Volume 14, Issue 2
summer 2017
Security Shredding News Serving the Security Shredding & Records Storage Markets
Visit us online at www.SecurityShreddingNews.com
ATTN: READERS !
Are you looking for Products, Equipment or Services for your business? If so, please check out these leading companies advertised in this issue:
Collection & Storage Containers Bomac Carts – pg 9
Equipment Financing TransLease Inc – pg 7
Lock & Locking Systems Lock America Intl. – pg 3
Mobile Truck Shredders
Alpine Shredders Ltd – pg 10 Shred-Tech Limited – pg 6 Vecoplan, LLC – pg 12
Moving Floor System Keith Manufacturing – pg 2
Stationary Shredders & Grinders Shred-Tech Limited – pg 6 Vecoplan, LLC – pg 12
Trade Associations NAID/Shred School – pg 8
(National Association of Information Destruction)
RIOS – pg 11
Website design Chachka – pg 9
HR Technology:
Time to Automate!
T
By Jim Sweeney
oday, employers have at their disposal various employee selection tools such as background checks, drug testing, assessments and reference checking. Of these solutions, reference checking tends to get the least attention or the lease effort. Generally it is because most employers do it the old fashion way which is highly unproductive and less effective. The old fashion way involves calling reference, playing phone tag, receiving little or no valuable information and generally prolonging the hiring cycle. As a result it often gets ignored or is done haphazardly. Isn’t there a better way? Of course there is. One of the true values of HR technology is when a solution can change a cumbersome and inefficient practice into quick and productive method of selecting quality employees. Skill Survey is an excellent example of technology that provides fantastic results. For the HR person, it simply requires inputting the candidates name and email address. The system does the rest. The system will generate an email to the candidate with a link. Clicking the link allows the candidate to
insert references and their email addresses. The system then sends each reference a job specific survey that takes about 10 minutes for them to fill out. When the references are complete, email notification is received and a report can be generated. Generally there is a 75 % response rate with 24 to 48 hours. The information is collated into one report and you can see how the candidate is evaluated by the references. References are known, but you cannot tell how each reference individually scored the subject. Key features of this automated process: •
You can require both past supervisors and peers and comparison is delineated on the report.
•
Each reference is presented with the same job specific questions.
•
Customized questions can be insert.
•
Unlimited references for one price.
•
It doesn’t prevent you from calling a reference for follow up. Continued on page 3
Security Shredding News
www.youtube.com/user/KeithMfgCo
www.keithwalkingfloor.com
2 Security Shredding News Summer 2017
Security Shredding News
HR Technology:
Time to Automate! Continued from page 1 •
It has built in safeguards to prevent fraudulent references.
•
Takes very little time and effort and is more consistent than calling reference.
I have been around the shredding industry for 15 years and actually owned a mobile shredding company at one point. I have also been around the employee screening industry for more than 25 years and I have seen some distinct similarities. Everything is moving towards automating our processes. Like our equipment, we want our employees to be reliable and dependable assets that operate smoothly and efficiently day after day. But with equipment, if things go wrong we fall back on warranties and often times receive guaranteed replacements. This is the reason so much time, effort and money goes into selecting the best equipment. It seems logical to bring this same mind set to the hiring process. If you had to spend about $40 extra on a piece of shredding equipment that netted you a better product, it increased your efficiency, it lasted longer and enhanced your reputation, would you spend the $40.00? Without a doubt! So why not spend another $40 on automating the hiring of a new employee that showed the same return. Jim Sweeney is the President of Inquirehire, Inc. Inquirehire is a member of NAID and a leading provider of employees screening solutions to the document destruction industry. Jim can be reached at jim@inquirehire.com.
Shred-Tech® Accelerates Growth with Opening of New Office in Raleigh
S
hred-Tech®, a manufacturer of highperformance shredding and recycling systems, recently announced plans to expand to a new factory location in Raleigh, NC to meet its increasing customer demands. The new 20,000 square-foot facility supports the company’s strategic plan to centralize its used truck and truck refurbishing business in Raleigh while consolidating the existing parts and service business currently based in Apex, NC. This expansion will give Shred-Tech the capacity and resources needed to achieve its growth objectives while improving customer service in the region. The site is located at 4701 Trademark Drive, Raleigh, NC.
