Storage & Shredding: Expert Advice

Records Management that Doubles as Risk Management

Posted by Arielle Burdulis on Mon, Mar 19, 2012 @ 01:19 PM

Have you made sure your data is safe? If not, there is a chance it will cost you financially. It could ruin your reputation as well.

In a recent news story, MetLife, headquartered in New York City, whose revenues topped $50 million in 2008, felt the effect of laws involving data storage security. Because they failed to use records management as risk management, they were fined $70,000. Apparently, when they moved from one location to the next, they discarded a lot of trash in the dumpsters outside the office. In it were sensitive records containing social security numbers, addresses and financial account information of people who were current and former clients of MetLife. The hard copy files remained in dumpsters outside the building for well over three days. During this time, anyone could have acquired the information and used it for identity theft.

In North Carolina, a news article from 2010 about Prompt Med spoke of a $50,000 fine, from the urgent care unit having thrown into a dumpster sensitive information including financial accounts and identification numbers of over 700 patients. Records management as risk management would have clearly helped here.

The Carolina Center for Development and Rehabilitation was highlighted in this article for having illegally disposed of the financial information of nearly two thousand patients in 2011. The fine for this was $40,000. The senior officers had plenty of warning about records management as risk management from the above previous incidents, but did not learn from it.

More and more information these days must be secured and companies are having to treat records management as risk management. With the advent of identity theft, any written, electronic, or printed records must be protected if they include personal information about a client. And if the records are to be discarded for any reason, they must be destroyed in a proper fashion, so that the information contained within is kept safe. From this was born the idea of records management as risk management.

Risk management rpocedures are extremely important to implement to prevent Identity theft. Identity theft is any person's personal information being used by another to illegally remove money from bank accounts, acquire loans and passports and commit other crimes. Identity theft is now also known as identity fraud.

There are state and federal laws in place across the country to ensure that the destruction of certain files is done so properly, in order to prevent Identity theft. If proper measures are not take, then the company responsible for not following the precautions can be given some fairly big fines.

In Massachusetts, the laws that aid in the prevention of identity theft are called the General Law 93H and 93I, and are applicable to all companies in the state of Massachusetts secure all data that include personal information, such as bank account numbers, credit and debit card numbers, and the like that have the ability to create identity theft opportunities.  

In addition, each company must have safeguards, by the employment of valid identification systems, in order to keep non-authorized personnel from gaining access through computers, or in hard copy files. The company must also keep all locations safe from outside the company. On a regular basis, companies shall be audited to ensure they within compliance. According to the 93I, a company must document the policy of their destruction procedures.

The fines for non-compliance of 93H requires for the company to pay five thousand dollars for each record that was not kept safe. For 93I, the fine is one hundred dollars for each record, with a cap of fifty thousand dollars. These ordinances came into law in 2005.

In addition to state laws, The Federal FACTA Disposal Rule maintains any person or business using consumer reports must make sure all the information within those reports remain completely secure when discarded.

In summary,the risks that someone takes for improper document disposal are inexplicable. Primarily, risks cannot be taken anymore because it is the law to practice safe and secure document disposal, but secondly when there are a multitude of risk management strategies available through document shredding and management companies, how can someone not take advantage of a simple way to reduce risk?

Need to start managing your risk? Or change your strategy? We can help... click on any of the buttons below to be on your way to a risk management solution!

 

 Click me Click me  Green Customized Shredding Quote

 

Tags: data protection, compliance laws, Records management, shredding worcester, Massachusetts State Laws, Office Records Destruction, 93I, Federal FACTA, 93H, Records Retention, HIPAA, document management, Document Destruction regulations, compliance, federal regulations, document shredding services worcester, records storage worcester, Certified document destruction, identity theft, shredding boston