Volume 12, Issue 4
y
winter
bu 201 ye 5-2 r iss s’ g 016 ue uid e
g
Visit us online at www.SecurityShreddingNews.com
ATTENTION: READERS !
Are you looking for Products, Equipment or Services for your business? If so, please check out these leading companies advertised in this issue:
Collection & Storage Containers Bomac Carts – pg 11
Consolidation, Drop in Service Providers Predicted for Saturated Shred Industry
Equipment Financing TransLease Inc – pg 15 Lock & Locking Systems Lock America Intl. – pg 3 Mobile Truck Shredders Alpine Shredders Ltd – pg 13 Shred-Tech Limited – pg 4 Moving Floor System Keith Manufacturing – pg 16 Software EZshred – pg 5
Stationary Shredders & Grinders Allegheny Shredders – pg 2 Ameri-Shred Corp. – pg 6 Shred-Tech Limited – pg 4 Trade Associations NAID (National Association of Information Destruction) – pg 12
T
By P.J. Heller
PRSRT STD U.S. Postage
PAID
Mentor, OH Permit No. 2
he maturity of the document destruction industry in the United States has resulted in a saturated market where any new entrants will find it tough going and existing companies will likely grow their businesses faster in the future through acquisitions and mergers, according to one industry veteran. “I don’t believe you’re going to see a lot of new document destruction services entering the industry in North America,” says Bob Johnson, chief executive officer at the National Association for Information Destruction (NAID). “I think we’re actually going in the other direction. I think we’re going into a cycle where there will be consolidation and reduction in capacity in North America. “There will be an occasional new entrant into the business,” he adds, “but it’s not going to be anything like we’ve seen in the past. For the most part, there will be a consolidation and actual shrinkage of service providers.” Such a scenario comes after more than a decade of increased demand and major acquisitions and mergers, among them Iron Mountain and Recall Holdings and the Cintas, Shred-It and Stericycle transactions. Consolidation and a reduction in the number of service providers — some of whom may fall by the wayside due to linking their prices for services to the value of recycled paper which has fallen sharply — will lead to a healthier environment for the industry, Johnson predicts. The demand for document destruction services has pretty much reached its peak, according to Johnson. That’s not to say every business that needs paper shredding is outsourcing its document destruction services.
For those that aren’t, he says, “I’m not so sure that anything is really going to push them to outsource if they’re not doing it already. It’s not like there’s a lot of virgin territory out there for our industry to grow into.” Johnson estimates that the document destruction market is 75 percent to 80 percent vended, but quickly adds that using such figures is a misnomer. “I’m pretty confident anecdotally that it’s true,” he says. “But it’s a misnomer because it indicates that 20 percent to 25 percent is left to grow into. My point is I don’t think we can ever get that 20 or 25 percent. Should we be saying it’s more like 100 percent vended? If you can’t get the other 20 or 25 percent, is it really there to get? You can say it’s not vended but it will never be vended.” Asked if he felt the market was saturated, Johnson replied, “I do. I do.
Continued on page 3
4 6
Inside This Issue Medical Center Fined for HIPAA Breach by Former Employee Federal Spending on Information Security to Reach $11 Billion by 2020
11 IRS Fails to Meet Information Security Requirements
13 HIPAA Compliance: HHS Audit Focus Shifts in 2016
14 University of Washington Agrees to
$750,000 Settlement for PHI Breach
www.alleghenyshredders.com
2 Security Shredding News Winter 2015-2016
solutions@alleghenyshredders.com
Security Shredding News
Consolidation, Drop in Service Providers Predicted for Saturated Shred Industry
Continued from page 1
PUBLICATION STAFF Publisher / Editor Rick Downing
Contributing Editors / Writers P.J. Heller Sandy Woodthorpe
Production / Layout Barb Fontanelle Christine Pavelka
Advertising Sales Rick Downing
Subscription / Circulation Donna Downing Editorial, Circulation & Advertising Office 6075 Hopkins Road Mentor, OH 44060 Ph: 440-257-6453 Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com
For subscription information, please call 440-257-6453 Security Shredding News (ISSN #1549-8654) is published bimonthly b y D o w n i n g & A s s o c i a t e s. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment. ©Copyright 2015 by Downing & Associates. Printed on Post-Consumer Recycled Paper
“We are very close in North America to what I would say is a situation where most of the companies that would need our services are using them already. I think we have saturated our market to a large degree. I think there are enough competitors in the market for the demand. Where we saw demand increasing wildly over the last 12 years, we’re not going to see that demand increasing wildly anymore.” Despite that, NAID has seen its membership grow. The organization has more than 1,900 member locations. “We’re growing as fast as we’ve ever grown in our history right now,” Johnson reports. “It’s not from new people getting in the marketplace. It‘s from existing companies who are in the business joining finally after all these years.” A big part of that may be due to the demand from companies who are outsourcing their document shredding services wanting to ensure that their vendors are NAID members or NAID certified. The NAID certification program, which is voluntary, verifies the qualifications of certified information destruction providers through a comprehensive scheduled and unannounced audit program. “They’re looking for someone with the proper qualifications,” Johnson says of businesses outsourcing their document destruction. “That also makes it more difficult for the new [shredding company] guy to get in. That favors companies that are doing it the right way. It doesn’t make it so easy for just anyone to hang out their shingle and get business.” Some of NAID’s growth is also coming from companies in the electronics destruction industry and from overseas, Johnson says. That growth is expected to continue even if traditional paper shredding company membership declines over the years. Unlike the U.S., shred companies overseas are seeing greater demand and opportunities, Johnson says. One example he cites is Japan, where he recently gave a speech, noting that the country is a “spittin’ image” of where the U.S. shredding market was 20 years ago. NAID is also helping to fund creation of a medical waste management association, which will be a totally separate organization. It was being supported at the behest of NAID members who were moving into hauling medical waste. “They came to us and said they wanted an association to do for them what NAID did for the secure document destruction industry and asked NAID to help get it started,” Johnson says. For the American document destruction market, Johnson says shredding companies seeking to grow in a saturated market may find that business acquisitions are the way to go. “I don’t think you have to be a business guru to see that if they want to grow in a market where you’ve got pretty good saturation . . . they can’t grow by getting new customers,” he says. “They could take customers away from other people. But one of the quickest ways for them to grow is to acquire companies. I think you will see a fresh appetite by the large companies to acquire other companies as a way to grow. It’s going to be a faster way to grow
than to go out and get new customers.” That could bode well for small document destruction companies, who might see some of their similar-size competitors gobbled up by large national organizations such as Shred-It or Iron Mountain with whom they may already compete. “If a large company acquires three or four of my competitors, it doesn’t make my life any tougher. In fact, it makes it easier because now I have less competition,” Johnson explains. “I’m not facing new competition. I’m actually facing less competition.” Competition from the larger national and regional businesses is something small shred companies have been facing for years and “they’ve been able to survive,” he notes. ”Because they [small businesses] are more nimble and responsive in their marketplaces, they often feel they do better against the large competitors rather than the small guys. So they might be better off if three guys get bought out and now they’re competing with a national company,” he says. Johnson also downplays the impact that medical waste-management firm Stericycle will have on the industry with its acquisition of Shred-It from business services provider Cintas Corp. That’s because the healthcare industry only accounts for about 15 percent of the document destruction industry, he estimates. “It’s hard to see how the synergy that they’re getting in the medical industry waste industry is going to have any kind of dramatic impact on the document destruction industry. Even if that synergy exists, it only affects a small percentage of the overall market for destruction services.” While Johnson didn’t want to speculate on other mergers or acquisitions in the near future, he admits “nothing would surprise me. “There aren’t many big companies to merge,” he notes. “. . . I don’t expect anything major in the next few years other than large companies will be back on the acquisition trail once they have fully digested and integrated all of the changes they’ve got going on now.”
