Skip to main content

Security Shredding & Storage News Nov/Dec 2012

Page 1

&

Volume 9, Issue 6

November / December 2012

Security Shredding Storage News

Serving the Security Shredding & Paper Recovery Markets Visit us online at www.securityshreddingnews.com

ATTENTION:  New HIPAA Rules to Impact Document READERS !

Are you looking for Products, Equipment or Services for your business? If so, please check out these leading companies advertised in this issue: Collection & Storage Containers Big Dog Shred Bins – 10 Bomac Carts – pg 7 Jake, Connor & Crew – pg 5

Destruction Industry By P.J. Heller

Equipment Financing TransLease Inc – pg 12 Lock & Locking Systems Lock America Intl. – pg 10

D

Mobile Truck Shredders Alpine Shredders Ltd – pg 14 Shred-Tech Limited – pg 6 ShredFast – pg 8 Vecoplan LLC – pg 7 Moving Floor System Keith Manufacturing – pg 6 Paper Balers IPS Balers, Inc. – pg 10 Replacement Parts Dun-Rite Tool – pg 12 ShredSupply – pg 9 Stationary Shredders & Grinders Allegheny Shredders – pg 5 Schutte-Buffalo Hammer Mill, LLC – pg 16 UNTHA America – pg 15 Waste commodity purchasers Dan-Mar Components – pg 13

PRSRT STD U.S. Postage

PAID

Mentor, OH PRSRT STD Permit No. 2 U.S. Postage

PAID

Mentor, OH Permit No. 2

ocument destruction companies that handle protected health information for healthcare providers may face greater scrutiny — and hefty mandatory fines — in the coming year as the government steps up enforcement of privacy and security rules under the Health Insurance Portability and Accountability Act (HIPAA). New rules to be announced soon are expected to make business associates — such as document destruction companies or other service providers — subject to the most substantive provisions of HIPAA, as well as all of its Security Rule, rather than allowing them to rely on their business associate agreements. Also expected are automatic mandatory fines for violations of “willful neglect” by either the healthcare industry or business associates of $10,000 to $50,000 per record, up to a maximum annual cap of $1.5 million. That maximum figure applies only on a per provision basis; violations of separate provisions are capped separately, not cumulatively. A document destruction company involved in a data breach that is subsequently found not to have trained its employees and to not have any written policies in place could be cited for willful neglect. “So whatever the data breach was, the U.S. Department of Health and Human Services (HHS) is going to hold them to the highest standard, the highest level of fines, because they’re finding it inexcusable that any organization touching data would not have written policies in place and employee training in place,” notes Bob Johnson, chief executive officer of NAID (National Association for Information Destruction). Health and Human Services reports that business associates have been responsible for 62 percent of the total number of patient records breached, according the Association of Corporate Counsel, a global bar association.

Another major issue to impact healthcare providers and their business associates will be an audit program anticipated in the coming year. The audits are mandatory under HITECH (the Health Information Technology for Economic and Clinical Health Act). HITECH was passed by Congress as part of the 2009 American Recovery and Reinvestment Act, more commonly known as the “Stimulus Bill.” “Health and Human Services has announced there will be a formal unannounced auditing program of both covered entities and business associates,” Johnson says. Covered entities include healthcare providers, health plans and healthcare clearinghouses. Although it is not known how many resources will be devoted to the audit program, “everybody’s on notice that they’re going to be checked by Health and Human Services at some point or they stand the possibility of it, and you never know where it’s going to come from,” he says. Leon Rodriguez, director of HHS’ Office for Civil Rights, has confirmed that

Continued on page 3

Inside This Issue

4 Using ARMA’s GARP Principles to Create a Compliant Records Management Program

6 Chicago Election Board Confirms 1200 Personnel Files Exposed 10 NAID Acquires Shred School 13 Easing of Medical Record Restrictions Ensures Post-Sandy Patient Care


We make recycling look completely different. R2/RIOS™ certification makes recycling electronics more profitable. What if you could reduce your business risk, enhance competitive advantage, and improve your company’s bottom line – all at the same time? Now you can. By investing in R2/RIOS™ certification your company is upgrading to the highest, most responsible standards in electronics recycling. Here’s how certification has helped others and can benefit you: • elevates quality of products and services, reducing customer issues • secures employee retention and job satisfaction • improves employee safety and decreases OSHA recordable incidents

• boosts environmental footprint and decreases risk of environmental issues • decreases commercial insurance premiums • provides due diligence to meet customer requirements • assures compliance with domestic and international laws What’s more, certification gives you the peace-of-mind of knowing your company has the highest “seal of approval” in electronics recycling. To get certified today, visit www.ISRI.org/certifyme

Visit&the R2/RIOS™ booth/ December at the E-Scrap 2012 Conference. Storage News. November 2012 2 Security Shredding

TM


Security Shredding & Storage News

New HIPAA Rules to Impact Document Destruction Industry Continued from page 1

PUBLICATION STAFF Publisher / Editor Rick Downing

Contributing Editors / Writers Chad Bevington P. J. Heller

Production / Layout Barb Fontanelle Christine Pavelka

Advertising Sales Rick Downing

Subscription / Circulation Donna Downing

Editorial, Circulation & Advertising Office 6075 Hopkins Road Mentor, OH 44060 Ph: 440-257-6453 Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.sssnews.com For subscription information, please call 440-257-6453 Security Shredding & Storage News (ISSN #1549-8654) is published bimonthly by Downing & Associates. Reproductions or transmission of Security Shredding & Storage News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment.  ©Copyright 2012 by Downing & Associates.

