“Three may keep a secret, if two of them are dead.” So wrote Benjamin Franklin in Poor Richard’s Almanack. Keeping a secret has never been easy, but telepressure and the blurring of work-life boundaries have compounded the difficulty. Recent surveys show that around two-thirds of data-breach incidents trace back to endpoints such as laptops and mobile devices. Work-from-anywhere (WFA) and work-from-home (WFH) arrangements have made corporate secrecy a much more difficult challenge. For many companies—particularly in creative or high-tech industries—however, maintaining secrecy is essential.
In this blog post, I highlight a few recent developments, some thoughts on how to address them, and a playbook for what to do when things go wrong.
Remote and hybrid work got a major boost during the pandemic. What had once been a privilege for senior executives became the norm, with most white-collar work going remote during COVID-19. Around 25% of paid workdays in the US now involve WFH. This has led to an uptick in both data breaches and litigation arising from them.
Here are a few recent cases that illustrate the importance of good data hygiene:
- TileBar v. Glazzio Tiles, No. 1:23-cv-01234 (E.D.N.Y. Apr. 5, 2024). Former TileBar employees, after shifting to remote roles and then to a competitor, downloaded and transferred confidential customer lists and pricing data from TileBar’s secure network to personal cloud storage and USB drives. The court denied defendants’ motion to dismiss, emphasizing the steps TileBar took—multi-factor authentication, dual-password protection, and handbook confidentiality policies—to safeguard its secrets.
- Key takeaway: take reasonable steps to safeguard trade secrets to enjoy DTSA protection.
- DraftKings Inc. v. Hermalyn, No. 1:23-cv-11223 (D. Mass. Jan. 12, 2024). A former DraftKings executive allegedly misappropriated over eighteen proprietary DraftKings documents by transferring them—using Slack, AirDrop, and other collaboration tools—to his personal devices after moving to a new employer. The decision underscores the perils of unsupervised cloud-based file sharing in hybrid environments.
- Key takeaway: restrict transfer to personal devices to reduce trade-secret misappropriation risk.
- Legend Biotech USA Inc. v. Liu, Case No. 2:23-cv-02965-BRM-LDW (D.N.J. Feb. 20, 2024). An employee emailed Legend Biotech’s confidential protocols and manufacturing data to his personal Gmail account during a period of remote work, then refused to return or confirm deletion of those files after termination. The court ordered forensic inspection of all his devices and accounts to locate any residual copies and granted a preliminary injunction.
- Key takeaway: implement robust WFH or WFA monitoring capabilities to reduce -secret misappropriation risk.
- Millenium Grp. of Delaware, Inc. v. Mikkola, No. 3:2023-cv-03081 (D.N.J. Apr. 15, 2024). A remote employee based in Texas accessed and copied Millenium’s New Jersey–based client lists via external storage devices after his termination. The court held that New Jersey courts had personal jurisdiction over the defendant and refused to dismiss the case. The court noted that the intentionally tortious conduct was aimed at the forum
- Key takeaway: block data transfers during post-employment transition.
- MGA Home Healthcare Colorado, LLC v. Thun, No. 1:22-cv-01011 (D. Colo. Sept. 28, 2023). MGA Home Healthcare had a bring-your-own-device (BYOD) policy. While working remotely, an employee downloaded its confidential patient-care manuals and scheduling software onto his personal cellphone. The court denied his motion to dismiss, finding that MGA Home Healthcare’s internal network protections and explicit post-termination confidentiality clauses were “reasonable measures” under the Defend Trade Secrets Act (DTSA).
- Key takeaway: avoid BYOD wherever possible. If unavoidable, use MDM/MAM enrollment, encryption, attestation, logging, and prohibitions on personal-cloud syncing.
What employers can do about confidentiality breach risks:
- Confidentiality Clauses. Employers should ensure that they have robust “work-from-anywhere” confidentiality clauses. These clauses should contain restrictions on device-network security, use in public places, and placement of the employer’s confidential information onto personal devices, as well as immediate breach notification requirements. Employers should avoid vague or overly broad terms that courts may be unwilling to enforce. “Best efforts” or “endeavors” clauses or references to “reasonably secure networks” are unlikely to persuade courts.
- Internal Policies and Employee Training. Data training is now routine at many employers. Much of the focus, however, is on general data hygiene and not directed toward risks inherent in hybrid or remote work. Employers should update their handbooks and training materials to account for such risks. This should include language explicitly prohibiting personal device transfers and mandating return of confidential information.
- Tech Controls & Audit Trails. While contract clauses are necessary, they aren’t sufficient. Employers should have tech controls in place with end-to-end encryption, zero-trust architectures, and DLP solutions. While there are real productivity benefits to work-from-anywhere solutions, they should be balanced with privacy and data security.
- Incident Response for Hybrid Breaches. Even the most foolproof plan may be vulnerable to breaches. Employers should have a plan in place for rapid response in the event of a network breach. Corporate legal and IT teams should coordinate on forensic preservation, incident diagnostic and any follow-up legal steps. These may include quick actions for injunctive relief and, if any client data is implicated, legally-required data breach notifications. Counsel should be looped in early to preserve privilege.
- LLM Use Restrictions. Employee upload of confidential information to LLMs is a large and growing risk. Such models are unlikely to be secure. Employers should categorically restrict upload of employer confidential information to such platforms without express approval.
Conclusion
While there have been some high-profile return-to-office announcements, hybrid and WFH arrangements are here to stay. Employers should plan accordingly and take reasonable steps to safeguard confidential information. This is particularly true with new AI technologies (more on that in a future post!). While secret-keeping is indeed an imperfect art form, employers must stay one step ahead.
Disclaimer: This blog is for informational purposes only and does not constitute legal advice. Reading or interacting with this content does not create an attorney–client relationship. You should consult a qualified attorney for advice regarding your specific situation. Mehaffy, PLLC disclaims all liability for actions taken or not taken based on this blog.