Now Even More Options for Customers Who Want Their Own Key Codes! Lock America Adds More New Key Codes for Padlocks and Console Locks. • Give your drivers and customers a single key that fits all the locks at a site. • Ask your console or bin supplier for new available key codes, or contact Lock America directly.
One Key Can Now Operate All Your Locks!
Tel: (951) 277-5180 Fax: (951) 277-5170 www.laigroup.com
800-422-2866
9168 Stellar Court Corona, CA 92883 sales@laigroup.com
Security Shredding News Winter 2015-2016
3
In the News Medical Center Fined for HIPAA Breach by Former Employee
R
ken@recycle.cc
www.recycle.cc
www.shred-tech.com
4 Security Shredding News Winter 2015-2016
ochester, NY – The New York State attorney general’s office has levied a $15,000 fine on The University of Rochester Medical Center for a confidentiality breach that involved 3,403 patients, reports a DemocraftChronical.com article. The attorney general’s office launched an investigation this year after URMC reported the breach, as required by the Health Insurance Portability and Accountability Act. The breach occurred last spring when a former URMC employee, a nurse practitioner from the Department of Neurology, shared patient records with an independent provider, Greater Rochester Neurology. According to the AG report, the nurse had become associated with Greater Rochester Neurology and had requested a list of patient names, addresses and diagnoses “to help ensure continuity of care for [URMC] patients she was leaving and [she] was provided the list for that purpose.” The breach was discovered when some of the patients who received letters from Greater Rochester Technology contacted URMC to find out what was going on. URMC stated in its report of the breach that the nurse did not have permission from either the medical center or from patients to share any information. As required by HIPAA, URMC filed a report with the state attorney general’s office within a few weeks of the violation. According to background information included in the settlement agreement, URMC officials interviewed, suspended and then fired the nurse practitioner. URMC also sent letters to the affected patients explaining the situation, and received assurance from Greater Rochester Neurology that all health information had been returned or deleted. In addition to the fine, URMC has been directed to provide staff training on HIPAA policies and procedures. The medical center has already disseminated specific procedures for handling patient information when employees leave or join the system. URMC also filed a breach notification with the federal Department of Health and Human Services, whose Office for Civil Rights investigates HIPAA violations.
In the News E-Waste Increases Challenge Collection Sites
A
s the lifespans for electronic devices shorten and more states enact bans on electronics waste in landfills, waste collection sites are dealing with oversupply, according MountainTimes.info, the ChicagoTribune.com and BusinessWire.com reports. The demand for certain electronics components and materials has softened and scrappers are experiencing lower sales, but e-waste recycling keeps growing in acceptance and popularity. Throughout the United States, residents, schools and small businesses continue to drop off old computers, monitors, printers, computer peripherals, TV sets, and other e-waste. Of the twenty-five states that ban electronics in landfills, Vermont has one of the highest per capita recycling rates in the country, yet its municipal collection sites are starting to have a tougher time getting rid of e-waste. Scrappers and haulers report that they are buying less from such collection sites because it’s harder to move the material and they are unable to get the prices they could a few years ago. One reason is the segmentation within the e-waste market that is making certain types of electronics next to impossible to offload. The global electronic waste management market is segmented on the basis of raw material, i.e., metal, plastic, glass and other materials. Worldwide, metals comprise the biggest share of electronic waste and the demand for it continues. But monitors and televisions that have cathode ray tubes (CRTs), for example, have become practically worthless since display technology changed. The problem is they take up a lot of space. According to the U.S. Environmental Protection Agency, almost 2.4 million tons of electronics were disposed of in 2009, an increase of more than 120 percent from 1999. Of this amount, only 25 percent were collected for recycling. The Dublin-based Research and Markets service predicts the global e-waste recycling market to increase at an adjusted growth rate of 10.7% over the period 2014-2019. Other sources put the global production of e-waste in 2014 at an estimated 41.8 million tons, with most e-waste being produced in Europe, the United States and Australia. China is world’s largest importer of electronic waste. Most e-waste produced is still sent to landfills. Effective reprocessing technology, which recovers the valuable materials with minimal environmental impact, is expensive. This factor is considered the major restraint for the e-waste market; however, the problem may be temporary. Many nations have adopted goals for developing recycling infrastructure for electronic waste management and this eventually may open new markets for e-waste.
Protected Patient Information on Medical Devices Extends to Peripherals
B
urlington, MA – Following an investigation into a stolen laptop, the U.S. Department of Health and Human Services’ Office for Civil Rights has levied an $850,000 fine on Lahey Hospital and Medical Center for potential HIPAA violations, according to a HealthcareITNews.com report. A breach notification was filed with HHS after a laptop containing protected health information of 599 patients was taken from an unlocked room at Lahey in August of 2011. The laptop was found missing from a stand it occupied with a portable CT scanner it was being used to operate. OCR conducted an investigation that turned up “widespread non-compliance with the HIPAA rules” at Lahey. Violations included failures to conduct a thorough risk analysis of the hospital’s electronic protected health information; physically safeguard a workstation that accessed patient data and maintain policies related to data security on workstations use in connection with diagnostic and lab equipment, according to the OCR report. OCR investigators cited Lahey for lack of a unique username to identify and track user identity on the laptop; failure to implement procedures that recorded and examined activity in the workstation at issue in the incident, and impermissible disclosure of 599 individuals’ PHI. “It is essential that covered entities apply appropriate protections to workstations associated with medical devices such as diagnostic or laboratory equipment,” said OCR Director Jocelyn Samuels, in a press statement. “Because these workstations often contain ePHI and are highly portable, such ePHI must be considered during an entity’s risk analysis and entities must ensure necessary safeguards that conform to HIPAA’s standards are in place.” Lahey is a nonprofit teaching hospital affiliated with Tufts Medical School.
EZshred Software Systems: Easy, Intuitive and Proven Effective!
