1 RECORDS/INFO MANAGEMENT & DOCUMENT RETENTION 10/22/14 D AM I AN M AL O N E Y Damian Maloney Records R E C Compliance O R D S C O M Specialist P L I AN C E S P E C I AL I S T Cumberland Electric Membership Corporation
2 WHO NEEDS RECORDS / INFO MANAGEMENT? Any and all business entities and most persons. It doesn t matter how small or larger your organization is there are laws and/or regulatory requirements that exist that require you keep documents or information for certain periods of time and that certain information be protected.
3 WHAT IS RECORDS/INFORMATION MANAGEMENT? Practice of maintaining the records and information of an organization from creation to eventual destruction or archival, and all steps in between. (Info Life Cycle)
4 WHEN DO WE NEED A RECORDS MANAGEMENT PROGRAM? NOW!! The sooner the better. Most organizations don t realize the liability associated with lack of a document / information retention program. Murphy s Law Proper management of documents/info goes a long way to mitigate potential liability/cost.
5 WHERE DO RECORDS/INFORMATION RESIDE? Physical Records Filing Cabinets, Drawers, Binders Warehouses Where you would least expect them. Breakroom Electronic Files / Information Primary Business Software(s) Servers / Virtual Servers / Clouds Shared Folders , , Cell Phones Third party and software Evernote! ASANA Hundreds more out there..
6 WHY RECORDS / INFORMATION MANAGEMENT? To Improve Efficiency and Productivity Managers and workers still spend up to 20% of time seeking information and up to 50% of the information they do find is irrelevant. Disaster Recovery Replication of Vital Records - Plan to ensure continuation of business and resumption of operations in event of disaster Business Continuity
7 WHY RECORDS / INFORMATION MANAGEMENT CONT. Ensure Legal & Regulatory Compliance and Mitigate Risk US is still the most litigious society in the world There are 13,000+ laws and regulations that address the management of records and information Key issues include; Access / Availability (JB-400) Security / Protection (Physical vs Electronic) Retention (Bonfires)
8 WHY RECORDS / INFORMATION MANAGEMENT CONT. Some of the sources of records/information retention requirements applicable to CEMC include; 1. USDA Rural Utilities Service (RUS Bulletin 180-2) 2. Code of Federal Regulations (CFR 18 CFR Ch. I) 3. Tennessee Corporate Records Law (TCA ) 4. Internal Revenue Service (IRS) 5. Fair Labor Standards Act 6. National Labor Relations Act 7. Tennessee Fair Labor Standards Act 8. Age Discrimination in Employment Act 9. Title VII of the Civil Rights Act of Employee Retirement Income Security Act 11. Occupational Safety and Health Act (OSHA) 12. Family Medical Leave Act of Americans With Disabilities Act 14. Employee Retirement Income Security Act (ERISA) 15. Tenn State Unemployment Compensation Insurance Law 16. Federal Energy Regulatory Commission (FERC).
9 WHY RECORDS / INFORMATION MANAGEMENT CONT. Civil Discovery Show me the money We work in a good industry, however Interrogatories & Request for production of documents (30 days) Second Set (30 days) Motion to Compel
10 WHY RECORDS / INFORMATION MANAGEMENT CONT. Federal Rules of Civil Procedure In 2006 the rules were revised to include ESI (Elecronically Stored Information) Over half the states have since adopted similar provisions, Tennessee included; Rule 37 Failure to Make or Cooperate in Discovery : Sanctions Rule Electronically Stored Information Judge should then weigh the benefits to the requesting party against the burden and expense of the discovery for the responding party Considering factors such as; ease of accessing the requested information the total cost of production compared to the amount in controversy the materiality of the information to the requesting party the availability of the information from other sources the complexity of the case and the importance of the issues addressed Plus 15 additional factors listed in the rule JUDICIAL DISCRETION!
11 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Identify your program administrator New position vs Existing personnel Realize the scope and workload that an undertaking of this magnitude will require. This person may not only develop and administrate the program but will also more than likely by the software administrator. Identify your organizational structure. Co-operative Municipality Not-for-profit From this, identify all sources of required record/information retention. Federal, State, Local Laws Regulatory Bodies Other sources Parent Organizations (TVA Service Standards) Lenders (RUS) Contracts (FEMA/TEMA)
12 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Perform an inventory and identify all documents/information with retention value. The where section of the presentation Meet with Managers and Key Personnel Identify the documents they produce and the data they utilize in their world. Find out where it s kept and document it. Determine what has retention value and what doesn t. 2 yrs into program & CEMC has over 500 doc types
13 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Create the organizations Retention Schedule; Inventory + Legal & Reg Requirements = Retention Schedule Remember when they taught you fractions? The least common denominator.
14 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? 98 Categories and growing!
15 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Get Support from the Top Down Create a policy and supporting procedures that address; Inventory of Records / Information Retention Schedule Documents / Info Destruction of Records and Data Legal Hold Process Access / Security Disaster Recovery
16 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Other related policies and procedures that may be a part of your program or separate are; Retention Policy Cyber Security Policy Personal Electronic Devices Policy Make sure your policy and procedures reflect what your actually doing for multiple reasons; This becomes auditable In a legal proceeding if it is determined that your organization applied your retention policy/schedule to selected documents and not others then there may be significant repercussions. (Back to Judicial Discretion) CEMC implemented it s Policy/Bulletin in May and it s on my calendar to modify accordingly.
17 HOW TO CREATE OR UPDATE A RECORDS / INFO MGMNT PROGRAM? Select a software that meets your records / information program wants and needs. Archiving of documents Workflows Legal Holds Retention/Destruction of Digital Files Performance Data Accessibility and so on CEMC uses Perceptive Software / ImageNow Many pro s and cons but you must select something that is right for your organization.
