United States v. RodriguezUnited States v. Rodriguez
Thе main issue in this appeal is whether the prying by a former bureaucrat is criminal: that is, whether the defendant violated the Computer Fraud and Abuse Act, which prohibits “intentionally accessing] a computer without authorization or ex-eeed[ing] authorized access, and thereby obtaining] ... information from any department or agency of the United States.”
I. BACKGROUND
From 1995 to 2009, Roberto Rodriguez worked as a TeleService reрresentative for the Social Security Administration. Rodriguez’s duties included answering questions of the general public about social security benefits over the telephone. As a part of his duties, Rodriguez had access to Administration databases that contained sensitive personal information, including any person’s social security number, address, date of birth, fathеr’s name, mother’s maiden name, amount and type of social security benefit received, and annual income.
The Administration established a policy that prohibits an employee from obtaining information from its databases without a business reason. The Administration informed its TeleService employees about its policy through mandatory training sessions, notices posted in the office, and a banner that appeared on every computer screen daily. The Administration also required TeleService employees annually to sign acknowledgment forms after receiving the policies in writing. The Administration warned employees that they faced criminal penalties if they violated policies on unauthorized use of databases. From 2006 to 2008, Rodriguez refused to sign the acknowledgment forms. He asked a supervisor rhetorically, “Why give the government rope to hang me?” To monitor access and prevent unauthorized use, the Administration issued unique personal identification numbers and passwords to each TeleService employee and reviewed usage оf the databases.
In August 2008, the Administration flagged Rodriguez’s personal identification number for suspicious activity. Administration records established that Rodriguez had accessed the personal records of 17 different individuals for nonbusiness reasons. The Administration informed Rodriguez that it was conducting a criminal investigation into his use of the databases, but Rodriguez continued his unauthorized use. None of the 17 victims knew that Rodriguez had obtained their personal information without authorization until investigators informed them of his actions.
Most of Rodriguez’s victims testified at trial. Cecilia Collins was married to Rodriguez from 1985 to 1990. In 2008 and 2009, Rodriguez used the Administration databases to determine how much Collins
Sally Culver lived with Rodriguez from 2001 to 2005. She testified that she had not spoken with Rodriguez since 2005. Culver testified that on one occasion, when she complained to Rodriguez about pay disparities at her place of work, Rodriguez stated that, if Culver gave him the name, birth date, and approximate age of a coworker, then he cоuld tell her how much that coworker earned. Culver declined Rodriguez’s offer and did not provide him the coworker’s name. Rodriguez also accessed the personal information of Culver’s father for nonbusiness reasons. Rodriguez also told Culver that, if he was ever asked about his unauthorized searches, then he would make up an explanation. In 2008 and 2009, long after Culver and Rodriguez ended their relationship, Rodriguez accessed Culver’s personal information 62 times.
Theresa Ivey had worked with Rodriguez at a post office, but Ivey had not spoken to Rodriguez since 1999. Ivey’s daughter testified that she met Rodriguez in 1993 when she was a child. In 2008, Rodriguez accessed Ivey’s personal information twice and her daughter’s personal informatiоn 22 times.
Diamselis Rodriguez worked at a restaurant that Rodriguez frequently visited. Rodriguez gave Diamselis a pair of earrings on her birthday. In 2008, Rodriguez accessed Diamselis’s personal information 20 times.
Dana Fennell, a professor of sociology from Mississippi, testified that she met Rodriguez at a Unitarian Universalist church study group when she was visiting her parents in Florida. Fennell interviewed Rodriguez for a study on the health effects of religion, but she did not consider him to be a friend. After Fennell returned to her home in Mississippi, she received flowers from Rodriguez on Valentine’s Day even though she had not given Rodriguez her address. Rodriguez later arrived at Fennell’s doorstep unannounced, and Fennell was surprised and frightened by his presence. On another occasion, Rodriguez mentioned Fennell’s father’s birthday to Fennell even though she had never mentioned her father to Rodriguez. Rodriguez also told Fennell that he had the ability to listen to the telephone conversations of others. Rodriguez later called Fennell to wish her a happy “half-birthday” although she did not recall telling Rodriguez her date of birth. Rodriguez accessed Fennell’s personal information on Administration databases 65 times, and he accessed the personal information of Fennell’s mother and father multiple times.
Jessica Fox also met Rodriguez at the church study group. Fox testified that she received a letter from Rodriguez at her home address and was shocked because she had not given Rodriguez her address, she ordinarily receives all her mail at a post office box, and her middle initial was on the envelope although she had not used it since grade school. Rodriguez accessed Fox’s personal information 45 times.