It’s SO EASY to use... it pays for itself! EZshred has a medical waste solution for companies that are in the medical waste transportation business. EZshred creates the manifests, tracks your medical waste inventory and saves the signed manifests, facilitating compliance with local, state and federal regulations. In addition one can scan medical waste contracts and alert your sales force of expiring contracts.
• • • • • • • • •
Maintain Customer Information Schedule Services Track Inventory Fleet Management Hard Drive Destruction Recycling Medical Waste Transportation Record Storage Document Destruction
Ask us about our Cloud Services!
www.ezshred.com Security Shredding News Winter 2015-2016
5
In the News Federal Spending on Information Security to Reach $11 Billion by 2020, According to Deltek Report
Epson Makes OfficeBased Waste Paper Recycling a Reality
H
N
erndon, VA – According to a new report from Deltek, federal information security spending is projected to increase over 5% per year while overall federal spending on information technology remains flat. Deltek’s new GovWin IQ report, Federal Information Security Market, 2015-2020, forecasts the federal demand for vendor-furnished information security products and services will increase from $8.6 billion in FY 2015 to $11.0 billion in 2020. As agencies struggle to stay ahead of the cybersecurity threats, more and more of their IT spend is being devoted to cybersecurity, reaching over 10% of IT spend by 2020. Federal efforts to improve agency cybersecurity amid capability gaps and budget, personnel, and regulatory constraints will drive targeted spending increases. As agencies continue to retool IT environments with cloud, mobility, and infrastructure solutions, strategies for addressing information security gaps with advanced processes, services, skillsets, and tools will drive investment strategies. Ninety-two percent of government respondents to a Deltek survey conducted for this report ranked cybersecurity as the top IT spending priority, easily surpassing initiatives like cloud computing and mobility, which require robust security themselves. Security vulnerabilities span a wide spectrum of needs. “The threat environment continues to underscore the imperative of shoring up defenses and advancing current capabilities,” said John Slye, Advisory Research Analyst for Deltek. “On one end
of the spectrum, agencies are likely to continue to invest in new technologies to improve situational awareness through network monitoring and security analytics. At the other end, there’s an ongoing need to address and maintain basic cyber hygiene.” Some other notable findings include: 1) The volume and variety of cyber-threats challenges government organizations to harden the security of the increasingly complex IT environments that they are managing today. Agencies will continue to rely on industry for the expertise needed to get and stay ahead of the security curve. 2) Challenges meeting security workforce goals with skilled personnel internally will sustain demand for contracted services. Offensive cyber solutions and other areas deemed ‘inherently governmental’ will continue to trim contractor addressability. 3) Federal policies will continue to embed cybersecurity into IT acquisitions and management strategies, shaping acquisition guidelines, contract types, and solicitations. Deltek’s Federal Information Security Market, 2015-2020 report explores trends in security spending and highlights major product and service categories, preferred contracting approaches, and small business utilization. “Federal information security remains a highly ‘people-based’ market, with spending on security services outpacing product spending,” said Kyra Fussell, Principal Analyst for Deltek. “Contractors that can provide highly experienced personnel will continue to be in demand.”
agano, Japan – Seiko Epson Corporation has developed a new machine that can transform offices into paper mills, reports TheVerge.com. Epson describes the “PaperLab,” still in prototype stage, as a compact office paper recycling system that can produce paper of various sizes and thicknesses, including card stock – and even colored and scented stock – from recycled office paper. According to the company’s website, the machine requires only a small amount of water to maintain humidity inside the system. “Dry Fiber Technology” takes care of the three major phases of papermaking: fiberizing, binding (adding strength or other properties), and forming. The system can produce the first new sheet of paper in about three minutes after waste paper is loaded and the machine is activated. The specifications posted on the Epson website note 14 A4 sheets per minute and 6,720 sheets in an eight-hour day – more than 13 reams of paper in an eight-hour workday. PaperLab’s compact size (approximately 2.6 x 1.2 x 1.8 meters) will allow it to fit in a variety of convenient locations. And, because the recycling process involves breaking down waste sheets into paper fibers, Epson says, PaperLab also provides a secure way of destroying confidential documents. A commenter on ArsTechnica notes that an Epson patent from 2013 on in-office paper recycling might reveal a little more about this process. The patent describes how waste paper is crushed using a “defibrating unit,” with the ink then removed by spinning the crushed matter through an air cyclone. Commercial production will begin in 2016, but Epson has not announced a selling price.
New CROSS CUT
industrial paper shredders 10 - 40 Horsepower 1000 - 2600 Lbs. / Hour www.ameri-shred.com info@ameri-shred.com
6 Security Shredding News Winter 2015-2016
Security Shredding News
2015-2016 Buyers’ Guide Directory category listings
Baler Manufacturers
Advanced Equipment Sales Ameri-Shred Corp American Baler Co BACE Balemaster USA Harris International Baler Corp IPS Balers Mfg Maren Engineering Corp Waste Processing Equipment, Inc
Baling Wire & Strapping Systems
Advanced Equipment Sales Cavert Wire Co, Inc Eastern Wire Products Wire Industries LLC
Business Consultants, Employment Services & Drug Screening K-2 Partners, LLC Lane-Link Group, Inc Shotgun Capital Advisors LLC
Conveyors & Moving Floor Systems
Advanced Equipment Sales Ameri-Shred Corp The C.S. Bell Co Cresswood Shredding Machinery HALLCO Industries, Inc KEITH Mfg Co
Document Storage Containers / Collection Carts
Big Dog Shred Bins USA Bomac Carts Jake, Connor & Crew Inc MOD-Meese Orbitron Dunne Co Schaefer Systems Intl
Dust Control Systems
Advanced Equipment Sales Ameri-Shred Corp Nordfab Ducting Ohio Blow Pipe
Electronics Recyclers
BCS Clover Environmental Solutions Dan-Mar Components Ex-It Technologies ZRG Inc
Fire Protection Systems, Vaults & Fire Prevention Services
Advanced Equipment Sales Critical Systems Fire Protection Intl Consortium Firelock Fireproof Modular Vaults FLAMEX, Inc
Insurance Providers
Downstream Data Coverage EMPLOYERS
Repair Services (Balers & Shredders)
Leasing Companies
Intek Truck & Equipment Leasing Trans Lease, Inc
Marketing, Advertising, Website Development & Online Services Artwork Advertising & Design Chachka Group NetGain
Merger & Acquisition Firms
K-2 Partners, LLC Lane-Link Group, Inc Shotgun Capital Advisors LLC Waterfront Capital, Inc
Rack Storage Systems
DACS, Inc Elite Storage Solutions Interlake Mecalux
Shred Truck Manufacturers & Dealers
Advanced Equipment Sales CMB Commercial Shredder Repair, LLC Dun-Rite Tooling Pacific Coast Shredder Repair Co
Routing, Billing & Inventory Software DHS Worldwide Software Solutions DocuData Software eRouteIt EZshred RouteOptix Inc
Security Locks & Alarm Systems
Alpine Shredders Ltd Ameri-Shred Corp AXO Shredders Shred-Tech Shredfast, Inc ShredSupply UltraShred LLC Vecoplan LLC
Babaco Alarm Systems Lock America International The Wilson Bohannan Lock Co
Security, Safety, Loss Prevention & Risk Management Specialists
Baker Security Group, LLC
Shredder Manufacturers (Plant-based)
Advanced Equipment Sales Allegheny Shredders Ameri-Shred Corp American Pulverizer Co Cresswood Shredding Machinery Cumberland Recycling Jordan Reduction Solutions Schutte-Buffalo Hammer Mill, LLC Security Engineered Machinery Co Shred-Tech UNTHA America Vecoplan LLC WEIMA America, Inc
Shredder Wear Parts
Dun-Rite Tooling ShredSupply Tryco Manufacturing Co
X-ray Film Recycling & Processing
Commodity Resource & Environmental Inc Pyromet
Security Shredding News Winter 2015-2016
7
2015-2016 Buyers’ Guide COMPANY INDEX
A
Advanced Equipment Sales Souderton, PA (215) 723-7200 www.advancedequipmentsales.com
Baker Security Group, LLC
Ameri-Shred Corp
Allegheny Shredders
PO Box 80 Delmont, PA 15626 (800) 245-2497, (724) 468-4300 solutions@alleghenyshredders.com www.alleghenyshredders.com As the premier manufacturer of high capacity shredding systems, Allegheny offers a total solution for your security needs. Whether you need to destroy documents, plastics, products or e-scrap, our superior American-made shredders, grinders and horizontal balers can do it all! Our cost-effective solutions and excellent customer support will help you collect, process and recycle for a profit! See ad on pg 2
3490 US 23 North Alpena, MI 49707 (800) 634-8981 info@ameri-shred.com www.ameri-shred.com U.S. manufacturer of industrial shredders and recycling equipment. Known for our durability and innovation, we provide time tested solutions backed by products that include hard drive shredders, paper shredders and product destruction shredders, along with box dumpers, conveyors, metering systems and custom equipment solutions. Our system integrations, installations and after-sale support are second to none. See ad on pg 6
American Baler Co Bellevue, OH
(800) 843-7512 www.americanbaler.com
PO Box 10279 State College, PA 16805 (814) 321-3102 Brian Baker brianbakercpp@comcast.net www.bakersecuritygroup.com B a ker S ecu ri t y G ro u p, LLC, i s a n independent security management consultancy and Pennsylvania licensed professional investigation firm. We help our clients to solve problems and prevent future problems through careful assessment and individualized solutions. Our services focus on the prevention of loss and the reduction of risk through the use of the best practices in the security industry.
BCS
Canoga Park, CA (888) 286-7188 www.scrapdr.com
Chachka Group
459 NW Adler St Madras, OR 97741 (541) 475-7286 chachka@chachkagroup.com www.chachkagroup.com Chachka is a unique collection of artists, writers, designers, photographers and programmers who transform everyday advertising into something special. S o m e t i m e s a m u s i n g. S o m e t i m e s thoughtful. Always effective.
See ad on pg 11
Clover Environmental Solutions Hoffman Estates, IL (815) 431-8100 www.clovertech.com
CMB Commercial Shredder Repair, LLC
Big Dog Shred Bins USA
Fuquay-Varina, NC (919) 577-6714 www.cmbcommercialshredderrepair.com
Bomac Carts
Commodity Resource & Environmental Inc (CRE)
Lakeside, CA (855) 792.4050 www.bigdogshredbins.com
American Pulverzier Co St. Louis, MO (314) 781-6100 www.ampulverizer.com
Artwork Advertising & Design Jesup, GA (912) 427-0589 www.artworks-ads.com
AXO Shredders Alpine Shredders Limited
30 Alpine Ct Kitchener, ON N2E 2M7 Canada (866) 246-5634 Guy Wakutz, Sales GWakutz@AlpineShredders.com www.AlpineShredders.com Alpine Shredders has engineered Mobile Shredding Equipment that is simple to maintain – with fewer moving parts than competitive equipment. Our low-RPM, hightorque shredder assembly increases the life of all hydraulics, pumps, gearboxes and shredder shafts. High tip force and aggressive hook profile ensures superior throughput even on the toughest dense paper. The end result is a shred truck that requires low maintenance and is ENGINEERED TO LAST. See ad on pg 13
Philadelphia, PA 484-953-3580 www.axo.cc
B
Babaco Alarm Systems Moonachie, NJ (800) 283-2222 www.babaco.com
BACE
Charlotte, NC (877) 506-2223 www.bacecorp.com
Balemaster USA Crown Point, IN (219) 663-4525 www.balemaster.com
8 Security Shredding News Winter 2015-2016
201 Badger Parkway Darien, WI 53114 (262) 882-5000 Cindy Lapidakis sales@bomaccarts.com www.bomaccarts.com Heavy-Duty utility carts are our specialty. From Recycling, Manufacturing, Shipping/ Receiving, Commercial Laundry and Mailrooms, our offering meets a broad range of uses in many industries. See ad on pg 11
C
The C.S. Bell Co
Tiffin, OH (888) 958-6381 www.csbellco.com
Cavert Wire Company, Inc Rural Hall, NC (800) 969-2601 www.cavertwire.com
116 E Prospect Ave Burbank, CA 91502 (818) 843-2811 Stacy Aesoph saesoph@creweb.com www.creweb.com CRE is celebrating their 35th anniversary as one of the world’s leading silver recovery companies. In just three decades, CRE has become the biggest “above-ground miners” in the Western U.S., harvesting silver from photographic and other by-products — over 15,000,000 pounds worth every year!
Cresswood Shredding Machinery Cortland, IL (800) 962-7302 www.cresswood.com
Critical Systems
Louisville, KY (502) 231-2402 www.critical-systems.net
Buyers’ Guide 2015-2016 COMPANY INDEX
Cumberland Recycling New Berlin, WI (262) 641-8600 www.cumberland-plastics.com
D
DACS, Inc
Portsmouth, VA (757) 393-0704 www.dacsinc.com
Dan-Mar Components Deer Park, NY (631) 242-8877 www.dan-mar.com
EMPLOYERS
Reno, NV (888) 682-6671 www.employers.com
eRouteIt
Lincoln, NE (402) 261-4067 www.erouteit.com
Ex-It Technologies
Naples, FL (239) 596-2254 www.exittechnologies.com
DHS Worldwide Software Solutions Orange Park, FL (800) 377-8406 www.dhsworldwide.com
Downstream Data Coverage
877-710-2498 Downstream@naidonline.org www.downstreamdata.com Downstream Data Coverage is professional liability insurance, developed exclusively for NAID members to address many of the shortcomings of standard professional liability coverage that leave service providers and their customers at risk.