Printed on 10% Post-Consumer Recycled Paper

enforcement of HIPAA’s privacy and security rules information (ePHI) that was stolen from the vehicle would be stepped up in 2013. His agency has been of a department employee. It was OCR’s first HIPAA conducting the pilot audit project; an estimated 115 enforcement action against a state agency. covered entities are expected to be audited with a In another case, Minnesota settled for $2.5 permanent compliance audit program which could million an action against a business associate that be launched in the coming year. alleged numerous violations of laws including “This audit program has exposed vulnerabilities HIPAA, Johnson reports. and issues that we can’t find any other way,” Rodriguez And in yet another case, the Massachusetts Eye says. “I think it will be good policy for us to really and Ear Infirmary and Massachusetts Eye and Ear keep this audit program going.” Associates Inc., agreed to pay $1.5 million to settle The audits in the pilot program, conducted by potential violations of the HIPAA Security Rule. consulting firm KPMG, do not involve business Although the president’s budget for fiscal associates such as document destruction companies year 2013 cuts the OCR budget by about or cloud computing providers, $2 million, it is not expected but those service providers to have much impact on “But now we’re seeing enforcement efforts. and others are expected to be included in future audits, “We will be able to, given where virtually every according to Linda Sanches, the pace we’ve already had senior adviser and health of monetary recoveries — contract has a clause in and this is just the opening information privacy lead in the Office for Civil Rights (OCR). threshold of our work — the it that says the service monetary recovery is really “A s t h e O C R a u d i t program moves from pilot to what will provide us a pretty a fully enforced program in provider will be liable for decent way of keeping our 2013, the number of surprise investigative capacity up audits and fines are expected any financial damages or and perhaps adding some,” to skyrocket,” predicts Mike Rodriguez said in an interview breach notification costs with HealthcareInfoSecurity. Klein, president and chief operating officer of Online “If Health and Human that they cause.” Tech in Ann Arbor, Mich., Services or state attorneys a provider of co-location, general receive a credible report managed servers and private cloud services. “While of an incident that could rise to the level of willful no one enjoys the threat of a government-sponsored neglect it’s mandatory that they investigate,” says audit program, and even worse, the possibility of NAID’s Bob Johnson. “They have to investigate if multimillion dollar fines, the U.S. government is they get such a report.” demonstrating that they are taking HIPAA law He stresses that service providers need to train enforcement seriously . . .” their employees and have policies and procedures in The Office for Civil Rights enforces the place to address privacy and security concerns. Any HIPAA Privacy Rule, which protects the privacy employee who finds the slightest discrepancy that of individually identifiable health information; the suggests a customer has a potential data breach, for HIPAA Security Rule, which sets national standards example, must report it to management. Management for the security of electronic protected health must then report it to the customer. information; and the confidentiality provisions of “A service provider doesn’t have to inform the the Patient Safety Rule, which protect identifiable authorities,” Johnson notes. “A service provider’s information being used to analyze patient safety only responsibility is to inform their customer. The events and improve patient safety. service provider will never have to do the data breach Increased enforcement efforts also involve notification. It’s always going to be the customer. state attorneys general, who have been trained to It’s going to be the primary data custodian that enforce HIPAA. At least four states have pursued has to clean up the mess, even if it’s caused by the HIPAA enforcement actions since July, according service provider.” to Elizabeth Johnson, a lawyer with Poyner Spruill Because of that, however, customers are now in North Carolina. looking at having service providers indemnify them “Covered entities should anticipate the trend of for damages they cause. In the past, this wasn’t much increased state enforcement will continue as reported of an issue in the document destruction industry, security breaches, HHS audits, and individual Johnson says. complaints continue to uncover compliance problems “But now we’re seeing where virtually every that reaffirm to government agencies their pursuit of contract has a clause in it that says the service such enforcement is often fruitful,” she says. provider will be liable for any financial damages or How fruitful that enforcement is can be seen in breach notification costs that they cause,” he says, cases such as one against the Alaska Department of noting that NAID offers its certified members an Health and Social Services. That agency agreed to pay insurance policy to cover them. $1.7 million to settle a HIPAA case involving a USB Elizabeth Johnson says business associates should drive possibly containing electronic protected health Continued on page 5

Security Shredding & Storage News. November / December 2012

3


Security Shredding & Storage News

Using ARMA’s GARP Principles to Create a Compliant Records Management Program — A Guide to Assist with the Proper Implementation of a Records Management Program —

D

eveloping a compliant records management program is essential for a productive, organized business, but it can be a challenging task. With numerous file labels, retention schedules and varying points of contact, organizing a system that achieves specific business goals while keeping operations compliant can leave records managers and IT professionals frustrated and confused. “In the insurance industry, there are multiple types of files and varying file requirements for each state in which we operate,” said Cathy Marsh, Assistant Vice President, Corporate Services at Ohio National Financial Services. “While it took us awhile to develop a consistent and streamlined records management program, it has been an integral step in keeping our business running smoothly.” To assist businesses with the creation, organization, security and maintenance of a records management program, ARMA International published the eight Generally Accepted Recordkeeping Principles (GARP®). As an authority of education on information management issues, ARMA International developed the principles with the help of individuals fully involved in recordkeeping. The eight key principles upon which GARP was developed can provide a framework for a successful records management program. These principles include:

1. Principle of Accountability. Appoint an appropriate person to oversee

the entire records management program. This person will be responsible for structuring the program, delegating tasks and assigning appropriate contacts within departments.

2. Principle of Integrity. Ensure records are authentic, unaltered and accurately

reflect the represented organization. Be able to prove an acceptable audit trail and creation of the record.

3. Principle of Protection. Implement standards to protect records and information that is confidential, privileged, secret or essential to business continuity.

4. Principle of Compliance. The records management program follows the

standards, laws and other binding authorities set by legal organizations or company standards.

5. Principle of Availability. Records are stored and organized in a manner that allows for timely, efficient and accurate retrieval of requested information.

6. Principle of Retention. The records management program follows a

retention schedule that was developed considering legal, regulatory, fiscal, operational and historical requirements.

7. Principle of Disposition. The organization takes secure measures to properly dispose of records at the end of their lifecycle.

8. Principle of Transparency. The records management program is easily understandable to employees and outside parties, including government authorities, auditors and investigators.

Customizing Records Management Processes

B

y using these eight principles as a framework, records managers can begin building their own program that reflects their specific business processes. It is important to understand how each principle applies to the organization. For example, when establishing the principle of accountability, records managers should consider the size of their business. For a small organization, it may be acceptable to have one person in charge of the records management program. This setup, known as a centralized system, appoints one individual who handles all information and decisions related to the program. This person is also responsible for implementing and executing all activity relevant to the records management policy. However, a large business with multiple departments and types of records will require additional oversight. This system would benefit from a decentralized records

By Chad Bevington

management program where a lead records representative oversees the activity of several departmental records representatives who assist with the implementation and execution of the program in specific areas of the business. These individuals manage the retention schedules, employee training and day-to-day functioning of the program. With this system, records representatives meet on a regular basis to discuss program successes or challenges, changes in the principles and ideas to further develop the system. This system helps delegate responsibility and ensures individual employees can easily contact a records representative when necessary. Similarly, records managers should consider the size and scope of their business when evaluating the principle of retention. Developing and following a retention schedule can be a challenge if an organization operates in multiple states with different regulations and laws and/or if they receive payments from customers in multiple states. To simplify the program and avoid multiple retention requirements, implement a retention schedule based on the state or region with the strictest regulations and longest longevity for retention. Using this method, the organization will meet all legal and regulatory requirements while streamlining the records management process and eliminating the need to separate files by state. To ensure compliance, decide the appropriate retention period for each type of record with the help of an attorney. “In our situation, we reviewed all the state recordkeeping requirements and found that Pennsylvania had the most rigorous standards,” said Marsh. “We used this as our benchmark and developed our program around that. It made the program a lot easier rather than negotiating around the legal requirements of several different jurisdictions.” When considering the availability and transparency principle, records managers are encouraged to review how documents are titled and create a standardized labeling system throughout all departments. Most employees will label records according to personal preference; however, as convenient as this is for individual employees, it results in an unorganized system. This can create a problem if an audit requires proof of a certain type of record and that record is unable to be retrieved. To create a streamlined system and reduce the amount of time spent filing and retrieving items, implement standards for labeling and storing records that can be integrated throughout all departments. “When we conducted an audit of our system, we found that we had more than 3,000 different records names,” Marsh advised. “For a journal voucher record, they were titled ‘JV’ or ‘J Voucher’—we had more than 100 different names for the same file. By setting a standard for titling documents, we were able to reduce the number of files to just 120 record names.”

Purging Old Records

W

hen paper records reach the end of the pre-determined lifecycle, GARP recommends secure and appropriate disposal. To ensure the highest standards of security are met, records managers should partner with an AAA NAIDcertified shredding provider that destroys documents on a scheduled basis and provides a certificate of destruction for a legal audit trail. While sometimes daunting, the task of organizing a company’s records is not an impossible task. By using GARP as a framework, records managers can develop a compliant and effective records management program that meets the specific needs of the business and ensures that documents are readily available—or destroyed—at pre-defined points in the process. Chad Bevington is Regional Business Director of Cintas Document Management. For more information, visit www.cintas.com/DocumentManagement.

4 Security Shredding & Storage News. November / December 2012


Security Shredding & Storage News

New HIPAA Rules to Impact Document Destruction Industry

[ Document protection? ]

Continued from page 3

“carefully review any business associate agreements provided to them by clients, because those contracts are much more likely now to include unfavorable terms for the business associate regarding breach notification, security obligations, liability and indemnification. “Business associates also should focus efforts on implementation of the Security Rule, which has been a special focus of HHS’s audits this year,” she advises. As liabilities for customers go up, service providers now will have those same liabilities, Bob Johnson says. “They’re in lockstep,” he says. Elizabeth Johnson agrees, noting that new rules, including the HIPAA Security Rule, will now apply directly to business associates, not just covered entities. “Under prior rules, business associates were only required to abide by the terms of their business associate agreements, not the rules directly,” she explains. “As a result, HHS can take enforcement actions against business associates and, due to a 60-fold increase in their fining authority, can seek a maximum monetary penalty of $50,000 per violation.” Although the government stresses the importantance of security and privacy for protected health information, it provides no specific information about destruction of that material. “Nowhere in any of the five HIPAA rules does it say a word about data For the right solution, contact: destruction, particle size, or anything about how or where PHI has to be www.jakeconnorandcrew.com destroyed,” Johnson wrote in a recent blog on the NAID website. or call 1-877-565 -JAKE (5253) Health and Human Services does say that proper disposal methods for paper records may include, but are not limited to, “shredding, burning, pulping Jake, Connor & Crew’s containers are We don’t just protect documents, recyclable, comply with LEED and CARB II or pulverizing the records so that PHI is rendered essentially unreadable, we protect your reputation. regulations and are JCAHO compliant. indecipherable and otherwise cannot be reconstructed. “Depositing PHI in a trash receptacle generally accessible by the public or Info Request #105 other unauthorized persons is not an appropriate privacy or security safeguard,” the agency says. “Instead, covered entities must implement reasonable safeguardsJCAC_SSSN_QuarterPgLockItAds.indd 2 12-08-30 to limit incidental, and avoid prohibited, uses and disclosures of PHI. Failing to implement reasonable safeguards to protect PHI in connection with disposal could result in impermissible disclosures of PHI.” Bob Johnson says the fact that document destruction is not addressed under HIPAA rules is not an issue. “Even though data destruction is not specifically required in writing by HIPAA, it is a requirement,” he says. “Like every other data protection law on the books, HIPAA is based on the reasonableness principle. No one could ever say it was ‘reasonable’ to discard information without destruction and still meet the requirement to prevent unauthorized access to PHI. “It is still important that destruction professionals know the distinction and talk about it correctly in the marketplace,” he adds. “To say HIPAA requires data destruction is not accurate. It is better to say HIPAA requires the prevention of unauthorized access to PHI, which, in turn, necessitates destruction. “It remains to be seen whether clearer requirements for destruction will Opt instead for the most effective solution for TOTAL DESTRUCTION emerge in the long overdue HITECH Final Rule,” he says. of electronic storage devices – the Allegheny Hard Drive Shredder! For both covered entities and their business associates, complying with Built with impact-resistant tool steel cutters HIPAA is no easy task. and an extremely powerful drive train, these Shred Nations, a network of more than 500 shredding companies across babies are the most rugged in the industry! North America, offers one solution. Make the smart choice–and spare yourself “What’s the best way to avoid a problem with the HIPAA police,” the any collateral damage! Lakewood, Colo.-headquartered company asks on its website. “Release nothing without a release, employ a certified contractor 800-245-2497 and shred everything as soon as permitted, get incontrovertible “Our Allegheny Hard Drive Shredder can proof, and make sure the world knows it. ■ Complete destruction with no shred 1500 hard drives in half a day – “Prescription: Take two aspirin, and call your shredder retrieval possible it’s already paid for itself tenfold.” ■ Destroys 25–45 hard drives per min. tomorrow morning.” TIM EARLEY - Advantage E-cycling

Document protection is never in question with Jake, Connor & Crew consoles and bins.

®

Need to Destroy Hard Drives?

■

attention: readers!

Ideal for contract shredding services, e-scrap recyclers

THE SHREDDING INDUSTRY ICON SINCE 1967

Would you like more information about products and equipment advertised in this issue? If so, please complete the Equipment Locator Service form located between pages 8 & 9 and fax to 440-257-6459.

solutions@alleghenyshredders.com

www.alleghenyshredders.com

Info Request #106

Security Shredding & Storage News. November / December 2012

5

1:59 PM


In the News NAID-Canada Members Elect Candidates to Board

I

n recent NAID Canada elections, Kevin Perry of Shred Guard in St. Johns, New Brunswick, Canada was elected to a two-year term as chairman of the NAID-Canada Board of Directors. Additionally, Greg Olynyck of EnviroShred based in Calgary, Alberta, Canada was elected to serve a two-year term as a director. Perry replaced Dave Carey of Iron Mountain as NAID-Canada’s chair, who will now assume the post of past chair. Wendy Banting of Secural Datashred in Vaughan, Ontario, Canada continues her term as director and Krisjan Backman of Phoenix Recycling in Winnipeg, Manitoba, Canada continues his term as secretary/treasurer. Both terms will expire November 2013. The chair of NAID-Canada also serves as a director on the NAID Global Board of Directors, which Perry will assume in March. NAID-Canada has experienced dramatic growth over the past few years, and currently boasts 120 member locations, 63 of which are NAID Certified.

Chicago Election Board Confirms 1200 Personnel Files Exposed

C

hicago, IL—According to an article on ChicagoTribune.com, 1,200 job applicant files were exposed inadvertently on the Chicago Board of Elections website recently. The information security company, Forensicon, which discovered the mistake, alleges that the breach also may include personal information of up to 1.7 million registered Chicago voters. An election board spokesman said the voter information is normally publicly accessible and no sensitive data was involved. However, for approximately one week in November, the names, addresses, driver’s license numbers and the last four digits of social security numbers of some 1,200 poll work applicants were displayed on a publicly-accessible page. The Board of Election Commissioners had the page removed immediately after being notified by Forensicon, and each of the job applicants whose personal data had been exposed was contacted. The breach occurred when a temporary website was created on November 6 to accommodate increased site traffic caused by Chicagoans searching for their new polling places. In 2006, the board had to correct a breach that involved the sensitive information of some 780,000 registered voters.

www.keithwalkingfloor.com

Info Request #117

Hospital Marketing Methods Questioned

C www.shred-tech.com

www.shred-tech.com

Info Request #157

olumbus, OH—The Columbus Dispatch reports that patient privacy may be compromised through popular marketing strategies that are being used by hospitals. Often administered under the rubric of “customer-relationship management,” the strategies employ predictive methodologies involving patient files. Patient data is used in this way to deliver specific promotional messages. For example, new mothers or patients with diabetes and heart conditions may find themselves receiving customized mailers and reminders. Attendees of health fairs and seminars, as well as health screening participants, may receive notifications promoting other hospital events and services. Hospitals such as OhioHealth and Mount Carmel say their marketing communications are largely educational and useful in developing preventive healthcare programming. They stress that that individual patient data is not revealed in ways that violate HIPPA rules. Both health systems say they use thirdparty companies to process their patient data, which is encrypted. In addition, they say such business associates are bound by health data privacy laws. Medseek, a provider of patient data processing services, reports that electronic health records make it possible for some 25 percent of U.S. hospitals to identify and reach such target audiences. Read more: http://www.ihealthbeat.org/articles/2012/11/13/some-hospitalsusing-patient-data-to-boost-marketing-campaigns.aspx#ixzz2EdGgr8vX.

6 Security Shredding & Storage News. November / December 2012


In the News Iron Mountain Announces Appointment of New CEO

Richard Reese to Retire from the Company after 31 Years

I

ron Mountain Incorporated (NYSE: IRM), the information storage and management company, recently announced that its Board of Directors has voted unanimously to appoint William Meaney President and Chief Executive Officer and a member of the Board, effective Jan. 7, 2013. He will succeed longtime Executive Chairman and CEO Richard Reese, who announced his intention to retire after 31 years at the Company. Meaney, 52, comes to Iron Mountain with more than 20 years of experience successfully overseeing diverse businesses in the United States, Europe, Asia and Africa. According to the Company, Meaney’s track record reveals a proven ability to drive growth even in challenging environments and maximize returns on investment in capital intensive businesses. Most recently, Meaney served as CEO of the Hong Kong-based Zuellig Group, a $12 billion, primarily businessto-business conglomerate that saw sales triple during his eight-year tenure from 2004-2012. Iron Mountain’s Board also announced that Al Verrecchia, lead independent director, will succeed Reese as Chairman of the Board effective in March 2013, when Reese will also retire from the Board. According to the Company, their Board believes that separating the chairman and CEO roles at this time represents the best leadership structure for the Company and is consistent with best practices for corporate governance. Verrecchia joined Iron Mountain’s Board of Directors in March 2010. He has also served as Chairman of the Board at Hasbro Inc. since 2008. Reese served as CEO from December 1981 to June 2008 and returned as CEO in April 2011. He also served as Chairman beginning in 1995 and as Executive Chairman since June 2008. During his tenure, he grew the business from a regional provider with $3 million in annualized revenues to a global leader in information management and storage with more than $3 billion in sales.

