional doctrines such as the Eighth Amendment, the Court often takes into account evolving facts and cultural transformations over time.  A more specific analysis of each component of the Amendment follows.

A.     War and Peace

The wartime/peacetime distinction in the amendment provides a useful contrast about the expansiveness of government power at different times. When compared to the Fourth Amendment, the framers of the Third Amendment provided a clear line of what is reasonable in times of war or peace.

B.     Soldiers

History is instructive. Early English case law reflects the concern over forced accommodations and board not only by soldiers, but also by the royal court and its entourage.[41] The prohibition extended to the soldiers’ instrumentalities, namely their horses.[42]  In the late 1700s, soldiers honorably fought in uniform generally within full view of the enemy. Times have changed. InEngblom, national guardsmen were considered soldiers, even though they were defending a domestic prison.  Today, the definition would certainly include cyber agents, military personnel who are paid to hack and disrupt another country’s software and hardware and to protect our own. Instead of horses, these cyber soldiers use codes or metal instrumentalities to invade others’ cyber spaces.[43] Using stealth and remote access to obtain and crunch data is the new face of warfare; these soldiers disrupt and disable various aspects of a country to keep it off balance and vulnerable. For example, deployment of the Stuxnet worm, placed on computers in Iran to disrupt its quest for nuclear weapons, is but one illustration of the new military.

C.         Quartering

Quartering historically came to mean an “act of a government in billeting or assigning soldiers to private houses, without the consent of the owners of such houses, and requiring such owners to supply them with board or lodging or both.”[44] Billeting can mean a letter ordering the assignment or the assignment itself.         This definition yields some insights.  Significantly, it is a military intrusion into home life—civilian life—by soldiers, which is why early English analysis incorporated the forced provision of board and the tethering of horses as part of quartering. Thus, it is the intrusion and diminishment of civil authority and life that matter, even if it is through remote access rather than the physical presence of the soldiers. An unmanned drone is the equivalent of a piloted plane. Would military personnel stationed regularly at businesses, or operating cameras on the rooftops of private residences or businesses, or even on all public mailboxes generate intimidation or intrusion into daily life? Would the intrusions still be significant if the soldiers were outside of the houses and businesses, in the curtilages, peering inside or the equivalent? Especially if seen or heard, electronic surveillance devices could significantly interfere with civilian community life and intrude on civilian authority. As one commentator has noted, “[G]overnment or industry surveillance of the populace with drones would be visible and highly salient. People would feel observed, regardless of how or whether the information was actually used.”[45]

Quartering today also can involve proxies, where the U.S. government knows and promotes the equivalent of private or foreign quartering for its own gain.  One illustration of proxy quartering might involve an agreement between countries to swap sensitive data on each other’s citizens, revealing the intricacies of civil life inside the cities and their residences or businesses.[46]

D.    Any Houses

The term “any houses” on its face appears highly restrictive.[47] Yet, at least in Engblom, it also means tenancies. While tenancies refers to residences, today there are a proliferation of buildings housing businesses, which fall within the types of civil occupancies where sensitive and confidential civil life occurs.  Invasions of these buildings without physical entry can occur regularly in the digital world, which is how the term should be judged and is in keeping with the intent of the framers.

While the term “any houses” could be more broadly construed to mean all private chattel or real property, including electronic devices,[48] this likely would expand the meaning of the amendment to become a version of the Fifth Amendment Takings Clause, not likely intended for the Third Amendment’s “houses” distinction, particularly when the Fourth Amendment protects not only houses, but also “persons, places, and effects.”

E.     Without Consent

Although the amendment permits quartering in peacetime with consent, if quartering extends to businesses, the government-private business partnerships create questions about the voluntariness of the relationships.  This is especially the case if the government inserts employees into the private business locations.  This type of relationship might not generate adequate voluntary consent.[49]


The Third Amendment no longer will be the forgotten amendment if it is considered to interlock with the Fourth Amendment to provide a check on some domestic mass surveillance intruding on civil life, particularly within the home, business or curtilage of each.  In the digital era, the dual purposes of the Amendment should be understood to potentially limit the reach of cyber soldiers and protect the enjoyment of a private tenancy without governmental incursion.

By Beverly Cohen*


On June 23, 2011, the United States Supreme Court, in Sorrell v. IMS Health Inc.,[1] determined that Vermont’s law prohibiting pharmacies from selling prescription data to “data-mining companies” violated the Free Speech Clause of the First Amendment.[2]  Data miners purchased the prescription data to aggregate and resell it to pharmacy manufacturers for marketing purposes.[3]  Drug manufacturers used the information to target physicians for face-to-face visits (“detailing”) by salesmen to convince the physicians to prescribe more of the manufacturers’ costly brand-name drugs.[4]  The prescription information purchased from the data miners enabled the manufacturers to target particular physicians who were not prescribing their brand-name drugs or who were prescribing competing drugs.[5]

Several states objected to drug manufacturers’ use of prescription information for detailing, contending that it increased sales of brand-name drugs and drove up healthcare costs.[6]  When these states passed laws preventing the pharmacies’ sale of the prescription information to data-mining companies and the use of this information by drug manufacturers,[7]the data miners and drug manufacturers sued.[8]

When the challenge to Vermont’s data-mining law reached the Supreme Court, the Court invalidated it on the grounds that it violated the Free Speech Clause.[9]  The Court held that the law did not survive strict scrutiny.  It prohibited the use of prescription information with a particular content (prescriber histories) by particular speakers (data miners and detailers)[10] and did not advance Vermont’s asserted goals of ensuring physician privacy, improving the public health, and containing healthcare costs in a permissible way.[11]

The Federal Privacy Rule,[12] implementing the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”),[13] is similar to the data-mining laws in its restrictions on the disclosure of private health information.[14]  This Article applies the HIPAA Privacy Rule to the practice of data mining and, surprisingly, finds that HIPAA restricts it.[15]  The Privacy Rule flatly prohibits any unauthorized use or disclosure of protected health information for marketing purposes.[16]  Nevertheless, the practice of data mining continues despite HIPAA.  In fact, at least one court has recently declared that nothing in HIPAA restricts data mining.[17]

The question post-Sorrell is whether the marketing provisions of the Privacy Rule, like Vermont’s data-mining law, also violate freedom of speech.[18]  Although there are obvious similarities between HIPAA’s marketing provisions and the marketing restrictions of Vermont’s data-mining law, there are also substantial differences.[19]  The structure of the Privacy Rule is quite unlike the data-mining law in that the discriminatory intent and impact that the Supreme Court found objectionable in Sorrell is largely absent in HIPAA.[20]  Unlike Vermont’s data-mining law, the Privacy Rule does not target disclosures with particular content or by particular speakers.[21]  Therefore, this Article concludes that it is likely that application of the Sorrell analysis to the Privacy Rule would yield a different answer.[22]

This Article explains the practices of data mining and detailing[23] and describes the state laws that sprang up to prohibit them.[24]  It next discusses the various judicial outcomes of the data miners’ challenges to those laws,[25] culminating in the Supreme Court’s invalidation of Vermont’s data-mining law in Sorrell.[26]  The Article then applies the HIPAA Privacy Rule to the Sorrell facts and finds that the marketing provisions of HIPAA disallow the unauthorized use of such information for sale to data miners.[27]  Finally, the Article compares the HIPAA Privacy Rule to the data-mining law invalidated in Sorrell and finds that their structures considerably differ.[28]  Based on these differences, the Article opines that HIPAA presents a substantially different question from that considered in Sorrell and likely yields a different answer.[29]

I.  The Targeted Practices: Data Mining and Detailing[30]

Every time a pharmaceutical prescription is filled, the pharmacy retains information describing the transaction.[31]  These records generally include the identification of the patient; identification of the prescribing physician, including his name, address, and phone number; the drug prescribed, its dosage, and its refill information; price; and insurance information.[32]  In many cases, state law requires this information to be collected and maintained by the pharmacies[33] so that the state can monitor cases of illicit prescriptions and fraudulent prescribing practices by physicians.[34]

Companies, such as IMS Health Inc. and Verispan, LLC,[35] are in the business of “mining” this pharmacy data.[36]  They purchase prescription data from the pharmacies that the pharmacies’ computer software has collected and encrypted so that individual patients cannot be identified by name.[37]  The prescription information that data miners purchase is estimated to encompass several billion prescriptions per year.[38]  The data miners then aggregate the entries,[39] group the information by prescriber, and cross-reference the prescribing history with information on each prescriber available through publicly accessible databases, such as the American Medical Association’s database of physician specialists.[40]  The ultimate reports that the data miners produce show each prescriber’s identity, medical specialty, and a complete history of the drugs he or she prescribed over a given period of time.

