Volume 13, Issue 2
summer 2016
Security Shredding News Serving the Security Shredding & Records Storage Markets
Visit us online at www.SecurityShreddingNews.com
ATTENTION: READERS !
Are you looking for Products, Equipment or Services for your business? If so, please check out these leading companies advertised in this issue:
Collection & Storage Containers Bomac Carts – pg 7
Preparing for Safety:
Equipment Financing
Practice is Vital in Helping to Prevent Loss Due to Workplace Violence
TransLease Inc – pg 12
Lock & Locking Systems Lock America Intl. – pg 3
Mobile Truck Shredders Alpine Shredders Ltd – pg 9 Shred-Tech Limited – pg 8 Vecoplan, LLC – pg 6
Moving Floor System Keith Manufacturing – pg 2
Stationary Shredders & Grinders Shred-Tech Limited – pg 8 Vecoplan, LLC – pg 6
Trade Associations NAID/Shred School – pg 5 (National Association of Information Destruction) RIOS™ (Certified Electronics Recycler) – pg 11
A
By Jay Hart, Director of Force Training Institute
s the national conversation regarding violence in the workplace suggests a heightened awareness stemming from increased media coverage, recent studies suggest there may be statistical evidence supporting this perceived frequency. According to the U.S. Bureau of Labor Statistics, about five percent of all businesses experience an instance of workplace violence each year. For larger organizations with over 1,000 employees, this rate is increased tenfold to 50 percent. A 2014 report from the FBI found active shooter incidents in the U.S. now occur on an average of once a month. Of these incidents, almost (45.6 percent) occurred at a business while nearly a quarter (24.4 percent) occurred at Pre-K to 12 schools and institutions of higher learning. Although active threats and the environments where they take place can vary from incident to incident, the common threads found throughout can be woven together to create the fabric of an effective and successful safety program. The following are lessons learned gleaned from past experience that businesses can use as tools for building a solid foundation for a safety-minded workplace:
Mindset to Clear the First Hurdle
M
PRSRT STD U.S. Postage
PAID
Mentor, OH Permit No. 2
ore often than not, active threat training is the elephant in the room. Everyone has seen or heard of incidents, but are reluctant to take the steps toward mitigation. The reasons may vary from believing it’ll make employees more fearful than empowered to worrying the training might not be “right” for the team. However, looking the other way is not a solution to any problem, much less one with harmful consequences. The aforementioned statistics illustrate
an increasing probability of an active threat incident, making it less an if and more of a when. Unfortunately, violence doesn’t discriminate on where it can take place, so the entire enterprise – be it headquarters, warehouse, or storefront – should be involved in preventative measures. Breaking through the barrier of apprehension begins with a holistic approach: one team, one goal. Leadership should evaluate the type of training fitting for their organization’s culture, articulate the vital importance of such training to employees, and clearly explain how the training will be implemented. Additionally, engaging in regularly scheduled workplace safety drills can at first seem intimidating. Members of the organization may consider the suggestion a type of fear mongering. But, the reality is practice makes perfect and in an active threat environment it can save lives. Armed with this knowledge, leaders can lay out a response plan and develop methods for calmly introducing the need to rehearse said plan to
Continued on page 3
Inside This Issue
4
Regulatory Investigations Following a Reported Breach
4
What’s New with HIPAA?
7
New York Presbyterian Agrees to $2.2 Million Settlement of Filming of Patients
9
Stericycle’s Performance Dogged by Acquisition Integration Lags
10 NAID Installs New Board Members
www.youtube.com/user/KeithMfgCo
www.keithwalkingfloor.com
2 Security Shredding News Summer 2016
Security Shredding News
Preparing for Safety:
Practice is Vital in Helping to Prevent Loss Due to Workplace Violence Continued from page 1
PUBLICATION STAFF Publisher / Editor Rick Downing
Contributing Editors / Writers Jay Hart Eric A. Packel Shannon Hartsfield Salimone Sandy Woodthorpe
Production / Layout Barb Fontanelle Christine Pavelka
Advertising Sales Rick Downing
Subscription / Circulation Donna Downing
Editorial, Circulation & Advertising Office 6075 Hopkins Road Mentor, OH 44060 Ph: 440-257-6453 Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com
For subscription information, please call 440-257-6453 Security Shredding News (ISSN #1549-8654) is published bimonthly b y D o w n i n g & A s s o c i a t e s. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment. ©Copyright 2016 by Downing & Associates. Printed on Post-Consumer Recycled Paper
employees, just like fire drills, severe weather drills and other emergency procedures.