The Most Expensive HIPAA & HITECH Breaches – So Far
S
ince 2011, the U.S. Health and Human Services Office for Civil Rights (OCR) levied a total of $22 million in fines on five healthcare businesses for failing to protect health information, according to a Gazette.com article. The five biggest settlements include: zz Advocate Health Care. In 2016, Advocate agreed to pay a $5.55 million fine for failing to assess ePHI risks and restrict physical access to its IT systems, as well as not having a proper business associate agreement in place. The company reported two burglaries resulting in thefts of five laptop computers and a data breach. Protected health information of 4 million individuals was potentially compromised, including credit card numbers and clinical information. The fine represents the largest Health Insurance Portability and Accountability Act settlement HHS has ever received. zz New York Presbyterian-Hospital and Columbia University. In 2014, the healthcare organization and the university reached a settlement of $4.8 million. Inadvertently, the health records of 6,800 individuals were publicly accessible on the internet, via Google and other search engines. zz Cignet Health. In 2011, Cignet agreed to a total fine of $4.3 million ($3 million of which was for willful neglect). The company failed to give a copy of medical records to 41 patients who requested them from September 2008 to October 2009. Under the HIPAA privacy rule, records must be provided no later than 60 days after a request. Unable to get copies of their records, the patients filed complaints with the HHS Office for Civil Rights, but Cignet remained uncooperative. Finally, the company complied with a Maryland federal court order. zz The Feinstein Institute for Medical Research. In 2016, Feinstein agreed to a $3.9 million fine related a theft of a non-encrypted laptop from an employee’s car. The patient records of 13,000 people — including their lab results, diagnoses and medications. The OCR ordered the company to correct weak risk management with regard to patient data. zz Children’s Medical Center of Dallas. In February of this year, Children’s Medical agreed to pay a $3.5 million fine for two data breaches involving ePHI of nearly 6500 patients. About 4000 non-encrypted patient records were exposed when a smartphone was stolen. The theft of unencrypted laptop exposed 2,500 other patients.
Now Even More Options for Customers Who Want Their Own Key Codes! Lock America Adds More New Key Codes for Padlocks and Console Locks. • Give your drivers and customers a single key that fits all the locks at a site. • Ask your console or bin supplier for new available key codes, or contact Lock America directly.
One Key Can Now Operate All Your Locks!
Tel: (951) 277-5180 Fax: (951) 277-5170 www.laigroup.com
800-422-2866
9168 Stellar Court Corona, CA 92883 sales@laigroup.com
PUBLICATION STAFF Publisher / Editor Rick Downing Contributing Editors / Writers Katie Pyzyk • Jim Sweeney Sandy Woodthorpe Production / Layout Barb Fontanelle • Christine Mantush Advertising Sales Rick Downing Subscription / Circulation Donna Downing Editorial, Circulation & Advertising Office 6075 Hopkins Rd., Mentor, OH 44060 Ph: 440-257-6453 • Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com For subscription information, please call 440-257-6453 Security Shredding News (ISSN #15498654) is published bimonthly by Downing & Associates. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment.
©Copyright 2017 by Downing & Associates Printed on Post-Consumer Recycled Paper
Security Shredding News Summer 2017
3
Security Shredding News
The Wider World of Electronics
Commercial and industrial electronic devices can be lucrative for refurbishers and recyclers, but the work demands specialized knowledge and skills—and it’s not without risk.
By Katie Pyzyk
W
hen you think electronics today, you might picture a person awash in the soft blue glow of a smartphone, tablet, laptop, or TV—or maybe one wearing a trendy fitness tracker or virtual-reality headset or piloting a drone. Yet other electronic machines have become so ubiquitous they’re nearly invisible: point-of-sale devices for swiping a credit or debit card, the check-in terminal and security scanners at the airport, the electric meters on your house. And what about all those machines behind the scenes in various professions and industries? As some have discovered, this wider world of commercial and industrial electronics has potential for electronics refurbishers and recyclers. “Nonconsumer” electronics is a varied space that covers a wide array of items and numerous industries. The hundreds of commercial and industrial device categories include the aforementioned credit-card processing machines and utility meters, as well as office equipment, computer servers, medical imaging equipment, and lab equipment. “If it plugs in or takes a battery, we’re going to look at it,” says Adam Dumes, vice president of Cohen Recycling (Middletown, Ohio). Nearly all electronics are made from common elements—namely, ferrous, nonferrous, and precious metals; plastics; and glass. Items like servers don’t necessarily require different recycling methods than desktop and laptop computers. “The same components are in there. … a server is no different than a big [computer] tower … . You’re still ultimately dealing with the same commodities once you’ve processed the obsolete electronics,” Dumes says. That said, some nonconsumer electronics require different, more intense processes and considerations, whether it’s to refurbish a product for resale, harvest valuable parts, capture the most value from its commodities, or properly manage its hazards. And the stakes can be high for something like medical equipment, says Tony Lively, president of ZRG (Carlsbad, Calif.), which specializes in such items. “You have to be very aware that this [equipment] can kill people” if it’s not handled properly.