The data miners’ customers for these reports are the pharmaceutical manufacturers because the reports are useful in facilitating the drug manufacturers’ practice of “detailing.”  This practice consists of drug-sales representatives visiting physicians and their staffs in a particular region where specific drugs are being marketed.[41]  At these face-to-face meetings, the sales representatives give the physicians “details” about their drugs (use, side effects, and risks) to convince the physicians that they are a better choice for their patients.[42]  Described as a “valuable tool,”[43] the data-mining reports allow the drug representatives to pinpoint prescribers who might be persuaded to switch to the manufacturer’s drugs or to prescribe the manufacturer’s drugs more frequently.[44]  The data-mining reports also enable the representatives to tailor their presentations based on the particular physician’s prescribing practices to maximize the effectiveness of their sales efforts:

That [data-mining] information enables the detailer to zero in on physicians who regularly prescribe competitors’ drugs, physicians who are prescribing large quantities of drugs for particular conditions, and “early adopters” (physicians with a demonstrated openness to prescribing drugs that have just come onto the market).  The information also allows the detailer to tailor her promotional message in light of the physician’s prescribing history.[45]

Merck’s use of data mining to market Vioxx provides an example of the usefulness of data mining to sell a particular drug:

When Merck marketed Vioxx, for example, it used a wealth of prescriber-identifying data to create monthly reports on individual prescribers in each detailer’s assigned territory.  The reports showed how many Merck versus non-Merck drugs the prescriber prescribed and estimated how many of these prescriptions could be substituted for Merck products.  Merck then tracked its detailers’ progress in converting prescribers in their territories to the Merck brand and gave detailers bonuses based on Merck’s sales volume and market share in the detailer’s territory.[46]

Detailing has been described as “a massive and expensive undertaking for pharmaceutical manufacturers.”[47]  Manufacturers reportedly spent $4 billion in 2000 for detailing,[48] employing some 90,000 sales representatives to make the physician office visits.[49]  The detailers often arrive with small gifts for the physicians and their staffs and drop off free drug samples for the physicians to try with their patients.[50]  It has been estimated that a single physician is visited by an average of twenty-eight detailers a week, and a specialist is visited by an average of fourteen detailers.[51]  Because of the time involved and high cost of detailing, drug manufacturers usually reserve it for marketing high-cost, brand-name drugs,[52] as opposed to lower-cost, generic drugs.[53]  Sales representatives try to convince physicians to switch from generic drugs to their brand-name drug, to utilize it instead of a competing brand-name drug, or to remain loyal to the brand-name drug when the patent expires and generic versions become available.[54]

II.  States’ Objections to Drug Manufacturers’ Use of Data Mining for Detailing

Some states, including New Hampshire, Maine, and Vermont, perceived that pharmaceutical manufacturers’ use of pharmacy data to enhance their detailing efforts increased the cost of prescription drugs with no concomitant improvement to the public health.[55]  These perceptions emanated from several factors.

First, the states became convinced that data mining improved the success of detailing.[56]  These states perceived that “detailers armed with prescribing histories enjoyed a significant marketing advantage, resulting in greater leverage, [and] increased sales of brand-name drugs.”[57]  This “leverage” refers to the detailer’s ability to target physicians who prescribe large quantities of generics, the ability to “zero in” on a physician’s particular prescribing choices, and the ability to “punish” physicians who abandon their loyalty to certain brand-name drugs.[58]  Thus, “prescribing histories helped the detailer to become more adversarial in her presentation and to focus on the weakness of the physician’s erstwhile drug of choice as opposed to the clinical virtues of the detailed drug.”[59]

Second, the states believed that the success of detailing often resulted from less than accurate and balanced information.  Vermont negatively characterized the detailers’ provision of information to physicians on pharmaceutical safety and efficacy as “frequently one-sided,” “incomplete,” and “biased.”[60]  The Vermont legislature found that the “[p]ublic health is ill served by the massive imbalance in information presented to doctors and other prescribers.”[61]  Vermont held detailers’ use of data mining responsible for creating “an unbalanced marketplace of ideas that undermines the state’s interests in promoting public health, protecting prescriber privacy, and reducing healthcare costs.”[62]

Third, the states perceived that detailing improperly influenced physicians’ prescription choices and unnecessarily raised the cost of prescription drugs.  New Hampshire viewed detailing as having a “pernicious effect” upon drug prescribing.[63]

The states’ “common sense” conclusion was that detailing worked to induce physicians to prescribe larger quantities of more expensive brand-name drugs.[64]  The fact “that the pharmaceutical industry spends over $4 billion annually on detailing bears loud witness to its efficacy.”[65]  Despite the much higher cost of detailed drugs, New Hampshire concluded that, based upon “competent evidence,” drugs that were aggressively marketed through detailing “provide no benefit vis-à-vis their far cheaper generic counterparts.”[66]  The State maintained that “detailers armed with prescribing histories encouraged the overzealous prescription of more costly brand-name drugs regardless of both the public health consequences and the probable outcome of a sensible cost/benefit analysis.”[67]

Finally, doctors themselves voiced “a predominantly negative view of detailing.”[68]  A 2006 survey by the Maine Medical Association reported that “a majority of Maine physicians did not want pharmaceutical manufacturers to be able to use their individual prescribing histories for marketing purposes.”[69]

III.  State Laws Regulating Data Mining[70]

In the interests of protecting prescriber privacy, safeguarding the public health, and containing healthcare costs,[71] New Hampshire in 2006 became the first state to enact a law limiting drug prescription data mining, known as the Prescription Information Law.[72]  The law prohibited the sale, transfer, use, or licensing of prescription records by pharmacies and insurance companies for any commercial purpose,[73] except for listed health-related purposes, such as pharmacy reimbursement, healthcare management, utilization review by a healthcare provider, and healthcare research.[74]  The statute did not prohibit the transfer of prescription information to fill patients’ prescriptions[75] and placed no restrictions upon prescription information that did not identify the patient or the prescriber.[76]

Shortly thereafter, Vermont followed suit, enacting Act 80, section 17 of the Vermont General Statutes to restrict the use of pharmacy records for drug marketing.[77]  Vermont’s policy goals, compatible with those of New Hampshire, were:

[T]o advance the state’s interest in protecting the public health of Vermonters, protecting the privacy of prescribers and prescribing information, and to ensure costs are contained in the private health care sector, as well as for state purchasers of prescription drugs, through the promotion of less costly drugs and ensuring prescribers receive unbiased information.[78]

Unlike the flat prohibition of New Hampshire’s statute, however, Vermont’s law adopted an “opt-out” approach, prohibiting insurers and pharmacies from selling or transferring prescription data for marketing purposes unless the prescriber opted out of the prohibition by consenting to the use.[79]  The law also prohibited pharmacy manufacturers from using the data for marketing absent prescribers’ consent.[80]  The law defined “marketing” as advertising or any activity that influenced the sale of a drug or influenced prescribing behavior.[81]  The statute contained a number of exceptions to the prohibition, most of which facilitated healthcare treatment and reimbursement, such as dispensing prescriptions, pharmacy reimbursement, patient care management, utilization review by healthcare professionals, healthcare research, and communicating treatment options to patients.[82]  The law also created a program to educate healthcare professionals on therapeutic and cost-effective drug prescribing.[83]

In 2008, Maine enacted similar legislation.  Its goals, like those of New Hampshire and Vermont, were “to improve the public health, to limit annual increases in the cost of healthcare and to protect the privacy of . . . prescribers in the healthcare system of this State.”[84]  Unlike Vermont’s “opt-out” approach, Maine passed an “opt-in” version, making it unlawful for a pharmacy to use, sell, or transfer prescription drug information for any marketing[85] purpose when the information identified the prescriber and the prescriber had opted in by registering for the statute’s protection.[86]  The law included a number of health-related exceptions to the definition of “marketing,” including pharmacy reimbursement, patient care management, utilization review by a healthcare provider, and healthcare research.[87]

IV.  Challenges to the Data-Mining Laws

With a number of other states considering enactment of similar laws,[88]and facing the loss of billions of dollars in business annually, several data-mining companies[89] and an association of pharmaceutical manufacturers[90] challenged the constitutionality of New Hampshire’s, Vermont’s, and Maine’s data-mining laws.[91]  The claims that survived to appeal included that the statutory prohibition violated the Free Speech Clause of the First Amendment, was unconstitutionally vague and overbroad under the First and Fourteenth Amendments, and offended the Commerce Clause.[92]

In 2008, the United States Court of Appeals for the First Circuit ruled in IMS Health Inc. v. Ayotte[93] that the New Hampshire statute regulated conduct, not speech, and therefore did not abridge the First Amendment rights of the data miners.[94]  Alternatively, the First Circuit ruled that even if New Hampshire’s law amounted to a regulation of protected speech, New Hampshire’s action to protect cost-effective healthcare passed constitutional muster.[95]  Utilizing the Central Hudson test,[96] the court found that healthcare cost containment was a substantial governmental interest,[97] data mining increased the success of detailing,[98] detailing increased the cost of prescription drugs,[99] and the statute was sufficiently tailored to achieve its objectives.[100]  The court summarily disposed of the remaining claims for vagueness[101] and violation of the Commerce Clause.[102]

When the challenge to the Maine statute reached the First Circuit in IMS Health Inc. v. Mills[103] approximately two years later, the court unsurprisingly relied upon its prior New Hampshire Ayotte ruling.[104]  The court rejected the First Amendment claim,[105] the vagueness claim,[106]and the Commerce Clause challenge[107] for the same reasons stated inAyotte.

