There’s a huge amount of business information floating around cyberspace,
from secure credit card transactions to confidential patient information or
just casual e-mails exchanged between two employees on company time.
But whether businesses are looking to protect client information
or keep tabs on employee diligence, federal legislation is beginning to take
on concrete meanings for publicly held companies.
Experts say even the smallest of operations is going to be held increasingly
accountable for the security of their customer transactions and for maintaining
accessible records of all communications, whether through the storage of e-mail
exchanges or archived copies of concrete correspondence.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
“There’s certainly a lot to pay attention to,” said Dr. Edward Eberle, a law
professor at Roger Williams University, referring to both legislation that’s
been passed and that’s still pending. “It’s all a work in progress, but what
that means in the litigation of citizens and businesses is still not really
clear,” he said.
“Meanwhile, we’re going to be seeing a lot of acrimonious debate over who’s
responsible for implementing what and when.”
The health care field has seen vast privacy changes spurred on by the Health
Insurance Portability and Accountability Act. Banks, and other firms with a
financial focus, have been the first at work on providing internal guidelines
and checks for opening new accounts as outlined in the Patriot Act.
After the Enron debacle, legislation was passed to ensure that business documents
could not be destroyed en masse, publicly held companies were faced with certifying
the processes that will produce the financial reports filed at the end of this
year.
The Sarbanes-Oxley Act of 2002, one of the first to address the need for retaining
electronic communications, already had summer compliance dates for its first
phase bumped back to last month. A much broader part of the act will soon require
the real-time disclosure of any event that might affect performance.
With research estimates put upward of 75 percent of all business documents
being created electronically, with less than one-third of those ever making
their way to paper, one Providence-based company took a new product, EmailXtender,
to market last month.
Entrepid, a consulting firm in Davol Square, has been making the rounds to
financial, banking and biotech firms (industries where compliance requirements
have been more clearly spelled out) to provide its software, server and storage
component for archiving e-mail communications. Among other features, the program
can allow businesses to search archived documents, monitor flagged words and
store “fingerprinted” copies of correspondence to guarantee their authenticity.
Fred Bedard, vice president of sales and marketing for the company, said the
retention policies outlined for public companies is usually to store documents
for the past several years, while most companies go with a “delete all” e-mail
policy in one or two months of receiving a message.
He said all businesses should be mindful that indiscriminately getting rid
of e-mail could delete correspondence that may be helpful in litigation, or
lead to company liability for spoliation of evidence.
“People are abusing the systems now,” said Bedard, who said the potential
use and abuse of electronic documents is always expanding. “There’s been a big
void in the management of those documents.”
Bedard said even smaller companies should have a policy in place, one that
is being enforced, to deal with their e-mail correspondence.
“It just makes good business sense,” said Bedard, rhetorically asking what
might happen if accounts receivable cashed checks as they came in but never
kept records.
“Imagine if you managed the rest of your business like people have been managing
their e-mail,” he said. “Private companies today are always looking to be acquired
or to go public. It makes sense to be managing your business the best way you
can. Even if you can offset one litigation or reduce costs during the discovery
process, it makes sense.”
Doug White, professor of computer information systems at Roger Williams University,
said electronic security itself has became a much bigger issue since the Patriot
Act was passed in the wake of Sept. 11. While the act allows law enforcement
to request business documents only by certifying that the records sought are
for an international terrorism or intelligence investigation, White said more
immediate changes to business documentation has been driven by the same privacy
standards spelled out for patients in 1996 by HIPAA.
“These privacy acts are pushing even small companies into a dangerous area,”
White said.
He added that companies with a financial focus (who also have the most to
lose with even the appearance of a compromised system) remain most at risk for
their systems to be entered and for information to be used maliciously. Generally,
White said hackers have been less concerned with tampering with information
and more intent on extracting information like credit card numbers, home addresses
or social security numbers that a company isn’t protecting.
Smaller businesses, many of whom have actually used the Internet to expand
their customer base, continue to rely on what White calls, “security through
obscurity” – crossing their fingers and hoping that people don’t target them.
“It’s getting harder and harder to find anything other than a global marketplace,”
law professor Eberle said. “And that’s all the more so for companies based out
in cyberspace.”
White suggested outsourcing – especially in the management of Web sites and
credit transactions – for small- to mid-sized businesses that can’t afford the
technology people to make their systems totally secure.
“Above all, businesses need to have a plan in place, even if they decide they’re
going to accept the risk,” White said. “The answer to what are they going to
do if their system is compromised should be similar to what are they going to
do if the office burns down. They need to know how they’re going to handle the
press, how they’re going to reassure the customer. Even small businesses should
think through that sort of thing.”
Eberle said companies are increasingly going to be held accountable not only
for supplying their own financial documents but also for keeping tabs on their
internal communications and the communications of their employees.
While Congress may have exempted U.S. citizens from the Pentagon’s proposed
Terrorism (formerly Total) Information Awareness program, bids have already
been put out by the Department of Defense to contract software companies to
develop databases capable of sifting through information spanning from sales
transactions to government resources like driver licenses and voter registration
lists.
“Certain aspects of behavior can be traced through the computer world,” Eberle
said, “whether that’s what Web sites you access or point of sales transactions.
… There seems to be a whole variety of things that can be called up on each
one of us that’s all up for grabs. And you never know how or what can turn up.
It looks like companies are going to be responsible more than ever for keeping
records on everything and everyone.”