A Growing Supply
T
he infiltration of electronics into everyday life is staggering. “We inject the intelligence of electronics into more and more aspects of our lives,” says Steven Elmore, program director of CyclePoint from SourceAmerica (Vienna, Va.). “Everything associated with our activity out in the world has become intelligent design-run,” including items from cars to refrigerators. Combine that proliferation of electronics with a shorter product life cycle, and you get a recycling sector with a rapidly growing supply. U.S. residents produced an estimated 3.4 million tons of consumer e-scrap in 2014, according to a recently released U.S. Environmental Protection Agency report, and nearly 42 percent of that was collected for reuse or recycling. That seems like a lot of material, but electronics recyclers think it’s just the tip of the iceberg. “The consumer portion really is a small percentage of the overall e-scrap category,” says Duane Beckett, CEO of Sunnking (Brockport, N.Y.). Not a lot of people think
4 Security Shredding News Summer 2017
about nonconsumer electronic devices falling under that electronics umbrella, he notes. The overall supply of nonconsumer electronics also seems to be growing—“It’s increasing, definitely,” Lively says—but these products differ from consumer electronics in at least one important way. Consumers seem to have accepted the idea that their electronic devices will break or become obsolete in just a few years. As these products’ life spans have shortened, their prices have come down, so consumers just replace the nonworking device with a new one. “If you look at the initial cost of a computer, laptop, or cellphone, you’re in the range of a few hundred dollars,” says Corey Dehmey, R2 director at Sustainable Electronics Recycling International (Boulder, Colo.). Thus, after a few years, the resale value for those consumer devices is rather low. For nonconsumer electronics, it’s a different story. “A lot of these machines are so expensive that [customers] wait to upgrade them as long as they possibly can,” Beckett says. Further, Dehmey says, “if you’re talking about an initial cost of $10,000 or $20,000, it makes the value of reusing and refurbishing that [nonconsumer] device—the residual value that you can sell it for— much higher. … There are more opportunities for [nonconsumer] reuse because of the residual value.” Refurbishing and resale have been part of some electronics recycling businesses from the beginning, while for others, sagging commodity prices in recent years have pushed them in that direction. “Two years ago we recognized pretty handily we were going to have to incorporate reuse and refurb, and not so much build the business model around the [recycling] and commodity value,” says CyclePoint’s Elmore. Electronics processors are likely to keep a foot in refurbishment even when commodity prices rebound, these recyclers say, because the revenue stream can be both higher and more consistent. “I don’t think [the industry is] flipping back” to focusing on disassembly and shredding in lieu of refurbishment and resale, Dumes says. “At the peak of the commodity markets, [the scrap is] still not going to come close to what a reusable product is going to be worth.”
Niche Knowledge
“I
n commercial and industrial electronics, usually the customers are very stringent,” says Jade Lee, president and CEO of Supply-Chain Services (Lombard, Ill.). “They demand that the service provider should have rigorous facility security [and] data sanitization and verification procedures in place, in addition to an organized and systematic process of asset audit, functionality testing, refurbishing/repairing, and detailed reporting.” Even if your facility has all that, experts in recycling nonconsumer electronics have a caution for you: Know the niche. Refurbishing such products—or even disassembling them for parts—requires extensive research and knowledge acquisition. “With the higher-end commercial stuff, we need higher-end technicians,” says Chris Ko, managing partner at ER2 (Mesa, Ariz.). “Whenever you deal with the commercial-level
Continued on next page
Security Shredding News Continued from previous page material, it has to be treated far differently than a laptop.” As Dehmey points out, “fewer people can do [refurbishment] because of the specialized nature.” Businesses report instituting rigorous training processes so employees can identify and repair these devices. Specialized training also protects the workers and the company when the products contain dangerous materials that require special handling or disposal. These focus materials may be the same as those in other electronic products—cathode-ray tubes, toner, cadmium, mercury, or lead—but they also could be oil or other fluids, glass in unexpected places, or radioactive materials that are unique to nonconsumer electronics. Trying to recycle or refurbish electronics containing any of those items without knowing about the hazards they contain could prove disastrous. Stored energy can be a safety concern as well: Many electronics can carry a powerful charge even after they’ve been unplugged. Data destruction concerns exist in the consumer electronics space, but the stakes can be even higher with specialized equipment in highly sensitive commercial and industrial fields. Servers can hold businesses’ heavily guarded trade secrets. A medical device could have caches of patient medical records protected by the Health Insurance Portability and Accountability Act. A variety of devices could store financial information. “We’ve even received … credit-card-producing machines … and the tape in there might have residue or a punch-out from a previous credit-card number,” Ko says. Before many refurbished items can be resold, they have to be tested and certified. Medical devices, for example, must be tested with special equipment and certified as patient-ready. “You have to have the documented proof that this piece of equipment has passed all the tests … so you know it’s not going to fail during the middle of a medical process,” Lively says. “No hospital is going to buy it if it hasn’t been tested.” In other words, commercial and industrial electronics can be “a lot different than the consumer computer [refurbishing] business where you buy something, have your guy in the back fix it up, and you sell it on eBay,” Lively says.
The Breakdown
E
ventually, upgrading a specific electronic product becomes impractical or impossible. That’s when it gets recycled for commodity value. Some nonconsumer electronics can go in the shredder right alongside consumer goods; others cannot due to their materials or construction. More robust products can take a hefty toll on typical sizereduction machinery, for example. “We use a combination of manual disassembly as well as a small shredding line that consists of … a ringmill with some magnetic sortation,” Beckett says. Recovered commodities include ferrous, nonferrous, and plastics, Lee says, just as with consumer electronics. “Once the material is … shredded, it can be very difficult to tell the difference between the two starting products,” Dumes says. A factor boosting the commodity value of commercial and industrial electronics is that they’re “typically built better, with higher-quality and higher-value materials,” Dehmey says. “The recovery of precious metals in [their] circuitboards—gold, palladium, and silver—typically has a higher concentration than a consumer desktop or laptop or printer,” for example. And the larger items might simply house a larger volume of recoverable commodities. But bigger isn’t always better. Large devices can be more difficult and more expensive to transport. They require “a lot more labor than consumer material,” Beckett says. “Some of that big equipment is logistically difficult on the rigging side” to ensure it does not get damaged—and that workers moving it are not harmed. Some refurbishers and recyclers have their own fleets and travel to client sites to pick up equipment, whether intact or partially dismantled. Others leave it up to customers to transport the items to the recycling facility. The third option is arranging for a shipping
company to transport the equipment. Those third-party shippers have to be top-notch companies that can handle bulky—yet fragile—items and their accompanying data privacy concerns, however. “There’s a chain-of-custody protocol that we need to follow” per the certification requirements of the National Association for Information Destruction (Phoenix) “if we arrange for a pickup, especially for products (such as PCs, servers, copiers, cellphones, etc.) with a hard drive or electronic media in them,” Lee says. Such security comes at a price: “Our shipping costs are crazy,” Lively says. Whether the equipment is being acquired for refurbishment or recycling makes a difference, too. Equipment to be scrapped is “not really that valuable, so transportation costs get high quickly” compared with value, Beckett says. On the other hand, the significantly higher resale price for refurbished equipment offsets some of the cost of shipping it. One high-value piece of refurbished equipment “makes it worth paying $150 to ship it across the country,” Dehmey says, whereas “that $150 would eat up all the proceeds of a laptop.” Transportation costs are a factor in making this primarily a domestic business, but overseas demand for certain specialized electronics is growing. Demand for refurbished medical equipment, for example, is on the rise in certain other countries, Lively says. Newer equipment draws a better price, of course, and often can find a buyer in the United States; older items move on to other North American markets, and then perhaps down the line to Asian markets. “Depending on what age the equipment is, it has a place,” he says. As with any scrap endeavor, refurbishers and recyclers must adhere to U.S. export restrictions and other countries’ import requirements.
