Development of your Company’s Record Information System and Disaster Preparedness The National Emergency Management Summit Thomas D. Anthony Frost Brown.

Slides:



Advertisements
Similar presentations
and Electronic Records Retention: IT Requirements Paul Dworak Office of Compliance
Advertisements

Introduction to Records Management Policy
Red Flags Rule BAS Forum August 18, What is the Red Flags Rule? Requires implementation of a written Identity Theft Prevention Program designed.
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Identification and Disposition of Official University Records University of Texas at Arlington Records Management.
Records Management for UW-Madison Employees – An Introduction UW-Madison Records Management UW-Archives & Records Management 2012 Photo courtesy of University.
Steps to Compliance: Managing Business Associates PRESENTED BY.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
IS BIG DATA GIVING YOU A BIG HEADACHE? Risk Reduction - Transactional, International and Liability Issues Oregon State Bar Corporate Counsel Section Fall.
Clean-up Days!.
© 2014 Nelson Brown Hamilton & Krekstein LLC. All Rights Reserved PRIVACY & DATA SECURITY: A LEGAL FRAMEWORK MOLLY LANG, PARTNER, NELSON BROWN & CO.
Ethical Issues in Data Security Breach Cases Presented by Robert J. Scott Scott & Scott, LLP
Ethical Issues in the Electronic Age Ethical Issues in the Electronic Age Frost Brown Todd LLC Seminar May 24, 2007 Frost Brown.
E-Discovery LIMITS ON E-DISCOVERY. No New Preservation Rule When does duty to preserve attach? Reasonably anticipated litigation. Audio sanctions.
W W W. D I N S L A W. C O M E-Discovery and Document Retention Patrick W. Michael, Esq. Dinsmore & Shohl LLP 101 South Fifth Street Louisville, KY
Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 Sara Juster, JD Vice President/Corporate Compliance Officer Nebraska.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
EDiscovery and Records Management. Records Management- Historical Perspective- Paper Historically- Paper was the “Corporate Memory” – a physical entity.
Developing a Records & Information Retention & Disposition Program:
Session V Records Management Process Development
Network security policy: best practices
Department of Commerce Records Management Training.
Created May 2, Division of Public Health Managing Records What is a Record? What is a Records Retention & Disposition Schedule? Why is this Important?
RECORDS MANAGEMENT MELANIE WELCH 1. What Is the Sunshine Law? The Sunshine law grants every person the Constitutional right to: ◦ View or copy any public.
Records Management Fundamentals
Why Information Governance….instead of Records & Information Management? Angela Fares, RHIA, CRM, CISA, CGEIT, CRISC, CISM or
Investigating & Preserving Evidence in Data Security Incidents Robert J. Scott Scott & Scott, LLP
UTA RIMUTA RIM Compliance and Common Sense Compliance: Texas requires all state agencies, city and county governments, school districts, and other government.
Electronic Records Management: What Management Needs to Know May 2009.
HIPAA PRIVACY AND SECURITY AWARENESS.
Planning an Audit The Audit Process consists of the following phases:
Attorney-Client Privilege and Privacy Considerations Between US Corporations & Foreign Affiliates General Counsel Conference, Washington, D.C. October.
