Data Security and Privacy: How Do We Cope?

Size: px
Start display at page:

Download "Data Security and Privacy: How Do We Cope?"

Transcription

1 Data Security and Privacy: How Do We Cope? Kathleen Jones, Iowa State University Nancy Krogh University of Idaho AACRAO 2008/Session 243 March 27, 2008

2 You have no privacy. Get over it. Scott McNealy, Chairman and CEO Sun Microsystems 1999

3

4 Privacy and Security Define privacy and security Discuss our current security environment Suggest a framework for addressing issues Discuss the role of the registrar in privacy and security solutions This session will not address specific technological solutions. It s about the people.

5 Dimensions of Privacy Personal Privacy the right or interest for individuals to keep their personal information, communications, and facts concerning them out of the hands of unauthorized parties. Privacy Protection the responsibility or stewardship role of a 3 rd party that holds personal data concerning an individual that has been entrusted to them. Insights on the Legal Landscape for Data Privacy in Higher Education Rodney Petersen, J.D. Government Relations Officer and Security Task Force Coordinator EDUCAUSE

6 Students Become More Insecure as Hackers Go to Colleges. Los Angeles Times, June 5, 2006

7 Privacy Rights Clearinghouse Report In 2007 alone, nearly 70 colleges experienced security meltdowns of some sort, according to the Privacy Rights Clearinghouse, a nonprofit consumer advocacy group. Campus computers have been hacked, laptops and flash drives have gone missing, and key records have been left unguarded online.

8 Security and Identity Management Identified as top concerns by CIO s and technology leaders in the eighth annual EDUCAUSE Current Issues Survey. EDUCAUSE Quarterly (Vol. 30, No. 2, 2007)

9 Top Concerns First time in the survey that security was split from identity and access management. 1. Funding IT was identified as most important issue followed by: 2. Security 3. Administrative/ERP systems 4. Identity and access management.

10 Security Issues Identified: Need for privacy and security policies that encompass all the IT resources of the campus. Procedures that reflect the goals of the policies An incident response plan Senior administrators who recognize their roles as information stewards.

11 Identity/Access Management Issues Identified: Strategy for managing digital identities. How effectively are students, faculty, and staff educated about their rights and responsibilities to manage their identities? How are SSN s and other identifying data used? Has the institutional formally established ownership of identity data in its systems?

12

13 Higher Ed Fails Privacy Test From a survey administered by Bentley College and Watchfire, an on line risk management company: 100% of doctoral universities and liberal arts institutions neglected privacy notices on at least one on line data collection form. 100% had at least one non secure page for a data collection form. Of the 51 school that had privacy notices, only 33% had notices that described how users could access their own information. April 26, 2006

14 Universities Need a Privacy Refresher Course Unfortunately, the results of this survey suggest that online privacy still is not a true part of the mission of the higher educational institutions. April 26, 2006

15 Mistakes, Not Hackers, Are to Blame for Many Data Security Glitches on Campuses, Report Says Educational Security Incidents Year In Review 2007

16 Number of Incidents By Information Exposed

17 In the News Questions Over Veterans' Data Loss Officials' Response to News of Information Theft Scrutinized U.S. Military Secrets for Sale at Afghan Bazaar Los Angeles Times, April 10, 2006 College official's e mail is hijacked Rutland Herald, March 30, 2006 Passwords revealed by sweet deal BBC News, April 20, 2004

18 More News University of Idaho announces computer theft Moscow Daily News, January 25, 2007 Obama, Clinton, McCain Passport Files Breached imprudent curiosity Bloomberg.com

19

20

21

22 Privacy and Security Strategies Prevention Detection Response Encompass all users Extend across campus and to agencies outside of the institution Include all formats Recognize this takes place in a climate of rising expectations for privacy and service and increasing regulation to ensure both.

23

24 Prevention What are we to do?!? Avoiding data loss admissions/registrar strategies Pay attention security breaches and trends Assess your institutional risk for similar occurrences Review and update IT policies Modify practices to minimize chance of inadvertent harm What s your strategy? Narrowly define need to know? Narrowly define which data fields users can see? Audit who accesses student records? Extensive FERPA and data security training? A combination of the above? Stay vigilant Remember security is never a finished product!!!