Collecting Sorting Recycling Phone:262.882.1227 Fax: 262.882.3389 www.bomaccarts.com

Sometimes big is just....weird!

Info Request #133

The “Mighty-Mite”

Introducing the “Smaller” Vecoplan VST-32 Shorty Non-CDL Mobile Shredder • 26,000 GVW, Non-CDL Mobile Shredding System • Curb-Side Toter Lift • “SureTrac”™ Gliding Floor Discharge System

Featuring the NEW VNZ-80 Shredder • Variable and Controllable, Screened Particle Size • Electric Drive • Large Infeed Hopper • Jam-Proof Design

Phone: (336) 252-4421

vecoplanllc.com Contact Vecoplan Today For More Information www.vecoplanllc.com Info Request #116

Security Shredding & Storage News. November / December 2012

7


www.shredfast.com

Info Request #158

8 Security Shredding & Storage News. November / December 2012


www.shredsupply.com

info@shredsupply.com

Info Request #129

Security Shredding & Storage News. November / December 2012

9


In the News Now Even More Options for Customers Who Want Their Own Key Codes! Lock America Adds More Common Key Codes for Padlocks and Console Locks. • •

Give your drivers and customers a single key that fits all the locks at a site. Ask your console or bin supplier for new available key codes, or contact Lock America directly.

One Key Fits All Your Locks with No Restrictions!

Tel: (951) 277-5180 Fax: (951) 277-5170 www.laigroup.com

800-422-2866 Corona, CA 92883 9168 Stellar Court sales@laigroup.com

Info Request #152

NAID Acquires Shred School

N

AID recently announced it has acquired the rights to the trade name Shred School® from Total Training Services, Inc. “As far as we were concerned, it was a no-brainer,” said NAID President Scott Fasken. “Shred School was a strong brand with a good reputation and a mission that aligns perfectly with NAID’s mission.” Regarding the transition, Total Training’s former President Ray Barry said, “It was very important to me that Shred School had a good home. The acquisition of the brand by NAID ensures it will. I can think of nothing better for it.” NAID intends to use the Shred School as a platform for providing advanced training for the association’s growing list of sales and marketing programs as well as traditional secure destruction sales techniques and regulatory issues. “We’re in the process of retooling the Shred School list of services and events,” said NAID CEO Bob Johnson. “In February 2013, we will reintroduce the program with a new website and a full explanation of new member benefits offered under its name.”

Macy’s Parade Confetti Compromising

T

www.ipsbalers.com Info Request #145

www.chachkagroup.com chachka@chachkagroup.com

10 Security Shredding & Storage News. November / December 2012

his season’s Macy’s Thanksgiving Day Parade was colorful for more than just the floats. The confetti – consisting of recycled shredded paper – represented an embarrassing security breach. According to an article posted on SecurityManagement.com, the confetti was sourced from legal documents involving several financial institutions. Nassau County Police Department officials immediately began investigating the data breach when a parade watcher brought in a strip of paper showing a Social Security number. The shred used for the confetti was traced to the police department itself. As NYPD was reviewing their document destruction policies, news of the incident prompted comment from the CEO of the National Association for Information Destruction (NAID), Bob Johnson. According to Johnson, documents that are outsourced for destruction are pulverized in massive volumes, commingled with the papers of hundreds of other businesses, and sent to a paper mill for destruction and recycling. This ensures that no identifiable information remains. All the links in the chain of custody are important because mistakes can happen. Last May, Boston’s South Shore Hospital was fined $750,000 when boxes of unencrypted computer tapes that contained protected health information were lost on the way to the document destruction company. In 2009, after the New York Yankees won the baseball World Series, shredded pay stubs, trust fund balance sheets, and financial information as confetti were showered on the team as it paraded up Broadway.

www.bigdogshredbins.com


In the News

Product/Equipment Profiles SEM Paper Shredder Exceeds NSA/CSS 02-01 Security Requirements

Jorgensen Conveyors for Multiple Applications

J

S

orgensen Conveyors designs and manufactures a line of process feeder conveyors for most material recycling applications. The conveyors include hinged steel belt conveyors, Z-Pan metal belt conveyors, combo metal chain and rubber belt conveyors, slider bed and troughing idler conveyors. The conveyors and systems are designed for a wide variety of recycling operations and can be used for handling paper, corrugated materials, metal, rubber, plastics, wood, construction, electronic and municipal waste as well as co-mingled materials. They also integrate with bailing, shredding, compacting, sorting, crushing, mixing and incinerating processes. Frame construction is open and modular, built in 5- and 10-foot bolt-together sections, with bolt-on side skirting. Frame sections are interchangeable. Belt tracking is made from durable ASCE 30 pound rail. Guarding is per industry standard requirements. Metal belt and combo belting are offered in 4, 6 and 9 inch pitch construction with standard belt widths of 48, 60 and 72 inches to suit the application.

ecurity Engineered Machinery (SEM) recently introduced the Model 344 High Security Paper Shredder, which exceeds current government requirements for the destruction of Top-Secret / Classified data. Already evaluated by the National Security Agency (NSA) and listed on the NSA/CSS 02-01 Evaluated Products List for high-security paper shredders, the Model 344 reduces paper to miniscule 0.8 mm x 2.5 mm particles that are up to 60% smaller than the shreds of competing units on the NSA EPL. Easily maneuverable on heavy-duty casters, the Model 344 shredder weighs 106 lbs. and is 19½” wide, 18½” deep, and 36½” high. It accepts up to eight sheets of paper at a time. A built-in automatic cutting-head oiling system includes a one-gallon bottle of oil that can be mounted on either side or the back of the machine. To ensure optimum safety, an electronically controlled safety flap in the 10¼” feed opening prevents fingers and ties from entering the cutting area. An auto-reverse/shutdown system prevents paper jams. The unit also shuts down if the 28-gallon waste bin is full, the door is ajar, or the shredder has been idle for 30 minutes.

