Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Pennsylvania Companies Must Protect Employees’ Sensitive Data

By Bianca A. Roberto on June 14, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

Employers, and likely all businesses, now have a specific duty to safeguard their employees’ personal data that is stored on internet-based computer systems, according to a recent decision by the Supreme Court of Pennsylvania. Prior legislation only required companies to report potential or actual data breaches to the individuals or businesses whose information may have been, or was, compromised.

In Dittman v. Univ. of Pittsburgh Medical Center, the court held that employers have a duty to exercise reasonable care to protect their employees against an unreasonable risk of harm if the company collects and stores the employees’ data on internet-based computer systems. Further, this duty is independent of any contractual obligations between the employer and employee. The court reasoned that by collecting the data without appropriate security measures, UPMC created a foreseeable risk of a data breach. In other words, UPMC should have known a cyber-criminal might take advantage of its vulnerable computer system and steal the data.

The case involved the theft of social security numbers, dates of birth, tax information, addresses, salaries and bank account information of more than 62,000 current and former UPMC employees. UPMC gathered the sensitive information as a condition of employment. The employees sought money damages for losses due to the filing of fraudulent tax returns and for the increased and imminent risk of identity theft.

This ruling is important because the decision likely extends to any entity (not just employers) that collects and stores sensitive personal data. Additionally, defendants can no longer claim the criminal act of a third party as an intervening act to shield them from liability. As such, this new decision will force companies to incur significant expenses to update their security protocols and will expose them to more risk and potential litigation.

Photo of Bianca A. Roberto Bianca A. Roberto

Bianca A. Roberto is a member of Stark & Stark’s Litigation, Bankruptcy & Creditors’ Rights, Employment, Beer & Spirits, and Business & Corporate Groups. Ms. Roberto concentrates her practice in all areas of civil and commercial litigation, including the counseling and representation of…

Bianca A. Roberto is a member of Stark & Stark’s Litigation, Bankruptcy & Creditors’ Rights, Employment, Beer & Spirits, and Business & Corporate Groups. Ms. Roberto concentrates her practice in all areas of civil and commercial litigation, including the counseling and representation of clients in estate litigation, business and commercial disputes, residential and commercial real property disputes, and employment matters.

Read more about Bianca A. RobertoEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Pennsylvania Law Monitor
  • Organization:
    Stark & Stark
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo