LTN Law Technology News
  • Home
  • News
  • Reviews
  • Commentary
  • Surveys
  • Events
  • LegalTech® Directory
  • About LTN
  • Register
  • Topics:
  • E-Discovery & Compliance
  • Litigation Support
  • Practice Management
  • Office Tech
  • Mobile Lawyer
  • Research & Libraries
  • Tech Law

Home > How to Prevent Employee Theft of Your Obsolete IT Equipment

Font Size: increase font decrease font

How to Prevent Employee Theft of Your Obsolete IT Equipment

By Kyle Marks All Articles 

Law Technology News

March 7, 2013

  •    
  •    
  •    
  •       Comments (1)
 
Kyle Marks, founder and CEO of Retire-IT

Kyle Marks, founder and CEO of Retire-IT

Photo of a junk pile of computers

Image: Anna Vignet

In retail, employee theft can be worse than shopper theft. Employees can easily learn the internal operations of a store. In some ways, the same can be said for theft inside a business. Employees have access to equipment and knowledge of which equipment will be missed and which won't.

As businesses struggle with strained budgets, information technology departments are becoming overworked and understaffed. Important security precautions turn into secondary priorities as employees focus on immediate needs. Some companies run out of time and resources to carefully screen potential hires, allowing questionable characters to become staff members. This combination of factors has led to an alarming vulnerability in the security of company data.

Once a piece of computer equipment has been relegated to the scrap heap, most business owners and CEOs write it off as no longer a part of the company inventory. However, the hard drives inside laptops, PCs, mobile devices, and even multifunction copiers, contain sensitive data about your business and your customers. If an employee steals a piece of equipment and gives it away or sells it, that sensitive data could end up in the hands of someone who will use it or sell it.

Before you dispose of one more piece of equipment, consider these possible revisions in policy and procedures that could protect your company against data leakage. Below are a few tips to follow that will help to prevent your disposed equipment from becoming a liability.

KNOW THE LAW

It is one thing for an inexperienced internet user to be unaware of public Wi-Fi risks or a trusting Facebook user to be oblivious of privacy risks. It is another thing for an organization to ignore the threat of employee theft of retired equipment. Last year, the U.S. Department of Health and Human Services, Office of Civil Rights (OCR) stressed that organizations must "have in place meaningful access controls to safeguard hardware." Effective safeguards must include all equipment, even retired equipment. The OCR also stressed that they "expect organizations to comply with their obligations" — ignorance is no longer a valid excuse for noncompliance.

RECOGNIZE THE CONSEQUENCES

It should be no surprise that the OCR has begun to apply unprecedented sanctions for violating the security and privacy regulations in the Health Information Portability and Accountability Act. There is no doubt that penalties can be punitive. However, the indirect costs of dealing with a breach and the impact of a privacy class action lawsuit can be much worse than penalties.

In May, the OCR fined BlueCross BlueShield of Tennessee $1.5 million for violations following the theft of 57 unencrypted retired hard drives. The cost of the fine was just the tip of the iceberg. In addition to the penalty, BCBST reportedly spent $17 million in investigation, notification, and protection efforts.

In July, eight separate privacy lawsuits filed against healthcare benefits provider TRICARE were consolidated to one case to be heard by a U.S District Court. The suits stem from the loss of a backup data tape and allege that TRICARE and its subcontractor were negligent for failing to respond to "recurring, systemic, and fundamental deficiencies in its information security." One suit was seeking an astounding $4.9 billion in damages.

A browser or device that allows javascript is required to view this content.

Continue reading

  • 1
  • 2
  • 3

Next



Subscribe to Law Technology News

You must be signed in to comment on an article

 

Reader Comments

  • Elaine Senra

    March 11, 2013 07:43 AM

    Excellent Article!

Comments are not moderated. To report offensive comments, click here.

Post a Comment »
Find similar content

Companies, agencies mentioned

    
  • AND POST POLICIES While
  • MULTIPLE EMPLOYEES
  • Tricare
  • Office of Civil Rights
  • ACCESS Store
  • US District Court
  • United States Department of Health and Human Services

Key categories

    
  • Information Security

Most viewed stories

    
  1. Big Law Whipped for Poor Tech Training
    •      
  2. 10 Devices You Should Never Take Along on a Business Trip
    •      
  3. Is Stanford Law the New Vortex of Legal Technology?
    •      
  4. Using Computer Forensics to Investigate IP Theft
    •      
  5. How the Predictive Coding Process Will Affect Paralegals
    •      
  6. Collaboration Is Key to Defending Cyberattacks
    •      
  7. ILTA Study to Gauge New Technologies' Impact on Law Practice
    •      
  8. Enron Sandbox Stirs Up Private Data, Again
    •      
  9. CEIC: the Destination for Digital Investigation
    •      
  10. Cisco E-Book Delivers Ethics on the Go
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Hiring Interns? Be Sure to Do It Right

ACC Weighs in on Arizona's In-House Pro Bono Rules

Ex-Dewey Partners Face New Foe in Firm's Bankruptcy

S&C Adds Linklaters Restructuring Partner in London
  •      
    • Subscription Required

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Enron Sandbox Stirs Up Private Data, Again

LegalTech West Coast Wraps Up With Ethics, VC News

In Tricky Prosecutions, Judges Play Peacemakers

Ropers Majeski Tries to Re-Invent Itself
  •      
    • Subscription Required

Fla. Attorneys Lead Force-Placed Insurance Fight

Lawsuit Names Missing Fla. Attorney for Alleged Fraud
  •      
    • Subscription Required

Summer Programs Still in a Drought

Lawyer Not Covered for Alleged Malpractice at Prior Firm
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Firm Takes Another Hit in Bid for 'Unconscionable' Fees

New York's Martin Act Faces Test in Challenge to 2005 Case

Castille Testifies in Favor of 'Civil Gideon' Funding

Workers' Comp Judges Can't Fight Rescinded Raise
  •      
    • Subscription Required

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Advising Clients on Weather and the Workplace
  •      
    • Subscription Required

Texas Sues BP, Others Over Deepwater Oil Spill Disaster
  •      
    • Subscription Required

'Follow That Escapee!'

Judge Who Tossed Defense Counsel Accused of 'Partiality'
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About LTN   |
  • Contact LTN   |
  • Advertise with Us   |
  • Sitemap
  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media