25 Some basic questions Access to student records on your campus Who can see which students? Who can see what student data? Who can see and screen scrape or download SSN s with names? How do you know if the person logging into a secure system is really that person? Do users of your student data understand FERPA and data security requirements? Where is your student data stored and is it secure? When are these files deleted?

26 System access risks access profiles Institutional policy on granting access to student data affects data loss potential Need to know definition narrow or broad? Instructors: Own classes only vs. all classes Directory and contact data only vs. full student record Advisers: Own advisees vs. all students Staff who work with specific populations Restricted to that population vs. all students If your need to know access is broad, do you ramp up your FERPA training accordingly?

27 Impact of access profiles Breadth of access for student system users affects risk Which users of your secure systems present the least risk STUDENTS they can only view their personal data Which users of your secure systems present the greatest risk REGISTRAR/ADMISSIONS staff those who can see and modify student and other data, possibly including access controls Risk assessment and remediation should consider breadth of access

28 Student Data Design of Views Not all users need access to the same data elements Instructors what is necessary for students in a course? Advisers what is necessary for advisees? Registrar staff what do they need to see or update? Query access who can download SSNs? One size fits all student data views vs. tailored views Ideal minimize access to data required for performance of duties Need to display No info release when appropriate Strongly recommended eliminate access to SSNs or credit card information with few exceptions

29 SSN Protection Policy SSN only one of many confidential data elements in student records BUT SSN with name poses the greatest potential for identity theft Best practice minimize use of and access to SSN asap, including old files and query access! Campus training should address the special risk category of SSN SSN protection can provide the greatest payback related to impact of data loss and notification costs if you don t have it, you can t lose it!!!

30 Don t forget the old stuff! ISU no SSNs on class list files since Fall 2001 (i.e. instructors have had no access to SSNs) SSN Breach.org FOR IMMEDIATE RELEASE: February 4, 2008 Iowa State University Prof. Posts 26 Students' SSNs Online This was a Spring 2001 class and the web page has since been removed SSNs can come back to haunt you for long after you think they re all gone!!!

31 Identity Management Identification: ensure electronic credentials for access to a system are granted only to the right person Initial creation of account verify identity Authentication: check validity of credentials at the time of access Each login to the secure service portal user ID and secure password Authorization: determine that the person so identified has been granted the authority to perform the requested actions Once in the portal, need to enforce permissions to view or update data

32 Identity Management Challenges Identification how to ensure that the person for whom the account is created IS that person If prior to being on campus, must be based on information known about the person If after on campus, require photo ID Authentication combination of UserID and password Best practice: strong password using current standards Not recommended: PIN Try limit: require password reset after set number of invalid tries, or incremental time delays for each invalid password Password expiration: FREQUENT! (every days, no reuse)

33 Data use confidentiality training Ideal one on one training sessions on FERPA and data security Second choice required training module with annual renewal Third choice security reminders in the data presentation Examples Watermarks: Shred don t toss, confidential, etc. Links: Link to student data confidentiality policy Symbols: Padlock for students with no info release, etc.

34 Data storage considerations Data released through secure portal WILL BE downloaded and stored on desktops, laptops, networks, etc. Ideal minimize potential risk in what is released Reminders to faculty/instructors regarding data security requirements You can t control the data once released but control what you can!!!

35 Institutional/departmental policies Can t control everything that happens on campus, but you can attempt to control what happens in your office! Develop an office policy to guide data storage and use within your own office Recommend to others on campus as appropriate! Iowa State University Office of the Registrar Data Security Best Practices developed in preparation for internal audit on data security

36 ISU Office of the Registrar Policy Social Security Number and University ID University ID Number is the primary choice for accessing systems and data (Social Security number should only be used when UID is not available or practical). Office clientele should not be asked to speak their ID number. The customer can key their own ID on provided data entry key pads at most customer service areas. When working with customers on the phone, ask if they are in a public place and warn them to take precautions when supplying ID and other confidential information.

