I’m thrilled to announce that Bedard Law Group is the new sponsor for the Compliance Digest. Bedard Law Group, P.C. – Compliance Support – Defense Litigation – Nationwide Complaint Management – Turnkey Speech Analytics. And Our New BLG360 Program – Your Low Monthly Retainer Compliance Solution. Visit www.bedardlawgroup.com, email John H. Bedard, Jr., or call (678) 253-1871.
Every week, AccountsRecovery.net brings you the most important news in the industry. But, with compliance-related articles, context is king. That’s why the brightest and most knowledgable compliance experts are sought to offer their perspectives and insights into the most important news of the day. Read on to hear what the experts have to say this week.
Court Faults Bank’s Investigation of ID Theft Dispute, Lets FCRA Claim Go Forward
A District Court judge in California has granted a defendant’s motion for summary judgment that it did not violate the Fair Debt Collection Practices Act but denied the motion over claims it violated the Fair Credit Reporting Act by not reasonably investigating an identity theft dispute, partially because it did not compare call recordings against one another going back eight years. More details here.
WHAT THIS MEANS, FROM VIRGINIA BELL FLYNN OF TROUTMAN PEPPER LOCKE: This ruling highlights the challenges furnishers face to prevail on summary judgment on a FCRA 15 U.S.C. § 1681s-2(b) reasonable investigation claim. The question of whether an investigation was reasonable is often a highly factual determination that courts are reluctant to grant summary judgment on.
Recent developments in case law have established that a FCRA claim must be based on a “readily and objectively verifiable” credit dispute. This is a relatively new and continues to be litigated throughout the country. Notably, here the court determined that the credit reporting dispute was “readily and objectively verifiable” distinguishing other cases where credit disputes about validity of the debt due required contract interpretation were legal questions and, therefore, not readily verifiable. In this case, the court found that whether the plaintiff was the person who opened the account was readily verifiable and not a legal question beyond the reach of a FCRA reasonable investigation claim. The court relied heavily on the fact that, during the investigation, the furnisher did not compare call recordings, some of which sounded like calls with somebody other than plaintiff, suggesting those calls were made by the alleged fraudster. This highlights the importance of furnishers reviewing all relevant materials in their file as well as external information where applicable to satisfy the “reasonable investigation” requirement of FCRA, especially where the ACDVs contain dispute code 103 and include an ID Theft Affidavit or police report.
THE COMPLIANCE DIGEST IS SPONSORED BY:
Appeals Court: One Unwanted Letter After Cease Request Not Enough for Standing
The Court of Appeals for the Eighth Circuit has reversed a lower court’s summary judgment ruling in favor of a plaintiff where the defendant was ordered to pay $60,000 in attorney’s fees, ruling that receiving a letter after a cease request was sent is not enough for the plaintiff to have standing to pursue her Fair Debt Collection Practices Act lawsuit. More details here.
WHAT THIS MEANS, FROM STEFANIE JACKMAN OF TROUTMAN PEPPER LOCKE: This decision offers a sensible and reasonable outcome. Kudos to the Eighth Circuit for recognizing this claim for what it is: an obvious and transparent attempt to manipulate the system by asserting a dispute that, at best, the consumer does not genuinely care about resolving one way or the other. As the court noted, this sort of legal manipulation should be sanctioned if perpetrated by an attorney. Letters like the one at issue here are sent thousands of times a day to creditors and collectors in order to place them in an impossible situation. Hopefully, other courts will follow suit and start clearing their dockets of these frivolous claims.
Court Rejects MTD, Says 1692e(8) Claim Doesn’t Require Written Dispute
A District Court judge in Georgia has denied a defendant’s motion to dismiss a Fair Debt Collection Practices Act, ruling that the plaintiff did not have to submit a dispute in writing in order to allege the defendant violated Section 1692e(8) of the statute. More details here.
WHAT THIS MEANS, FROM DAVID SCHULTZ OF HINSHAW & CULBERTSON: For a long time, it seemed like 1692g and the initial communication timeframe were the genesis of the highest percentage of FDCPA claims. We now see a lot of 1692e dispute claims. Often those claims arise because the communication that contains a dispute is not particularly clear (for instance, it raises many issues and does not specificly say “dispute”). This court confirmed that the dispute does not need to be in writing and oral disputes should also be accepted, which can mean that the credit reporting tradeline should be noted with a dispute. (FYI, a new battle involves what dispute notation should be used but that is an issue for a different column).
One benefit to 1692e is that it includes that the collector must “know or should have known” about the dispute. That, and 1692k BFE, may provide a defense to these types of claims.
N.Y. Appeals Court Joins Majority in Rejecting Hunstein-Based FDCPA Claims
In a case that was defendant by Jonathan Robbin at J. Robbin Law, a New York Appeals Court has reversed a lower court’s ruling and granted a defendant’s motion for summary judgment in a Hunstein third-party disclosure case, ruling that the use of a mail vendor to contact a consumer in a legitimate attempt to collect a debt is “not a practice the [FDCPA] was meant to prohibit.” More details here.
WHAT THIS MEANS, FROM CRYSTAL DUPLAY OF FROST ECHOLS: Plaintiff David Ginocchio filed suit against Resurgent Receivables, LLC, alleging that Defendant Resurgent shared Ginocchio’s private information with a third-party mailing vendor without his consent. Resurgent demonstrated that using a mailing vendor to contact a consumer for legitimate debt collection is not deceptive or misleading, and thus not a violation of NYGBL §349. Similarly, the appellate court held that FDCPA doesn’t prohibit debt collectors from using mailing vendors. Resurgent’s conduct was therefore not unlawful under the FDCPA nor under NYGBL §349. The decision underscores that routine business practices, such as using mailing vendors, are not per se deceptive or fraudulent under these statutory frameworks.
