Dear Diary, Meet Discovery

Erin Eilers • August 7, 2026

Dr. Fauci and the Myth of Workplace Cyber Privacy


There are certain things that should never meet your work computer.


Your résumé for the job you’re secretly applying for.


Your highly opinionated group chat.


Your side hustle spreadsheets.


And, apparently, your diary.


Recently, more than 1,000 pages of Dr. Anthony Fauci’s pandemic-era journal entries were released by Sen. Rand Paul as part of a congressional investigation. According to Health and Human Services Secretary Robert F. Kennedy Jr., the entries had been retrieved from government computer servers. News reports also confirmed that the entries were created on a government computer.


Regardless of what you think about Fauci, COVID, Congress, Rand Paul, or any of the other topics capable of ruining Thanksgiving dinner, there is a terrific HR lesson buried in this story:


Your work computer is not your personal diary.


Neither is your work email.


Neither is Teams.


Neither is Slack.


Neither is the company Google Drive.


And while we’re here, the company Wi-Fi probably isn't the ideal place to conduct activities you'd prefer your employer never know about either.


“But It Was Personal.”


That’s where employees often get confused.


Something can be personal in subject matter without necessarily being private from the organization whose technology you used to create, transmit, or store it.


Employers commonly have policies notifying employees that company systems may be monitored, accessed, reviewed, retained, or audited. Exactly what an employer may legally access depends on the circumstances, the employer’s policies, applicable state and federal laws, and the systems involved.


But from a practical standpoint, employees should operate under a very simple rule:


If you would be horrified to see it enlarged on a screen in a conference room, don't put it on your work computer.


That rule has served people well for decades.


Delete Does Not Mean Gone


Here’s another popular workplace technology myth:


“I deleted it.”


Wonderful.


The computer may have other plans.


Emails, documents, messages, internet activity, cloud files, backups, archived data, retention systems and other electronic records can survive long after someone clicks Delete.


And once litigation, a government investigation, a subpoena, a records request, or an internal investigation enters the picture, electronic information can become very interesting very quickly.


In HR, we have another name for some of that information:


Evidence.


Or, as I like to call it:


Dear Diary, meet Discovery.


Employees Aren't the Only Ones Who Need This Reminder


Employers have some homework here too.


If your organization expects employees to have limited privacy when using company technology, say so clearly.


Your handbook and technology policies should address things like:


  • Company ownership and permitted use of devices and systems
  • Whether employees may use company technology for limited personal purposes
  • Email and messaging
  • Internet usage
  • Monitoring
  • Passwords and system access
  • Confidential and proprietary information
  • Cybersecurity expectations
  • Artificial intelligence tools
  • File storage
  • Remote work
  • Personal devices used for company business
  • Employees' expectations of privacy


And please don't dust off the technology policy someone wrote in 2014 and assume you're covered.


In 2014, ChatGPT didn't exist, TikTok didn't exist, remote work wasn't commonplace, ransomware hadn't become an everyday business concern, and half your employees weren't conducting business from something they unlock with their face.


Technology changed.


Your policies should have changed with it.


Managers: You Aren't Exempt


I would also caution executives and managers against believing workplace technology rules are simply something we impose on employees.


They're not.


Leaders often have access to the most sensitive information in the entire organization—compensation, employee complaints, medical information, investigations, financial data, strategy, passwords, customer information and confidential conversations.


That makes sloppy technology habits at the executive level particularly dangerous.


Don't text confidential employee information because it's convenient.


Don't forward company documents to your personal email so you can “work on them later.”


Don't store employee records in random folders.


Don't share passwords.


And perhaps most importantly after our latest national example:


Don't keep your diary on the company server.


The Bottom Line


Workplace technology is an incredibly useful tool.


It is not a vault for your deepest personal thoughts.


Employees should understand that when they use an employer's computer, email, network, messaging platform or cloud storage, their activity may not carry the same expectation of privacy they have on their own devices.


Employers, meanwhile, should establish reasonable technology and monitoring policies, communicate those expectations clearly, apply them consistently, and make sure their actual practices comply with the law.


The lesson doesn't require taking a political side.


It requires remembering something HR professionals have been saying since somebody first discovered employees could send jokes through the office email system:


Don't put anything on a work computer that you wouldn't want your boss, HR, IT, an attorney (or apparently Congress) to read someday.


Because the internet remembers.


Servers remember.


Backups remember.


And sometimes, so does your diary.


I'm Erin Eilers with The Eilers HR Group: helping businesses Calm the Chaos and protect themselves before “private” becomes Exhibit A.


By Erin Eilers July 17, 2026
It's About Control, Not the Contract
By Erin Eilers July 17, 2026
Why Every Supervisor Needs a Leave Playbook
By Erin Eilers July 5, 2026
You can’t brag about “open communication” while protecting the office tyrant.