Four months after Mills, the United States Court of Appeals for the Second Circuit ruled on the same issues with regard to the Vermont statute in IMS Health Inc. v. Sorrell.[108]  In Sorrell, the Second Circuit disagreed with nearly every basis for the First Circuit’s two prior decisions.  Applying theCentral Hudson test,[109] the court found that although Vermont did have a substantial interest in lowering healthcare costs and protecting the public health,[110] the statute did not directly advance those interests.[111]  Rather, the court characterized Vermont’s law as an attempt “to bring about indirectly some social good or alter some conduct by restricting the information available to those whose conduct the government seeks to influence.”[112]  Moreover, the court found that Vermont had “more direct, less speech-restrictive means available” to accomplish its goals.[113]  As less restrictive alternatives, the court suggested that the State could have assessed the results of its campaign to encourage the use of generics or could have mandated the use of generic drugs as a first course of treatment.[114]  Failing these critical prongs of the Central Hudson test, the court ruled that Vermont’s law unconstitutionally restricted freedom of speech.[115]

With the First Circuit and Second Circuit Courts of Appeal thus directly at odds on the constitutionality of the data-mining laws, the United States Supreme Court granted certiorari to consider Vermont’s appeal in Sorrell v. IMS Health Inc.[116]

V.  The Supreme Court’s Decision

In June 2011, the Supreme Court, in a six to three ruling,[117] held that Vermont’s drug prescription data-mining law violated the First Amendment.[118]  While conceding that Vermont’s asserted policy goals of containing pharmacy prescription costs and protecting public health were legitimate concerns,[119] the Court held that the statute was a broad, content-based rule[120] that did not satisfy strict scrutiny.[121]

Initially, the Court unequivocally held that the Vermont law was content and speaker based, as it prohibited the sale of pharmaceutical prescription data only for marketing purposes[122] and only to pharmaceutical manufacturers.[123]  Because the law “impose[d] burdens that are based on the content of speech and that are aimed at a particular viewpoint,” the Court ruled that it must apply strict scrutiny.[124]

The Court flatly rejected Vermont’s argument that the law regulated conduct as opposed to speech.[125]  Instead, the Court ruled that “[f]acts, after all, are the beginning point for much of the speech that is most essential to advance human knowledge and to conduct human affairs.  There is thus a strong argument that prescriber-identifying information is speech for First Amendment purposes.”[126]

Applying the Central Hudson test, whereby “[t]here must be a ‘fit between the legislature’s ends and the means chosen to accomplish those ends,’”[127] the Court held that none of the State’s asserted justifications—prescriber privacy, protecting public health, and reducing healthcare costs—withstood scrutiny.[128]  First, because the law permitted disclosure of prescription information for a number of other purposes and applied the ban only to marketing, the Court rejected the privacy justification.[129]  The Court ruled that Vermont’s statute “permits extensive use of prescriber-identifying information and so does not advance the State’s asserted interest in physician confidentiality.”[130]  In particular, the Court objected to the State’s own ability to use the same prescription information to engage in “counter-detailing” efforts to promote generic drugs.[131]  Moreover, the Court observed that privacy remedies less restrictive of speech were available.[132]  For example, prescribers could simply decline to meet with detailers.[133]  Even though physicians might find the use of their prescription histories by detailers to be “underhanded” or tantamount to “spying,”[134] the Court declared that “[s]peech remains protected even when it may . . . ‘inflict great pain.’”[135]

In similar fashion, the Court declared that Vermont’s stated policy goals of improving public health and reducing healthcare costs did not withstand scrutiny under the Central Hudson test,[136] because the law “does not advance them in a permissible way.”[137]  The law sought to protect patients’ health and cost-effectiveness only indirectly, aimed at the fear that physicians, admittedly sophisticated consumers,[138] would make poor purchasing decisions if given truthful information by detailers.[139]

In short, the Court viewed the statute as a means for the State to advance its own views over those of pharmacy manufacturers by stifling protected speech.[140]  The Court stated that if the statute had provided for only a few narrowly tailored exceptions to its ban on the sale or disclosure of prescription information, then its position that it was not targeting a disfavored speaker and disfavored content might be stronger.[141]  But, here, the law permitted disclosure of the same information to countless others and even to the State itself to persuade physicians to prescribe generic drugs.[142]  The Court declared that free access to and use of privately held information is “a right too essential to freedom to allow its manipulation to support just those ideas the government prefers.”[143]  The Court concluded that “the State has left unburdened those speakers whose messages are in accord with its own views.  This the State cannot do.”[144]

Several days after the Sorrell decision was issued, the Supreme Court vacated the First Circuit’s finding that the Maine data-mining laws were valid and remanded the case to the court for further consideration in light ofSorrell.[145]  Three months later, the New Hampshire District Court issued an order declaring that New Hampshire’s data-mining laws were invalid in light of Sorrell.[146]

VI.  Applying the HIPAA Privacy Rule to Data Mining

Since New Hampshire, Vermont, and Maine each enacted state laws that prohibited pharmacies from selling prescription information to data miners for use in detailing, presumably these states perceived that such laws were necessary to ban the practice.  This necessity apparently stemmed from the states’ belief that nothing in the HIPAA Privacy Rule prohibited these data sales by the pharmacies.  This Part of the Article explains why that belief is not supported by the text of HIPAA.

A.     Provisions of the HIPAA Privacy Rule

The HIPAA Privacy Rule[147] regulates covered entities’ use and disclosure of protected health information.[148]  The covered entities regulated by HIPAA include most health plans and healthcare providers.[149]  The term “provider” is defined by the Rule as “a provider of medical or health services . . . and any other person or organization who furnishes, bills, or is paid for health care in the normal course of business.”[150]

Under HIPAA, any time a covered entity uses or discloses protected health information, the use or disclosure must comply with HIPAA’s privacy provisions.[151]  The term “use” is broadly defined as “the sharing, employment, application, utilization, examination, or analysis” of health information protected by HIPAA.[152]  “Disclosure” is also broadly defined as “the release, transfer, provision of, access to, or divulging in any other manner of information outside the entity holding the information.”[153]

The health information protected by the Privacy Rule includes any information relating to healthcare treatment or payment[154] that has a potential to identify the patient to whom the information applies.[155]  Identifiers that can render health information protected include, inter alia, the patient’s name, address, social security number, phone number, photograph, zip code, treatment date, employer, and names of spouse and children.[156]  Furthermore, any identifier that is not specifically named in the Privacy Rule but, due to its uniqueness, has a potential to identify the subject of the information also renders the information protected.[157]

Under the Privacy Rule, any use or disclosure of protected health information by a covered entity must be explicitly permitted or required by HIPAA.[158]  The Privacy Rule requires disclosure in only two instances: (1) when the subject of the protected health information (“the individual”)[159]requests access to his own healthcare information,[160] and (2) when the Secretary of the Department of Health and Human Services (“HHS”) requests access in order to enforce HIPAA.[161]  All other uses and disclosures authorized by the Privacy Rule are permissive.[162]

Most of the permissive uses and disclosures under the Privacy Rule fall into two broad categories.[163]  First, covered entities may use and disclose protected health information for “treatment, payment, or healthcare operations.”[164]  “Treatment” is defined as the rendering of healthcare services to individuals or managing their care.[165]  “Payment” comprises paying insurance premiums and reimbursing providers.[166]  “Health care operations” broadly encompasses operating the business of healthcare entities, including such activities as business management and administrative activities, quality assessment, evaluating the credentials of providers, customer service, and obtaining legal and auditing services.[167]  Thus, treatment, payment, and healthcare operations cover the myriad activities that allow the healthcare industry to function.

The second broad category of permissive uses allows covered entities to use and disclose protected health information for twelve public-interest activities.[168]  These include, inter alia, participating in public-health activities to prevent or control disease; reporting abuse, neglect, or domestic violence; complying with healthcare audits and investigations; assisting law enforcement activities; engaging in healthcare research; and assisting national security and intelligence activities.[169]

If a covered entity’s use or disclosure of protected health information does not fit within one of the Privacy Rule’s enumerated required or permitted use and disclosure, then the use or disclosure may not occur[170] unless the individual authorizes the use or disclosure in writing.[171]

As the primary goal of HIPAA is to protect the privacy of individuals’ healthcare information,[172] HIPAA grants individuals rights of access to their own information and rights to control its uses and disclosures by covered entities.  These rights include the following:
(1) A right of individuals to access upon request their own protected health information,[173] along with a right to appeal denials of access;[174]

(2) A right of individuals to seek to amend their protected health information possessed by covered entities,[175] as well as a right to submit a written statement disagreeing with a denial of an amendment;[176]

(3) A right of individuals to receive an accounting of certain disclosures of their protected health information made by covered entities;[177]

(4) A right of individuals to request covered entities to restrict certain permissible uses and disclosures of their protected health information;[178]

(5) A right of individuals to request confidential communications of protected health information from providers and health plans,[179] which providers must accommodate[180] and which health plans must accommodate if the individuals state that they will be in danger unless accommodation is made;[181]

(6) A right of individuals to agree or object before covered entities make certain disclosures;[182]

(7) A right of individuals to authorize disclosures to third parties;[183] and

(8) A right of individuals to receive a Notice of Privacy Practices from covered entities, describing the covered entities’ uses and discloses of their protected health information and the individuals’ rights thereunder.[184]

B.     HIPAA’s De-identification and Marketing Provisions

HIPAA’s de-identification and marketing provisions are especially relevant to data mining.  In Sorrell, the data mining involved de-identification because, when the pharmacies’ computer software collected the raw prescription data, the software encrypted or stripped out the patients’ identifying information.[185]  Therefore, when the pharmacies sold the information to the data miners, it had been de-identified because the patients’ names could no longer be identified.[186]

The Privacy Rule provides that once protected health information is de-identified, it is no longer protected by HIPAA and thus is not subject to HIPAA’s use and disclosure restrictions.[187]  HIPAA gives explicit instructions on what information must be removed from protected health information to render it de-identified.[188]  Further, HIPAA specifically permits covered entities to de-identify protected health information.[189]  Moreover, HIPAA defines “health care operations,” one of the permissive uses and disclosures of protected health information under the Privacy Rule,[190] to include a covered entity’s creation of de-identified information when the de-identification relates to a “covered function.”[191]

HIPAA’s marketing provisions are also particularly relevant to data mining.  The data miners purchased the prescription information to market their aggregations and reports to pharmaceutical manufacturers.[192]  The drug manufacturers, in turn, purchased the prescription information to more effectively market their brand-name drugs to prescribers.[193]

HIPAA expressly provides that covered entities’ uses and disclosures of protected health information for the purpose of “marketing” are subject to heightened restrictions.[194]  HIPAA defines “marketing” in two ways.  First, marketing includes “a communication about a product or service that encourages recipients of the communication to purchase or use the product or service.”[195]  However, this definition excludes communications made for description of plan benefits, for treatment of the individual, or for case management or care coordination of the individual.[196]  Second, marketing includes a covered entity’s sale of protected health information to a third party to assist that party in marketing its products.[197]

HIPAA’s primary marketing restriction is that whenever a covered entity uses or discloses protected health information for marketing purposes, the individual must expressly authorize the use or disclosure.[198]  This mandate is stated emphatically: “Notwithstanding any provision of this subpart,[199] other than the transition provisions in § 164.532,[200] a covered entity must obtain an authorization for any use or disclosure of protected health information for marketing . . . .”[201]

The Rule states only two exceptions to this requirement that the individual must authorize the marketing uses and disclosures.  First, an authorization is not needed if the marketing consists of a face-to-face communication between the covered entity and the individual.[202]  Second, an authorization is not needed if the marketing consists of a promotional gift of nominal value provided by the covered entity.[203]  The affected individual must authorize all other marketing uses and disclosures.[204]

C.     How HIPAA’s Marketing and De-identification Rules Impact Data Mining

While Vermont and other states apparently believed that it was necessary to enact a law to prohibit pharmacies from selling prescription information to data miners, surprisingly, such laws were probably not necessary.  HIPAA already appears to have prohibited those sales, rendering the state laws inconsequential.

As explained above, HIPAA requires an authorization from every affected individual before his protected health information can be used or disclosed by covered entities for marketing purposes.[205]  Each Vermont pharmacy qualifies as “a provider of medical or health services” and as an entity that “furnishes, bills, or is paid for health care in the normal course of business.”[206]  Thus, the pharmacies are covered entity providers under HIPAA.[207]  The prescription information collected and retained by the pharmacies constitutes “protected health information,” as it includes the patients’ names and addresses, as well as other identifying information.[208]

Moreover, the pharmacies’ disclosures of prescription information to the data miners appear to have been “for marketing.”[209]  The pharmacies made the disclosures to data miners to enable the data miners to sell their aggregations and reports of pharmacy data to their customers, including drug manufacturers.[210]  Further, the data miners disclosed the prescription information to drug manufacturers to use in marketing their brand-name drugs to physicians.[211]  Selling prescription information for these purposes appears to qualify as marketing under the Privacy Rule’s broad definition: “a communication about a product or service that encourages recipients of the communication to purchase or use the product or service.”[212]

The “rub” with this analysis, however, is that according to the facts inSorrell, the pharmacies did not disclose “protected health information” to the data miners because the information had been de-identified by the pharmacies’ computer software prior to the sale.[213]  As stated above,[214] HIPAA expressly permits covered entities to de-identify protected health information, thereby removing it from any constraints that HIPAA imposes.[215]  Therefore, the pharmacies’ de-identification of their prescription information may have removed the information from the category of “protected health information”[216] and thereby enabled the pharmacies to make whatever use they wished of the information without violating HIPAA.[217]

But HIPAA’s marketing restrictions do not prohibit only unauthorized disclosures of protected health information.  The restrictions also prohibit the pharmacies from even using protected health information for marketing purposes.[218]  Creating de-identified information from protected health information appears to constitute a use of the protected health information because the pharmacies must “employ” and “utilize” the protected information in order to de-identify it.[219]  In fact, the Privacy Rule itself refers to the “use” of protected health information to create de-identified information.[220]  Here, the purpose of the pharmacies’ de-identification of the prescription information was to facilitate sales of the information to the data miners and to enable sales of the data miners’ aggregations and reports to the drug manufacturers, all for the purpose of marketing brand-name drugs to prescribers.[221]  Therefore, the de-identification itself appears to qualify as a marketing use,[222] so that the pharmacies would be prohibited from such use without the individuals’ express authorization under the Privacy Rule.[223]

Further, the Privacy Rule’s explicit statement that covered entities may de-identify protected health information[224] does not negate the authorization requirement.  The requirement that covered entities must obtain an authorization before any use or disclosure related to marketing expressly states that this requirement is imposed “[n]otwithstanding any provision of this subpart.”[225]  HIPAA’s de-identification provisions, on the other hand, lack this vital “notwithstanding” language.[226]  Therefore, the requirement to obtain individuals’ authorizations for any use or disclosure related to marketing trumps the de-identification provisions.  Although HIPAA expressly permits covered entities and their business associates to de-identify protected health information,[227] it appears that any such use (i.e., de-identification) of protected health information for marketing purposes may not occur without written authorizations from the affected individuals.[228]

Under this reading of HIPAA, whenever the purpose of the de-identification is marketing, the pharmacy must first obtain a written authorization from every individual whose protected health information is being so used before any pharmacy de-identifies its prescription information.[229]  Granted, the requirement to obtain authorizations is not an outright prohibition against the de-identification, subsequent sale, or ultimate use of the information for marketing.  However, the requirement to obtain an authorization from every individual—where billions of prescriptions are being disclosed[230]—places such an enormous burden on the pharmacies that, for all practical purposes, it quashes use of the information for data mining.[231]  Not only will pharmacies need to obtain written authorizations from every individual before his information may be de-identified or disclosed, but it is likely that most of these patients will either refuse to furnish the authorizations or not bother to execute them.[232]  Consequently, HIPAA’s authorization requirement adds so much additional effort and cost to data mining that drug companies will probably no longer find it a cost-effective tool for detailing.[233]

D.     Continuing Failure to Use HIPAA to Restrict Data Mining

It is apparent that parties continue to fail to apply the marketing provisions of the Privacy Rule to restrict data mining.  In a recent case, Steinberg v. CVS Caremark Corp.,[234] prescription drug purchasers sued a pharmacy chain for, inter alia, its disclosures of the purchasers’ prescription information to data miners.  Plaintiffs challenged the pharmacies for accepting remuneration from drug manufacturers for (1) sending letters to the consumers’ physicians suggesting that they prescribe alternate drugs, and (2) selling de-identified prescription information directly to the drug manufacturers and data companies.[235]  The plaintiffs brought state law claims for violation of Pennsylvania’s Unfair Trade Practices and Consumer Protection Law, unjust enrichment, and invasion of privacy.[236]

The United States District Court for the Eastern District of Pennsylvania dismissed the complaint for failure to state a claim.[237]  In so doing, the court made erroneous findings that nothing in the Privacy Rule restricted the defendants’ activities.[238]  First, the court declared that the pharmacies’ sale of de-identified drug prescription information to pharmaceutical manufacturers and data companies for marketing purposes did not offend the HIPAA Privacy Rule because the information had been de-identified prior to sale.[239]  Second, the court stated that the pharmacies’ use of the plaintiffs’ protected health information to send marketing notices to the plaintiffs’ physicians did not violate HIPAA because this constituted permissible healthcare operations.[240]

In fact, the Privacy Rule does not permit either activity.  Without authorizations from the affected individuals, the pharmacies could not use the plaintiffs’ protected health information (even when such use is de-identification) for marketing purposes,[241] thereby rendering the unauthorized de-identification itself illicit.  Further, without the appropriate authorizations, the pharmacies could not disclose protected health information to the plaintiffs’ physicians for marketing purposes,[242] even under the guise of suggesting “treatment alternatives.”[243]  While the court correctly observed that HIPAA does not provide a private right of action, thereby precluding the plaintiffs from bringing a claim directly under HIPAA,[244] the HIPAA violations could arguably have served as bases for the plaintiffs’ state law claims.

