Home Back Issues July/August 2013 Time to make security a business priority

Time to make security a business priority

| Print |  Email
Articles - July/August 2013
Monday, July 08, 2013

BY SHAWN M. LINDSAY

As a business, do you ever handle or use a client’s credit card number or social security number? How about a client’s financial documents, date of birth, driver’s license number, medical records or any other sensitive personal information? If none of these, maybe your website collects information from children under the age of 13, or maybe you have a smartphone app that uses location services? For most of you, the answer will be yes, and the manner in which you handle the information is serious business.

Information privacy and data security issues involve nearly every facet of a business. With the rapid development of digital and information technology, businesses of every size now collect, process and warehouse all sorts of personal information with a variety of technologies, from USB drives to tablets to the cloud. The laws and regulations that govern the handling of personal information are numerous, complex, vary by location and are constantly changing. If a business does not take appropriate care to protect against prohibited access to or loss of personal information, it can be subjected to significant fines and, more important, considerable damage to its reputation.

A few recent examples illustrate the exposure to risk. In February of this year, while on vacation in Hawaii, a hospital surgeon had his laptop — containing personal health information of approximately 4,000 patients — taken during a burglary. The hospital involved offered patients free identity theft monitoring, among other things. This past March, the online note-taking servicer Evernote was hacked, and all of its 50 million users needed to reset their passwords. And late this spring, the Utah Department of Technology Services revealed that 780,000 individuals were affected by the theft of Medicaid information, including social security numbers. Utah had to send a report to the U.S. Department of Health and Human Services to assess potential violations of HIPAA.

Big businesses are not the only ones experiencing technology breaches. Breaches have recently occurred with small dental and medical offices, grocery stores and online retail stores. As a business, what can you do to protect your clients’ confidential information and reduce your potential liability? You can promote prevention, detection and correction.

Interestingly, most data breaches are caused by mundane events like employees losing a USB drive or smartphone, or unwittingly misusing the Internet. One way you can promote prevention is by educating employees. Negligent employees are the top cause of loss. Privacy and security risk is no longer just an IT department problem; it is everyone’s problem. Empower employees to take responsibility for the security processes in place. You can do that yourself, or there are partners that can help you do it. For example, Swan Island Networks offers a solution, Cybero, which provides employees with real-time alerts about the latest social engineering exploits, social media activism and manufactured scams.

You can promote detection by evaluating your risks and improving your compliance. You can do this yourself, or you can partner with experts to assist. For example, ID Experts is a Portland company that can conduct a compliance assessment, a penetration test, a security-risk analysis and an incident response test. With this information, you can then promote correction by formulating a comprehensive remediation plan.

What’s most important is to have a privacy and security team in place. When dealing with privacy and security risks, there is no margin for error. So get that team in place and make sure privacy and security is a priority. It’s always better to build a fence on top of the hill then have an ambulance at the bottom of the hill.

0713 InformationSecurityShawn M. Lindsay is counsel to the firm at Lane Powell and co-chair of the firm’s Privacy and Security Practice Group. He can be reached at 503-778-2124 or This e-mail address is being protected from spambots. You need JavaScript enabled to view it .

 

More Articles

The future of money

March 2014
Tuesday, February 25, 2014
BY JAKE THOMAS

An ancient institution moves slowly into the digital age. 


Read more...

How to handle the unexpected

Contributed Blogs
Friday, March 28, 2014
03.28.14 thumb disasterBY TOM COX | OB BLOGGER

The next mysterious (or disastrous) event could be one that you or your team might suddenly need to respond to, probably under intense scrutiny.


Read more...

Eking out a living

News
Tuesday, April 08, 2014
04.08.14 thumb ourtable-coopfarmsBY HANNAH WALLACE | OB BLOGGER

It may be obvious, but most farmers don’t make a lot of money. According to preliminary data from the 2012 Agriculture Census, 52% of America’s 2.1 million principal farm-operators don’t call farming their primary occupation. Farm cooperatives may offer a solution.


Read more...

Banishing oil burners reaps benefits for schools

News
Tuesday, April 01, 2014
04.02.14 thumb co2schoolsBY APRIL STREETER | OB CONTRIBUTOR

Three years ago, PPS set out to begin to convert the 1930s-era boilers from diesel/bunker fuel to cleaner-burning natural gas. Oregon’s largest school district has realized impressive carbon dioxide emissions reductions, setting an example for public and private institutions.


Read more...

The 2014 List: The Top 34 Medium Companies to Work, For in Oregon

March 2014
Thursday, February 27, 2014

100best14logoWebOur 100 Best Companies project turned 21 this year, so pop open the Champagne. Our latest survey gives us plenty to cheer.

 


Read more...

Rapid ascent

March 2014
Tuesday, February 25, 2014
IMG 4255-2BY AMY MILSHTEIN

Kelly Dachtler, president of The Clymb, redefines outdoor retail.


Read more...

How to boost web traffic

News
Thursday, April 10, 2014
BY JESSICA RIDGWAY  | OB WEB EDITOR

04.10.14 thumb seo-trafficSEMpdx hosted a workshop this week for entrepreneurs, website developers and others interested in search engine optimization (SEO).  Here are a few tips and tricks aimed at bumping up your search engine rankings.


Read more...
Oregon Business magazinetitle-sponsored-links-02
SPONSORED LINKS