Preventing Employee Identity Fraud: Policy and Practice Issues for Employers
Gerald E. Calvasina, Richard V. Calvasina, Eugene J. Calvasina · Journal of Legal Ethical and Regulatory Issues · 2007
ABSTRACT According to a 2002 report by TransUnion, one of U.S.'s three credit bureaus, No. 1 underlying source of is of employer records. Human Resource departments are a prime target for this type of crime someone steals a wallet, they get one name, one SSN - when they steal personnel files, they get away with 10, maybe 100 names and numbers (Wells, 2002, p. 33). This paper will examine potential legal and employee relations consequences associated with of employer and fraud, what employers can do to prevent of employer records, and what employers can do to minimize negative consequences associated with their being utilized in fraud. INTRODUCTION workplace is source of most used in and financial fraud (Payroll Managers Report, 2006). In May of 2006, United States Department of Veterans Affairs (VA) reported that identifying information for up to 26.5 million veterans was part of take in a burglary of one of it's employees homes. The stolen data was stored in a laptop computer and external hard drive employee had taken home. The employee, a data analyst with agency, was not authorized to take data home and his behavior was in violation of VA policies (FirstGov, 2006). The (VA) incident is largest and one of latest in a long list of recent security breaches to make headlines. The incident also highlights role of employer in this regard. Wells, citing a 2002 report by TransUnion, one of U.S.'s three credit bureaus, reported that the No. 1 underlying source of is of employer records (Wells, 2002, p. 33). Human Resource (HR) departments are particularly rich sources of information that can be utilized in fraud. Personnel files that include payroll, benefit, and tax data, contain pieces of information that can facilitate thief s objective and often are secured under auspices of HR function. HR is a big target... When someone steals a wallet, they get one name, one SSN. When they steal personnel files, they get away with 10, maybe 100 names and numbers (Wells, 2002, p 33). In this paper, potential legal and employee relations consequences associated with of employer and are examined. In addition, what employers can do to prevent of employer records, and what employers can do to minimize negative consequences associated with their being utilized in are presented. BACKGROUND ON THE PROBLEM The genesis of problems associated with and can be traced to passage of Social security Act in 1936. Initially, an individual's Social security Number (SSN) was to be utilized to track workers' contributions to social security fund. Marc Rotenberg, in his statement and testimony before subcommittee on Commerce, Trade, and Consumer Protection Committee on Energy and Commerce in May of 2006 noted that public concern over potential abuse of SSN was so high that first regulation issued by new Social security Board declared that SSN was for exclusive use of Social security system (Rotenberg, 2006). Eventually, legislation was enacted that allowed SSN to be utilized for other purposes, including authorization granted to Internal Revenue Service to use SSNs as taxpayer identification numbers in 1961 (Rotenberg, 2006). Rotenberg further cited a U.S. Department of Health, Education & Welfare report prepared in association with enactment of Federal Privacy Act of 1974 that outlined many of concerns with use and misuse of Social security Number that show a striking resemblance to problems we face today. Although term identity theft was not yet in use... report that provided basis for comprehensive privacy legislation in 1974, described risks of a Standard Universal Identifier, how number was promoting invasive profiling, and that many of uses were clearly inconsistent with original purpose of 1936 Act (Rotenberg, 2006). …