Don’t Store Client Payment Information

By on Apr 30, 2015

One of my more popular workshops is “Managing Errors and Omissions in a 24-7 World.” In this program, I highlight emerging technology solutions and the advantages and benefits, as well as the pitfalls, these solutions bring to managing errors and omissions within your agency organization.

One item I talk about is agency staff storing customer electronic payment information within the agency management system. This information could include credit and/or debit card numbers, card expiration date, and the CVC code (the 3 or 4 digit number on the back of the card). It also includes bank routing numbers and bank account numbers used to process ACH transactions.

Before you think “we do not do that” and delete this email, please don’t assume that your staff does not capture this information. Very often, agency owners have no idea what happens at the desktop.

I have been in multiple agencies over the last six months where I observed staff on the phone with clients making electronic payments on their behalf on the insurance company website. In many cases, they were writing down the credit card information on a yellow pad and then entering it into the insurance company payment processing page.

Some CSRs have told me that they capture this information as part of the client notes so they do not have to keep asking for the payment information.

While many agencies understand that they should not be capturing credit card information, it is a more common practice to scan and store checks received in payment for insurance premiums as part of the client file. These scanned checks are then attached to an activity note to verify the payment was received.

Your agency should not capture any client electronic payment information within your systems.

Period.

Forty-seven states, the District of Columbia, Guam, Puerto Rico, and the Virgin Islands have all enacted legislation that requires private entities to notify individuals of security breaches of information involving personally identifiable information (PII).

While there are slight variations within each state, most statutes identify personal information that requires notification if breached as:

“An individual’s first name or first initial and last name in conjunction with any one or more of the following data elements, 1) Social Security number; 2) driver’s license number; 3) or account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.”

Electronic payment information falls under this definition regardless of whether it is credit card/debit card information or bank account information. The bank routing number and bank account number contained on a check will be considered as part of the definition of “personal information” and be subject to the state data breach notification requirement.

The liability your agency is incurring as a result of this practice is substantial.

But Isn’t It Required…?

A common reason the agency is storing this payment information is that the “carriers require us to keep that information.”

Another common reason I’ve heard to keep copies of client checks is for EFT payment setups on carrier websites. The carriers say they don’t want customer banking information sent to them, so agencies are keeping a copy of the check in an activity in case there are questions down the road or the EFT doesn’t get set up properly by the carrier.

If this is your procedure, it appears the insurance companies have successfully transferred the additional liability because of a data breach from themselves to you their agencies.

My recommendations:

  • Make sure your staff understands that they should not be capturing in any form — in the management system or written down on yellow pads — any type of electronic payment information.
  • Do not scan checks and attach them to the client file. There is no need for any agency to keep this payment information.
  • Verify with every insurance company their actual requirements regarding retention of electronic payment information (including checks). Make sure to ask for this verification in writing from an officer of the insurance company.
  • Push back hard against any insurance company that says you are required to keep electronic payment information.

Storing client electronic information is simply bad business practice. Your organization cannot and should not take on the additional liability exposure if this personal information is breached.

How does your organization verify that staff does not store client electronic information?

10 Comments

  1. Hey Steve! Hope you are doing well. In addition to client credit card and checks, we also have vendors that now include their bank routing and account numbers on their invoices just in case we want to pay them via ACH. These documents are also scanned into our system rather than stored in a paper file. I thought it was kind of odd to have vendors place this information on all of their invoices, but that seems to be the trend. Thoughts on this?

    • Jeff, this is an interesting wrinkle. I do include links to an electronic payment process on my invoices, but never include bank account information. Just seems like a bad practice to me.

      If the invoices are paper-based and you are scanning them, I would recommend you use a black magic marker to block out the bank account information. If the invoice is a PDF then you can use the redact function to block out that information in the electronic version prior to attaching it within your system.

  2. We used to keep payment info in the client’s file but have stopped doing this because of the security issues. If we can’t enter the payment direct into the company’s payment site, we shred the payment information as soon as we can.

    If the payment info comes over the email or fax, we delete that information as soon as possible. Although I realize that electronic data is harder to “delete” than shredding a piece of paper!

    • Susan, I’m glad you no longer keep payment information on the client file. You are correct, it is harder to delete electronic data than shredding a piece of paper.

  3. “Don’t store Client Payments” How should we handle? We’ve always made payments for customers.

    • Hi Jim. Thanks for your comment.

      You have to decide for your organization if the additional liability you incur by handling a client’s electronic payment information is worth the additional risk you incur.

      I think it is a training process for both your staff and your clients. The whole purpose of electronic payment is for the client to be able to easily make online payments. It may be as simple as directing the client to the payment portal (likely on a carrier website) and walking them through the steps of making the payment on their own.

      I also believe that the agency should no longer rely on the insurance company payment processing services. It’s just one other reason why your clients go directly to the insurance company instead of through your agency. I wrote about this in a previous TechTip that’s located here: https://techtips.steveanderson.com/2014/09/18/it-is-time-to-update-your-payment-process/

  4. We do not accept cc payments period. If the company they are with accepts them, and now days most do, then we give them the number to call. When we do a transaction that involves scanning or faxing a check, we destroy the check after processing. We have no records in TAM of any of our clients’ cc information or banking information.

  5. Interesting you should post this today. I did a presentation on Data Breach this morning at a networking meeting. I definitely agree with your assessment of the problem and that avoidance is the ideal. However, we’ve decided that avoiding the risk is not something that we can do practically and so have purchased Data Breach coverage.

  6. Steve, with a few workflow changes, our office can comply for the most part. However, our Benefits Department is required to send a copy of an insured’s voided check along with the application. We send this to the carrier via automated faxing software. We can choose to not “attach” the fax to the client file, but doesn’t the faxing software maintain a copy and that is on our backup as well?

    I agree with Edward that although we can give it a good try, I’m not sure we can do business in some cases. So it’s best to make sure that we have the proper coverage.

    • Vicki, I agree that there is only so much you can reasonably do and still be able to conduct business. I think it would be an easy step to not attach the fax to the client file. You may also be able to check settings on your faxing software to see if you can set the software to not store the image that was faxed. But, at some point you do actually have to get some business done. For me, the issue is taking all of the reasonable steps you can take to protect information. And, as you suggest, make sure you have proper coverage in place if you need it.

Submit a Comment

Your email address will not be published. Required fields are marked *