Tides v. the Boeing Co.Tides v. the Boeing Co.
OPINION
We hold today that by its express terms, the whistleblower provision of the Sarbanes-Oxley Act,
I. BACKGROUND 1
In January 2007, plaintiffs Matthew Neumann and Nicholas Tides began working as auditors in Boeing’s IT Sarbanes-Oxley (“SOX”) Audit group. Tides worked in St. Louis, and Neumann was based in Seattle. At the time, the IT SOX Audit group was one of two departments housed within Boeing’s Corporate Audit organization. It was charged with helping the company comply with SOX’s requirement that it annually assess the effectiveness of its internal controls and procedures for financial reporting.
See
Tides and Neumann claim that tensions were high in the IT SOX Audit group upon their arrival in January 2007 because management feared that Deloitte & Touche might declare a “material weakness” in the company’s internal controls. They allege that managers pressured IT SOX auditors to rate Boeing’s internal controls as “effective” and fostered a generally hostile work environment. Beginning in February 2007, Tides and Neumann began separately expressing concerns about this perceived pressure and several deficiencies in Boeing’s auditing practices that they viewed as potential violations of SOX. Their primary concern related to Boeing’s use of PriceWaterhouseCoopers contractors in the internal auditing of the company’s IT controls. Tides and Neumann repeatedly complained to management about the practice of giving the contractors managerial authority over Boeing employees, as well as the involvement of the contractors in both the design and audit of Boeing’s internal controls. They also expressed concerns about the integrity of data stored in the software system Boeing used to record its IT SOX audit results. Both auditors believed that the system permitted unauthorized users to alter the ratings given to the company’s internal controls.
At some point in late April 2007, Andrea James, a reporter with the
Seattle PostIntelligencer,
left messages on Tides’ and Neumann’s work phones asking each of them to speak with her about an article she was writing on Boeing’s compliance with SOX. Neither Tides nor Neumann immediately responded to her requests, hoping instead to resolve their concerns internally with the help of management and human resources. At the time, both were aware that Boeing had in place a policy that restricted the release of company information to the news media. Boeing’s policy, PRO-3439, required employees to refer “[i]nquiries of any kind from the news media” to the communications
In late May 2007, James contacted Neumann again, this time showing up uninvited at his home with another Post-Intelligencer reporter. Neumann agreed to speak with them about Boeing’s compliance with SOX. He described the pressure he felt to render positive audit results and detailed a recent meeting where he and other IT SOX auditors expressed concerns over the role of PriceWaterhouseCoopers contractors in audits of Boeing’s internal controls. James asked Neumann if he knew of any examples of significant deficiencies in Boeing’s internal controls going unreported or of any auditors being instructed to change their findings, but he said he didn’t know of any specifics. Several days after their meeting, James emailed Neumann an excerpt of a draft of her article. Neumann responded that the excerpt looked good and sent James the text of an email that he and other IT SOX auditors recently received from a manager. The manager’s email reminded employees that Boeing policy prohibited the release of information to the media without prior approval from the communications department.
Tides contacted James in July 2007 after receiving what he viewed as a negative and unsubstantiated performance evaluation for the second quarter of the year. He forwarded her a series of work-related emails from his Boeing computer. Most of the emails documented the concerns he previously raised with management and human resources regarding perceived problems with the IT SOX Audit group’s auditing practices. Tides also forwarded James several internal Boeing documents, including copies of the company’s policies governing contract labor.
On July 17, 2007, the Post-Intelligencer published the article “Computer security faults put Boeing at risk,” co-authored by James. The article reported that “[f]or the past three years, The Boeing Co. has failed, in both internal and external audits, to prove it can properly protect its computer systems against manipulation, theft and fraud.” It detailed, among other things, a threatening company culture perceived by employees involved in SOX compliance, a record of poor internal audit results indicating that many of the company’s computer system controls were failing, and an internal allegation that audit results were being manipulated.