Rodriguez accessed the personal information of several other women he met at the church study group. Annemarie Jiоvenetta considered Rodriguez to be an acquaintance, and Rodriguez accessed Jiovenetta’s personal information 23 times. Joan Ginnell considered Rodriguez to be her friend, and she testified that he seemed romantically interested in her. Rodriguez accessed Ginnell’s personal information 30 times. Catherine Schuman avoided Rodriguez after it became apparent that he wanted a romantic relationship with her, and Rodriguez attempted to access her information 29 times. Rodriguez
On April 2, 2009, a grand jury indicted Rodriguez with 17 misdemeanor counts of violating the Computer Fraud and Abuse Act. The indictment charged Rodriguez with “intentionally accessing] a computer without authorization or exceeding] authorized access, and thereby obtaining] ... information from any department оr agency of the United States.”
During his opening statement, Rodriguez’s attorney conceded that Rodriguez had “access[ed] things that were unauthorized.” Rodriguez also testified in his defense and admitted accessing the personal information of the victims. Rodriguez testified that he had accessed the personal information as part of a whistle-blowing operation to test whether his unauthorized use of the databases would trigger the attention of the Administration because he was conducting an investigation into improper denials of disability benefits. Rodriguez admitted that he did not access the victims’ records as a part of his duties as a TeleServiee representative. On July 29, 2009, the jury rejected Rodriguez’s argument about his cоnduct and returned a guilty verdict on all 17 counts.
The presentence investigation report provided a statutory maximum sentence of one year of imprisonment,
After considering the statutory factors for sentencing,
II. STANDARDS OF REVIEW
Two standards of review apply in this appeal. We review questions of statutory interpretation
de novo. United States v. Rahim,
III. DISCUSSION
Our discussion of this appeal is divided in two parts. We first discuss whether Rodriguez’s conduct supports a conviction under section 1030(a)(2)(B). Next, we dis
A. Rodriguez Exceeded His Authorized Access Under Section 1080(a)(2)(B) When He Accessed Personal Records for Nonbusiness Reаsons.
Rodriguez argues that he did not violate section 1030(a)(2)(B) because he accessed only databases that he was authorized to use as a TeleService representative, but his argument ignores both the law and the record. The Computer Fraud and Abuse Act makes it a crime to “intentionally aecess[] a computer without authorization or exсeed[] authorized access, and thereby obtain[ ] information from any department or agency of the United States.”
Rodriguez contends that the interpretation of the Act by the Ninth Circuit in
LVRC Holdings LLC v. Brekka,
Rodriguez also relies on
United States v. John,
B. Rodriguez’s Sentence is Reasonable.
Rodriguez argues that his sentence of 12 months of imprisonment is unreasonable both procedurally and substantively. The party challenging a sentence has the burden of establishing unreasonableness.
United States v. Talley,
The district court committed no procedural error. A sentence is procedurally unreasonable if the district court erred by “failing to calculate (or improperly calculating) the Guidelines range, treating the Guidelines as mandatory, failing to consider the
Rodriguez argues that his sentence is procedurally unreasonable because the district court should not have considered that there were multiple victims in its decision to vary upward because an enhancement under section 2Bl.l(b)(2)(A) of the sentencing guidelines was the “proper mechanism” for considering multiple victims, but we disagree. This Court has held that a district court can rely on factors in imposing a variance that it had already considered in imposing an enhancement,
United States v. Amedeo,
Rodriguez’s burden of establishing that his sentence is substantively unreasonable is heavy.
See Gall,
Rodriguez’s sentence is substantively reasonable. Rodriguez argues that the sentence of 12 months of imprisonment is unreasonable because he is 54 years old, he has no prior criminal history, the offense was nonviolent, and he has already lost his job as a result of his actions, but the district court considered Rodriguez’s personal characteristics and reasonably determined that an upward variance of six months was necessary to reflect the seriousness of the offense, promote respect for the law, and protect the public from future criminal conduct by Rodriguez. The district court was entitled to find that an upward variance was warranted based on the number of victims and the extensive nature of Rodriguez’s unauthorized access. Although Rodriguez did not use the information he obtained to commit another crime, he used the information in a manner unwelcomed by his victims. Rodriguez’s sentence of 12 months of imprisonment does not lie outside the range of reasonable sentences.
See McBride,
IV. CONCLUSION
The judgment of the district court is AFFIRMED.