Pennsylvania Companies Must Protect Employees’ Sensitive Data

By Stark & Stark on June 14th, 2019

Posted in Pennsylvania Law Monitor

Employers, and likely all businesses, now have a specific duty to safeguard their employees’ personal data that is stored on internet-based computer systems, according to a recent decision by the Supreme Court of Pennsylvania. Prior legislation only required companies to report potential or actual data breaches to the individuals or businesses whose information may have been, or was, compromised.

In Dittman v. Univ. of Pittsburgh Medical Center, the court held that employers have a duty to exercise reasonable care to protect their employees against an unreasonable risk of harm if the company collects and stores the employees’ data on internet-based computer systems. Further, this duty is independent of any contractual obligations between the employer and employee. The court reasoned that by collecting the data without appropriate security measures, UPMC created a foreseeable risk of a data breach. In other words, UPMC should have known a cyber-criminal might take advantage of its vulnerable computer system and steal the data.

The case involved the theft of social security numbers, dates of birth, tax information, addresses, salaries and bank account information of more than 62,000 current and former UPMC employees. UPMC gathered the sensitive information as a condition of employment. The employees sought money damages for losses due to the filing of fraudulent tax returns and for the increased and imminent risk of identity theft.

This ruling is important because the decision likely extends to any entity (not just employers) that collects and stores sensitive personal data. Additionally, defendants can no longer claim the criminal act of a third party as an intervening act to shield them from liability. As such, this new decision will force companies to incur significant expenses to update their security protocols and will expose them to more risk and potential litigation.

Multiple locations to better serve your needs—

Hamilton, NJ

100 American Metro Boulevard
Hamilton, NJ 08619
Phone: 609.896.9060
Secondary phone: 800.535.3425
Fax: 609.896.0629
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer

Marlton, NJ

40 Lake Center, 401 NJ-73, Suite 130
Marlton, NJ 08053
Phone: 856.874.4443
Secondary phone: 888.241.7424
Fax: 856.874.0133
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer

Yardley, PA

777 Township Line Road, Suite 120
Yardley, PA 19067
Phone: 267.907.9600
Fax: 267.907.9659
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer

New York, NY

5 Pennsylvania Plaza 23rd Floor
New York, NY 10001
Phone: 800.535.3425
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer

Philadelphia, PA

The Bellevue 200 S Broad St #600
Philadelphia, PA 19102
Phone: 267.907.9600
Secondary phone: 800.535.3425
Fax: 215.564.6245
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer

Bridgeton, NJ

78 W Broad St
Bridgeton, NJ 08302
Phone: 856.874.4443
county best pa pennsylvania reviews south jersey berks northhampton montgomery bucks lehigh valley gloucester burlington mercer