For more information call 262-242-3089 or visit www.jorgensenconveyors.com.

For more information, contact James T. Norris, Norris & Company at 508-510-5626 or jim@norrisco.com or visit www.semshred.com.

It’s not just a policy, it’s a concept Downstream Data Coverage is professional liability indemnification offered to NAID certified members that better protects data-related service providers and their customers. While competitors may copy the policy, they can’t copy the concept. • By linking coverage to NAID Certification, policyholders are grouped with other safe insurance risks. Over time, this translates to substantially lower premiums. • With the support of NAID, Downstream Data is an effective marketing differentiator. • Eventually Downstream Data will be member-owned, captive insurance, giving policyholders more control. • The policy can be modified individually or across the board to improve coverage.

Learn how Downstream Data can give you more control of your business. Visit www.downstreamdata.com or call 877-710-2498.

TM

Downstream Data Coverage® is sold in the United States as a surplus line, claims-made policy through Association Insurance Management. Downstream Data Coverage and the Downstream Data Coverage logo are registered trademarks of the National Association for Information Destruction, Inc.

Security Shredding & Storage News. November / December 2012 11


In the News State of South Carolina Tax Records Database Hacked Shredder Truck Financing Made Easy

• Low Initial Investment • Lease or Loan Financing • Financing new or pre owned equipment

• Simple Application Process • Serving the U.S. & Canada • Competitive Rate Structure

Financing The World Of Transportation Terry Lee Direct: 303-301-7651 . Cell: 937-620-9400 tlee@transleaseinc.com . www.transleaseinc.com Info Request #160

For Mobile & Plant-Based Systems

REPLACEMENT TOOLING –

LOW-RPM, SINGLE-SHAFT SHREDDERS/GRINDERS

Allegheny Cresswood Granutech Shred-Tech SSI Untha Vecoplan Weima

Manufactured in the Midwest

800 209 3145 www.dun-rite.com www.dun-rite.com Info Request #143

C

olumbia, SC—According to an article on GreenvilleOnline.com, the hacking of South Carolina’s Department of Revenue database is one of the nation’s biggest electronic heists. The tax returns database holds 3.6 million unencrypted Social Security numbers and 387,000 mostly encrypted credit and debit card numbers. Thought to be at risk are individuals who filed returns going back to 1998. Officials termed the initial intrusion, which occurred in August, a “scouting mission.” That was followed by two browsing hacks. The actual data theft happened on September 13. The breaches went undetected until October when a computer crimes office of the U.S. Secret Service made the discovery. Since then, security surrounding the breach has been tight. Details, other than the dates and acknowledgment that the hacker was foreign, have been out of bounds to the media while the investigation unfolds. South Carolina Gov. Nikki Haley ordered an assessment of all the state’s computer systems, but specifics about that investigation are being kept under wraps. What’s more, officials can’t (or won’t) tell whether the state’s computer system is still vulnerable. The Department of Revenue has contracted Mandiant, a computer security firm recommended by the Secret Service, to fix the leak. Questions remain as to whether the files in the hacked database were removed or copied and whether the state had paid a ransom to the hacker to retrieve the data. Officials say that all but 16,000 of the credit and debit cards were encrypted. Whether Social Security numbers in the state’s system can be encrypted is not known. Affected individuals have been notified and the state is paying for a year of credit-protection service to monitor any identity thefts that occur. The international investigation is further complicated because South Carolina’s computer system is decentralized. As is with many states, the boards, agencies, universities and commissions operate their own systems.

Employees Fired for HIPAA Violations in Ohio Hospital Shooting

A

kron, OH—Federal privacy rules under HIPAA, the Health Insurance Portability and Accountability Act, prohibit healthcare workers from looking at patient files unless the information is needed to do their jobs. A violation of these rules occurred at Akron General Medical Center in Ohio last August, according to a report on Ohio.com. Hospital management learned that an unspecified, but “small” number of employees had viewed the electronic medical files of a patient who was shot while in the hospital’s intensive care unit. The employees, who weren’t involved with the patient’s care, were terminated. The employees had accessed the records after John H. Wise, 66, fatally shot his wife, Barbara. Hospital spokesman, Jim Gosky, said the recent violations were “isolated incidents,” and the patient information was not shared by the employees with others. He added that the closed system limits who can access patient files. “It doesn’t happen a lot, fortunately, because employees know, but you can’t let the curiosity get the better of you,” Gosky said. “That’s human nature and we understand that, but it still doesn’t justify the fact that the policies were violated.” The Professional Staff Nurses Association, which represents about 800 nurses at Akron General, has not confirmed whether any nurses were fired. Privacy violations in high-profile criminal cases have happened elsewhere. Thirty-two employees were fired last year at a Minnesota hospital for unauthorized viewing of medical records involving a mass overdose. In 2010, a California hospital was fined $95,000 by state health regulators for allowing unauthorized employees to view medical records that sources told the Los Angeles Times were the files of Michael Jackson. A survey of patient privacy breaches by technology security firm Veriphyr found that the majority of such violations involve fellow workers, friends or relatives who are curious to see the medical records.