37 ISU Office of the Registrar Policy Password Security Create secure passwords that are as long as possible and contain combinations of numbers and alpha characters Do not write down passwords and keep them where others can access that information Change your passwords often Do not share passwords of logins with others

38 ISU Office of the Registrar Policy Workstation Security Do not store confidential information on personal hard drives or easily portable storage devices Always log off your computer when you leave your work area Workstations should automatically switch to screen saver and password protection after X minutes of non usage Care should be taken to shield computer screens from public/customer view to protect confidential information Any paper material containing confidential information should be shredded or put in confidential recycle and not be left out in public view Take care when discussing any confidential information in a public accessible area of the office

39 ISU Office of the Registrar Policy E mail security When sending e mails including student information, the following guidelines apply: Do not send both full name and university ID in the same . Sending only university ID is the best practice. Sending university ID plus first two letters of the last name in the same communication is acceptable, when additional identifying information is needed. When possible, pick university e mail addresses from the global directory rather than keying in E mail address directly. This practice keeps the routing internal to campus computer servers, which are more secure. Recheck all e mail addresses before sending!

40 ISU Office of the Registrar Policy Sending data files by e mail A data file containing confidential information, excluding social security number, may be sent electronically IF password protected. The data file and password must be sent in separate s. For information on how to password protect a file, go to:

41 ISU Office of the Registrar Policy Disposal of Confidential Information All hard drives and other computer storage devices will be cleansed of data or destroyed before disposal. Confidential reports or any paper containing confidential information will be shredded or put in locked confidential recycle after use. Old microfiche containing confidential information will be shredded or destroyed when no longer needed.

42 ISU Office of the Registrar Policy Other data protection advisories Reports, microfiche and other printouts should no longer contain Social Security Number. University ID should be used and only when necessary. Electronic reports on AccessPlus that require passwords and access set up are preferred over microfiche and paper reports. Credit card numbers should never be stored on computer files. Paper transcript orders containing credit card information will be kept in a locked area and shredded/destroyed when no longer needed.

43 What s next? What are your concerns in the area of data security? Discussion Thank You!

44 Resources EDUCAUSE Home > EDUCAUSE Major Initiatives > SECURITY TASK FORCE EDUCAUSE Home > Resources > Browse > Cybersecurity > Chronicle of Higher Education Information technology Campus Technology AACRAO AACRAO Security Newsletter

Section 5 Identify Theft Red Flags and Address Discrepancy Procedures Index

Section 5 Identify Theft Red Flags and Address Discrepancy Procedures Index Index Section 5.1 Purpose.... 2 Section 5.2 Definitions........2 Section 5.3 Validation Information.....2 Section 5.4 Procedures for Opening New Accounts....3 Section 5.5 Procedures for Existing Accounts...

More information

Covered Areas: Those EVMS departments that have activities with Covered Accounts.

Covered Areas: Those EVMS departments that have activities with Covered Accounts. I. POLICY Eastern Virginia Medical School (EVMS) establishes the following identity theft program ( Program ) to detect, identify, and mitigate identity theft in its Covered Accounts in accordance with

More information

Oklahoma State University Policy and Procedures. Red Flags Rules and Identity Theft Prevention

Oklahoma State University Policy and Procedures. Red Flags Rules and Identity Theft Prevention Oklahoma State University Policy and Procedures Rules and Identity Theft Prevention 3-0540 ADMINISTRATION & FINANCE July 2009 Introduction 1.01 Oklahoma State University developed this Identity Theft Prevention

More information

Privacy Data Loss. Privacy Data Loss. Identity Theft. The Legal Issues

Privacy Data Loss. Privacy Data Loss. Identity Theft. The Legal Issues Doing Business in Oregon Under the Oregon Consumer Identity Theft Protection Act and Related Privacy Risks Privacy Data Loss www.breachblog.com Presented by: Mike Porter March 10, 2009 2 Privacy Data Loss

More information

Wellesley College Written Information Security Program

Wellesley College Written Information Security Program Wellesley College Written Information Security Program Introduction and Purpose Wellesley College developed this Written Information Security Program (the Program ) to protect Personal Information, as

