Tuesday, September 7, 2010

Cloud Computing and E-Discovery

This week, I'd like to talk about cloud computing and electronic discovery.
What is 'cloud computing'?

To understand the concept, first think of the traditional way of storing information on a computer. When you save a document, you can save it on your computer's hard drive, which is located inside the machine.
If you are on a network, you can also save the document remotely, usually on a bigger hard drive you can access over your network.

In each case, you know where the document is physically located: either on the hard drive inside your computer, or on a larger hard drive in another computer on your network.

Turning to cloud computing, it is possible you are already familiar with the basic concept, if you use internet-based email:
When you send and receive email using an online email account, you don't know where those emails are actually located. They could be sitting on a server right next to you, or on a server thousands of miles away, around the world. But you don't really care. What matters to you is that you can send and receive email, and read emails you have saved in your archive.

Cloud computing is very similar:
You store data on a network, but you don't know where that data is actually located, and you don't really care.
The 'cloud' metaphor gives you the mental image of sticking data into a cloud in the sky, and pulling data back out of it. Once the data is in the cloud, you can't see where it is, and you don't know if there is one copy, or many copies, or if the data is moving from computer to computer. Again, though, you don't care, as long as you can pull the data back out of the cloud. And, of course, as long as the data is secure while it is in the cloud.

Another useful analogy is to compare cloud computing to electricity service.
Cloud computing users may pay for the amount of data they send into, and bring out of, the cloud, just like the way consumers of electricity pay for the amount of electricity they bring into their buildings, to power their appliances and lights.

What are the advantages of cloud computing?
Lower cost and more flexibility.
To store data, a user doesn't need to buy a lot of hard drives, which may be eventually be idle and empty if the user's storage needs change. The user also doesn't need to maintain a network to store and access data.

What are some of the e-discovery challenges related to cloud computing?

One is the concept of possession and control of data.
The end user is almost always in control of the data, as he or she can decide how and when to put it on the cloud, or to remove it from the cloud.
But who is in possession of the data? The end user, or the entity which owns the storage space in the cloud where the data resides?

Another question relates to preservation of attorney-client privileges when storing data in the cloud. Are these privileges preserved?

Document preservation obligations are another concern. If you store your data on the cloud, and you are required to preserve, and not destroy, certain data, can you make sure that the data remains intact?

Privacy questions may also arise. The European Union's privacy standards are much more strict than those in the United States. Where is data being stored? Is it subject to the jurisdiction and the laws of the EU? Of the US? Or of another location?

These are some of the interesting electronic discovery questions relating to cloud computing, and they deserve their own discussions. For the moment, I hope I have introduced the concept of cloud computing, and some of the e-discovery issues related to it.

Monday, August 16, 2010

HIPAA HITECH - E-Discovery and the Healthcare Industry

This week, I'd like to talk about HIPAA HITECH.


What is HIPAA HITECH?


Well, HIPAA is a 1996 federal law on health insurance, and it stands for:


Health
Insurance
Portability and
Accountability
Act


In 2009, HIPPA was amened to add the HITECH Act. This, in turn, stands for:


Health
Information
Technology for
Economic and
Clinical
Health
Act


It's the 'Information Technology' of HITECH that hints at the law's purpose. According to the U.S. Department of Health and Human Services (HHS), HITECH is intended "to promote the adoption and meaningful use of health information technology." HITECH covers security and privacy issues when a person's health information is transmitted electronically.


HIPAA HITECH brings the world of electronic discovery to the world of health care in the form of "electronic health records" and how these records are handled.


HIPAA HITECH is complicated, and has many aspects. I'd like to touch on just a few, this week:

  • The law extended privacy protections to 'business associates' of 'covered entities'. Basically, health information has to be kept private not only by health care providers, but also by their business associates.
  • The law also has new breach notification requirements. If health information is released to the outside world, notification must be made, as per new regulations of HHS (which were required under the new law).
  • Another significant change in the law includes new rules on how to account for disclosures of a person's health information.

These changes are just a few of the changes under HIPAA HITECH (although they are some of the more significant ones). In the months to come, I plan to discuss more, and more detailed, aspects of HIPAA HITECH.

Thursday, July 29, 2010

E-Discovery basics: The Sedona Conference

This week on Discovering E Discovery, I'd like to talk about the Sedona Conference.

The Sedona Conference is a research and educational institute based in Sedona, Arizona. The Conference strives to improve law and policy in the areas of antitrust law, complex litigation and intellectual property rights.

The Sedona Conference's first Working Group is called 'Electronic Document Retention and Production', and it deals with the subject of e-discovery. Starting in 2002, a lot of very smart people have met together to talk about current issues in, and challenges to, the world of electronic discovery.

Working Group 1 released its first publication in 2003, and it was cited by Judge Scheindlin in the Zubulake cases.

The Sedona Conference's website can be found here. The documents published by Working Group 1 are found here. They are a very valuable resource for e-discovery professionals.

Everyone who works in electronic discovery should be familiar with the Sedona conference, and its Working Group 1!

(A short post this week, but Discovering E Discovery is in a brief summer hiatus.)