DocuData Software Montreal, QC Canada (866) 789-2789 www.docudatasoft.com
Dun-Rite Tooling
Cortland, IL (800) 209-3145 www.dun-ritetooling.com
E
Eastern Wire Products Jacksonville, FL (800) 351-8138 www.eastern-wire.com
Elite Storage Solutions Irvine, CA (949) 757-1377 www.elitestoragesolutions.com
I
Interlake Mecalux
Melrose Park, IL (877) 632-2589 www.interlakemecalux.com
Intek Truck & Equipment Leasing Roseland, NJ (973) 403-7788 www.intekleasing.com
International Baler Corp Jacksonville, FL (800) 231-9286 www.intl-baler.com
IPS Balers Mfg EZshred
PO Box 8 Chesterland, OH 44026 (877) 392-7123 Tiffanie Julian tjulian@ezshred.com Built for shredding companies, EZshred is a simple to use software system to run your shredding business. From scheduling and routing to invoicing and reporting, EZshred gives you time to manage and grow your business. Ask about our cutting-edge handheld bar code scanning, recycling, record storage and medical waste solutions as well! See ad on pg 5
F
Fire Protection Intl Consortium
Concord, CA (925) 825-4643 www.globalfireprotection.com
Firelock Fireproof Modular Vaults Kutztown, PA (610) 756-4440 www.firelock.com
FLAMEX, Inc
Greensboro, NC (336) 299-2933 www.sparkdetection.com
H
HALLCO Industries, Inc
Baxley, GA (800) 280-2313 www.ipsbalers.com
J
PO Box 1 Madras, OR 97741 (800) 547-6161, (541) 475-3802 sales@keithwalkingfloor.com www.keithwalkingfloor.com The KEITH WALKING FLOOR unloading system increases efficiency in the mobile document destruction environment. Installed in a shred truck, the moving floor system stores shredded documents and automatically unloads them once the truck reaches a secure location. Unloading time is under five minutes and no tipping is needed. See ad on pg 16
L
Lane-Link Group, Inc Heath, TX (972) 772-5680 www.lane-link.com
Jake, Connor & Crew Inc
1-199 Trillium Dr Kitchener, ON N2E 1W9 Canada (877) 565-5253 Wil Vasey, Sales Director sales@akeconnorandcrew.com www.jakeconnorandcrew.com Jake, Connor & Crew is the world’s largest direct manufacturer of containers for the document protection, waste & recycling industries. Our exclusive shredding consoles and wheeled containers are engineered to exceed the quality and security demands of the global shredding industry. We guarantee the security of your customers’ sensitive information.
Jordan Reduction Solutions Birmingham, AL (888) 733-8248 www.jordanreductionsolutions.com
Tillamook, OR (503) 842-8746 www.hallcoindustries.com
K
Harris
Villanova, PA (215) 690-1133
Baxley, GA (800) 447-3526 www.harrisequip.com
KEITH Mfg Co
K-2 Partners, LLC
Lock America International
9168 Stellar Court Corona, CA 92883 (800) 422-2866, (951) 277-5180 sales@laigroup.com www.laigroup.com For over 30 years, Lock America has been an innovative market leader in a wide range of industries that demand lock and security hardware. See ad on pg 3
M
Maren Engineering Corp South Holland, IL (800) 875-1038 www.marenengineering.com
MOD-Meese Orbitron Dunne Co Ashtabula, OH (800) 772-7659 www.meeseinc.com
Security Shredding News Winter 2015-2016
9
2015-2016 Buyers’ Guide COMPANY INDEX
N
NetGain
Waste Processing Equipment, Inc
Barrie, ON Canada (888) 797-2455 www.netgainseo.com
Rainsville, AL (256) 638-6355 www.maxpakbalers.com
Nordfab Ducting Reno, NV (866) 652-1588 www.nordfab.com
P
Pacific Coast Shredder Repair Co Newark, CA (877) 434-9747 www.pcsrco.com
Pyromet
Aston, PA (610) 497-1743 www.pyromet999.com
R
RouteOptix Inc
Kitchener, ON N2R 1J3 Canada (866) 926-7849 www.routeoptix.com
Waterfront Capital, Inc
Shredfast, Inc
13026 W McFarlane Road, Bldg C-2 Airway Heights, WA 99001 (509) 244-7076 Karl Ellwood karl@shredsupply.com www.shredfast.com Shredfast builds the finest document shredding, secure collection and media destruction equipment in the industry. Our newest product, the 2016 PT-125, has the legendary Shredfast quality in a non-CDL hydraulic shredder - it will increase your productivity and decrease downtime. All of our products are designed, tested and manufactured in the U.S.
Hampton, NH (603) 601-2304 www.untha-america.com
Security Engineered Machinery Co
Shred-Tech
295 Pinebush Road Cambridge, ON N1T 1B2 Canada (800) 465-3214 shred@shred-tech.com www.shred-tech.com Shred-Tech® is globally recognized for designing and manufacturing firstclass reduction systems and shredding machinery to cost-effectively meet your waste reduction and recycling needs. See ad on pg 4
U
UNTHA America
Buffalo, NY (800) 447-4634 www.hammermills.com
Southlake, TX (817) 421-5940 www.shotguncapital.com
4475 E 74th Ave #103 Commerce City, CO 80022 (877) 600-6423, (303) 301-7651 Terry Lee, Business Development Mgr tlee@transleaseinc.com www.transleaseinc.com Our vision at Trans Lease is to provide you with the means to capture and grow expanding markets through our ability to provide financial choices and personal service. Since 1991, Trans Lease has expanded, doing business in all 50 states plus Canada and Puerto Rico, with a lease fleet of more than 5,000 units. See ad on pg 15
Spokane Valley, WA (877) 468-5872 www.ultrashred.com
Schutte-Buffalo Hammer Mill, LLC
Shotgun Capital Advisors
Trans Lease, Inc
UltraShred LLC
S
Westboro, MA (800) 225-9293 www.semshred.com
W
V ShredSupply
13026 W McFarlane Road, Bldg C-2 Airway Heights, WA 99001 (866) 520-8762 Karl Ellwood info@shredsupply.com www.shredsupply.com At ShredSupply, our mission is to be your industrial shredding supply company. We provide quality pre-owned and refurbished mobile shredding equipment, parts, service and rentals. Our equipment is dependable due to our thorough reconditioning and testing process by our highly skilled mechanics and technicians.
T
Tryco Manufacturing Co Decatur, IL (217) 864-4541
10 Security Shredding News Winter 2015-2016
Fort Lauderdale, FL (954) 525-8448 www.waterfrontcapital.com
WEIMA America, Inc
3678 Centre Circle Fort Mill, SC 29715 (888) 440-7170 info@weimaamerica.com www.weimaamerica.com For more than 25 years WEIMA has remained focused on the art of shredding and briquetting. We are passionate about improving these technologies. We invite you to profit from this growing wealth of knowledge and experience by specifying a WEIMA solution to your next challenge - the WEIMA team is ready.
