Is that statement by Iron Mountain's attorney believable, though?
If cage or server access was shared between Iron Mountain customers, how can Iron Mountain not have a record of what's in what cage or what's on what server?
If Iron Mountain customers like OSS were free to add or remove things without Iron Mountain's knowledge, then their (OSS's) access would've been limited to cages or servers dedicated to their (OSS's) own clients' data. Allowing an OSS ex-employee the same access they previously would've had should be a non-issue, from Iron Mountain's perspective.
What iron mountain does know is which drives are owned by oss. What they don't know is which drives owned by oss have the station's data on them. Hopefully nothing is comingled and drives are dedicated to a customer. Seemingly only oss knows and they went bankrupt so who knows what shape the records are in.
It's also possible IM serves a scaleable storage system that mingles data across customers. If you S3 they don't isolate clients per physical drive, they store blocks pretty randomly across millions of drives.
Plus the case above: OSS could have had another company storing sensitive medical records, and this hands over those drives to a PBS station.
If cage or server access was shared between Iron Mountain customers, how can Iron Mountain not have a record of what's in what cage or what's on what server?
If Iron Mountain customers like OSS were free to add or remove things without Iron Mountain's knowledge, then their (OSS's) access would've been limited to cages or servers dedicated to their (OSS's) own clients' data. Allowing an OSS ex-employee the same access they previously would've had should be a non-issue, from Iron Mountain's perspective.