Risky Business
E
lectronics recycling involves navigating risks and regulations beyond those of processing traditional scrap metals. Recycling and refurbishing nonconsumer electronics can bring on even further business liability. “The insurance to run a company like this is much higher than it would be for a company selling just [consumer] computers,” Lively says. Some estimate those insurance costs could be up to five times higher— enough to dissuade some from entering this niche. “The large amounts of insurance and liability is probably a differentiator for a lot of people,” Ko says. One way to demonstrate a commitment to risk mitigation and business integrity, these sources say, is by investing in certification, such as through the R2/RIOS™ or e-Stewards® programs, although those certifications don’t have specific guidelines for recyclers of nonconsumer electronics. “In the eyes of the R2 standard, all electronics are treated the same,” Dehmey says. Working in information-dense and privacy-sensitive sectors requires tenacity to maintain integrity and strong business relationships, recyclers say. “[Customers] absolutely need to have trust and confidence in what we’re doing,” Dumes says. Education and transparency are key, especially regarding data destruction. “[Customers] have to understand how your processes and procedures are in place to prevent data leakage” in order to build trust, Ko says. Some suppliers like to audit the e-scrap facilities they partner with, which isn’t a problem for those that maintain high standards. “We have stringent procedures [for] implementing programs and executing tasks,” Lee says. Corporations and original equipment manufacturers that verify excellence through audits “are the customers we love to work with, as they value the rigorous process and infrastructure that we have devoted [ourselves] to establish in the past 20 years.” Nonconsumer electronics isn’t the easiest niche in e-scrap recycling. It requires a lot of planning, effort, and weighing cost-benefit ratios, but “at the same time, it’s extremely rewarding and beneficial,” Ko says. Katie Pyzyk is a contributing writer for Scrap magazine (scrap.org). This article originally appeared in Scrap’s March/April 2017 issue. Reprinted with permission.
Security Shredding News Summer 2017
5
Security Shredding News
Rising Container Rates Impact the Paper Market
HIPAA Enforcement Steady and On Course
O
W
ver the past year, recyclers have been dealing with soaring freight rates for recovered paper shipments between Europe and China – in some cases, more than $1,000 per container. According to a statement by the Bureau of International Recycling (BIR) trade group, freight costs for shipments between Europe and China shot up more than $1000 per container - or $40 a ton – in the first few months of 2017. Although BIR figures show a downward trend to $2000 per container with stabilization around $1200-1400 in the coming months, BIR leaders are urging closer dialog between paper recyclers and the shipping industry. Rates were just one of the topics discussed at a May gathering of paper recyclers in Hong Kong. Another issue, China’s National Sword initiative, which was conceived to eliminate contaminated recyclables deemed unsuitable for use as a secondary raw material. Recyclers at the Hong Kong meeting discussed concerns that China’s zero-tolerance policy could direct volumes away from China, impacting the world market as the paper goes elsewhere. For European corrugated and mixed paper shipments to China, a steep price decline around the start of the second quarter of 2017 had been followed by an almost immediate recovery, according to a BIR report. Lower stocks and more stable containerboard orders for mills in China and strong fiber demand in Europe helped buoy the prices. Meanwhile, Japanese paper mills have been favoring the fiber suppliers who can offer larger volumes, a trend that could lead to consolidation within the supply sector and create a competitive environment in which small companies will be the losers, a BIR statement noted.
www.shred-tech.com
6 Security Shredding News Summer 2017
riting in a blog on SWLaw.com, attorney, Allison Bans emphasizes that HIPAA Privacy and Security are priorities at the US Department of Health and Human Services (HHS). In just the first four months of 2017, HHS’ Office for Civil Rights (“OCR”) announced seven settlements with covered entities and business associates with fines totaling over $14 million. “For some context, OCR assessed over $23.5 million in 2016, which was a record-breaking year,” Bans writers. In addition to breach investigations, the agency has been conducting audits. Round two of Phase 2 of the Privacy, Security, and Breach Notification Audit Program started in late 2016, running slightly behind the announced schedule. The Phase 2 audits are being conducted in three rounds. Rounds 1 and 2 were remote desk audits of covered entities and business associates, aimed at reviewing compliance with specific requirements of the Privacy, Security, or Breach Notification Rules. Round 3 consists of onsite audits of covered entities and business associates and looks at more HIPAA compliance issues than the desk audits, with potential for onsite desk audits. The impact of the Trump administration on HHS policy is yet to be seen, given the appointment of Roger Severino as Director of OCR. Severino comes from the Heritage Foundation, a conservative think tank. Bans notes, however, that HIPAA enforcement is not a major partisan issue and it seems unlikely new leadership will alter the agency’s mission to secure patient health information, Bans notes. “Covered entities and business associates may be well advised to continue their course in HIPAA compliance efforts,” Bans advises. Allison Bans practices employee benefits law with a focus on health and welfare plans for the firm, Snell & Wilmer.
