Employers MyEnroll360 Security

Personal Email and Work Data Don't Mix

Sending a work document to a personal email account can move sensitive information outside of an employer’s security protections.

5 min read By BAS Knowledge Team
Illustration of a laptop displaying a security shield and padlock, representing the risk of moving work data to personal email or storage

It can seem harmless. An employee needs to finish a project at home, so they email a spreadsheet to their personal account. Someone wants easier access to a document, so they save it to a personal cloud storage account. Another employee sends a file to a personal email address so they can print it from a home computer.

These shortcuts may be convenient, but they can create significant privacy and security risks.

Employers establish security controls around company email, systems, devices, and approved storage locations for a reason. When employees move company information outside those environments, the organization’s security protections may no longer apply.

What Information Is at Risk?

HR and benefits departments routinely work with information that should not be transferred to personal accounts or systems. This may include Social Security numbers, dates of birth, addresses, payroll information, banking information, benefit elections, dependent information, medical or health plan information, and other personally identifiable information (PII) or protected health information (PHI).

The risk is not limited to employee information. Contracts, financial records, internal reports, customer information, business plans, passwords, and other confidential company information may also require protection.

Even a document that appears routine can contain information that should remain within company-controlled systems.

Why Personal Accounts Create a Security Problem

Company systems typically have security controls that an employee’s personal email or cloud storage account may not have. Organizations may use access controls, multi-factor authentication, encryption, monitoring, retention policies, data backup, and other safeguards to protect company information.

Once an employee sends a file to a personal account, the employer may lose control over who can access it, where it is stored, how long it is retained, whether additional copies are created, and whether it is ultimately deleted.

Personal accounts may also be shared with family members or accessible from multiple personal devices. Files may automatically synchronize to phones, tablets, computers, or cloud backup services without the employee realizing how many copies have been created.

A single email sent for convenience can therefore result in company information being stored in several places outside the employer’s control.

PHI Requires Additional Attention

For employers and organizations subject to HIPAA, moving electronic PHI outside approved systems can present additional concerns.

The HIPAA Security Rule requires regulated entities to use appropriate administrative, physical, and technical safeguards to protect electronic PHI. This includes protecting against unauthorized access and reasonably anticipated threats and ensuring that workforce members comply with applicable security requirements.

Cloud storage also requires careful consideration. When a HIPAA-regulated entity uses a cloud service provider to create, receive, maintain, or transmit electronic PHI on its behalf, HIPAA requirements may apply to that relationship, including requirements concerning business associate agreements.

An employee should therefore never assume that a personal email account, personal file-sharing application, or personal cloud storage service is an acceptable place to store PHI simply because the service is password protected.

Working From Home Doesn’t Change the Rules

Remote and hybrid work can make personal email especially tempting.

An employee who cannot easily access a document from home may think the quickest solution is to email it to a personal account. But working remotely does not eliminate the employer’s privacy and security requirements.

Employees should use company-approved methods for accessing files and systems remotely. If those methods are unavailable or an employee cannot complete a task without transferring information to a personal account or device, the employee should contact the appropriate internal resource rather than create a workaround.

Convenience should not override security procedures.

Don’t Forget About Personal Cloud Storage

Personal cloud storage can create the same concerns as personal email.

Employees may be accustomed to using consumer applications to save and share personal files. That does not mean those applications are approved for company information.

Uploading a work document to a personal cloud account can place information outside the employer’s security environment and potentially outside its retention, deletion, access, and monitoring controls. The employee may also unintentionally create additional copies through automatic synchronization or backup features.

The same caution should apply to personal file-sharing applications and other unapproved online storage services.

What Employers Can Do

Employers should establish clear expectations about where employees may store and transmit company information. Policies should address the use of personal email, personal devices, cloud storage, file-sharing applications, and other unapproved services.

Employees should also understand that security policies apply regardless of where they are working.

Training can reinforce a simple rule: if company information needs to leave an approved system, employees should not create their own solution. They should stop and determine the approved way to access, transmit, or store the information.

Employers should also make sure employees know where to turn when approved technology creates an obstacle. Employees are more likely to find an unauthorized workaround when they do not know how to get help.

A Small Convenience Can Create a Large Risk

Sending a work document to a personal email account may save a few minutes, but it can also move sensitive information beyond the protections the employer put in place to safeguard it.

HR departments are entrusted with some of an organization’s most sensitive information. Keeping that information within approved systems is one of the simplest ways employees can help protect it.

Before forwarding a document to a personal account, uploading it to personal cloud storage, or transferring it to an unapproved device, employees should ask a simple question: Is this an approved way to handle company information?

If the answer is unclear, don’t send it.

Benefit Allocation Systems (BAS) provides online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.

MyEnroll360 integrates with major insurance carriers for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and others), and with leading payroll platforms for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and others).

This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.

Topics
MyEnroll360 Security Security Employers

Benefits Administration Updates

Receive Benefits Administration Updates from BAS

Practical compliance and administration guidance delivered directly to your inbox. Unsubscribe anytime.