Business

What Fauci’s diary leak should remind employees about privacy at work

Last month, Anthony Fauci was subpoenaed by Republican Senator Rand Paul regarding the origins of COVID-19 and his broader pandemic policy oversight. 

Paul has disagreed publicly over the origins of the virus and accused Fauci of a cover-up as the pandemic ensued. Following Fauci’s departure from his position as the director of the National Institute of Allergy and Infectious Diseases in 2022, Paul remained committed to conducting an “investigation into the origins of COVID-19 and risky taxpayer-funded life sciences research.” 

Now, at the center of Paul’s argument is Fauci’s pandemic-era diary. Paul released more than 1,000 pages which revealed what Fauci journaled about during the height of the coronavirus pandemic. It included entries about his newfound fame and an accidental butt-dial to Barbra Streisand, layered between tallies of COVID-19 cases and deaths and contemplations about the pandemic’s origins. 

Fauci’s entries serve as a reminder to employees: never treat a work account or device like a personal one.

“If you’re going to keep anything personal, you don’t keep it on a work computer, a work system, or a work device in any way,” says Bryan Sullivan, partner at Early Sullivan Wright Gizer & McRae LLP. “The company or the employer owns that, whether it’s the U.S. government or not. You have no privacy when it comes to using work technology.”

Fauci saved his personal entries on government servers. After parsing through various servers, Health and Human Services Secretary Robert F. Kennedy Jr. said on Fox News that he provided the records to the committee. 

Matthew Tokson, a professor at the University of Utah’s S.J. Quinney College of Law, says there is a lesson to be learned from Fauci’s diary debacle. “Don’t write anything there that if it would become public, would embarrass you,” he says.

“Any personal information that is shared on a work email, for example, can be produced during the discovery process if an employer is involved in any kind of litigation,” Tokson says.

While employees may cite concerns about privacy, companies often search devices when investigating instances like workplace harassment and racial discrimination. In employment litigation or internal investigations, electronic discovery includes the search of devices, with subpoenas being the standard legal mechanism used to obtain data the employer cannot directly access. 

Tokson points out that work-related documents on a private device, or work-related information from a private email account could be subject to subpoena. “Email is the most common context,” Tokson says. “If you’re on your work email even from your own home devices—which I know I am and other people are—that’s likely going to be subject to discovery and litigation and come out in subpoena.” 

While courts try to limit device search to some degree through narrowed search terms or date ranges, the protocols tend to vary. Tokson notes that information unrelated to work would generally be outside the scope of subpoenas, regardless of device — but that also varies by case. 

“If you have documents on your work computer but they’re not [work-related], those are things that are protected,” Tokson says. “But if it’s work-related in whatever way, then that’s the stuff that will be out of your hands.”

Laws about what employers can and can’t do also vary by state.

While the federal Electronic Communications Privacy Act permits broad monitoring of company-issued devices under exceptions, company electronic monitoring policies can vary state by state. In Connecticut, Delaware and New York, for instance, employers have to provide written notice before monitoring employee emails, internet use or phone calls. In California, where there are also notice obligations, a combination of state labor codes and court ruling determine how companies can monitor employee devices. Similarly, when it comes to subpoenas for those devices, courts don’t apply one clear set of rules, either. But Sullivan says it’s a “universal rule” that “employees have no right of privacy” when it comes to sharing information on company devices and servers.

In the case that an employer is based in one state and the employee another, it’s typically up to the court to decide which state law to abide by. The rules become murkier when thinking about personal devices used for work, or if, say, a company pays for a phone bill but doesn’t own the device.

“That gets into more of a gray area,” Sullivan says. “But, the bottom line is, if you’re using your personal device for work, to the extent that it overlaps, your work will have a right to inspect that device.” In other words, if you have a work email and personal email on one phone, an employer could have the right to inspect your phone for the work email but not the personal email. 

Sullivan also urges employees to actually read the employee handbook, which typically contains technology policies—including whether or not employees grant the company the right to search their devices. He adds that most companies tend to include a provision allowing employers to inspect personal devices used for work. That’s why he also recommends people carry two phones, including one that is strictly for work-related purposes and the other for personal use. 

“Most people don’t even think about it or bat an eye,” Sullivan says. “They’ll save stuff in their own personal folder on their work computers, and use their work email for personal stuff just because it’s there and it’s easier. So, my guess is, [Fauci] probably didn’t even think about this.”

Fauci’s story fits in line with some high-profile cases in which people’s work-related private thoughts became public through varying means. Hillary Clinton’s use of a private email server became a years-long political and legal debate when those messages were subpoenaed. Sony Pictures executives spent months fixing the fallout of a 2014 cyberattack that made years of internal employee emails public on the internet.

For employees, the best practice is to keep personal information as private as possible — and certainly not on company servers or devices.

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Secret Link