CFPB Reopens Rulemaking on Personal Financial Data Rights
The Consumer Financial Protection Bureau today issued an Advance Notice of Proposed Rulemaking, to revisit its open banking rule, known as the Section 1033 rule, under the Dodd-Frank Act. The move follows a Kentucky district court’s stay of a lawsuit challenging the 2024 rule, which was criticized for exceeding statutory authority and risking consumer data security. More details here.
WHAT THIS MEANS, FROM LESLIE BENDER OF EVERSHEDS SUTHERLAND: As promised, the Consumer Financial Protection Bureau (the “CFPB”) has begun the process it reports that it will expedite to revise and reissue Open Banking Rules under Section 1033 of the Consumer Financial Protection Act (“CFPA”). Developing interpretive rules under this section of the CFPA has presented a challenge to each of the CFPB’s leaders since the agency’s inception. What is interesting now is that the current CFPB leadership has agreed with the plaintiffs in the Forcht Bank challenge, specifically that the last CFPB leaders exceeded their statutory authority in the version of rules they promulgated. Meanwhile, the White House and Congress have promoted the idea of the US being a crypto capital of the world, and arguably right-sized Section 1033 Open Banking rules could help further the current Administration’s objectives.
Another event to keep in your peripheral vision regarding Open Banking is the potential impact that Section 1033 rules might have on fintechs or other innovative financial institutions that meet consumers’ needs. Because industry’s compliance deadlines were approaching under Section 1033 so many financial institutions began taking steps and making public announcements about their support for open banking. The timing of the current CFPB leadership’s ask of the Forcht Bank court in Kentucky to stay proceedings to give it a chance to re-write the Section 1033 rules may coincidentally follow a public announcement JP Morgan Chase made that it would begin charging firms and fintechs for access to consumers’ data despite its public support for open banking to allow consumers “more seamless and secure payment choices.” See both https://www.jpmorgan.com/payments/solutions/open-banking and https://www.paymentsdive.com/news/fintechs-blast-jpmorgan-over-data-fees/753021/
Even if you have no plans to respond to any of the three dozen questions the new CFPB advance notice of proposed rulemaking (“ANPR”) lays out – industry is encouraged to review these questions for insight into what changes to the original final Section 1033 rules this CFPB may be planning. The ANPR published in the Federal Register on August 22 can be found right here. One final note, a motion to lift the stay in the Forcht Bank case (stayed at the CFPB’s request, without objection) for the limited purpose of postponing the Section 1033 Rule’s compliance deadlines was filed on August 13, but has not yet been granted or denied by the Court – to potentially give industry some breathing room for coming into compliance with Section 1033 regulations. Stay tuned for more details
Timing is Everything: Late Argument on Choice-of-Law Costs Collector in Fee Dispute
A Florida appeals court has reversed a lower court’s ruling and determined that a consumer is entitled to have his attorney fees covered by a collector that dismissed a collection lawsuit it filed, saying that the collector didn’t assert the choice-of-law provision from the underlying agreement soon enough in the proceedings. More details here.
WHAT THIS MEANS, FROM BRENDAN LITTLE OF LIPPES MATHIAS: A debt buyer commenced an action against a consumer in Florida state court asserting a cause of action for account stated based on an account the debt buyer acquired from Capital One. The consumer filed an answer and counterclaim against the debt buyer. Eventually, the debt buyer dismissed its account stated cause of action against the consumer. Pursuant to a Florida statute, the consumer, as the prevailing party, moved the Court to recovery his attorneys’ fees and costs. In response to the consumer’s motion, the debt buyer argued that the consumer’s motion should be denied because Virginia law governed the parties’ relationship, not Florida. The trial court agreed and denied the consumer’s motion for attorneys’ fees. On appeal, the Second District Court of Appeals reversed determining that the debt buyer waived its right on the choice of law argument because the debt buyer failed to articulate in its complaint or in response to the consumer’s counterclaim that Virginia law applied. As a result, the consumer was entitled to his attorneys’ fees as the prevailing party.
One Click, $2 Million: NY DFS Penalizes Company Over Phishing Breach
One customer service employee who clicked on one email has led to an enforcement action that will cost a company $2 million to settle with the New York Department of Financial Services, the regulator announced yesterday. More details here.
WHAT THIS MEANS, FROM MONICA LITTMAN OF KAUFMAN DOLOWICH: This consent order is a very costly example of why it is important to have robust policies and procedures in place for cybersecurity issues. A click on a phishing email by one of Healthplex’s employees led to over one hundred thousand emails containing private health data and non-public information (“NPI”) being compromised. The New York Department of Financial Services (“NYDFS”) alleged that Healthplex did not maintain a data retention and disposal policy. Such a policy could have resulted in the secure disposal of the NPI that is no longer necessary for business purposes and would minimize the amount of NPI that is accessible to an unauthorized third party during a cybersecurity event. The NYDFS also alleged that Healthplex failed to implement mandatory multi-factor authentication and did not timely notify NYDFS of the incident in accordance with New York’s cybersecurity regulation. New York’s cybersecurity regulation indicates that certain policies are not best practices but are mandatory. Now is the time to review and assess your agency’s security policies and employee training in an attempt to mitigate the risk of a cybersecurity incident.
I’m thrilled to announce that Bedard Law Group is the new sponsor for the Compliance Digest. Bedard Law Group, P.C. – Compliance Support – Defense Litigation – Nationwide Complaint Management – Turnkey Speech Analytics. And Our New BLG360 Program – Your Low Monthly Retainer Compliance Solution. Visit www.bedardlawgroup.com, email John H. Bedard, Jr., or call (678) 253-1871.












