Polsinelli Shughart PC

Our AttorneysAttorneys

Ari M. Bai
Randy L. Canis
Corey Casey
Elton F. Dean III
Brian B. Diekhoff
Kathryn J. Doty
Gregory P. Durbin
Robert O. Enyard Jr.
Jeffrey E. Fine
Judith S. Heeter
Christopher L.E. Hines
Todd S. Hofmeister, Ph.D
Paul A. Jenny
Timothy J. Keefer
J. Morgan Kirley
Gregory M. Kratofil Jr.
Philip N. Krause
Glenn H. Lenzen
David J. McCrosky
Lisa L. Mueller
Andrea M. Porterfield
Rebecca Riley-Vargas, Ph.D
Kelley A. Schnieders
Teddy C. Scott, Ph.D
Matthew J. Smith
Timothy D. Steffens
James M. Stipek
Richard P. Stitt
Lawrence A. Swain
Micah D. Trotti
Tracey S. Truitt
Patrick C. Woolley

 

To learn more about
our Science and
Technology group,
click here.

 

 

June 2010
    

A Polsinelli Shughart Update:

Is Your Copier a Data Breach Waiting to Happen?

 

Prompted by a recent CBS News report on inadvertent disclosures of personal information stored on copy machine hard drives, the U.S. Federal Trade Commission (FTC) has begun contacting copier manufacturers and resellers to determine whether they are warning customers of potential data security vulnerabilities and providing options for secure copying. While the FTC may be investigating copier manufacturers and resellers, companies that own, lease or use copiers or similar multifunction printers need to be aware of the relevant data security issues in order to take proper steps to avoid an inadvertent security breach.

Almost every copier manufactured since 2002 contains a hard drive that stores documents copied, scanned and emailed by the machines. Sensitive personal information about a company’s customers and employees may be stored on those hard drives in the event documents containing that information were copied, scanned or emailed using the copier. As the CBS News investigation illustrated, many copier users are unaware that this personal information is being stored and many organizations fail to take the proper steps to ensure that this personal information is secured and destroyed (whether immediately after copying or upon disposal of the copier itself).

Many state and federal laws regulate the security measures used to maintain and dispose of personal information about individuals. Additionally, laws in almost every state (and federal laws governing certain industries) require a company that has experienced a data breach resulting in the unauthorized disclosure or acquisition of unencrypted personal information notify the affected individuals. Therefore, failing to properly secure and destroy personal information that may be collected by a copier could subject a company to onerous notification requirements, substantial liability and a public relations nightmare.

Just ask Affinity Health Plan. CBS News found personal information maintained by Affinity on a copier hard drive that it acquired during its investigation. Shortly after the report aired, Affinity notified over 400,000 customers and employees of the potential disclosure of their personal information (which included medical records).

Companies should review their present security policies and practices to determine the appropriate next steps, which may include the following:

  • Working with the manufacturer or reseller of the company’s copier to ensure document images are erased immediately or after a specified period of time
       
  • Developing an information security policy, or amending an existing policy, to address copier data security issues, including:
       
    1. Potential retention of documents and security of any networked copiers or similar devices
         
    2. Restrictions on the copying of documents containing personal information
         
    3. Prohibiting employees from using public copiers (e.g., those not controlled by the company) to copy documents containing personal information in the limited circumstances where such documents may be copied
         
    4. Ensuring any data retained on copier hard drives is destroyed in the appropriate manner based upon applicable legal/industry standards upon disposal of the copier at the end of its life
         
  • Placing warnings on copiers and adequately training employees to ensure that they are aware of the potential risks
 

For More Information

If you have any questions about these or other data privacy and security issues or if would like assistance creating or reviewing your policies to ensure they address these issues, please contact:

 

Polsinelli Shughart | In the News

Headlines and Bylines from polsinelli.com

To learn more about our RSS feeds, click here.

Polsinelli Shughart Expands Science and Technology Practice With Patent Attorney

Changing Workplace Issues Prompt Polsinelli Shughart and the Missouri Chamber of Commerce and Industry to Co-Produce Human Resources Manual

Client Advisory: Update: Qualifying Therapeutic Discovery Tax Credit Program

Get more news from polsinelli.com.

 

Click here to learn more about our RSS feeds.

 

About Polsinelli Shughart PC

With more than 500 attorneys, Polsinelli Shughart PC is a national law firm that is a recognized leader in the areas of business litigation, financial services, bankruptcy, real estate, business law, labor and employment, construction, life sciences and health care. Serving corporate, institutional and individual clients regionally, nationally and worldwide, Polsinelli Shughart is known for successfully applying forward-thinking strategies for both straightforward and complex legal matters. The firm can be found online at www.polsinelli.com.

 
   
With offices in Kansas City, St. Louis, Chicago, Denver, Phoenix, Washington DC, New York, Wilmington DE, Overland Park, St. Joseph, Springfield, Jefferson City, Topeka, Edwardsville

 

If you know of anyone who you believe would like to receive our e-mail updates, or if you would like to be removed from our e-distribution list, please contact Therese O'Shea.

Polsinelli Shughart PC provides this material for informational purposes only. The material provided herein is general and is not intended to be legal advice. Nothing herein should be relied upon or used without consulting a lawyer to consider your specific circumstances, possible changes to applicable laws, rules and regulations and other legal issues. Receipt of this material does not establish an attorney-client relationship.

Polsinelli Shughart is very proud of the results we obtain for our clients, but you should know that past results do not guarantee future results; that every case is different and must be judged on its own merits; and that the choice of a lawyer is an important decision and should not be based solely upon advertisements.

Polsinelli Shughart® is a registered trademark of Polsinelli Shughart PC.

 

Copyright

Copyright © 2010 Polsinelli Shughart PC.

 
Polsinelli Shughart PC