VII.  Applying the Sorrell Analysis to the HIPAA Privacy Rule

Both the data-mining laws and HIPAA impose restrictions on the use of health information for marketing.[245]  Both restrict pharmacies from selling de-identified prescription information to data miners.[246]  Although the Supreme Court invalidated the Vermont data-mining law in Sorrell,[247]HIPAA still effectively prevents pharmacies from using protected health information for marketing purposes—that is, de-identifying it for sale to data miners.[248]  Thus, the Sorrell holding raises a question of whether the marketing restrictions in the HIPAA Privacy Rule, like the data-mining law in Sorrell, violate the First Amendment rights of the data miners and drug manufacturers to obtain access to prescription information for marketing purposes.

At first glance, aspects of the data-mining laws and HIPAA’s marketing provisions appear quite similar.  Both bodies of law were motivated by substantial governmental interests—prescriber privacy, public health, and healthcare cost containment for the data- mining laws,[249] and privacy of patients’ medical information for the HIPAA Privacy Rule.[250]  Both laws seek to restrain the use of health information for marketing purposes.[251]  Both define marketing in similar ways.[252]  And both list a number of healthcare-related exceptions to their marketing restrictions.[253]

Despite these similarities, there are substantial grounds to argue that important distinctions between the data-mining laws and the HIPAA Privacy Rule predominate in any comparison.  First, the parties who sought protection are quite different.  The data-mining laws aimed to maintain the privacy of prescribers,[254] many of whom had complained that allowing drug manufacturers access to their prescribing history allowed the detailers “to target them for unwelcome marketing calls.”[255]  The Sorrell Court observed, however, that physicians are hardly hapless victims of detailing.  The Court noted, for instance, that “many listeners find detailing instructive,”[256] and physicians could “simply decline to meet with detailers.”[257]  In fact, the Court characterized prescribing physicians as “sophisticated and experienced consumers.”[258]

Quite unlike the physicians in Sorrell,[259] the HIPAA Privacy Rule seeks to protect private patients from unwarranted invasions into their most private medical information.[260]  Contrasted to physicians, private healthcare patients are typically much more in need of protection.  The medical records amassed on their behalves are done involuntarily, a necessary byproduct of seeking medical treatment.[261]  Not only are many individual patients undoubtedly less sophisticated than physicians, but they may also be unable to watchdog illicit uses of their medical records, particularly if they are ill or aged.  In fact, most patients are probably unaware of the many uses and disclosures of their medical information by covered entities that HIPAA permits.[262]  To address these concerns, HIPAA sets clear limits to covered entities’ uses and disclosures of individuals’ protected health information.[263]  It provides a means whereby covered entities must obtain individuals’ authorization for uses and disclosures that are not expressly permitted by HIPAA,[264] and whereby patients can prevent certain uses and disclosures prior to their occurrence.[265]  As a result, a strong argument can be made that the HIPAA Privacy Rule, unlike the data-mining laws, is a reasoned response to the critical need to protect patients’ medical privacy.

Second, the Supreme Court criticized Vermont’s data-mining law for attempting to advance its goals in too indirect a way.[266]  The State restricted access to prescription information in order to restrict data mining, which in turn would impair detailing, which in turn would result in physicians writing fewer prescriptions for brand-name drugs, which in turn would contain healthcare costs and avoid unnecessary health risks.[267]  HIPAA, on the other hand, directly accomplishes its goal of protecting individuals’ medical privacy by conferring upon the individuals themselves the ability to control, within certain limits,[268] the uses and disclosures of their own protected health information by covered entities.[269]

Third, there were readily available less restrictive alternatives to the data-mining laws that could have accomplished the asserted purposes of achieving prescriber privacy, protecting the public health, and containing pharmaceutical costs.  The Sorrell Court observed that physicians could easily refuse to meet with detailers, thereby preventing the detailers from using the physicians’ prescriber histories to pressure them into purchasing expensive brand-name drugs.[270]  Further, Vermont’s law authorized funds for a drug education program to provide physicians with information on “cost-effective utilization of prescription drugs.”[271]  Accordingly, before prohibiting data mining of pharmacy prescriptions, the State could have waited to see if that program was successful in limiting sales of nongeneric drugs.[272]

In contrast, with regard to HIPAA, there is no readily ascertainable less restrictive means to protect the privacy of patients’ medical records other than to permit limited uses and disclosures and to require patients’ consent for everything else.[273]  Congress, with limited exceptions,[274] conferred upon individuals the ability to control uses and disclosures of their own protected health information by covered entities.[275]  Requiring individuals to authorize uses and disclosures that are not otherwise needed to allow the healthcare industry to operate[276] and enable critical public interest activities[277] is therefore a direct means of achieving that control.  As a reasonable exercise of that control, HIPAA requires individuals to authorize any uses or disclosures of their protected health information to sell items or services that are not related to the individuals’ own healthcare management.[278]  As marketing third-party items and services is not critical either to providing and paying for individuals’ treatment or to enabling public interest activities, the authorization requirement for marketing uses and disclosures is necessary to achieve HIPAA’s privacy goal.

Fourth, the discriminatory impact of the data-mining laws that offended the Supreme Court in Sorrell[279] is largely absent in HIPAA.  The Sorrell Court characterized Vermont’s data-mining law as pointedly aimed at “diminish[ing] the effectiveness of marketing by manufacturers of brand-name drugs.”[280]  Convinced that detailing increased prescriptions for expensive brand-name drugs over just as effective and cheaper generic alternatives, the State sought to discourage detailing:

“In its practical operation,” Vermont’s law “goes even beyond mere content discrimination, to actual viewpoint discrimination.”  Given the legislature’s expressed statement of purpose, it is apparent that [the Vermont law] imposes burdens that are based on the content of speech and that are aimed at a particular viewpoint.[281]

The Sorrell Court found the State’s eradication of pharmacy data mining to be value based because “the State . . . engage[d] in content-based discrimination to advance its own side of a debate.”[282]  The law prohibited the communication of accurate information by detailers even though some prescribers found the information to be helpful.[283]  Also, the Court found that some brand-name drugs may be better for patients than their generic equivalents.[284]  Nevertheless, the State restricted access to prescription information to suppress speech with which it did not agree, while allowing access for itself and others to promote generics.[285]

This pointedly discriminatory goal and impact of Vermont’s data-mining law is absent with the HIPAA Privacy Rule.  Although marketing is not included in HIPAA’s list of permitted uses and disclosures,[286] it falls within a very broad category of all nonpermissive uses and disclosures for which an authorization is required.[287]  Admittedly, HIPAA singles out marketing for special restrictions,[288] as it comprises one of only two uses specified in HIPAA where protected health information may not even be de-identified absent the individual’s authorization.[289]  Here, however, it is all marketing that is so treated, not the more pointed restriction of a particular use by a particular speaker that was present in Sorrell.[290]

Consequently, the overall structure of the data-mining laws and the HIPAA Privacy Rule is markedly different.  Amid the thousands of uses and disclosures to which medical information is subject,[291] Vermont’s data-mining law pointedly prohibited only one—pharmacies’ disclosure of prescription information for marketing and the use of that information by drug manufacturers to market their drugs.[292]  Consequently, any nonmarketing use of prescription information was permitted.[293]  Even with regard to marketing uses, exceptions allowed the information to be utilized for “health care research,” to enforce “compliance” with health insurance preferred drug lists, for “care management educational communications” provided to patients on treatment options, for law enforcement operations, and as “otherwise provided by law.”[294]  Pharmacies could sell the information to insurers, researchers, journalists, the State, and others.[295]  The State itself could use the information for “counterdetailing” activities.[296]  Accordingly, the Court concluded that while the law “permits extensive use of prescriber-identifying information,”[297] it targeted only one use (marketing) and one user (drug manufacturers) for its prohibition.[298]

In contrast, the HIPAA Privacy Rule regulates from the reverse vantage point.  It declares at the outset that no use or disclosure of protected health information may occur unless it is specifically permitted by the Rule.[299]  Therefore, opposite to the structure of the data-mining laws, the prohibitions are virtually limitless, while the allowable uses are distinctly limited.[300]  Generally, the Privacy Rule permits uses and disclosures that fall within two broad categories[301]: (1) those that are related to healthcare treatment, payment, and business operations of the covered entities[302]and (2) those that are related to public interest activities that are so critical to society’s well being that Congress deemed they should not be hindered by medical privacy concerns.[303]  All nonpermitted uses must be authorized.[304]  While, like the data-mining laws, HIPAA earmarks marketing for special restrictions,[305] even those limitations are more broadly drawn in HIPAA, applying to all types of marketing, not just marketing of brand-name drugs by pharmaceutical manufacturers.[306]  This is quite different from Vermont’s prohibition applying solely to pharmacies’ and insurers’ sales of prescription information for drug marketing.[307]  In fact, the Sorrell Court itself pointed out the marked differences between the structure of Vermont’s data-mining law and the HIPAA Privacy Rule:

[T]he State might have advanced its asserted privacy interest by allowing the information’s sale or disclosure in only a few narrow and well-justified circumstances.  See, e.g., Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. §1320d-2; 45 CFR pts. 160 and 164 (2010).  A statute of that type would present quite a different case than the one presented here.[308]


While several states found it necessary to pass laws prohibiting pharmacies from selling de-identified prescription information to data miners for use by drug manufacturers to market their brand-name drugs, a solid argument can be made that the HIPAA Privacy Rule already restricted such sales.  HIPAA prohibits covered entities, including pharmacies, from using protected health information for marketing purposes without the individuals’ authorization.  As a result, it appears that the Privacy Rule restricts pharmacies from even de-identifying protected health information for marketing purposes unless the affected individuals authorize such use.