®
Specialist in Mobile Shred Truck Financing • LOW INITIAL INVESTMENT • LEASE OR LOAN FINANCING • FINANCING NEW OR PRE-OWNED EQUIPMENT
• SIMPLE APPLICATION PROCESS • SERVING THE U.S. & CANADA • COMPETITIVE RATE STRUCTURE
We Provide a Convenient and Cost-Effective Solution!
Financing The World Of Transportation For a Quote or More Information Contact: Eastern States Western States Terry Lee Cassie Bergo Direct: 303-301-7651 | Cell: 937-620-9400 Direct: 303-301-7685 | Cell: 303-324-8340 tlee@transleaseinc.com cbergo@transleaseinc.com
www.transleaseinc.com WWW.TRANSLEASEINC.COM Security Shredding News Summer 2017
7
Security Shredding News
OCR Releases a Quick-Response Check-List to Help HIPAA-Covered Organizations Deal With Cyber-Attacks
T
he HIPAA Security Rule requires HIPAA covered entities and business associates to identify and respond to suspect or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity or business associate; and document security incidents and their outcomes. The HIPAA Security Rule also requires HIPAA covered entities and business associates to establish and implement contingency plans, including data backup plans, disaster recovery plans, and emergency mode operation plans. In June, the HHS, Office for Civil Rights (OCR) released A QuickResponse Checklist to help HIPAA-covered organizations deal with any cyber-attack that potentially exposes or exposes patient healthcare information. In the event of a cyber-attack or similar emergency an entity: •
Must execute its response and mitigation procedures and contingency plans. For example, the entity should immediately fix any technical or other problems to stop the incident. The entity should also take steps to mitigate any impermissible disclosure of protected health information, which may be done by the entity’s own information technology staff, or by an outside entity brought in to help (which would be a business associate, if it has access to protected health information for that purpose).
•
Should report the crime to other law enforcement agencies, which may include state or local law enforcement, the Federal Bureau of Investigation (FBI), and/or the Secret Service. Any such reports should not include protected health information, unless otherwise permitted by the HIPAA Privacy Rule. If a law enforcement official tells the entity that any potential breach report would impede a criminal investigation or harm
national security, the entity must delay reporting a breach (see below) for the time the law enforcement official requests in writing, or for 30 days, if the request is made orally. •
Should report all cyber threat indicators. Reports should be made to federal and information-sharing and analysis organizations (ISAOs), including the Department of Homeland Security, the HHS Assistant Secretary for Preparedness and Response, and private-sector cyberthreat ISAOs. Any such reports should not include protected health information. OCR does not receive such reports from its federal or HHS partners.
•
Must report the breach to OCR as soon as possible. The breach must be reported no later than 60 days after the discovery of a breach affecting 500 or more individuals, and notify affected individuals and the media unless a law enforcement official has requested a delay in the reporting. OCR presumes all cyber-related security incidents where protected health information was accessed, acquired, used, or disclosed are reportable breaches unless the information was encrypted by the entity at the time of the incident or the entity determines, through a written risk assessment, that there was a low probability that the information was compromised during the breach. An entity that discovers a breach affecting fewer than 500 individuals has an obligation to notify: individuals without unreasonable delay, but no later than 60 days after discovery; and OCR within 60 days after the end of the calendar year in which the breach was discovered.