The Wilson Bohannan Lock Co Marion, OH (800) 382-3639 www.padlocks.com
Wire Industries LLC Stockbridge, GA (770) 507-5700 www.wireindustriesllc.com
Vecoplan LLC
PO Box 7224 High Point, NC 27264 (336) 861-6070 Bob Gilmore info@vecoplanllc.com www.vecoplanllc.com Vecoplan engineers, manufactures, and provides parts and service on a range of shredders and systems for processing medical waste, destroying confidential records, and recycling scrap. An integral component in turnkey waste sterilization systems, our machines are used to shred sharps, textiles, plastics, and for red bag processing. AAA NAID compliant for secure destruction of paper, film, disks, and hard drives.
Z
ZRG Inc
Carlsbad, CA (760) 438-8825 www.zrginc.com
Attention Advertisers !
Now is the time to schedule your 4-color logo/photo listing in next year’s Buyers’ Guide Issue. For more information, contact Rick Downing at 440-257-6453.
In the News IRS Fails to Meet Information Security Requirements
W
ashington, D.C. – According to a Tax-News.com article, the Internal Revenue Service (IRS) is not doing enough to protect the confidentiality of taxpayers. The 2015 review by Treasury Inspector General for Tax Administration (TIGTA) has turned up a number of deficiencies in the IRS’s Continuous Monitoring Management, Configuration Management, and Identity and Access Management practices. The report concludes that the IRS has failed to meet US Federal Information Security Modernization Act (FISMA) requirements in those areas. The IRS’s Information Security Program generally complied with the FISMA requirement, but fell short of meeting certain Department of Homeland Security requirements. TIGTA warned: “Until the IRS takes steps to improve its security program deficiencies and fully implement all security program areas in compliance with FISMA requirements, taxpayer data will remain vulnerable to inappropriate and undetected use, modification, or disclosure.” “The IRS collects and maintains a significant amount of personal and financial information about taxpayers,” said J Russell George, the TIGTA. “As custodians of this sensitive information, the IRS has an obligation to protect it against unauthorized access or loss.” Following a breach involving personal information of 334,000 taxpayers this year, concern about tax fraud linked to identity theft in the United States has increased.
www.bomaccarts.com
sales@bomaccarts.com
Triple-S Management Agrees to $3.5 Million Fine for Multiple Breaches
T
riple-S Management, an independent licensee of the Blue Cross Blue Shield Association based in Puerto Rico has agreed to pay a $3.5 million penalty and conduct an enterprise-wide risk analysis, among other corrective actions, reports HealthCareInfoSecurity.com. Over the past five years, the company and its subsidiaries have reported a number of large incidents – some affecting more than 500 individuals, and others impacting fewer than 500 individuals, causing OCR to look for systemwide compliance deficiencies. The largest of the breaches reported by Triple-S in 2010 affected 475,000 individuals and is included HHS’ “wall of shame” website that lists major breaches. Among the noncompliance issues OCR found are its failure to implement appropriate administrative, physical and technical safeguards to protect the privacy of its beneficiaries’ PHI; sharing beneficiary PHI with an outside vendor with which it did not have an appropriate business associate agreement; use or disclosure of more PHI than was necessary to carry out mailings; failure to conduct an accurate and thorough risk analysis that incorporates all IT equipment, applications and data systems utilizing ePHI; and failure to implement security measures sufficient to reduce the risks and vulnerabilities to its ePHI to a reasonable and appropriate level. OCR has directed Triple-S to evaluate and address any environmental or operational changes that affect the security of the ePHI it holds and implement policies and procedures, as well as a training program that meets HIPAA requirements for protected information, as well as security and breach notification rules. In February 2014, a government agency in Puerto Rico levied a $6.8 million HIPAA sanction against Triple-S subsidiary, Triple S Salud, for a 2013 breach involving a mailing error that affected about 13,000 beneficiaries (see Huge Fine in Puerto Rico Breach). That enforcement action by the Puerto Rico Health Insurance Administration, also known by its Spanish language acronym “ASES,” required Triple S to implement a plan that would ensure breaches do not reoccur at the company. The largest OCR HIPAA settlement to date was a 2014 resolution agreement - which included a $4.8 million penalty and corrective action plan - with New York-Presbyterian Hospital and Columbia University tied to a 2010 breach. Also in December HHS levied an $850,000 fine on Lahey Hospital and Medical Center for potential HIPAA violations.
www.chachkagroup.com chachka@chachkagroup.com Security Shredding News Winter 2015-2016 11
Product/Equipment Profiles
In the News Blue Line Technology Introduces First Line Facial Recognition
B
l u e L i n e Te c h n o l o g y, a n emerging leader in security and access control solutions, recently introduced First Line Facial Recognition, a state-of-the-art camera based system developed by veterans of law enforcement. First Line Facial Recognition is designed for threat detection, access control and concierge applications with a robust service distribution across many industries. “After many successful projects, which have produced quantifiable results, we’re excited to announce the success of First Line Facial Recognition Software,” said Paul Brauss, CEO. “With the state-of-the-art software our system harnesses, we’re able to offer the most sophisticated facial recognition technology on the market.” In order to implement First Line Facial Recognition, the user creates a database that is custom-designed for their specific needs. The system then monitors, detects and alerts the user when a threat or unknown subject’s face is captured. The face is then placed into one of three categories: known, unknown or alert. If the face is known and cleared, access is granted. If the face is unknown or identified as a “threat,” access is not granted and an alert is sent to the user. Blue Line Technology’s First Line Facial Recognition contains an easy-to-use interface which allows the user to add, store and edit data both directly on the unit and through a seamless webs interface. The software can be used for prevention and immediate detection of both external and internal threats. The system is also designed for access control for any secured areas in which easy access or greater control is desired. “There are many times that threats are made against specific organizations,” continued Brauss. “When this occurs, we can set up our system to recognize the face of the person who made the threat and deny access to a building where an incident could potentially take place. It’s a practice in preventative policing and will save innocent lives.” For more information, visit bluelinetechnology.com.
European Paper Recycling Down from 2014
P
reliminary end of year statistics for European paper recycling show a 0.7% decline over last year’s numbers to 47.2 million tonnes in 17 EU states and Norway, according to the Confederation of European Paper Industries (CEPI). The total, however, shows a slight increase over the past decade – 1% higher than the figure for 2005 – despite a drop in paper and board production of 7.6%. For 2015, paper and board production is expected to be 0.3% lower than last year at 90.8 million tonnes, with increases for packaging paper and board (+2.3% to 44.3 million tonnes) and for sanitary & household paper (+1.5% to 7.1 million tonnes) failing to offset a decline of 4.3% to 35.4 million tonnes in graphic paper output. Paper and board industry turnover is 2.8% higher than last year in the CEPI zone, according to the preliminary statistics. In Germany, mark-downs for mixed and supermarket recovered paper and board achieved by paper mills were fairly uniform and widespread, but as in October, the downward pressure was greater in northern and western Germany than in the south. Yet there was no sign of an oversupply as the paper industry continued to be able to take up “good” volumes. Consumers of sorted graphic paper collected for de-inking report improvement in supplies. Paper producers say this is a relief after a few months of “summertime drought,” and they are now able to achieve “slight downward price adjustments here and there.” The European recycled paper numbers are based on the CEPI’s own data, and members’ financial reports that were available by mid-November.
Register now and save! April 7-9, 2016
REGISTRATION NOW OPEN
Renaissance Orlando at SeaWorld
• • • •
New Profit Centers Proven Residential Strategies Mastering Nat’l Accounts Product Innovations
• • • •
Unlimited Networking Web Sales Generation Biggest Industry Trade Show Early registration discounts
www.naidconf.org 12 Security Shredding News Winter 2015-2016
In the News State Enforcement of HIPAA: Connecticut Attorney General Acts
H
artford, CT – The Connecticut attorney general has entered into a $90,000 settlement agreement with two Health Insurance Portability and Accountability Act (HIPAA)-covered entities following its investigation into a breach of more than 8000 patient records, reports a NationalLawReview. com article. Hartford Hospital and EMC Corporation (EMC) are the two entities named in the settlement agreement. The breach occurred in 2012 after the hospital contracted EMC to analyze patient data as part of the hospital’s review of readmissions. A laptop containing unencrypted protected health information (PHI) of about 8,883 Connecticut residents was stolen from an EMC employee’s home. The employee had been employed by and had received the laptop from an EMC subsidiary, which EMC had previously acquired. EMC reported the theft to Hartford the day after the laptop was found missing. It was then that the hospital discovered it had not entered into a HIPAA-required business associate agreement with the contractor. The hospital notified all affected patients of the breach and filed a report with the Connecticut Attorney General’s office. Although the laptop was never recovered, the hospital maintains no evidence has surfaced indicating that the patient information has been misused. “The responsibilities of those who maintain and use personal information under HIPAA and Connecticut’s privacy laws are clear and are appropriately intended to protect the privacy of the patients,” Attorney General Jepsen said. “All healthcare providers and any contractors who work with healthcare providers should pay close attention to these responsibilities and review their
internal controls and policies to ensure that they’re doing all they possibly can to comply with the law and to keep this information safe.” In an Assurance of Voluntary Compliance signed in November, Hartford and EMC have agreed to implement new procedures and strengthen training requirements and policies already in place. Corrective measures by the hospital include clarifying procedures to ensure that contractual agreements are properly executed with vendors and implementing minimum privacy and security controls covering sharing PHI with vendors, specifically, new contract templates that incorporate applicable provisions of the Health Insurance Portability and Accountability Act (HIPAA). EMC must establish and maintain policies for responding to events involving unauthorized acquisition, access, use or disclosure of PHI. Hartford already has enhanced its annual mandatory compliance training and developed new training for business managers that spells out their HIPAA obligations. In addition, the compliance agreement requires that both the hospital and EMC follow privacy standards and provisions under HIPAA with regard to hardware and software security and for protecting data that is transmitted across wireless or public networks. Encryption of files or data containing PHI prior to its transmission or transfer must be done, whenever applicable. The compliance agreement also requires Hartford to submit a report in one year that demonstrates it has completed the corrective measures
HIPAA Compliance: HHS Audit Focus Shifts in 2016
W
ashington, D.C. – As the Department of Health and Human Services shifts gears for its next wave of audits, the focus expands beyond education to enforcement, reports GovInfoSecurity.com article authored by attorney, Anna Spencer. Covered entities are likely to see future HIPAA compliance audits leading to enforcement actions, including financial settlements, she predicts. Ms. Spencer is a partner at law firm Sidley Austin LLP. “I believe this round of [compliance] audits will likely lead to at least some enforcement actions because ... covered entities and business associates have had some time to get their houses in order, and also there is a significant amount of political pressure on the agency right now,” she says. HHS’ Office for Civil Rights (OCR) conducted audits in 2011 and 2012 of 115 covered entities of varying sizes and types for their level of compliance with the HIPAA privacy, security and breach notification rules. So far, OCR’s HIPAA enforcement actions have developed out of mainly, large breach investigations. In 2014, New York-Presbyterian Hospital and Columbia University agreed to a $4.8 million settlement. The incident, which involved unsecured patient data on a network, affected about 6,800 patients. Spencer says that OCR already has selected the contractor that will manage the 2016 round of audits. A soon-to-be-published audit protocol will reveal specific areas of review. She adds that the agency has signaled that audits will be more rigorous than in the past, and though the protocol is not likely to be drastically different from the first one, it will include more requirements for business associates. The 200 HIPAA-covered entities currently slated for audits next year appear to be quite broad in terms of types of organizations, but Spencer says it appears that high revenue (thus, impact on large numbers of patients) may indicate OCR’s direction. Previously audited organizations that had large (more than 500 records) breaches may not be specifically targeted, however. Spencer emphasizes that all covered entities have a documented risk assessment in place to provide a baseline. This, she says, is critical for meeting HIPAA compliance and security rules. In the first round, she says, as many as two-thirds of covered entities had not completed this crucial step. In addition, she says it’s important to have designated security and compliance officers and documented practices and procedures in place for protecting patient information. One new development related to HIPAA compliance, is pressure by lawmakers and the Office of the Inspector General for a requirement that covered entities offer potential victims identity theft solutions.