The recent Sorrell holding, invalidating Vermont’s data-mining law on the ground that it violates the Free Speech Clause of the First Amendment, raises the question of whether the marketing provisions of the HIPAA Privacy Rule could be deemed invalid for similar reasons.  Both the data-mining laws and the HIPAA Privacy Rule restrict pharmacies from selling de-identified prescription information to data miners for marketing purposes.

However, it is evident that there are fundamental distinctions between the data-mining laws and HIPAA’s marketing restrictions.  The two laws protect different parties and are structured very differently.  Most significantly, the discriminatory intent and effect of the data-mining laws are largely absent in HIPAA.  These distinctions present a substantially different question regarding HIPAA from that considered in Sorrell and likely would yield a different answer.[309]

          *     Professor of Law, Albany Law School.
       [29].   See infra Part VII.
By Derek E. Bambauer

Cyberlaw is plagued by the myth of perfection.

Consider three examples: censorship, privacy, and intellectual property.  In each, the rhetoric and pursuit of perfection has proved harmful, in ways this Essay will explore.  And yet the myth persists—not only because it serves as a potent metaphor, but because it disguises the policy preferences of the mythmaker.  Scholars should cast out the myth of perfection, as Lucifer was cast out of heaven.  In its place, we should adopt the more realistic, and helpful, conclusion that often good enough is . . . good enough.

Start with Internet censorship. Countries such as China, Iran, and Vietnam use information technology to block their citizens from accessing on-line material that each government dislikes.  Democracies, too, filter content: Britain blocks child pornography using the Cleanfeed system,{{1}} and South Korea prevents users from reaching sites that support North Korea’s government.{{2}}  This filtering can be highly effective: China censors opposition political content pervasively,{{3}} and Iran blocks nearly all pornographic sites (along with political dissent).{{4}}  However, even technologically sophisticated systems, like China’s Golden Shield, are vulnerable to circumvention.  Users can employ proxy servers or specialized software, such as Tor, to access proscribed sites.{{5}}  This permeability has led many observers to conclude that effective censorship is impossible, because censorship is inevitably imperfect.{{6}}  Filtering is either trivially easy to bypass, or doomed to failure in the arms race between censors and readers.  The only meaningful censorship is perfect blocking, which is unattainable.

And yet, leaky Internet censorship works.  Even in authoritarian countries, few users employ circumvention tools.{{7}} Governments such as China’s capably block access to most content about taboo subjects, such as the Falun Gong movement{{8}} or coverage of the Arab Spring uprisings.{{9}}  Those who see imperfect censorship as useless make three errors.  First, they ignore offline pressures that users face.  Employing circumvention tools is like using a flashlight: it helps find what you seek, but it draws attention to you.  China has become adept at detecting and interfering with Tor,{{10}} and Iran recently purchased a sophisticated surveillance system for monitoring Internet communications.{{11}}  Bypassing censorship in cyberspace may have adverse consequences in realspace.  Second, most Internet users are not technologically sophisticated.  They use standard software, and the need to install and update specialized circumvention tools may be onerous.{{12}}  Finally, governments do not need perfect censorship to attain their goals.  They seek to prevent most people from obtaining prohibited content, not to banish it entirely.  Censorship that constrains the average user’s ordinary web browsing generally suffices.

Privacy discourse too is obsessed with perfection.  The reidentification wars have pitted researchers who assert that anonymizing data is impossible{{13}} against those who argue the risk of breaching properly sanitized datasets is vanishingly small.{{14}}  While the arguments are dauntingly technical (for those unfamiliar with advanced statistics), the empirical evidence points toward the less threatening conclusions.  The only rigorous study demonstrating an attack on a properly de-identified dataset under realistic circumstances revealed but 2 out of 15,000 (.013%) participants’ identities.{{15}}  Moreover, critics of anonymized data overlook the effects of incorrect matches. Attackers will have to weed out false matches from true ones, complicating their task.

Opponents make three mistakes by focusing on the theoretical risk of re-identification attacks on properly sanitized data.  First, the empirical evidence for their worries is slight, as the data above demonstrates.  There are no reports of such attacks in practice, and the only robust test demonstrated minimal risk.  Second, anonymized data is highly useful for socially beneficial purposes, such as predicting flu trends, spotting discrimination, and analyzing the effectiveness of medical and legal interventions.{{16}} Finally, the most significant privacy risk is from imperfectly sanitized data: organizations routinely release, deliberately or inadvertently, information that directly identifies people, or that enables an attacker to do so without advanced statistical knowledge.  Examples are legion, from the California firm Biofilm releasing the names and addresses of 200,000 customers who asked for free Astroglide samples{{17}} to AOL’s disclosure of user queries that allowed researchers to link people to their searches.{{18}}  Concentrating on whether perfect anonymization is possible distracts from far more potent privacy threats emanating from data.

Intellectual property (“IP”) in the digital age is similarly obsessed with perfection.  IP owners argue that with the advent of perfect digital copies, high-speed networks, and distributed dissemination technologies, such as peer-to-peer file-sharing software, any infringing copy of a protected work will spread without limit, undermining incentives to create.  This rhetoric of explosive peril has resulted in a perpetual increase in the protections for copyrighted works and in the penalties for violating them.{{19}}

The quest for perfect safeguards for IP predates the growth of the commercial Internet.  In September 1995, President Clinton’s administration released its White Paper, which argued that expanded copyright entitlements were necessary for content owners to feel secure in developing material for the nascent Information Superhighway.{{20}}  Without greater protection, the Paper argued, the Superhighway would be empty of content, as copyright owners would simply refuse to make material available via the new medium.

This prediction proved unfounded, but still persuasive.  In the last fifteen years, Congress has reinforced technological protection measures such as Digital Rights Management with stringent legal sanctions;{{21}} has augmented penalties for copyright infringement, including criminal punishments;{{22}} has pressed intermediaries, such as search engines, to take down allegedly infringing works upon notification by the copyright owner;{{23}} and has dedicated executive branch resources to fighting infringement.{{24}}  And yet, pressures from content owners for ever-greater protections continue unrelentingly.  In the current Congress, legislation introduced in both the House of Representatives and the Senate would, for the first time in American history, have authorized filtering of sites with a primary purpose of aiding infringement{{25}} and would have enabled rightsowners to terminate payment processing and Internet advertising services for such sites.{{26}}  These proposals advanced against a backdrop of relatively robust financial health for the American movie and music industries.{{27}}

Thus, the pursuit of perfection in IP also contradicts empirical evidence.  Content industries have sought to prohibit, or at least hobble, new technologies that reduce the cost of reproduction and dissemination of works for over a century—from the player piano{{28}} to the VCR{{29}} to the MP3 player{{30}} to peer-to-peer file-sharing software.{{31}}  And yet each of these advances has opened new revenue horizons for copyright owners.  The growth in digital music sales is buoying the record industry,{{32}} and the VCR proved to be a critical profit source for movies.{{33}}  New copying and consumption technologies destabilize prevailing business models, but not the production of content itself.{{34}}

Moreover, perfect control over IP-protected works would threaten both innovation and important normative commitments.  The music industry crippled Digital Audio Tapes{{35}} and failed to provide a viable Internet-based distribution mechanism until Apple introduced the iTunes Music Store.{{36}}  The movie industry has sought to cut off supply of films to firms such as Redbox that undercut its rental revenue model,{{37}} and Apple itself has successfully used copyright law to freeze out companies that sold generic PCs running MacOS.{{38}}  And, the breathing room afforded by the fair use and de minimis doctrines, along with exceptions to copyright entitlements, such as cover licenses, enables a thriving participatory culture of remixes, fan fiction, parody, criticism, and mash-ups.  Under a system of perfect control, copyright owners could withhold consent to derivative creators who produced works of which they disapproved, such as critical retellings of beloved classics, for example Gone With The Wind,{{39}} or could price licenses to use materials beyond the reach of amateur artists.{{40}}  Perfection in control over intellectual property is unattainable, and undesirable.

