This will be a presentation from a former paralegal that hopped over to the cyberspace. As a plaintiffs litigation paralegal, I witnessed so many wrong things surrounding the lack of confidentiality surrounding client’s PHI and PII. I will include how I managed to obtain medical records without a HIPAA or proper documentation in place via fax, how I received a death certificate without proper documentation (full SSN’s are located on Death certificates), how Social Security releases SSN’s of a deceased person on a quarterly basis; thus, opening the gap for stolen identities of a deceased person. I will also include a personal story of how when we send call centers overseas, they do not know about HIPAA laws here in the US and how I could have walked out of a storage facility with a box full of many other peoples medical records. This storage facility houses medical records, but the problem was from a well-known corporate health company (will not disclose the name). I will also discuss how not performing proper due diligence can be costly with legal ramifications. Trust but verify. So, I was assigned a case that allegedly people worked up. When I was cross referencing facts, they had signed up the brother of the deceased claimant, spoke to the brother, provided case information. The problem with this is the deceased claimant had a wife at death and the brother was not the rightful legal person to talk to. I had to OSINT the surviving spouse, have her provide her marriage license to prove she is who she confirmed she is, provide the Last Will & Testament & her ID, among other docs that had to be signed. I will present the issue that could’ve happened for not proper due diligence.