18 CEMC RECORDS MANAGEMENT PROGRAM Set goals and launch program Goals of CEMC Records Management Program; Identify, Organize, and Capture All Business Documents in One Location (ImageNow) Establish and Implement Records Mgmt & Retention Policy & Associated Procedures Increase Efficiency-Mitigate Liability Make CEMC a Paperless Entity (Or as close as possible!!)
19 RECORDS/INFORMATION MANAGEMENT AND RETENTION Questions
Written Information Security Programs: Compliance with the Massachusetts Data Security Regulation Melissa J. Krasnow, Dorsey & Whitney LLP A Note discussing written information security programs (WISPs)
Small Business Legal Audit Checklist 2008 Stuart Adams 1. Basic Disaster Preparation and Planning None of us like to think about disasters, and many of us have an it won t happen to me attitude. The following
The Impact of Electronically Stored Information on Corporate Legal and Compliance Management White paper The impact of electronically stored information on corporate legal and compliance management: An
Records Management Best Practices Guide A Practical Approach to Building a Comprehensive and Compliant Records Management Program Protecting and Managing the World s Information. Since 1951, Iron Mountain
AAMC Uniform Clinical Training Affiliation Agreement Project Frequently Asked Questions 1. Where did this AAMC Uniform Clinical Training Affiliation Agreement come from? The Association of American Medical
White Paper How Long Should Email Be Saved? Sponsored by Symantec, Inc. Copyright 2007 Contoural, Inc. Table of Contents Introduction... 3 Considering Email retention... 3 Can IT Set Email Retention Policy?...
REED COLLEGE ediscovery GUIDELINES FOR PRESERVATION AND PRODUCTION OF ELECTRONIC RECORDS TABLE OF CONTENTS A. INTRODUCTION... 1 B. THE LANDSCAPE OF ELECTRONIC RECORDS SYSTEMS... 1 1. Email Infrastructure...
AUDITOR OF STATE WA S H I N G T O N NOV 11, 1889 Washington State Auditor s Office Troy Kelley Independence Respect Integrity Performance Audit Health Care Authority s Oversight of the Medicaid Managed
WHITE PAPER ediscovery: In-house vs. Outsource? www.dsicovery.com 877-797-4771 414 Union St., Suite 1210 Nashville, TN 37219 (615) 255-5343 Table of Contents Introduction.........................................................
RECORDS MANAGEMENT MANUAL Date: September, 2007 Authored By: University Archives Contents 1. Records Management at UBC 3 A) Purpose of The Records Manual 3 B) Benefits of Records Management 3 C) Some Records
2008 ISACA. All rights reserved. www.isaca.org. Electronically Stored Information and Cyberforensics By Albert J. Marcella Jr., Ph.D., CISA A New Age of Discovery The US Sarbanes-Oxley Act, US Health Insurance
Live your dream. Advisor Succession Planning Guide 2 Advisor Succession Planning Guide Introduction Many financial advisors are looking to grow their businesses by buying a practice while others are looking
WHITE PAPER N Considerations for Archiving in An Osterman Research White Paper Published July 2013 SPONSORED BY sponsored by SPON sponsored by Osterman Research, Inc. P.O. Box 1058 Black Diamond, Washington
Sponsored by ediscovery: The New Information Management Battleground Developments in the Law and Best Practices Kahn Consulting Inc. (847) 266-0722 email@example.com Introduction The following
HIPAA SECURITY AND POLICIES AND PROCEDURES 1 HIPAA SECURITY AND POLICIES AND PROCEDURES By: Michele Cuper THESIS FOR MASTERS DEGREE INFORMATION ASSURANCE CAPS 795 DAVENPORT UNIVERSITY PRESENTED TO: DR.
Records Management: Seven Best Practices for Staying Ahead of the Curve 2014 Table of Contents Introduction... 3 Obtain Executive Support... 3 Define A Records Management Approach... 4 Create A Clear Policy
Guide for taxpayers Our approach to information gathering This publication is current at November 2013. For the most current version, visit our website at ato.gov.au/infogathering OUR COMMITMENT TO YOU
Comptroller s Handbook AM-RPPS Asset Management (AM) Retirement Plan Products and Services February 2014 Office of the Comptroller of the Currency Washington, DC 20219 Contents Introduction...1 Types of
White Paper May 2006 Applying Electronic Records Management in the Document Management Environment: An Integrated Approach Written by: Bud Porter-Roth Porter-Roth Associates Table of Contents Introduction
ESI Risk Assessment: Critical in Light of the new E-discovery and notification laws Scott Bailey, CISM Christopher Sobota, J.D. Enterprise Risk Management Group Disclaimer This presentation is for informational
GUIDE TO SMALL BUSINESS RECORDKEEING To make your business #CAOWERED, call today and let s get started. TABLE OF CONTENTS BASIC CONSIDERATIONS 2 CONVENIENCE AND FLEXIBILITY 2 When starting a small business,
U.S. Department of Labor Office of Federal Contract Compliance Programs Technical Assistance Guide for Federal Supply and Service Contractors August 2009 U.S. Department of Labor Employment Standards Administration
HIPAA Security Risk Analysis Toolkit In January of 2013, the Department of Health and Human Services Office for Civil Rights (OCR) released a final rule implementing a wide range of HIPAA privacy and security
A Formtek Whitepaper Getting Both Best-Practice and Best-Value in a Records Management System 1855 Gateway Blvd. Suite 570 Concord, CA 94520-5715 Phone: 1.800.367.6835 www.formtek.com 2012 Formtek, Inc.
ICC CYBER SECURITY GUIDE FOR BUSINESS ICC CYBER SECURITY GUIDE FOR BUSINESS Acknowledgements The ICC Cyber security guide for business was inspired by the Belgian Cyber security guide, an initiative of