The myth of perfection persists because it is potent.  It advances policy goals for important groups—even, perhaps, groups on both sides of a debate.  For censorship, the specter of perfect filtering bolsters the perceived power of China’s security services.  It makes evasion appear futile.  For those who seek to hack the Great Firewall, claiming to offer the technological equivalent of David’s slingshot is an effective way to attract funding from Goliath’s opponents.  Technological optimism is a resilient, seductive philosophical belief among hackers and other elites{{41}} (though one that is increasingly questioned).{{42}}

Similarly, privacy scholars and advocates fear the advent of Big Data: the aggregation, analysis, and use of disparate strands of information to make decisions—whether by government or by private firms—with profound impacts on individuals’ lives.{{43}}  Their objections to disclosure of anonymized data are one component of a broader campaign of resistance to changes they see as threatening to obviate personal privacy.  If even perfectly anonymized data poses risks, then restrictions on data collection and concomitant use gain greater salience and appeal.

Finally, concentrating on the constant threat to incentives for cultural production in the digital ecosystem helps content owners, who seek desperately to adapt business models before they are displaced by newer, more nimble competitors.  They argue that greatly strengthened protections are necessary before they can innovate.  Evidence suggests, though, that enhanced entitlements enable content owners to resist innovation, rather than embracing it.  The pursuit of perfection turns IP law into a one-way ratchet: protections perpetually increase, and are forever insufficient.

We should abandon the ideal of the sublime in cyberlaw.  Good enough is, generally, good enough.  Patchy censorship bolsters authoritarian governments.  Imperfectly anonymized data generates socially valuable research at little risk.  And a leaky IP system still supports a thriving, diverse artistic scene.  Pursuing perfection distracts us from the tradeoffs inherent in information control, by reifying a perspective that downplays countervailing considerations.  Perfection is not an end, it is a means—a political tactic that advances one particular agenda.  This Essay argues that the imperfect—the flawed—is often both effective and even desirable as an outcome of legal regulation.

*    Associate Professor of Law, Brooklyn Law School (through spring 2012); Associate Professor of Law, University of Arizona James E. Rogers College of Law (beginning fall 2012).

By Margot Kaminski

My friends, who are generally well educated and intelligent, read a lot of garbage.  I know this because since September 2011, their taste in news about Justin Bieber, Snooki, and the Kardashians has been shared with me through “social readers” on Facebook.{{1}}  Social readers instantaneously list what you are reading on another website, without asking for your approval before disclosing each individual article you read.  They are an example of what Facebook calls “frictionless sharing,” where Facebook users ostensibly influence each other’s behavior by making their consumption of content on other websites instantly visible to their friends.{{2}}  Many people do not think twice about using these applications, and numerous publications have made them available, including the Washington PostWall Street Journal, and Guardian.{{3}}

I intend to prompt conversation about social readers on three fronts.  First, social readers are part of a shift toward real name policies online, and, for a number of reasons, should remain opt-in rather than becoming the default setting.  Second, if people do choose to use these applications, they should know that they are making that choice against a backdrop of related battles in privacy law concerning the right to consume content without a third party sharing your activity more broadly.  And third, when individuals choose to use these applications, they may be sharing their habits more widely than they think.

I.  Social Readers and Online Real-Name Policies

Social readers are part of a larger trend toward linking online activity to Internet users’ real identities.  Unlike America Online’s use of invented screen names, the two major social networks, Facebook and Google+, require users to register with their real names or verified pseudonyms.{{4}}  Both Google and Facebook aim to link user activity outside of the social network to one identifiable, real name profile, although Google’s aspirations currently appear limited to other Google services, while Facebook’s ambitions are broader.{{5}}  This real-name model is desirable to online companies and their supporting advertisers because it is easier to advertise to someone if you know who he or she is, and know all of his or her online behavior.

Business concerns are not the only motivating factor behind the shift toward real-name policy.  There is also an argument that real-name policies on comment forums may make people behave more civilly toward each other, because they are part of a social community that imports accountability into the online context.{{6}}  This has been compelling to some newspapers.  The Huffington Post, for example, has a Social News feature that encourages readers to log in through their Facebook accounts and comment on articles under their real identities.{{7}}  However, shifting to real name policy creates other problems, such as preventing pseudonymic or anonymous whistleblowing by commenters, and chilling more controversial or critical speech.{{8}}

Social readers are part of this potential collapse of anonymous or pseudonymic online activity.  It used to be the case that reading an article on the New York Times was a separate activity from communicating to your friends on a social network.  Social readers, however, import your reading activity from the newspaper website into your social network and broadcast it instantaneously under your real name.  Your presence on the other website is no longer anonymous.

Despite the potential benefits to companies, the decision to allow instantaneous sharing of all content consumed elsewhere connected to a user’s real identity should remain firmly in the hands of Internet users.  As individuals, we construct discrete identities for different circumstances: one for work, one for home, one for our closest friends.{{9}}  This is in fact the idea behind Google+’s “Circles” feature, which allows a user to tailor the parts of his or her identity that are visible to each “Circle,” whether it be friends, co-workers, or family.{{10}}  For a social network to retain value by mirroring reality, it needs to allow us to retain these distinctions.  Before social readers, one’s decision to read US Weekly at the gym would not be broadcast to one’s coworkers.  If one is forced to sign up for an US Weekly social reader, however, one’s network would see every article read.  This first point is about one’s relationship as an individual to other individuals: we should each be able to control the parts of our identity we want shown to other people.  We do this in real life; we should be able to do this online.  There may also be a benefit to media companies of allowing individuals to be pickier in their sharing: friends might take recommendations more seriously if they are deliberate and limited, rather than a list of everything their mutual friend haphazardly read.{{11}}

Already, some companies have experienced a backlash from making such pervasive sharing the default option for their software.  For example, in September 2011, the music service Spotify announced a partnership with Facebook that would allow new users to sign up only if they have a Facebook account.{{12}}  Users started seeing their music playlists automatically shared on Facebook; they could opt out of the service, but only by manually disabling the sharing feature.{{13}}  In response to a strong negative reaction, Spotify rolled out a more visible new privacy feature to allow users to “hide their guilty pleasures,” according to the Spotify CEO.{{14}}  The strong reaction to Spotify’s automatic frictionless sharing, and the fact that many newspapers have decided not to create social reader applications at all, shows that if users’ interests are kept in mind, frictionless sharing should remain an option, not the default.

II.  Social Readers and Other Privacy Law Battles

Coincidentally or consequentially, the legal debate over privacy and media consumption has taken on new dimensions at the same time that companies move toward frictionless sharing.  As people on Facebook allow the Washington Post to broadly share every article they have ever read, others are fighting to protect reader records from third parties.

First, it’s important to address whether, and why, reader privacy is important.  Librarians are adamant about the importance of reader privacy.{{15}}  The American Library Association has affirmed a right to privacy for readers since 1939,{{16}} and states that “one cannot exercise the right to read if the possible consequences include damage to one’s reputation, ostracism from the community or workplace, or criminal penalties.  Choice requires both a varied selection and the assurance that one’s choice is not monitored.”{{17}}  This concern comes in part from a historical awareness of how the government might abuse knowledge of citizens’ reading material.  Reading material can be used by the government to track dissidence.  Famously, Joseph McCarthy released a list of allegedly pro-communist authors, and the State Department ordered overseas librarians to remove such books from their shelves.{{18}}  Imagine if social readers had existed during the McCarthy era—the government would have been able to check each person’s virtual bookshelf for blacklisted material.  With the advent of data mining, the reading choices that seem innocuous to you can cumulatively be indicative of patterns, intent, or allegiances to others, including law enforcement.{{19}}

The United States has surprisingly scattered law on the question of readers’ privacy.  There is no federal statute explicitly protecting it.  This means that companies are not specifically prohibited on a federal level from sharing your reading history with others.  In practice, librarians usually require a court order for the government to obtain reader records, and most states make that requirement explicit.{{20}} The PATRIOT Act famously raised ire from librarians by permitting the government under certain circumstances to request library patron records secretly and without judicial oversight.{{21}}

Although there is no federal reader privacy statute, related laws concerning library patrons exist in forty-eight states.{{22}}  Recently, there has been a push at the state level to expand protections for reader privacy beyond libraries.  The California Reader Privacy Act, which was signed into law in October 2011 and took effect in January 2012, extends the type of protections traditionally afforded to library patrons to all books and e-books, although it does not extend to other types of reading online.{{23}}  Government entities must obtain a warrant before accessing reader records, and booksellers or providers must be afforded an opportunity to contest the request.  Booksellers must report the number and type of requests that they receive.{{24}}  Requests made in the context of civil actions must show that the requesting parties are using the “least intrusive means” and have a “compelling interest” in the records, and must obtain a court order.

The First Amendment could arguably protect readers from the discovery of their reading history by the government or by third parties using the court system to obtain the information.  A series of cases have given rise to a standard protecting the anonymity of online speakers.{{25}}  Julie E. Cohen has suggested that the First Amendment should extend its protections to a similar right to read anonymously.{{26}}  However, there has not yet been a case where a litigant has successfully made this argument to protect digital reader records under the First Amendment.

