The report, first obtained by the Associated Press and sent to members of Congress, cites “longstanding, systemic weaknesses” related to communications that started before Clinton’s appointment as secretary of State.
However, the report says that by the time Clinton took office in 2009, the standards for email security were “considerably more detailed and more sophisticated.” The department revised guidelines through 2011, according to the report, and “Secretary Clinton’s cybersecurity practices accordingly must be evaluated in light of these more comprehensive directives.”
In a statement, campaign spokesman Brian Fallon said that Clinton’s opponents “are sure to misrepresent this report for their own partisan purposes.”
“The report shows that problems with the State Department’s electronic recordkeeping systems were longstanding and that there was no precedent of someone in her position having a State Department email account until after the arrival of her successor,” Fallon said, adding that the report showed her use of a personal email account “was not unique.” It also shows her use of a personal email was known to officials within the Department and that there is no evidence of a successful hack of her server.
The review came after revelations last year that Clinton exclusively used a private email account and server while in office. The Federal Bureau of Investigation is separately probing whether any classified information crossed her server. The investigation has cast a shadow over her presidential campaign, though Clinton is close to clinching the delegates needed to win the Democratic presidential nomination.
The 78-page report says the department and its secretaries were “slow to recognize and to manage effectively the legal requirements and cybersecurity risks associated with electronic data communications, particularly as those risks pertain to its most senior leadership.”
Following the release of the audit, Mark Toner, a State Department spokesman, said the department is “”already working” to upgrade email and records systems, according to the Associated Press.
Among the violations cited was Clinton’s use of mobile devices to conduct official business on her personal account and private server. She did not seek approval from senior information officers, who would have denied the request because of security risks, the audit said.
The audit said Clinton falsely believed that, because her emails were being sent to State Department employees, they would automatically be preserved in the system. She should have printed and filed them, the report said. Because she did not do so, and surrender them upon leaving, she did not comply with the Federal Records Act. This also led to gaps in her email archives.
Clinton has been repeatedly asked about her use of the private server, which was set up at her home in Chappaqua, New York. She’s apologized for it and said she did not send anything marked classified at the time over email.
The report also detailed email practices of other secretaries of State, including the staff of Powell and Rice, from 2001 to 2008. The audit identified more than 90 employees who periodically used personal accounts to conduct official business. The report highlights one June 3, 2011 email to Clinton with the subject line “Google email hacking and woeful state of civilian technology.” The email, from a former director of policy planning read: “State’s technology is so antiquated that NO ONE uses a State-issued laptop and even high officials routinely end up using their home email accounts to be able to get their work done quickly and effectively.”
Republican National Committee Chairman Reince Priebus blasted Clinton on Twitter following release of the report, saying her “bad judgment” had “endangered” national security.




