Company possible breaking FACTA laws and/or violation employee's personal information

Status
Not open for further replies.

justchecking

New Member
I believe the company I am working for has some serious issues with their security of employee's personal information among other issues, to the point now that I am starting to question my employment there and the fact they have my personal information as well. Including FACTA, I believe there are various state and federal laws about employers protecting this information.

Over the course of the last few years I have found documents with all manner of a person's personal information strewn all over the building. This information contains names, SSNs, addresses, phone numbers. I have found these in very public areas of the building, laying on desks, posted on walls, etc. I have also received emails containing other employee's information as well, including their names, SSNs, addresses, phones numbers again on multiple times.

I have reported these events to HR staff and managers multiple times, but it keeps happening. The company seems to care very little for how accessible this information is to anyone in our building, or anyone entering, including non-employees. So far, I have taken it on myself to remove these documents from accessible areas, black out employee SSNs, shred documents laying around, place other documents in locked areas, return documents to HR, and much more.

I should also state that I am not a member of HR or management, I am a hourly employee, for all intents and purposes I am pretty much just the repair guy for the building.

Most recently, I found binders of employee records in an area of the building accessible to every employee, client, vendor, maint staff, cleaning crews, and any other person who enters our building. Included in this was copies of drivers licenses, SSN cards, addresses, names, phone numbers, medical information, bennifits information, and any other information an employer might have on employees. Also included were former employees. Literally 100s of people personal information. Also, were completed applications for employment with our company, including all those peoples personal information as well who were simply applying for jobs.

In the area I live, jobs are hard to come by, and especially in my field. I feel that if I push the issue any more I will become a "problematic" employee and they will find a reason to terminate me. The company does not have any issues with that, I have been asked several times in the past to target certain employees for termination before they have done anything warranting it that I am aware of.

I do not know what to do.
 
Protection of social insecurity numbers is required by employers. You're right about the law.

If you have a union shop, maybe the union can address this. Otherwise, whistleblower statutes will protect you. You might want to contact social insecurity and see what they advise.


Sent from my iPhone using Tapatalk
 
I thought so, the basic information i was looking through included the following:
FACTA - Fair and Accurate Credit Transactions Act
FACTA applies to every business that maintains Customer or Employee information for a business purpose. Customer or Employee Information lost under the wrong circumstances can result in:

* Civil and state penalties up to $1,000 per violation
* Federal penalties as high as $2,500 for each incident
* Possible individual lawsuits
* Possible class-action lawsuits

HIPAA - Health Insurance Portability and Accountability Act
HIPAA Security Rule
The HIPAA Security Rule applies to every business that retains or collects Health Information. Medical Information lost under the wrong circumstances can result in:

* Fines up to $250,000 per occurrence
* Up to 10 years jail time for executives

Also information about NY state laws for Social Security Number Protection:
jonesday.com/newsknowledge/publicationdetail.aspx?publication=3778

+++++++++++++++++++++
The possibilities on the damage to the company sound pretty significant, there is easily at least 500-1000 peoples information laying around. If I choose to persue this further, I am not sure if I should get legal help to protect myself in advance and/or to make sure I do things right. Sounds like whistleblower issues can be very tricky and dangerous territory for the employee. Sounds like a very grey area, there is also mention of Qui Tam laws and such, but I am very unfamiliar with the terminology but sounds like it only affects fraud.
 
Status
Not open for further replies.
Back
Top