Subscribe Today! Call 440-257-6453 or Email downassoc2@oh.rr.com.

12 Security Shredding & Storage News. November / December 2012


In the News Lock America International CEO Frank Minnella Announces Lock America Reorganization

Easing of Medical Record Restrictions Ensures Post-Sandy Patient Care

F

A

rank Minnella, CEO of Lock America International, Inc. of Corona, California announced recently that he will be stepping back from daily involvement in company operations to move to an advisory strategic role. “I’ve been active in the security lock business for over thirty years, and it’s time for a new generation to take over operations and marketing for Lock America. Watson Visuwan, who is moving up from Sales Manager to Vice President of Marketing, has proven himself in many roles at Lock America over the last 15 years. With the promotion of Dan Walsh to Sales Manager, and the development of the rest of our team, Watson has the resources to take the company into new markets while building on our success in our present businesses,” says Minella. Lock America International has developed and marketed a wide range of innovative locks and security products for many industries, including amusement, coin-op, information destruction, newspaper distribution, recycling, self-storage, propane and vending.

Registration is Open for NAID’s Annual Conference

O

nline registration for the National Association for Information Destruction’s (NAID) annual conference opened Monday, Nov. 26. The 2013 NAID Annual Conference will be a three-day event in Nashville, Tenn., at the Gaylord Opryland Hotel and Convention Center. “We’re so excited to be coming to Nashville this year,” said NAID CEO Bob Johnson. “The location is easy to get to, and Nashville has a charm and atmosphere that will strike a chord in NAID members around the world.” Joe Calloway, author of the bestselling book “A Category of One” will be the keynote speaker at this year’s conference, NAID in Nashville: Tune in for Success. There will be sessions about social media, expanding residential markets, sales and marketing techniques, the current state of the destruction industry and much more. Those individuals who register for the conference before Feb. 1, 2013, will receive a 25 percent deep saver discount. Register at https://www.etouches.com/ NAID2013AC and learn more about the speakers, sessions, and venue. For questions about the event, contact NAID Director of Events and Programs Jamie Steimer at jsteimer@naidonline.org.

Reach More of Your Market ... Advertise in Security Shredding & Storage News.

Call Rick Downing at 440-257-6453 or email rickdowning@oh.rr.com.

lbany, NY—According to a report on BloombergNews.com, New York Governor Andrew M. Cuomo asked the federal government to temporarily waive certain medical records privacy restrictions. He took this action to help expedite care for patients affected by Hurricane Sandy. Waivers required by Medicare, Medicaid, the Children’s Health Insurance Program (CHIP), and the Health Insurance Portability and Accountability Act were approved for New York and New Jersey by Health and Human Services Secretary Kathleen Sebelius under Section 1135 of the Social Security Act. Emphasizing good faith inherent in the easing the restrictions, the changes that Cuomo requested affect administrative and recordkeeping rules, including documentation, patient relocation, billing and reimbursement requirements. Patient care and billing now can be provided even where standard documentation is missing. Patients can be relocated from damaged facilities to more secure settings. The changes also help streamline procedures for acceptance of new patients and approvals for relocating provider operations. For more information: The New York Section 1135 waiver is available at http://www.cms.gov/About-CMS/Agency-Information/Emergency/Downloads/ Hurricane-Sandy-PHE-Declaration-and-Section-1135-Waiver-for-NewYork-10-31-12.pdf. The New Jersey Section 1135 waiver is available at http://www.cms.gov/ About-CMS/Agency-Information/Emergency/Downloads/Hurricane-Sandy_ PHE-Declaration-and-Section-1135-Waiver-for-New-Jersey-11-1-12.pdf.

Cintas Announces New Nationwide Hard Drive Destruction Program Solution uses secure and efficient process to safely and sustainably destroy digital data

C

intas Corporation (NASDAQ:CTAS), recently launched its hard drive destruction program. According to the Company, the new service safely and efficiently destroys computer hard drives through a compliant recycling process, eliminating risks of data breaches and helping organizations stay compliant with state and federal disposal laws. “Many discarded hard drives contain information that is confidential and recoverable,” said Karen Carnahan, President and COO, Cintas Document Management. “Complete destruction is the best way to protect this sensitive business data. Our certified solution offers organizations the assurance that confidential files will not be exposed and they will remain compliant with data privacy standards.”

Attention: Document Destruction Contractors! Help Your Customers Find a Home for Their Outdated Electronics Do what many ‘leading recyclers’ have done ... Partner with Dan-Mar and turn your scrap into cash! Precious metal value is going up and so is the demand for electronic scrap. As a global leader in asset recovery, Dan-Mar is ready to present you with fresh thinking on how you can maximize your profits. Call Dan-Mar today! ph: 631-242-8877 • fax: 631-242-8995 150 West Industry Court, Deer Park, NY 11729 e-mail: smartini@dan-mar.com • www.dan-mar.com

The Name to Trust in Surplus™

Dan-Mar Buys: • • • • • • • • •

Precious Metal Military Electronics Semiconductors Components Scrap PC Boards Telecommunications Integrated Circuits Networking & Test Equipment E-Scrap

Info Request #114

Security Shredding & Storage News. November / December 2012 13


In the News Analysts Predict $14 billion in US Government Security Spending by 2017