For additional details on OCR’s recommendations for preventing and responding to a ransomware attack, see OCR’s ransomware guidance: https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdf
Data Destruction by the Book Finally, a book that tells the customer what reputable data destruction service providers have always wanted to say. • • • • •
How to pick a service provider What do regulations require Risk management best practices What to include in an RFP or contract Includes forms, policies & templates
Order your copy today! www.naidonline.org 8 Security Shredding News Summer 2017 Disposition halfpg ShreddingNews317.indd 1
This is the book your customers will soon be reading. 3/17/17 10:22 AM
Security Shredding News
Texas Health System Settles Potential HIPAA Disclosure Violations
W
ashington, D.C. – Memorial Hermann Health System (MHHS) has agreed to pay $2.4 million to the U.S. Department of Health and Human Services (HHS) for potential disclosure violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, according to a HHS news statement. OCR initiated a compliance review of MHHS based on multiple media reports suggesting that MHHS disclosed a patient’s protected health information (PHI) without an authorization. In September 2015, a patient at one of MHHS’s clinics presented an allegedly fraudulent identification card to office staff. The staff immediately alerted appropriate authorities of the incident, and the patient was arrested. Disclosure of the patient’s name to law enforcement was permissible under the HIPAA Rules; however, MHHS subsequently published a press release concerning the incident in which the patient’s name was included in the title of the release. In addition, MHHS failed to timely document the sanctioning of its workforce members for impermissibly disclosing the patient’s information. “Senior management should have known that disclosing a patient’s name on the title of a press release was a clear HIPAA Privacy violation that would induce a swift OCR response,” said OCR Director Roger Severino. “This case reminds us that organizations can readily cooperate with law enforcement without violating HIPAA, but that they must nevertheless continue to protect patient privacy when making statements to the public and elsewhere.” The resolution agreement and corrective action plan may be found on the OCR website at http://www.hhs.gov/hipaa/for-professionals/complianceenforcement/agreements/MHHS/index.html
www.bomaccarts.com
sales@bomaccarts.com
OCR Emphasizes Corrective Action Plans
F
or the past couple of years, Health and Human Services’ Office for Civil Rights (OCR) has been scrutinizing the risk management practices of covered entities. Writing in MedCityNews, attorney Ira Parghi says this focus is evident in the agency’s settlement agreement terms – specifically, the requirement for corrective action plans (CAPs). In a dozen HIPAA breach cases, the OCR has directed violators to perform an annual Risk Analysis and have an up-to-date Risk Management Plan in place, according to Parghi, who specializes in health information privacy and security and data informatics for Ropes & Gray in San Francisco. Compliance is becoming ever more challenging, however. “It is telling that not a single Risk Analysis or Risk Mitigation Plan reviewed in these cases was found to pass regulatory muster,” she wrote. The OCR wants all HIPAA-covered entities to more closely and consistently account for, and guard electronic equipment, data systems, and applications that contain or store ePHI. Annual Risk Analysis and Risk Management Plans are formal vehicles for accomplishing this, and the OCR has been sending a stern message that such plans should be developed and carried out in a comprehensive, not a cursory manner, according to Parghi. “All 12 CAPs have required the covered entity to either develop new policies or revise existing (inadequate) ones,” she wrote. “Many also expressly instruct the entity to distribute and upload the policies, train employees on them, and regularly review them. In some cases the requirement is worded broadly, though in others the OCR sets forth numerous specific subject areas (in one case, 15!) in which the entity must review or develop policies,” the attorney explained. “It suggests that, once the OCR undertakes a Security Rule-related investigation, it “pops the hood open” and looks around widely, investigating and imposing remediation with respect to a broad range of Security Rule requirements, even where the technical cause of the security incident at issue may be narrow.”
www.chachkagroup.com chachka@chachkagroup.com
Security Shredding News Summer 2017
9
Security Shredding News
No Business Associate Agreement? That’s a $31K Mistake
T
he Center for Children’s Digestive Health (CCDH) has paid the U.S. Department of Health and Human Services (HHS) $31,000 to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule and agreed to implement a corrective action plan. CCDH is a small, for-profit health care provider with a pediatric subspecialty practice that operates its practice in seven clinic locations in Illinois. In August 2015, the HHS Office for Civil Rights (OCR) initiated a compliance review of the Center for Children’s Digestive Health (CCDH) following an initiation of an investigation of a business associate, FileFax, Inc., which stored records containing protected health information (PHI) for CCDH. While CCDH began disclosing PHI to Filefax in 2003, neither party could produce a signed Business Associate Agreement (BAA) prior to Oct. 12, 2015. CCDH had impermissibly disclosed paper records relating to 10,728 patients to FileFax. CCDH also failed to receive from FileFax any HIPAA-compliant assurances indicating that FileFax had implemented appropriate safeguards to ensure the confidentiality, integrity, and availability of PHI prior to CCDH’s disclosure. Writing in a blog, Dickinson Wright attorney, Sara H. Jodka says,
“This settlement is worth noting is because it highlights the need for HIPAA-covered entities to obtain signed HIPAA-compliant business associate agreements (BAA) with all vendors prior to disclosing any protected health information.” A BAA must explain the business associate’s responsibilities, including allowable uses and disclosures of PHI, as well as advise the covered entity that the failure to comply with HIPAA rules can result in financial penalties being issued, Jodka wrote. The business associate must agree not to use or disclose any PHI unless required to do so under the terms of the BAA or as required by law. Importantly, the business associate must also notify the covered entity in the event that any PHI is accessed or disclosed along within the deadline time for doing so, she continued. The OCR instructed CCDH adopt a corrective action plan that includes updating policies and procedures, conducting staff training on those policies and procedures and ensuring employees are responsible for obtaining HIPAA-compliant BAAs from all business associates.