We do have one federal law protecting user privacy during content consumption: the Video Privacy Protection Act (“VPPA”),{{27}} which prohibits the disclosure of personally identifiable video rental information to third parties without a user’s specific consent, and prohibits disclosure of the same to police officers without a warrant.{{28}}  This strangely precise piece of law arose after Supreme Court nominee Robert Bork had his video rental records disclosed in a newspaper.{{29}}

Companies have realized, however, that VPPA is a hurdle to their business models.  In December 2011, the House of Representatives passed H.R. 2471, amending VPPA to allow the disclosure of video rental records with consent given in advance and until that consent is withdrawn by the consumer.{{30}}  This change would allow companies such as Netflix to get a one-time blanket consent to disclose user records through frictionless sharing on Facebook.  The Senate Judiciary Committee held a hearing on H.R. 2471 on January 31, 2012, at which many privacy concerns were raised.{{31}}

III.  Oversharing

Those who currently use social readers may be sharing their reading activity far more broadly than they expect.  Your close friends are not the only ones who can see your Facebook profile.  A Freedom of Information Act (“FOIA”) lawsuit by the Electronic Frontier Foundation revealed that law enforcement agencies use social media to obtain information about people by going undercover on social media sites to gain access to nonpublic information.{{32}}  And even if no police officer or other informant has posed as a friend of yours, using a social network to broadcast your reading records means you have shared those records with a third party—the social network itself—which under United States v. Miller means the police may not need a warrant to obtain those records from the social network.{{33}}

Perhaps more significantly, even if we get rid of the Miller doctrine, as Justice Sotomayor recently suggested, the wholesale sharing of your reading history with Facebook friends may ultimately impact the Supreme Court’s understanding of what constitutes a “reasonable expectation of privacy.”{{34}}  In the 1967 seminal Supreme Court case on wiretapping, Katz v. United States, Katz placed a phone call in a public phone booth with the door closed, and was found to have a reasonable expectation of privacy in the phone call, so a warrant was required for wiretapping the phone.{{35}}  Justice Alito recently contemplated that we may be moving toward a world in which so many people share information with so many friends that social norms no longer indicate a reasonable expectation of privacy in that information.{{36}}  Without a reasonable expectation of privacy, there will be no warrant requirement for law enforcement to obtain that information.  This analysis is troubling; sharing information with your friends should not mean that you expect it to be shared with law enforcement.  This would be like saying that just because you sent wedding invitations to 500 of your closest friends, the government is justified in opening the envelope.  The size of the audience for private communication should not change the fact that it is private.

The recent trend toward social readers and other types of frictionless sharing may at first glance seem innocuous, if inane.  But it has occurred just as privacy advocates are pushing to create more privacy protections for readers through state laws, and may result in the loss of VPPA, the one federal law that protects privacy in content consumption.  And users may not understand that sharing what they read with friends may mean sharing what they read with the government, as well.  That is a whole lot more serious than just annoying your friends with your taste for celebrity gossip.  Indeed, it may be another step toward the death of the Fourth Amendment by a thousand cuts.{{37}}

* Research Scholar in Law and Lecturer in Law at Yale Law School, and Executive Director of the Information Society Project at Yale Law School.

By: M. Ryan Calo

Professor Patricia Sánchez Abril opens her article, Private Ordering: A Contractual Approach to Online Interpersonal Privacy, with a profound insight: online interpersonal privacy suffers from a case of broken windows.[1] By “broken windows,” Professor Abril refers to the well-evidenced phenomena that instances of minor disrepair can promote an overall environment of antisocial behavior.[2] Just as a building with one broken window will almost certainly have many more, so could other contexts degenerate if small infractions go visibly unaddressed.

There may be times when upholding an agreement of confidentiality is not in the public interest and even the mantle of law is overkill. For instance, what if a student’s use of a social network reveals that she is a danger to herself or others, but her peers have all contracted not to say anything?

Professor Abril invokes the metaphor of broken windows in the context of online interpersonal privacy to illustrate “the role of norms vis-à-vis legal rules in shaping human behavior.”[3] Specifically, she believes that some combination of four factors—the dominance of sharing-culture, the lack of close-knit groups, the dearth of opportunities for user control over data, and the misapplication of contract law—“conspire to create a public perception of ambivalence toward breaches of interpersonal privacy, perpetuating social disorder.”[4] Professor Abril ultimately “calls on the power of contract to create context and thereby address many online interpersonal privacy concerns.”[5]

I agree with much of Professor Abril’s sophisticated reframing of the problem.  I also see promise in her proposal to leverage contracts to combat a perception that “anything goes” on the Internet.[6] In particular, I appreciate the role Professor Abril has in mind for contract law: not just to create enforceable rights, but more importantly, to signal the solemnity of the transaction.  In her words: “Even when not readily enforceable by legal means, the mere existence of a contract serves the important role of expressing and establishing social norms.”[7]

Indeed, one way to challenge Professor Abril’s argument is to question whether contracts formed in the way she describes will carry any legal water at all.  Arguably, they will not.  Creative Commons gains force from copyright law, which provides an affirmative right that the right holder may then pare back or renounce.[8] The same is not true where, as in interpersonal privacy, there is no underlying statutory right.[9]Even if we agree that opening an e-mail or accepting a friend request can constitute both consideration and assent for purposes of contract formation, it is hard to imagine how damages might be calculated.  Professor Abril concedes at length that damages may prove an insurmountably high hurdle to recovery of a successful claim.[10]

In many ways, observing that a system of interpersonal contracts may in practice be unenforceable misses the point.  What Professor Abril seems to be after is “a new set of norms;”[11] she wants to leverage the formality of contract law to “create context.”[12] Regardless of whether a court would permit recovery for a breach of Professor Abril’s protocol, the very use of that protocol—its mere existence—tends to combat the prevailing cavalier attitude toward interpersonal privacy that we see today.[13] It helps mend the broken windows.

But this observation raises a second question: if all we are doing is signaling, ought we not to prefer a nonbinding, norms-based approach to online communication such as that championed by Jonathan Zittrain and Lauren Gelman?[14] These authors eschew the use of law per se in favor of a model based outright on principles of neighborliness.  There may be times when upholding an agreement of confidentiality is not in the public interest and even the mantle of law is overkill.  For instance, what if a student’s use of a social network reveals that she is a danger to herself or others, but her peers have all contracted not to say anything?[15]

Both models suffer, incidentally, from a common limitation.  No matter how user-friendly the signal is, when faced with too much signaling, users may begin to tune it out.  What effect will a sea of icons, or the need to click assent for every bit of content, have on the average user?  Judging by the literature on information overload generally, and “wear out” specifically, there is a danger users will become inured to even a standardized system of online communication.[16]

This brings me to a final point about how best to improve a social environment.  What is interesting about the broken windows theory is not necessarily that vandalism influences norms; presumably there are many phenomena that influence norms.[17] It is that broken windows are features of the physical environment—they are a form of architecture.[18]

Professor Abril is hardly unaware of the importance of design, as evidenced by her condition that user-to-user contracts be “user-friendly” and “standardized.”[19] Importantly, she is also aware of the existence of literature in psychology suggesting that the form of social interactions helps dictate its content.[20] She nevertheless underemphasizes what I consider to be a crucial point: the very design of a website has a powerful effect on user experience.  Many of the problems we face online result directly from design decisions that we could—and in some cases, ought to—revisit.

Consider the broken window of oversharing.  Design is instrumental both to promote and to combat this ostensible problem.  Social networks in particular are built to make sharing as attractive as possible.  Status-update fields loom large at the top of the screen, beckoning participation.  Comment fields are prepopulated with the user’s picture as though she has already begun to comment (might as well do so!).  These design decisions are not accidental.[21] Meanwhile, sharing content online has immediate, positive effects, whereas the downsides to sharing are not immediately felt.[22] The undergraduate deciding to share pictures of last night’s party probably has his fraternity brothers, not prospective employers, in mind.  He experiences positive feedback in the form of comments and “likes”; he may never know why he did not get that job.

Or consider the insight that people are more likely to disclose personal details to websites that are casual in design, as opposed to formal.  In a study by Leslie John and her colleagues, subjects were more likely to admit to controversial conduct when the study was presented in a silly, playful format.[23] This insight has policy repercussions.  We are ostensibly most concerned with the online disclosure behavior of children, for instance, so much so that we have a special law around it.[24] And yet what are the most casual websites on the Internet, including with respect to online forms that collect information?  The kids don’t stand a chance.

A more direct and potentially more effective way to address online privacy’s broken windows is to examine the design of websites themselves—windows, in a sense, onto the Internet.  What we need in privacy, I believe, is a set of architectural values—both aesthetic and systematic—capable of transforming the web experience in ways that promote public policy goals such as privacy and security.  In the 1970s, architect Oscar Newman revolutionized public housing by introducing the concept of defensible space.[25] We need an Oscar Newman for online privacy.

How might the design of websites, phones, energy meters, and other products help provide the user with an accurate mental model of data practice?  How might we empower users to frame their content in ways that limit abuse without recourse to contracts or even words?  These are the challenges that Acquisiti, Nancy Kim,[26] Woodrow Hartzog,[27] and others have started to address in their work (and which underpin my own notion of nonlinguistic or “visceral” notice).[28] In a sense, this Article is not a response to Professor Arbil’s thought-provoking and well-argued article.  It is an invitation.  Professor Abril ought to take her own metaphor more literally.