Flexible Response Plans Can Adapt
V
iolence is seldom a cookie cutter affair and as such a “one size fits all” response is likely an ineffective solution. Conversely, having too many threat-specific responses can be confusing, if not outright dangerous. While different threats do warrant varying responses, a series of “stovepipe” procedures can cripple a person with tunnel vision during a high stress scenario. All active threat response plans should be built upon the same principles so even if the minute details are lost in the heat of the moment, team members can still make informed decisions to ensure the safety of themselves and others. Streamlining processes encourages a quick implementation and retention of information. Knowledge increases confidence, confidence increases decisiveness, and it is decisive action in a critical incident that saves lives. With that said, practicing applying flexible response plans to a variety of threat situations is encouraged. Familiarizing employees with protocols for various weapon threats, single and multiple person attacks, bomb threats and other possibilities empower them to be able to push down panic and stick to the plan in the heat of the moment.
Clear Communication Plans
A
cohesive “one-team” mindset supported by a response plan based on fundamentals and foresight cannot take place without clear communication before, during, and after a critical incident. The language plays a critical role in an active threat response program and can dictate the program’s success or failure. Such language should be consistent with current policies and procedures so the program is both effective and legally defensible. Each company will need to tailor its active threat response plan to fit its culture and workplace environment. Thankfully, a simple concept utilized by premier agencies already exists so organizations may build a clear and coherent plan: “Run, Hide, Defend.” During drills, company leaders should notice incidences when employees are not utilizing proper language. If instances like this occur, additional training meetings should be scheduled to remind all employees of the importance of being able to communicate clearly and efficiently during a threat situation. Clearing any confusion before an incident occurs is essential to successful plan execution.
Rehearse All Roles
C
ommunication during a critical incident is by no means limited to employees, but extends to customer interaction as well. How the company communicates around and with customers during an active threat incident can play a vital role in minimizing harm and mitigating supplemental harm as a result of panic.
Every active threat mitigation plan should include an emergency communication strategy which may contain one or two common components: First is the use of a code like “Code Adam” alerting employees to a specific issue while customers and vendors remain unaware of any possible issues. The second option is to use “plain English” so that everyone quickly gains situational awareness. For example, instead of using “Code Red” for an active shooter incident, the alert would announce there is an active shooter situation in progress so employees, customers, and vendors can take decisive actions to seek safety. Whatever method of communication is determined best for an organization, during drills some employers should be designated as customers, vendors and any other third parties that may be present at a business during a threat. In addition to rehearsing how employees should interact, leaders should also analyze if employees know how to safely communicate the active threat plan to people who have not received company training. Every active threat situation will unfold differently, especially since external factors such as the weather, type of environment, and other variables can present unpredictable outcomes. By being proactive over what can be controlled, such as implementing sound training strategies, companies can be prepared for and respond to an active threat to the best of its ability. Through the empowerment of its most valuable assets – its people – companies can mitigate risks and protect the safety of its employees, customers, and community. Force Training Institute (FTI) is a Los Angeles-based consulting firm specializing in critical incident response and active shooter mitigation training. Founded and operated by former and current military and law enforcement officials, FTI has quickly earned its name as a trusted source for emergency preparedness through services rendered to industry leaders such as Rite Aid, Ford, REI, Gap, Boeing and the Retail Association of Maine.
Now Even More Options for Customers Who Want Their Own Key Codes! Lock America Adds More New Key Codes for Padlocks and Console Locks. • Give your drivers and customers a single key that fits all the locks at a site. • Ask your console or bin supplier for new available key codes, or contact Lock America directly.
One Key Can Now Operate All Your Locks!
Tel: (951) 277-5180 Fax: (951) 277-5170 www.laigroup.com
800-422-2866
9168 Stellar Court Corona, CA 92883 sales@laigroup.com
Security Shredding News Summer 2016
3
Security Shredding News
Regulatory Investigations Following a Reported Breach
O
By Eric A. Packel, BakerHostetler counsel
nce a data security incident is made public, the potential ramifications include a wide-ranging investigation by a regulatory agency, such as state attorneys general. However, according to BakerHostetler’s 2016 Data Security Incident Response Report, regulatory investigations were slightly lower for incidents the firm managed in 2015 – 24% – down from 31% the year before. While these statistics show that an investigation is not necessarily inevitable following every reported data incident, the frequency is such that the response to any data incident should be handled with an eye towards a potential investigation by a government agency. This means thinking long-term, instead of just getting through the immediate incident response. Actions to take in this regard include putting a litigation hold in place, retaining forensic investigation companies through counsel to help maintain the attorney-client privilege, and limiting email discussions of the incident amongst staff. Also, since the word “breach” has legal implications, use the term “incident” in any internal documentation. Communications to the public and notifications to affected individuals must not only meet legal obligations, but should always be drafted with considerations on how they may be perceived by a regulator. This means that consistency is a must across all communications.
What should you expect from regulators?
S
o when the proverbial knock on the door from a regulator does occur, what should you expect? In addition to details on the incident itself and the remediation and mitigation steps taken in response, regulatory investigations will generally focus on data security practices as a whole across the organization – not just as they may relate to the particular incident facts. So be prepared to provide all policies and procedures relating to data security, perhaps going back as far as 6 years. Regulators will also ask for proof of technical controls in place, such as screen shots of enterprise encryption tools and access controls, as well as event logs relating to anti-virus tools. Additionally, the information requests from regulators may include these types of questions, some of which can be onerous: • A detailed narrative explanation of how the incident occurred. • A time-line of events beginning from the discovery of the incident to the present date.
The vulnerability exploited in connection with the incident. A list of all complaints or inquiries pertaining to the incident. Details regarding all remedial measures taken. How long, and in what manner, personal information is stored, both at rest and in-transit. Copies of all policies and procedures in place that detail how personal information is to be stored. Description of the network infrastructure utilized. Copies of any internal and/or external audits pertaining to data security. All communications regarding the incident.
• • • • • • • •
Further increasing the burden of regulatory oversight, sometimes a company may find itself subject to multiple investigations at the same time from different regulators. In healthcare, we often see separate investigations initiated by the Department of Health and Human Services Office for Civil Rights (OCR) a state attorney general (AG) or even multistate investigations by several AGs. In insurance, we have seen investigations by AGs, departments of insurance, and OCR. In education, we have seen investigations by AGs and the Department of Education. In retail/restaurants/ hospitality, we have seen investigations by AGs and the Federal Trade Commission (FTC).
How can you prepare for a regulatory investigation?
R
egardless of which regulator may be conducting the investigation, most are working from the same playbook, and best practices for responses include:
• • • • •
Show that your organization takes the investigation seriously; Don’t highlight, but also do not try and hide “bad” facts; Highlight the facts that do put your organization in the best light; Emphasize corrective actions taken since the incident; and Provide supporting documentation, if available, that demonstrates compliance efforts.
While an investigation can be distracting and time-consuming, it is always best to put in the time and effort into preparing an appropriate and strategic response. By doing so, organizations can potentially avoid further scrutiny, not to mention significant fines and penalties.
What’s New with HIPAA?
A
By Shannon Hartsfield Salimone, Holland & Knight LLP
number of new developments have taken place related to Health Insurance Portability and Accountability Act (HIPAA) privacy and security compliance, and enforcement is increasing. Healthcare providers, health plans and other covered entities, as well as business associates, should use this opportunity to re-examine their HIPAA compliance programs. Federal government agencies have been busy publishing guidance and resources that may be useful.
Phase 2 of the HIPAA Privacy, Security, and Breach Notification Rules Audit Program
T
he Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act) required the federal Department of Health and Human Services’ Office for Civil Rights (OCR) to audit covered entities and business associates. OCR’s initial audit program, developed in 2011 and 2012, assessed 115 covered entities. OCR, for a number of years, has also been conducting complaintdriven compliance investigations, as well as investigations of certain entities that self-reported breaches. On March 21, 2016, OCR announced “Phase 2” of its audit program. Providers and other covered entities have already begun receiving emailed letters asking for updated contact information so that OCR can more effectively
4 Security Shredding News Summer 2016
communicate with the entities should they be selected for the audit. Failure to respond will not shield a hospital or other covered entity from being included in the audit program, so it is important to check email spam filters to make sure that an email has not been held up in delivery. OCR intends to audit a broad spectrum of covered entities and business associates of various sizes, types and locations. The audits could be conducted on site or by desk review. Interestingly, OCR will not include entities with an open complaint investigation or compliance review in this program. Covered entities will be asked to provide to OCR a list of business associates, who then could become potential audit targets. OCR has published an optional template that covered entities could use to provide information about business associates. The template calls for 27 data elements for each business associate. Covered entities and business associates will have only 10 business days to respond to audit requests. A final audit report will be completed within 30 business days after the auditee responds. Depending on the results of the audit, OCR may initiate a compliance review which, presumably, could lead to enforcement action. Even though more stringent state laws that are contrary to HIPAA preempt HIPAA’s provisions, OCR has indicated that its audit program will not consider state-specific privacy and security rules.
Continued on next page
In the News Continued from previous page
Updated Audit Protocol
O
CR has just released a revamped and updated audit protocol that applies to both business associates and covered entities. It established performance criteria for specific provisions of the HIPAA regulations, and also includes specific questions auditors may ask and documents that may be requested during the audit process. Entities in the healthcare sector could use this protocol to assess their current state of compliance.
Resources for Medical App Developers
M
obile app developers in the healthcare space sometimes have challenges in determining how various laws and rules, including HIPAA, apply to their products. Hospitals and other healthcare providers sometimes have their own mobile apps. In late 2015, OCR launched a website where app developers can ask questions and OCR, as well as members of the public, may post responses. The questions and answers are anonymous. OCR has indicated that comments posted to the site will not subject anyone to enforcement action. Instead, the site is designed to serve as a resource and promote dialogue. Included on the site is a document that discusses specific hypotheticals that might apply to various app designs, and then analyzes how HIPAA might apply to the app. The Federal Trade Commission (FTC) has developed an interactive decision tool for mobile health apps. It is designed to assist mobile app developers in determining whether HIPAA, the Federal Food, Drug, and Cosmetic Act, the Federal Trade Commission Act, and FTC’s Health Breach Notification Rule may apply to their products.
