What risk does outsourcing of various information system functions pose
to satisfying the principles of confidentiality and privacy?
Outsourcing is used by a company to help cut cost while hopefully increasing
efficiency. This is done by hiring a third part to take over certain operations
that were previously done in house. While there are many reasons a company
might outsource certain operations, organizations should be careful when
considering offshore outsourcing. Offshore outsourcing is when the third
party resides in a different country than the organization doing the
outsourcing. CFI Team (2022) list four disadvantages to outsourcing, include
risk of losing sensitive data and loss of controls. Davion (2004) provides a
case study in which a healthcare company outsourced medical transcriptions
to another company. This company then used a subcontractor. The
subcontractor and the medical transcription company got into a dispute and
the subcontractor threated to release all of the records they had been
responsible for transcribing on the web. b While HIPPA laws are in place to
make these practices illegal, the subcontractor was not a citizen, nor residing
in the United States. It does however require any medical organization dealing
with patient records and considering outsourcing to ensure any contract they
have requires the other parts to use “appropriate safeguards to prevent use or
disclosure of the information other than as allowed by the contract.” This
means that when considering outsourcing an organization must have a strong
legal team and a very black and white contract. This means being aware of the
laws in other countries as well. The contract should be able to hold up in both
countries’ courts, as jurisdiction can play a significant role in the outcome of
the case. Additionally, the physically farther away an outsourced operation is
from the parent organization, the harder it is to maintain control over daily
operations. There is no way to just stop in and check on operations, and you
have to operate on good faith that the contracted controls are in place and
being managed appropriately.
What do you think an organization’s duty or responsibility to protect the
privacy of its customers personal information should be? Explain.
United States Federal law requires that any organization that collects or
houses personal b b b b b b b b b b b b b information must tell you how it is collected, used,
shared, and protected. Additionally, it also limits how that information can be
sued. In truth, legally there is a patchwork of laws requiring a certain level of
privacy protection for customers, as more situations come up, the more laws
that get put in laced. The Federal Trade Commission is the man enforcer of
these laws, and they have been known to take this role extremely seriously.
For example, there was a case involving Google in 2012 in which they were
accused of misrepresenting their privacy policy. Google ended up having to
pay more than $22.5 million and change its policies/practices (Harrington,
2022). This shows that organizations have a social duty to protect all of the
data and information of its customers, as well as a legal obligation to.
Customer personal information is akin to intellectual property being loaned
out to the company in order for the customer and the organization to engage in
a business arrangement. If this property is stolen or mismanaged by the
organization, they have failed in their duties to the customer, the same way as
if a machine loaned to a company is mismanaged and ends up damaged. They
would owe the leasing company damages, and that becomes costly to the
organization.
References
Davino, M. (2004, March). Assessing privacy risks in outsourcing. Journal of
AHIMA (75) 3, 42-46.
Harrington, D. (2022, September 2). U.S. privacy laws: The complete guide.
Retrieved on December 8th, 2022 from https://www.varonis.com/blog/us-
privacy-laws