Survey Shows Small Business Owners Lack Policies for Confidential Paper Files
N
ew York, NY – Weak risk management could be making small businesses vulnerable to data theft, according to independent market research company, Ipsos. The company just released findings of its seventh annual Shred-It Information Security Tracker Survey. Conducting an online poll of Shred-It customers, Ipsos found that 39 percent of American small business owners (SBOs) lack any sort of policy for managing their confidential paper. Three in ten SBOs (32 percent) SBOs think that loss or theft of paper documents would not damage their organization, while three in ten (31 percent) think that a potential data breach wouldn’t have a significant impact on their organization. American C-suite executives express particularly cavalier opinions toward preventing data theft via paper files. Of those who have no policy for managing confidential paper documents, 6 percent indicated that document theft would not hurt their business, while 1 percent said they believed a data breach would have significant impact. The survey findings show that close to 40 percent of the C-suite executives surveyed expect their organizational paper volume to increase over the next year. Almost half (49 percent) of SBOs shred all documents, both confidential and not. Yet just one in ten (13 percent) say they keep their confidential documents in a locked console in the office until a professional shredding company destroys the materials. Regular document destruction and electronic device disposal events have been declining, too. The survey showed that confidence in secure destruction of both paper and electronic media seems to be decreasing. Strong understanding of compliance issues, reinforced by training on company information security procedures are most prevalent in financial, legal and insurance industries. In the retail sector, about 65 percent of the survey respondents indicated a good understanding of the legal requirements for storing, keeping or disposing confidential materials. Yet only one in ten (12 percent) said they use a locked console and a professional shredding service. Overall, the respondents working in each of four main small business sectors – retail, public services, real estate and business services – indicated weak policies and inconsistency for dealing with confidential papers and electronic device disposal and destruction.
Advertise here and reach over 3,000 businesses involved in ... Document & Product Destruction • Records & Media Storage Medical / Pharmaceutical Waste Transporting
For more information, contact Rick at 440-257-6453 or email rickdowning@oh.rr.com.
10 Security Shredding News Summer 2017
www.certifymerecycling.org info@certifymerecycling.org
Security Shredding News Summer 2017 11
PRSRT STD U.S. Postage
PAID
Cleveland, OH Permit #1737
6075 Hopkins Rd • Mentor, OH 44060 • Ph: 440-257-6453 • Fx: 440-257-6459 • Email: downassoc2@oh.rr.com
Inside This Issue
VOL. 14 NO. 2
Summer 2017
HR Technology: Time to Automate! PAGE 1 The Wider World of Electronics PAGE 4 Rising Container Rates Impact the Paper Market PAGE 6 OCR Releases a Quick-Response Check-List to Help HIPAA-Covered Organizations Deal With Cyber-Attacks PAGE 8 Security Shredding & Storage News, Mobile - 1/2 page, 4C No Business Associate Agreement? That’s a $31K Mistake PAGE 10 266.6mm h] [10 1/2inc
Shreds Everything!
533.4mm [21inch]
800mm h] [31 1/2inc
m 1108.6m nch] [43 21/32i
rail
Shreds Everything!
E EDD R R H H S S CKS S U CK TRU R T new & USed Single-Shaft RotaRy ShReddeRS PieRce & teaR ShReddeRS cdl & non-cdl
WITH
W
ba c fa ge ked Pa ctoRnUin by Rt S & y diRe Se ec RV t ice
IT H
(336) 285-0021 www.VecoPlanllc.com 5708 UwhaRRie Road • aRchdale, nc 27263
26' - 1"
Shreds Everything!
rail 8' - 7"
Yep, That Too! 35' - 4" Truck Curb Side Vie
w
17 Body (Tail End)
1,200 Cubic Feet Shredded Materia Storage Capacity