Next Steps
A
lthough compliance with HIPAA and other regulations can be daunting, the government has published these and many other resources that can provide assistance. Regulatory compliance is an ongoing process. In light of the OCR audit program, now would be a good time for healthcare providers and others in the healthcare industry to review and update their compliance programs.
Raleigh Orthopaedic, OCR Reach $750,000 Settlement
R
aleigh, NC — Bloomberg News on BNA.com reports that Raleigh Orthopaedic Clinic PA (ROC) of North Carolina will pay a $750,000 fine for failing to have a business associate agreement in place before disclosing 17,300 patient records with a third-party vendor. ROC reached a settlement with the Office of Civil Rights following allegations that it potentially violated the HIPAA Privacy Rule by transferring X-ray films to a data storage firm in 2013. The case underscores the importance of HIPAA-covered entities maintaining up to date business associate agreements (BAAs). Eric Fader, an attorney with Day Pitney LLP in New York, notes that since the Health Information Technology for Economic and Clinical Health (HITECH) Act was signed in 2009, some covered entities still haven’t executed business associate agreements with all of their business associates. Fader says covered entities need to be mindful that compliance in previous years does not mean compliance with changes that were mandated by the 2013 HIPAA omnibus rule. “Simply maintaining PHI, without accessing it, is enough to make an organization a business associate, Fader said. This would apply to companies that provide data storage and backup services to health-care providers,” he says. In addition to the $750,000 fine, ROC has agreed to enter into a two-year corrective action plan (CAP) with the OCR. The clinic has six months from the signing of the CAP to provide the OCR with a list of all of its business partners, as well as copies of all BAAs. These and all related CAP documents must be kept for a period of six years. According to an article written by Stacey Borowicz and Sarah Persinger of Dinsmore and Scholl law firm, under the CAP, ROC must: • Establish a process to assess whether entities are business associates; • Designate a responsible individual to assure BAAs are in place prior to disclosing any PHI to a business associate; • Create a standard template BAA; • Establish a standard process to maintain documentation of BAAs for at least six years beyond the date of termination of a business associate relationship; and • Limit disclosure of PHI to the minimum necessary to accomplish the purpose for which the business associate was hired. The settlement wasn’t an admission of liability by the clinic, nor was it a concession by the OCR that the clinic wasn’t in violation of the HIPAA rules.
Industry Training for Key Staff! You can’t send all your key employees to NAID 2017, but you can send them to Shred School. July 27-28
Denver, Colorado Aug. 24-25
Orlando, Florida Sept. 7-8
Summit, New Jersey Oct. 5-6
Los Angeles, California Oct. 19-20
Go to www.shredschool.com for more information or to register.
Chicago, Illinois Security Shredding News Summer 2016
5
In the News HIPAA Enforcement: Business Associate Agreements Are a Must
Laptop Containing Football Players’ PHI Stolen
W
N
ashington, D.C. – Laptop theft is one of the most common causes of patient information breaches and it is growing more expensive for HIPAA-covered entities as federal regulators clamp down hard, according to a NationalLawReview.com article prepared by attorney Dena Feldman. Already this year, laptop thefts were central to two multi-million settlements with the Office of Civil Rights: • $1.55 million settlement – North Memorial Health Care, Robbinsdale, MN A laptop was stolen from a business associate’s locked car in 1997. It affected the protected health information (PHI) of 9497 patients. There was no business associate agreement in place with the business associate. The hospital failed to conduct a risk assessment as required by the HIPAA Security Rule. In addition to the $1,550,000 payment, North Memorial is required to develop an organization-wide risk analysis and risk management plan, as required under the Security Rule. North Memorial will also train appropriate workforce members on all policies and procedures, newly developed or revised, pursuant to this corrective action plan. • $3.9 million settlement – Feinstein Institute for Medical Research (research branch of the Northwell Health), Manhasset, NY A laptop was stolen from an employee’s car. Approximately 13,000 patients’ and research participants’ PHI was affected. OCR alleged that the Institute’s security process was “limited in scope, incomplete, and insufficient to address potential risks and vulnerabilities” to PHI. OCR also found that the Institute did not maintain adequate HIPAA security policies and procedures. • $750,000 settlement – Raleigh Orthopaedic Clinic, P.A., NC A failure to execute a business associate agreement prior to turning over PHI (x-rays and related documentation) of 17,300 to a potential business partner. Raleigh Orthopaedic is a Securitygroup Shredding & Storage Newsand - 1/2 4C surgery center in the Raleigh, provider practice that operates clinics an page, orthopaedic North Carolina area. The settlement includes a monetary payment of $750,000 and a robust corrective action plan. Dena Feldman is an associate with Covington & Burling LLP’s Washington, DC office where she practices in the areas of health care, federal-state programs, and public policy and government affairs.
The
ational Football League team, the Washington Redskins, has experienced a breach of players’ medical data after a laptop computer belonging to a Redskins athletic trainer was stolen, according to an NFL.com statement. A laptop containing player data was stolen from a Redskins trainer’s locked car in April. The laptop was password-protected, but unencrypted. In a statement issued by the team’s head office, there was no reason to believe the laptop password was compromised and the National Football League’s electronic medical records system was not impacted by the theft. “No social security numbers, Protected Health Information (PHI) under HIPAA (Health Insurance Portability and Accountability Act), or financial information were stolen or are at risk of exposure,” the statement noted. A MedCity News article reports that the records date back 13 years, covering current and former players’ medical information, as well as that of the attendees of the annual Scouting Combine. In a post on its website, the NFL said, “Once we became aware of the theft, we promptly worked with the club and the NFL Players Association to identify the scope of the issue.” The sports club added that it was “taking all appropriate steps to notify any person whose information is potentially at risk. As the NFLPA memo confirms, the theft of data involves information maintained by one club and no information maintained by any club on the NFL Electronic Medical Records system was compromised and the theft is entirely unrelated to that system.” The NFL directed its member teams to re-confirm that they have reviewed their internal data protection and privacy policies and that medical information is stored and transmitted on password-protected and encrypted devices; and that every person with access to medical information has reviewed and received training on the policies regarding the privacy and security of that information.
ience Of
hredding
It’s In Our DNA
Destruction Equipment - Mobile • General purpose, pierce & tear shred trucks • Non-CDL shred trucks • “The Beast” VST-42e shred trucks • Used shred trucks
Destruction Equipment - Plant Based • Shredders • Shredding lines: conveying systems, dust collection • Turn-key document destruction plants with integrated controls
Conveyors, Sorters & Handling Equipment • Mechanical & pneumatic conveyors • Box dumpers • Truck unloading containment systems • Baler Feed
Parts, Service, Training • Full line of OEM parts in stock and ready to ship • 24-7 telephone support • On-site service • Mechanical training • Sales training
(336) 285-0021 • www.vecoplanllc.com vecoplanllc.com
6 Security Shredding News Summer 2016 Destruction Equipment
All The Elements For Your Success!
In the News New York Presbyterian Agrees to $2.2 Million Settlement of Filming of Patients
W
ashington, D.C. – According HealthDataManagement and New York Times articles, New York-Presbyterian Hospital has agreed to a $2.2 million settlement and a corrective action plan for the unauthorized filming of two patients while participating in the “NY Med” television series. In compliance with a two-year corrective action plan, the hospital will develop new policies and procedures to ensure that photography, video or audio recordings— for purposes not related to the provision of medical care—can only be done with authorization from a patient or the patient’s personal representative. Workforce and business associate training policies are spelled out in the plan, as well. The federal fine involves the case of a man who was hit by a garbage truck in 2011 and taken to NewYork-Presbyterian Hospital/Weill Cornell Medical Center. A crew from the ABC network’s program “NY Med,” filmed as doctors unsuccessfully sought to save his life. Although his face was blurred and his voice was muffled, the dying man’s widow recognized her husband while watching the show the next year. A spokesperson from the American College of Emergency Physicians, said the decision could end real-life shows taped in hospitals. In a statement, the hospital said it did not believe it had violated HIPAA privacy rules by allowing the filming for the television show, which it says “was intended to educate the public and provide insight into the complexities of medical care and the daily challenges faced by our dedicated and compassionate medical professionals.” In 2013, a civil suit was brought by the family of the dying patient against NewYork-Presbyterian Hospital and its former chief surgical resident Sebastian Schubl. The suit, which went to the New York State Court of Appeals, alleges breach of the doctor-patient confidentiality. Though the suit was allowed to proceed, the court did not allow the family to pursue its claim for emotional distress damages against the hospital, doctor and the television network. The judges acknowledged that while the conduct was offensive, it was not outrageous enough to justify damages sought by the plaintiff. Meanwhile, New York lawmakers have proposed a bill that would make it a crime to film patients without consent, with certain exceptions. A trade group representing hospitals in New York City said its members would voluntarily agree to allow filming of their patients only if the patients grant prior consent. The latest fine follows a 2010 HIPAA investigation into a breach of a data network shared by New York-Presbyterian Hospital (NYP) and Columbia University. NYP paid out $3.3 million and Columbia paid $1.5 million.