More information

Teacher Activities Page Directions

Teacher Activities Page Directions Teacher Activities Page Directions The Teacher Activities Page provides teachers with access to student data that is protected by the federal Family Educational Rights and Privacy Act (FERPA). Teachers

More information

Hamilton College Administrative Information Systems Security Policy and Procedures. Approved by the IT Committee (December 2004)

Hamilton College Administrative Information Systems Security Policy and Procedures. Approved by the IT Committee (December 2004) Hamilton College Administrative Information Systems Security Policy and Procedures Approved by the IT Committee (December 2004) Table of Contents Summary... 3 Overview... 4 Definition of Administrative

More information

Information Security Policy

Information Security Policy Information Security Policy Policy Contents I. POLICY STATEMENT II. REASON FOR POLICY III. SCOPE IV. AUDIENCE V. POLICY TEXT VI. PROCEDURES VII. RELATED INFORMATION VIII. DEFINITIONS IX. FREQUENTLY ASKED

More information

Contact: Henry Torres, (870) 972-3033

Contact: Henry Torres, (870) 972-3033 Information & Technology Services Management & Security Principles & Procedures Executive Summary Contact: Henry Torres, (870) 972-3033 Background: The Security Task Force began a review of all procedures

More information

NC s Identity Theft Protection Act

NC s Identity Theft Protection Act NC s Identity Theft Protection Act What Does it Mean for Local Health Departments? Jill Moore UNC Institute of Government Two Issues Managing security breaches Collection and use of SSNs Security Breaches

More information

BERKELEY COLLEGE DATA SECURITY POLICY

BERKELEY COLLEGE DATA SECURITY POLICY BERKELEY COLLEGE DATA SECURITY POLICY BERKELEY COLLEGE DATA SECURITY POLICY TABLE OF CONTENTS Chapter Title Page 1 Introduction 1 2 Definitions 2 3 General Roles and Responsibilities 4 4 Sensitive Data

More information

Information Security Policy

Information Security Policy Information Security Policy Touro College/University ( Touro ) is committed to information security. Information security is defined as protection of data, applications, networks, and computer systems

More information

Information Security

Information Security Information Security Table of Contents Statement of Confidentiality and Responsibility... 2 Policy and Regulation... 2 Protect Our Information... 3 Protect Your Account... 4 To Change Your Password...

More information

Appendix 4-2: Sample HIPAA Security Risk Assessment For a Small Physician Practice

Appendix 4-2: Sample HIPAA Security Risk Assessment For a Small Physician Practice Appendix 4-2: Administrative, Physical, and Technical Safeguards Breach Notification Rule How Use this Assessment The following sample risk assessment provides you with a series of sample questions help

More information

The Department of Health and Human Services Privacy Awareness Training. Fiscal Year 2015

The Department of Health and Human Services Privacy Awareness Training. Fiscal Year 2015 The Department of Health and Human Services Privacy Awareness Training Fiscal Year 2015 Course Objectives At the end of the course, you will be able to: Define privacy and explain its importance. Identify

More information

SCRIPT: Security Training

SCRIPT: Security Training SCRIPT: Security Training Slide Name Introduction Overview 1 Overview 2 Overview 3 Text Welcome to the MN WIC Program Security Training Module for all MN WIC Program staff provided by the MN Department

More information

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012

HIPAA Privacy and Security. Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 HIPAA Privacy and Security Rochelle Steimel, HIPAA Privacy Official Judy Smith, Staff Development January 2012 Goals and Objectives Course Goal: To introduce the staff of Munson Healthcare to the concepts

More information

Cyber Self Assessment

Cyber Self Assessment Cyber Self Assessment According to Protecting Personal Information A Guide for Business 1 a sound data security plan is built on five key principles: 1. Take stock. Know what personal information you have

More information

Identity Theft Prevention Program. Effective: November 1, 2009

Identity Theft Prevention Program. Effective: November 1, 2009 Identity Theft Prevention Program Effective: November 1, 2009 I. BACKGROUND Galveston College ("College" / Institution ) developed this Identity Theft Prevention Program ("Program") pursuant to the Federal