H

info@alpineshredders.com

www.alpineshredders.com

erndon, VA—The website GovWin. com reports that US federal government spending on information security will increase in the next five years, which is mostly good news for providers of a wide range of securityrelated services. The biggest drivers for increased spending will include cloud and mobile computing technologies. The assessment on government information technology spending was conducted by forecasters from the contracting services company, Deltek. Their report highlights the fed’s changing priorities. Information security expenditures – from hiring specialists to administering programs that support cybersecurity policies – now rank in importance above the fed’s other IT needs. GovWin is a government contracting service of Deltek. The analysts report that modernization, data center consolidation, mobility and telework, as well as analytics and big data, now top the Fed’s security needs lists. Threats to data, networks and other hard-asset security areas continue to grow in frequency, complexity, variety and persistence. Meanwhile, security compliance policies, such as FISMA, CyberScope, HSPD-12 call for expansion and investment, the analysts say. Spending on development of security-related technologies, including vulnerability awareness, intrusion detection, identity/access management, etc., is expected to increase to meet the challenges of technology gaps. Employee outsourcing will decline even though qualified cybersecurity professionals are hard to come by. This is because the government plans to rely more on internal human resources initiatives, the report notes. Budget cuts, and appropriation delays, in addition to the integration of continuous monitoring capabilities and improved risk management, tend to moderate outsourcing demand for the near term. Yet Deltek analysts predict US government spending on vendor-furnished information security products and services will increase to $14.3 billion in 2017, up from $9.9 billion in FY 2012. For more information: Federal Information Security Market, FY 2012-2017 http://www.dhs.gov/federal-information-securitymanagement-act-fisma

Europe Paper Recycling Increases, Quality Improves

B

russels, Belgium—According to an article posted on LetsRecycle.com, EU countries overall are recycling an average of 70.4 percent of paper that is collected. The amount recycled is increasing and, importantly, the quality of recycled paper is improving. The 2011 figures, which are the latest ones available, show that the UK’s paper recycling topped the list at 78.7 percent, while the twelve other countries reported recycling rates near 60 percent. Paper recycling is monitored by the European Recovered Paper Council (ERPC). In 2000, this Brussels-based industrial organization, adopted and launched its First European Declaration on Paper Recovery to help the countries meet recycling targets. To determine the recycling rates, ERPC’s annual report uses data compiled by the Confederation of European Paper Industries (CEPI) through questionnaires to national member associations. The report now includes figures on carbon reduction and other indicators along with the volume of paper collected and the recycling rate the agency monitors. Approximately 58 million tons of paper was collected in 2011– the same as in previous years-but 9.2 million ton (16 percent ) of it was sent for recycling, led by Norway and Switzerland, which are not part of the EU-27. The paper recycling industry is looking at ways to divert previously rejected types of paper (packaging bearing adhesive residue, for example) from the waste stream and make valuable use of it. The ERPC report also notes research by CEPI which shows that paper and paperboard were the most recycled materials in Europe in 2010, followed by steel coming in second place (71 percent), glass (68 percent) and aluminium (64 percent). In the US, paper recycling is hovering at 66.8 percent, with 52.7 tons collected, according to the American Forest & Paper Association’s report for 2011. The organization has launched its Better Practices Better Planet 2020 initiative, establishing a goal of 70 percent paper recovery by 2020. Fo r m o r e i n fo r m at i o n : h t t p : / / w w w. paperrecovery.org/ http://paperrecycles.org/stat_ pages/recovery_rate.html http://www.afandpa.org/Sustainability/

Mark Your Calendar! Plan Now to Attend Security Shredding / Medical Waste Mgmt Conference November 3-5, 2013 Orlando, FL Info Request #101

14 Security Shredding & Storage News. November / December 2012


The reliable brand!

• High Capacity • Tough & Economical

The reliable brand!

• Continuous Feeding • Low Noise and Dust • Simple to Operate • High Capacity • Low Maintenance ••High Capacity Tough & Economical ••Tough & Economical Continuous Feeding ••Continuous Low NoiseFeeding and Dust • Low Noise and Dust

• Simple to Operate

• Simple to Operate

• Low Maintenance

• Low Maintenance

The RS SeRieS: ReVOLUTiONARY ShReDDiNG TeChNOLOGY – UNCOMPROMiSeD UNThA ReLiABiLiTY

The RS SeRieS:

The RS SeRieS: ReVOLUTiONARY ShReDDiNG TeChNOLOGY – ReVOLUTiONARYUNThA ShReDDiNG TeChNOLOGY – UNCOMPROMiSeD ReLiABiLiTY UNTHA shredding technology America Inc. UNCOMPROMiSeD UNThA ReLiABiLiTY

5 Merrill Industrial Drive, Hampton, NH 03842 Phone 603 601 2304, Fax 603 601 2423 info@untha-america.com, www.untha-america.com

Info Request #130

UNTHA shredding technology America Inc. Security Shredding & Storage News. November / December 2012 15 5 Merrill Industrial Drive, Hampton, NH 03842 Phone 603 601 2304, Fax 603 601 2423 info@untha-america.com, www.untha-america.com


unlike a shredder, the

E-CYCLER doesn’t just cut it...

it

E-nihiLatEs.

Schutte-Buffalo hammermill’s e-cycler is the alternative to a shredder. unlike the cutting action of a shredder, the e-cycler hammer mill pulverizes e-scrap, scouring confidential data and liberating recyclable components in one pass.

• ½ the cost of a shredder with lower maintenance costs and a higher production capacity • completely scours information to illegibility • renders electronic components unusable and unrecognizable • four-way reversible steel hammers crush and shatter the material • interchangeable screens guarantee a properly-sized end product • liberates components for easy separation and recycling • pulverizes hard drives, printed circuit boards, cDs & DVDs, cellular phones and more

1-800-447-4634

America’s fastest growing hammermill company

6 1 D e p o t S t r e e t, B u f f a l o , N Y 1 4 2 0 6 • 7 1 6 . 8 5 5 . 1 5 5 5 • f a x : 7 1 6 . 8 5 5 . 3 4 1 7 • e - m a i l : info@hammermills.com i N f o @ h a m m e r m i l l S . c o m • www.hammermills.com www.hammermillS.com

590-14_Security_Shrednews_mag_FT_M.indd 1

Info Request #132

11/3/11 10:34 AM


Turn static files into dynamic content formats.

Create a flipbook
Security Shredding & Storage News Nov/Dec 2012 by Downing and Associates - Issuu