At some point prior to the publication of the Post-Intelligencer article, Boeing caught on that several employees were likely releasing company information to the media. As a result, it authorized an investigation that included the monitoring of both Tides’ and Neumann’s work computers and email accounts. The investigation revealed that the two auditors were communicating with James without permission. Two months after the publication of the Post-Intelligencer article, Tides and Neumann were interviewed separately by HR investigators about their communications with James. Both admitted to speaking with her about Boeing’s auditing practices and to providing her with company documents. After the interviews, Boeing suspended Tides and Neumann indefinitely. Their cases were then referred to an Employee Corrective Action Review Board, a committee composed of five voting members and one non-voting ethics advisor to evaluate charges of employee misconduct. After reviewing the applicable Boeing policies and the investigative reports detailing the two auditors’ contacts with the media, the Board unanimously voted to terminate Tides and Neumann effective September 28, 2007 and October 1, 2007, respectively. Both were later informed in writing that:
It has been determined that you created an unacceptable liability for the Company. Specifically, you violated PRO-2227, Information Protection, by disclosing Boeing information 3 to non-Boeing persons without following appropriate procedures, obtaining necessary approvals and putting in place appropriate safeguards. In addition, you violated PRO-3439 by not referring inquiries from the news media to Communications, and by releasing information without approval in accordance with the requirements of said PRO. Your actions are aggravated by the fact that the information had an adverse effect on the Company’s reputation and its relations with its employees, customers, shareholders, suppliers and other important constituents, causing significant liability. The Company deems your behavior in this incident as unacceptable and in violation of its expectations as defined in PRO-1909.
Following their terminations, Neumann and Tides filed SOX whistleblower complaints with the Occupation Safety and Health Administration
4
on December 21, 2007 and December 26, 2007, respectively. After over nine months of delay, the agency issued letters acknowledging Tides and Neumann’s right to proceed de novo in federal court.
5
Tides and Neumann filed separate complaints in district court, alleging that they were terminated in violation of
II. STANDARD OF REVIEW
We review the district court’s grant of summary judgment de novo.
Evanston Ins. Co. v. OEA Inc.,
III. DISCUSSION
SOX’s whistleblower provision,
The issue in this case comes down to whether the plaintiffs’ disclosures to the
Post-Intelligencer
were protected under
(a) No [publicly-traded company] ... may discharge, demote, suspend, threaten, harass, or in any other manner discriminate against an employee in the terms and conditions of employment because of any lawful act done by the employee—
(1) to provide information, cause information to be provided, or otherwise assist in an investigation regarding any conduct which the employee reasonably believes constitutes a violation of section 1341 [mail fraud], 1343 [wire fraud], 1344 [bank fraud], or 1348 [securities fraud], any rule or regulation of the Securities and Exchange Commission, or any provision of Federal law relating to fraud against shareholders, when the information or assistance is provided to or the investigation is conducted by—
(A) a Federal regulatory or law enforcement agency;
(B) any Member of Congress or any committee of Congress; or
(C) a person with supervisory authority over the employee (or such other person working for the employer who has the authority to investigate, discover, or terminate misconduct).
The plaintiffs contend that their disclosures of perceived SOX violations to the
Post-Intelligencer
were protected under
When Congress wants to protect the disclosure of any information to any entity, it knows how to do so. The Whistleblower Protection Act prohibits retaliation against government employees and job applicants for
“any
disclosure of information” that the employee or applicant reasonably believes constitutes “a violation of any law, rule, or regulation, or ... gross mismanagement, a gross waste of funds, an abuse of authority, or a substantial and specific danger to public health or safety” as long as “such disclosure is not specifically prohibited by law and if such information is not specifically required by Executive order to be kept secret in the interest of national defense or the conduct of foreign affairs.”
Although we need not resort to the legislative history of
In sum, the plain meaning of the statutory language excludes the expansive interpretation advanced by the plaintiffs. We therefore hold that
AFFIRMED.
Notes
. Because Tides and Neumann appeal from an order granting Boeing summary judgment, we set forth the relevant facts in the light most favorable to them.
See Chuang v. Univ. of Cal. Davis, Bd. of Tr.,
. An information technology (“IT”) control is a policy or procedure implemented by a company to ensure the confidentiality and integrity of its IT functions, such as a procedure requiring the testing and approval of software before installation on a company computer.
. PRO-2227 defines "Boeing information” as "all non-public information that is owned by Boeing.” Under the policy, "[a]ll Boeing information is presumed to have value and be proprietary, confidential, and/or trade secret information.”
. The Secretary of Labor has delegated responsibility for receiving and investigating whistleblower complaints to OSHA, an agency within the Department of Labor.
See Day v. Staples,
. If the Secretary of Labor does not issue a final decision within 180 days of the filing of the complaint and there is no showing that such delay is due to the bad faith of the claimant, then the claimant may seek de novo review in district court, which will have jurisdiction over the action regardless of the amount in controversy.
. Amicus curiae the National Whistleblowers Center argues that disclosures to the media may also be protected under