www.bomaccarts.com
sales@bomaccarts.com
FDIC Cybersecurity Lapses Draw Scrutiny from House Committee
W
ashington, D.C. – The latest security breach at The Federal Deposit Insurance Corporation has prompted investigation by the House Science, Space and Technology Committee, reports Marketwatch.com. The breach occurred when sensitive bank plan information was published in The Wall Street Journal prior to official announcements by bank executives. The leaked information consisted of the names of certain the banks whose “living wills” were rejected by the Federal Reserve Bank. Bank living wills contain strategies for rapid and orderly resolution in the event of material financial distress or failure of financial institutions with total consolidated assets of $50 billion or more and nonbank financial companies that are supervised by the Federal Reserve. The documentation is submitted periodically to the Federal Reserve and the Federal Deposit Insurance Corporation. Since 2002, the Electronic Government Act and the Federal Information Security Management Act (FISMA) have defined how government information, operations and assets must be secured against natural or man-made threats. The Federal Information Security Modernization Act of 2014 requires executive branch departments and agencies to report “major” security incidents to Congress within seven days. Yet the FDIC has withheld reporting breaches to Congress sometimes for months, FDIC’s chief information officer Lawrence Gross, told the Committee. The FDIC has stepped up security risk management by launching internal audits to review its process for identifying and reporting major security incidents, as required by law.
www.chachkagroup.com chachka@chachkagroup.com Security Shredding News Summer 2016
7
In the News Accent Wire Acquires L&P Wire-Tie Systems
Main IT Security Breach Cause: Human Goof-Ups
A
C
ccent Wire recently announced that it has acquired L&P Wire-Tie Systems, a division of Leggett & Platt®, and will rename the combined company Accent Wire-Tie. L&P Wire-Tie, based in Carthage, Missouri, is a manufacturer of wire-tying machinery and a leading baling wire distributor. “We are delighted to welcome L&P Wire-Tie to the Accent family. This acquisition couples LPWT’s legacy and establishment in the industry with Accent’s innovation and reputation for service. The recycling and waste industry will enjoy an unrivaled supply chain for baling wire and an enhanced ability to supply and service equipment,” said Bill Sims, President and CEO of Accent Wire-Tie. By combining resources, the new Accent Wire-Tie will become a global leader in supplying baling wire, wire-tying machinery and service, and other bale packaging solutions to the recycling and waste industry, the company stated.
NAID Names Brock Miller, CSDS ‘Member of the Year’
P
hoenix, AZ – Brock Miller, CSDS, of Shred Northwest in Gresham, Oregon has been named Member of the Year by the National Association for Information Destruction (NAID). The award was presented during a ceremony at the NAID’s annual conference in Orlando. Fla. attended by approximately 700 secure destruction professionals. In presenting the award NAID President Don Adriaansen said, “Without exception, the colleagues and NAID staff who recommended Brock for this honor, consider him the embodiment of positivity, productivity and integrity”. Cited among his qualifications was that Miller currently serves as Chairman of the Certified Secure Destruction Specialist (CSDS) Board of Regents and is a member of NAID’s Complaint Resolution Council, which Adriaansen stated is “without doubt one of the most important and difficult leadership bodies in the organization.” In accepting the prestigious award, Miller said, “within this association is real, and authentic leadership...I am confident the future will be significantly impacted by the leadership in this very room”.
www.shred-tech.com
8 Security Shredding News Summer 2016
incinnati, OH – According to the 2016 Shred-It Security Tracker information security survey, an increasingly mobile workforce is exposing businesses to more data security vulnerabilities than ever. The main culprit? Human error. Shred-It’s 2016 North America State of the Information Security Industry report notes that companies are becoming increasingly aware of information security risks. The problem is, they are not implementing the protocols and training needed to ensure customer and competitive information remains secure in a mobile work environment. With the number of mobile workers in the US expected to reach 105 million by 2020, more workers are using the tools of the modern workforce, including laptops, USBs and cloud storage to connect from outside the traditional office environment. To help businesses of all sizes ensure their corporate policies and training around data protection and security keep pace with the evolving work environment, Shred-it suggests seven simple workplace guidelines: 1. Remind employees not to leave hardware or materials in vehicles, hotels, coffee shops or elsewhere. 2. Limit the type of documents that employees can remove from the office, as there is no way to ensure data is secured when outside of the company’s control. 3. Encrypt all phones and hard drives, and activate passwords on electronic devices. 4. Perform a regular cleaning of storage facilities and avoid stockpiling obsolete electronic devices. 5. Destroy all unused hard drives using a third-party provider who has a secure chain of custody and confirms destruction. 6. Regularly review your organizations information security policy to incorporate new and emerging forms of electronic media. 7. Schedule on-going training so employees understand best practices for protecting confidential information – in and out of the workplace.
In the News Legal Shred, Inc. Forms Strategic Partnership with HV Shred
Stericycle’s Performance Dogged by Acquisition Integration Lags
L
L
egal Shred, Inc., “The Identity Protection Company”, announced that it has reached an agreement to partner with HV Shred, a document destruction company. The partnership of HV Shred will expand Legal Shred’s offerings and enable Legal Shred to better deliver its identity protection and document destruction solutions to customers beyond its Florida-based business. “HV Shred has grown into one of the top providers in shredding and document destruction services in the Hudson Valley region, making them an ideal addition to our business and mission,” said Jason Fredricks, Founder and Vice-President of Legal Shred, Inc. “This partnership will enable us to better serve our customers in the identity protection business, and we are excited about the new opportunities this will create for our growth.”
