Let’s send an unencrypted thumb drive via mail. What can possibly go wrong, right?
No, Human Resource Advantage. You do not get to put an unencrypted thumb drive with employee records in the regular mail to TrustHCS and then claim you take the security of personal information in your control “very seriously.”
From your own investigation, that drive contained names, Social Security numbers, dates of birth, bank account information, postal and email addresses, and any leave of absence requests, including those submitted under the Family Medical Leave Act for several current and former employees of TrustHCS.
Heck, there wasn’t even any password protection (not that that would have done much).
And where were you in all this, TrustHCS? Did your contract with Human Resource Advantage permit them to send you sensitive employee records without any encryption or protection? If it did, why? And if it didn’t, are you still using them?