Compliance Management Platform ™. Compliance Management Platform Compliance is the New Marketing – Position yourself to thrive in the new regulatory and.
RECORDS MANAGEMENT Office of Compliance. OBJECTIVES Four main objectives of a Records Management Program: –Increase efficiency of record keeping. –Protection.
Lesson 5-Legal Issues in Information Security. Overview U.S. criminal law. State laws. Laws of other countries. Issues with prosecution. Civil issues.
Against: The Liberal Definition and use of Litigation Holds Team 9.
LeToia Crozier, Esq., CHC Vice President, Compliance & Regulatory Affairs Corey Wilson Director of Technical Services & Security Officer Interactive Think.
Developing Plans and Procedures
P RINCIPLES 1-7 FOR E LECTRONIC D OCUMENT P RODUCTION Maryanne Post.
CORPORATE RECORDS RETENTION POLICY TRAINING By: Diana C. Toman, Corporate Counsel & Assistant Secretary.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
Records Management and Open Government Texas State Library and Archives Commission Presented by Bonnie Zuber.
SCHOOLS FINANCE OFFICERS MEETINGS Records Management, “Paper-Lite” Environments and Procedures when a school closes Elizabeth Barber.
All Employee Basic Records Management Training. Training Overview 1.Training Objectives 2.Clark County RIM Program 3.Key Concepts 4.Employee Responsibilities.
1Copyright Jordan Lawrence. All rights reserved. U. S. Privacy and Security Laws DELVACCA INAUGURAL INHOUSE COUNSEL CONFERENCE April 1, 2009 Marty.
Legal Holds Department of State Division of Records Management Kevin Callaghan, Director.
Chris Apgar, CISSP President, Apgar & Associates, LLC December 12, 2007.
Data Security & Privacy: Fundamental Risk Mitigation Tactics 360° of IT Compliance Anthony Perkins, Shareholder Business Law Practice Group Data Security.
Record Retention to Manage Risk F. Jay Meyer Vice President & Senior Attorney TD Banknorth, N.A. Portland, Maine.
RECORDS MANAGEMENT Office of Business Affairs. OBJECTIVES Four main objectives of a Records Management Program: –Increase efficiency of record keeping.
Chapter 4: Laws, Regulations, and Compliance
Investigations: Strategies and Recommendations (Hints and Tips) Leah Lane, CFE Director, Global Investigations, Texas Instruments, Inc.
1 Information Governance (For Dental Practices) Norman Pottinger Information Governance Manager NHS Suffolk.
RECORDS MANAGEMENT TRAINING City of Oregon City. INTRODUCTION TO RECORDS MANAGEMENT
HOW TO AVOID COMMON DATA BREACH PITFALLS IAPP Privacy Academy 2014.
Registrar RML Training Records Management Assistance (281) Records Management 1.
Business Continuity Planning 101
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
Wisconsin Department of Health Services Purchase of Services Contract Guide Julie Anstett and Lucinda Champion Friday, May 6, 2016 Wisconsin Department.
RECORDS MANAGEMENT TRAINING City of Oregon City. INTRODUCTION TO RECORDS MANAGEMENT.
Data Minimization Framework
Development of your Company’s Record Information System and Disaster Preparedness The National Emergency Management Summit Thomas D. Anthony Frost Brown.
Responding to a Data Breach 360° of IT Compliance
Chapter 3: IRS and FTC Data Security Rules
Records Management Compliance Training
Red Flags Rule An Introduction County College of Morris
Current Privacy Issues That May Affect Your Credit Union
RECORDS AND INFORMATION
General Data Protection Regulation
Presentation transcript:

Development of your Company’s Record Information System and Disaster Preparedness The National Emergency Management Summit Thomas D. Anthony Frost Brown Todd LLC Attorneys at Law 201 E. Fifth Street Cincinnati, Ohio (513) February 4, 2008 Track 2.07

Principal Purposes Efficient and effective management; Good business practices; Destruction and elimination; Adherence to laws and regulations; Avoidance of fines, sanctions, obstruction of justice charges; Avoidance of spoliation of evidence; Safeguard and back-up records; Protection of individuals and their information. 2

Business Requirements Products or services; Dependence on product designs, blueprints, specifications, formulas; Use of plans, operational models and manuals; Use of data banks of individual information; Training and safety under OSHA, etc.; Purchasing methods and protocols; Intellectual property, sales and marketing literature; Information technology, accounting and management; Other business rules of the organization. 3

State Law Regulatory Agencies Banking Utilities Real Estate Tattoos Health Care Uniform Preservation of Business Records Act Data Breach Notification Acts 4

Federal Laws Section 6801 and 6805(b)(2) of the Gramm-Leach-Billey Act, 15 USC Section 6801; Section 552 of the Freedom of Information Act; Section 552(a) of the Privacy Act; The National Archives in Records Administration, 44 US Code Chapter 21; The Federal Records Act, 44 US Code Chapter 21; The Federal law on disposal of records, 44 US Code Chapter 23; The Internal Revenue Code; The Paper Reduction Act, 44 US Code Chapter 35; The Health Insurance Portability and Accountability Act of 1996 (HIPPA), 42 US Code 1320d-2(d)(2); The Sarbanes Oxley Act of 2002, Public Law ; The Administrative Procedures Act, 5 US Code Chapter 5; The PATRIOT Act; The Environmental Protection Act. 5

International Laws The Safe Harbor Act which was adopted in 1998 by the European Union and also known as the European Union Data Protection Directive. The Canadian Personal Information Protection and Electronic Documents Act (PIPEDA). France: CNIL Guidelines. Ireland: Data Protection Acts of 1998 and Germany: Federal Data Protection Act. Italian: Personal Data Protection Code. Asian Pacific: Economic Conference privacy principles. 6

The Seven Steps 1. Form the management team. 2. Create the response team. 3. Categorize all records. 4. Identify all retention requirements. 5. Prepare the record retention policy. 6. Prepare the backup and retrieval plan. 7. Train all parties on response and their roles in it. 7

Formation of Management Team Legal Department Tax Staff Information Technology Senior Management Review record retention policies of other companies Create timelines, milestones, and targets Leadership “buy-in” and enforcement 8

The Response Team The team leader = in-house counsel Information technology Litigation support specialists Outside counsel Attorney-client privilege Outside storage vendor Communications team 9

The Response Quick and efficient implementation of the response plan Business copies and personal copies. All forms of media All forms of electronic equipment Educate IT personnel IT backup schedules, retention and destruction protocols, networks, servers, and the electronic mapping Back up mapping and management IT for business purposes only “Blind” copies easily revealed Halt destruction FRCP rule 16(c) and 16(h) pretrial conferences 10

The Response Relevance and Privilege Engage crisis communications group Use intrusion detection technology Internal notification of data security breaches Plan for data security breaches Adopt measures to contain and control breaches Formulate crisis communications content 11

The Response Identify law enforcement agency contacts Prepare written procedures for notification of victims Conduct assessment of scope of breach Notify affected individuals as soon as possible Deploy crisis communications plan 12

Notification By Conspicuous notice on website Notice to major media outlets – 75% of population At least ¼ page ads in newspapers for 3 weeks No less than 45 days within discovery of event 13

Sort by Category and Format Letters Corporate Records Contract Business Records Written Electronic Folders 14

Retention Requirements 1. Statutes of Limitations 2.Business Needs 3.Historical Value 4.Legal and regulatory requirements 5.Business and industry practices 15

Prepare the Policy Policy must be “reasonable” To be reviewed by a hostile third party Express desire to satisfy business and legal requirements Specify rational for each retention period Federal, international and state retention requirements Consider and plan for possible disaster scenarios Be conservative Identify all official records Identify official authority Reasonably comprehensive Avoid selective destruction Create back up plans Communicate back up plans to employees Develop comprehensive communication plan 16

Spoliation of Evidence Never destroy records involved in litigation Spoliation worse than damaging documents Fines, penalties and more… 17

Publishing, Training and Oversight Distribute policy to all company personnel Train on meaning, purpose, and operation Practice disaster simulations Practice dealing with all forms of media All must comply Periodically audit and revise Senior management engagement and approval 18

Documentation Approvals of proper executives General counsel, CIO, director of taxation, vice president or president Policies, procedures, audits, revisions Engage outside storage vendors Operational implementation 19

Document Destruction Have clear plans and processes Keep notes of what was destroyed, when, and by whom Avoid appearance of selective destruction No individual discretion Impose litigation “Holds” Create and follow business rules 20 Cinlibary