New Southeast Region Mobile Document Destruction System Rep for Shred-Tech
S
hred-Tech, Cambridge, ON recently announced that Mike Campbell will be joining Shred-Tech as their new mobile shredding and collection truck representative for the southeastern United States. Mike has approximately 15 years experience in the document destruction industry. He played a key role in building one of the largest shredding businesses in North Carolina, before its acquisition. And for the last several years Mike has been successfully selling mobile and stationary shredding equipment.
ake Forest, IL – TheStreet.com reports a price slip of almost 30 percent for waste handler, Stericycle. Stericycle’s first-quarter revenue was $874.2 million, up 31.8 percent from Q1 of 2015. But earnings ($1.11 a share) declined by 4 cents. Analysts with TheStreet.com blame lower hazardous waste revenues, although currency fluctuations had an impact on that – revenue would have actually risen 35.4 percent, they say, had exchange rates been stable. In addition, expected cost savings from the acquisition of document destruction company, Shred-It, have not happened. Then, too, Stericycle’s medical waste incineration business has taken some hits. Amid public opposition, air quality citations and related investigations, the company’s Idaho incineration facility, the largest in western United States, has been forced to make upgrades and concentrate on relocation. The updated full-year earnings estimate range is $4.90 to $5.05 a share, down from $5.28 to $5.35 a share previously reported. Revenue is now pegged at $3.6 billion to $3.66 billion versus $3.65 billion to $3.72 billion. As the integration of Shred-It continues, analysts predict a two-year delay in some $20 million of cost savings associated with the acquisition. By the end of 2018, margins and profitability should fall into line. RBC Capital also expects the company to overcome the challenges associated with industrial hazardous waste next year. Earnings and dividends for two competitors, Republic Services and Waste Management, however, are outperforming Stericycle and yielding 2.5% in dividends.
U.S. Paper Recovery Rate Increased to 66.8 Percent in 2015
W
ashington – The American Forest & Paper Association (AF&PA) recently announced that 66.8 percent of paper consumed in the U.S. was recovered for recycling in 2015. (U.S. paper recovery rate statistics are available at www.paperrecycles.org/statistics.) “Industry efforts, the voluntary, market-driven recovery system, and the millions of Americans who make the decision to recycle every day have helped to keep U.S. paper recovery at continuously high levels,” said AF&PA President and CEO Donna Harman. “Our industry will continue to support and implement education programs and initiatives to inform consumers about the importance of paper recycling, and encourage the continued expansion of access to paper recycling nationwide,” said AF&PA Board Chairman and Packaging Corporation of America Chairman and CEO Mark Kowlzan. The annual paper recovery rate has nearly doubled since 1990 and the industry has set a goal to exceed 70 percent paper recovery for recycling by 2020 as part of its Better Practices, Better Planet 2020 sustainability initiative.
Legal Shred Acquires Stay Green Shredding
L
egal Shred, the identity protection company, announced that it has reached an agreement to acquire Glen Cove, New York-based Stay Green Shredding. The acquisition will cement Legal Shred’s position as the area’s leading provider in document destruction. “We are excited about Stay Green becoming part of the Legal Shred brand. Our combined knowledge and experience allows us to offer the best in document destruction services,” said Jason Fredricks, Founder and Vice-President of Legal Shred. “This is a great win for our communities, employees, and most importantly, our customers. I personally look forward to continue to exceed customer expectations through this combined organization.” Through this acquisition, Legal Shred will now expand its presence throughout Long Island, New York. “Our philosophies are very similar, with an emphasis on customer service,” said Fredricks. “We look forward to working with the community of Glen Cove, New York to bring high quality identity protection services for consumers and businesses alike.” This acquisition also brings the hands-on expertise of Joe Ferguson of Stay Green Shredding to the Legal Shred team. Mr. Ferguson’s experience runs the gamut in document destruction from his previous tenure at Shred-It and Brinks Document Destruction.
Security Shredding News Summer 2016
9
In the News NAID Installs New Board Members
P
hoenix, AZ – The National Association for Information Destruction (NAID), the non-profit trade association for the secure information destruction industry, installed its newly elected board members during its annual membership meeting on April 8, 2016. The meeting was held in conjunction with the organization’s annual conference. The newly installed NAID board of directors include, President, Don Adriaansen, CSDS, of Doylestown, Penn.-based TITAN Mobile Shredding, LLC., President Elect, Eric Haas of A.R.M.S. Inc, located in DePere, Wis., Past President, Mr. R. Stephen Richards, CSDS, of Nashville, Tenn.-based Richards & Richards, and as Secretary, Patrick DeVries, CSDS, of DeVries Information Management based in Spokane, Wash. Newly installed Directors include Gina Lentine, CSDS, of Assure Shred in Ringoes, NJ, and Brock Miller, CSDS, of AccuShred NW in Gresham, Ore. And finally, reinstalled as Vendor Liaison, Vladimir Vasak of K-2 Partners, LLC based in Villanova, Penn. The installation of officers reflects the results of the recent NAID board election held electronically in March. During a board meeting following the official installation, the NAID Board approved the appointment of Glenn Laga of Guardian Data Destruction based in South Hackensack, NJ to fill the director seat vacated by Pat DeVries who was elected Secretary. NAID President Don Adriaansen says an active board of directors is one of the keys to NAID’s long record of success. “The fifteen members of the board clearly represent a healthy cross section of the industry,” says Adriaansen. “I have learned from experience that these professional take their responsibilities very seriously, which in turn translates to a strong and successful association.”
Lifetime Assistance, Inc. launches Classified Scanning & Shredding Combines Names for its Document Management Divisions
R
ochester, NY – Lifetime Assistance, Inc. recently announced that, effective immediately, two of its locally owned subsidiaries - Classified Shredding Services and Lifetime Document Management - will now operate under the new name of Classified Scanning & Shredding. The company offers a comprehensive suite of document management services -scanning, cloud computing and certified document destruction - all done at its facility located at 425 Paul Road in Chili. “We chose to combine both names into one to capture the natural synergy between closely related services,” says Lou Ann Owens, CSDS and Marketing & Sales Manager at Classified Scanning & Shredding. “By coordinating multiple capabilities under one roof, we are able to offer a complete solution that makes it easier for our customers to do business with us, as opposed to doing business with multiple vendors.” Owens adds, “There are also economies of scale that come from doing everything in-house, which allows us to pass along greater savings to our customers, making these services even more affordable.” Classified Scanning & Shredding will benefit from streamlined communication and cross marketing - which in the long run will promote growth within the business. Currently, Classified Scanning & Shredding employs 55 full- and part-time workers, including those with developmental disabilities. The disabled workers were previously trained at the Lifetime Assistance work center, which employs 125 disabled workers. The new division and workforce will focus on providing high-quality, costeffective solutions that meet virtually every need, from document capture/scanning (including document prepping) to secure digital storage and access to certified document destruction.
Product/Equipment Profiles Vecoplan, LLC Introduces New Line of Shredding Trucks
V
e c o p l a n recently introduced its MST line of s h re dd i n g t r u c k s. The new line expands Vecoplan’s family of shredding truck models, and will be marketed in addition to its vaunted VST series. Whereas the VST will continue to serve customers for the more sophisticated, and high security jobs, as well as special apps, the new MST series is more general purpose in nature. It will initially be offered in two models, a 33,000 GVW CDL model, and a 26,000 non-CDL GVW model. The MST series will be available with various chassis-cab brands. The MST truck line is being produced in partnership with AXO Shredders. The new MST line will utilize AXO’s Fatso 500-16 shredders, a proven design when it comes to “Pierce & Tear” shredders. Vecoplan will adopt certain other design features from the AXO trucks, however the MST line will be produced exclusively in Vecoplan’s North Carolina plant. With this arrangement, Vecoplan essentially becomes AXO’s North American distribution partner.
Vecoplan, LLC Launches New Website
V
ecoplan LLC, a leading manufacturer of industrial shredders and recycling systems, has updated and launched a new version of www.vecoplanllc.com. Built on a responsive platform, (http://www. vecoplanllc.com/) automatically formats for laptops, tablets and mobile phones providing Vecoplan’s customers the best user experience possible on the device of their choice. Designed with customers in mind, the new site begins by highlighting markets served by Vecoplan including: Plastics, Paper, Wood, Biomass, Waste, Special Apps, and Custom Systems. Next a link to equipment and services provided by Vecoplan enables users to access details on technologies offered by the company including: Shredding, Conveying, Screening, Separating, Storage, and Feeding machinery. Enhanced search features throughout the site provide in-depth information but in a concise format. The site also provides downloadable literature on Vecoplan’s products & services, links to Vecoplan’s YouTube channel, blog & other social media, a virtual sample room containing before and after photos of shred tests on a spectrum of materials, details on how to set-up a test on your specific material, and features a contact link on all pages. “Having quick links for customers to contact us throughout the site has been key to the redesign of our site.” stated Kim James – Marketing Director Vecoplan LLC, “One of our strongest assets is the sheer experience of our people. The website is a valuable tool, but nothing replaces the direct communications between someone that’s looking for a solution and someone who has been there & done that!”
For more information contact Vecoplan at: Phone: 336-861-6070, Email: info@vecoplan or visit our website at www.VecoplanLLC.com.
10 Security Shredding News Summer 2016
www.certifymerecycling.org info@certifymerecycling.org
Security Shredding News Summer 2016 11
tlee@transleaseinc.com
www.transleaseinc.com