Security Shredding News Winter 2015-2016 13
In the News HIPAA Compliance: HHS Report Spells Out Weaknesses in OCR Oversight
W
ashington, D.C. – The U.S. Department of Health and Human Services’ (HHS) Office of Inspector General (OIG) says the Office for Civil Rights (OCR) must take stronger action in HIPAA privacy breaches and audits, a Mondaq.com article reports. The report precedes a delayed second phase of OCR’s audit program, which is due to roll out in 2016. The audit program follows two years of pilot investigations into breaches and other non-compliance issues, such as staff training. The findings of an OIG study on OCR’s audits beginning in 2014 are reported in a document blatantly titled, “OCR Should Strengthen Its Oversight of Covered Entities’ Compliance with the HIPAA Privacy Standards.” Foremost, HHS wants OCR to take closer scrutiny of HIPAA compliance issues. Investigations of largescale breaches, along with overall ever-increasing concerns about cyber security, identity theft and protected health information are driving HHS’ pressure on OCR. Two main problem areas found by HHS were hospitals and individual healthcare providers. Pharmacies and health insurance companies can expect more oversight, as well. HITECH Act requirements have been in effect since early 2010, but OCR has not fully implemented an audit program for covered entities, the HHS report says. Unauthorized computer access to medical condition, prescriptions, or treatment history could expose patients to an invasion of privacy, identity theft, or other harm. OIG’s primary corrective action recommendation was that OCR immediately should implement a permanent audit program. With its feet to the fire, OCR has accepted this finding and undertaken to launch audits in early 2016. HHS is calling on OCR investigators to be more diligent in reviewing various types of HIPAA compliance documentation, as well as following up on corrective actions taken in response to previous investigations. The parent agency is also directing OCR to develop an efficient method to search for and track covered entities that reported prior breaches, though the report acknowledges inadequacies with OCR’s Program Information Management System (PIMS). Because of certain limitations in data entry and search capabilities, tracking and identifying covered entities with multiple small breaches using PIMS has been difficult. In fact, HHS found that about a quarter of OCR’s cases it reviewed had incomplete documentation. Smallbreach information was incomplete or missing in PIMS. Without checking for a history of investigations, OCR cannot identify covered entities that may have systemic issues in safeguarding PHI. In addition to software upgrades, HHS wants OCR to develop a policy requiring OCR staff to check whether covered entities reported prior breaches. Because OCR’s primary oversight activity is responding to complaints, one area that has not been given a lot of scrutiny is Part B providers—or covered entities, in general—that do not regularly address HIPAA privacy standards. So, for example, HHS wants OCR to pay more attention to pharmacy operations, locating areas in need of improvement, such as training. In its review, HHS found that twenty-seven percent of Part B providers reported that they were unfamiliar with OCR’s jurisdiction over the Privacy Rule. Without knowing that OCR has this jurisdiction, Part B providers may not be aware of, and may not access OCR resources on how to comply with the Privacy Rule. HHS wants OCR to continue to expand its outreach and education efforts to Part B providers.
e-cycleNYC Residential E-Waste Recycling Program Expands to Service all New Yorkers Joint Effort by ERI, New York City and Manufacturers to Provide Drop-off Locations in Every Borough
N
ew York, NY – In a joint press conference held recently by the New York City Department of Sanitation (DSNY), Electronic Recyclers International (ERI) and proactive manufacturers, it was announced that the City’s groundbreaking e-cycleNYC (www.nyc.gov/ecycle) program is broadening its scope, and will expand the e-waste & hazwaste collection process beyond participating residential buildings. All New York City residents can now drop off e-waste at one of the five permanent collection points called Household Special Waste Sites. The sites, conveniently located in each borough, are adding e-waste as part of its currently successful collections of batteries, bulbs, paint, and other unwanted household items. It was also announced that the program’s residential pick-up component is now serving more than 500,000 households. The e-cycleNYC program is a public-private partnership between DSNY and ERI. Fully funded by electronics manufacturers, the program is free for NYC taxpayers and participating residential buildings. “The e-cycleNYC program is a true partnership with support from manufacturers as well as both labor and property owners,” said Sanitation Commissioner Kathryn Garcia. “Through collaboration and teamwork we have been able to forge the most comprehensive electronics recycling service offered in the nation. We’re proud to have set an example for the rest of the country and look forward to continued growth for this important initiative.” With the program, New York City-area buildings with at least 10 units can receive on-site pickup of stored electronics, including TVs, monitors, computers, laptops, small servers, printers/scanners, tablets/e-readers, mobile phones, MP3 players, VCRs/DVRs/DVD players, video game consoles, cable/satellite boxes, fax machines, keyboards, mice and hard drives.
14 Security Shredding News Winter 2015-2016
University of Washington Agrees to $750,000 Settlement for PHI Breach
S
eattle, WA – The University of Washington Medicine has agreed to pay a $750,000 penalty as part of a resolution for a protected health information breach affecting 90,000 individuals, reports a DataBreachToday.com article. The fine imposed by Health and Human Services (HHS) represents the first action taken by the Department of Health and Human Services for a breach stemming from a malware-related incident. Though the resolution agreement does not specifically mention phishing, an Office for Civil Rights (OCR) spokeswoman acknowledged to media that “the incident [at UWM] involved a forged email containing malware in an attachment.” UWM filed a breach notification with OCR on Nov. 27, 2013 within weeks of discovering that protected health information of approximately 90,000 individuals was inappropriately accessed after an employee downloaded an email attachment infected with malware. “The malware attack occurred in October 2013 when an employee opened an email link to review a document. The malware provided potential access to contact and other information needed for billing patients that was stored in files on the employee’s desktop computer,” UWM says. “When the potential breach was discovered, UWM notified the FBI and the OCR.” According to investigation documents, the malware compromised the organization’s IT system, affecting the data of two groups of patients. For 76,000 patients, names, medical record numbers, dates of service, and/or charges or bill balances were exposed. For another 15,000 patients, information compromised included names, medical record numbers, contact information, dates of birth, charges or bill balances, Social Security numbers, insurance identification or Medicare numbers. OCR’s investigators also found fault with UWM’s oversight of its affiliated HIPAA-covered entities. In particular, risk assessments and responses to potential risks and vulnerabilities in their respective environments were found to be inadequate. Corrective actions required by OCR require UWM to “develop a current, comprehensive and thorough risk analysis of security risks and vulnerabilities to include the ePHI created, received, maintained or transmitted by UWM facilities and applications, which had been excluded from its August 2014 ‘HIPAA meaningful use risk assessment.’” Bottom line, the OCR action indicates that covered entities must assess all ePHI for security risks, not just the EHR-related ePHI assessed to fulfill HITECH Act meaningful use program requirements. Also, failure to encourage a culture of awareness that includes training and regular security reminders will come under scrutiny. UWM includes several healthcare related entities under the umbrella of the University of Washington, including University of Washington Medical Center, the primary teaching hospital of the University of Washington School of Medicine. This summer, Washington State Governor Jay Inslee signed an update to the state’s breach notification law to require notification to affected individuals within 45 calendar days after initial discovery of any breach of electronic or paper records.
tlee@transleaseinc.com
www.transleaseinc.com Security Shredding News Winter 2015-2016 15
POWERFUL
KEITH Drive Unit
SAFE
No Tipping To Unload
FAST
Unloads In Under 5 Minutes
SEE IT WORK
Scan code or visit: www.youtube.com/user/KeithMfgCo youtube.com/user/KeithMfgCo
IT’S WHAT WE DO
™ If you want a fast RELIABLE and efficient SELF-UNLOADER, the KEITH® WALKING FLOOR® is the solution for you. With a load CAPACITY of up to 16 ton*, the system stores shredded documents and AUTOMATICALLY unloads them once the truck reaches a secure location.Your truck is your CHOICE. Make sure the unloader is KEITH. *KMD 300
www.keithwalkingfloor.com
1-800-547-6161 2015 KEITH Mfg. Co. KEITH, KEITH logo and WALKING FLOOR are registered trademarks of KEITH Mfg. Co. Manufactured under license.