More information

Protecting Student Identity Principles of Good Practice University System of Georgia

Protecting Student Identity Principles of Good Practice University System of Georgia Protecting Student Identity Principles of Good Practice University System of Georgia August 2002 Protecting Student Identity Principles of Good Practice University System of Georgia August 2002 Currently

More information

THE UNIVERSITY OF NORTH CAROLINA AT GREENSBORO IDENTITY THEFT PREVENTION PROGRAM

THE UNIVERSITY OF NORTH CAROLINA AT GREENSBORO IDENTITY THEFT PREVENTION PROGRAM Program Adoption THE UNIVERSITY OF NORTH CAROLINA AT GREENSBORO IDENTITY THEFT PREVENTION PROGRAM As a best practice and using as a guide the Federal Trade Commission s ( FTC ) Red Flags Rule, implementing

More information

DRAFT National Rural Water Association Identity Theft Program Model September 22, 2008

DRAFT National Rural Water Association Identity Theft Program Model September 22, 2008 DRAFT National Rural Water Association Identity Theft Program Model September 22, 2008 This model has been designed to help water and wastewater utilities comply with the Federal Trade Commission s (FTC)

More information

MIT s Information Security Program for Protecting Personal Information Requiring Notification. (Revision date: 2/26/10)

MIT s Information Security Program for Protecting Personal Information Requiring Notification. (Revision date: 2/26/10) MIT s Information Security Program for Protecting Personal Information Requiring Notification (Revision date: 2/26/10) Table of Contents 1. Program Summary... 3 2. Definitions... 4 2.1 Identity Theft...

More information

U.S. Department of the Interior's Federal Information Systems Security Awareness Online Course

U.S. Department of the Interior's Federal Information Systems Security Awareness Online Course U.S. Department of the Interior's Federal Information Systems Security Awareness Online Course Rules of Behavior Before you print your certificate of completion, please read the following Rules of Behavior

More information

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by: HIPAA Privacy Officer Orientation Presented by: Cathy Montgomery, RN Privacy Officer Job Description Serve as leader Develop Policies and Procedures Train staff Monitor activities Manage Business Associates

More information

Electronic Data Security: Designing Good Data Protection Plans

Electronic Data Security: Designing Good Data Protection Plans Electronic Data Security: Designing Good Data Protection Plans Dean Gallant Harvard University FAS Assistant Dean for Research Policy and Administration & Executive Officer, Committee on the Use of Human

More information

Identity Theft Prevention Program Derived from the FTC Red Flags Rule requirements

Identity Theft Prevention Program Derived from the FTC Red Flags Rule requirements Identity Theft Prevention Program Derived from the FTC Red Flags Rule requirements 1.0 Introduction In 2003, Congress enacted the Fair and Accurate Credit Transactions Act of 2003, 15 U.S.C. Section 1681,

More information

How To Protect Data At Northeast Alabama Community College

How To Protect Data At Northeast Alabama Community College Information Systems Security Policy Northeast Alabama Community College Center for Information Assurance Northeast Alabama Community College 138 AL Hwy 35, Rainsville, AL 35986 (256) 228-6001 1 5/22/2014

More information

NETWORK INFRASTRUCTURE USE

NETWORK INFRASTRUCTURE USE NETWORK INFRASTRUCTURE USE Information Technology Responsible Office: Information Security Office http://ooc.usc.edu infosec@usc.edu (213) 743-4900 1.0 Purpose The (USC) provides its faculty, staff and

More information

POL 08.00.02 Information Systems Access Policy. History: First issued: November 5, 2001. Revised: April 5, 2010. Last revised: June 18, 2014

POL 08.00.02 Information Systems Access Policy. History: First issued: November 5, 2001. Revised: April 5, 2010. Last revised: June 18, 2014 POL 08.00.02 Information Systems Access Policy Authority: History: First issued: November 5, 2001. Revised: April 5, 2010. Last revised: June 18, 2014 Related Policies: NC General Statute 14-454 - Accessing

More information

HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE

HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE HIPAA SECURITY RISK ASSESSMENT SMALL PHYSICIAN PRACTICE How to Use this Assessment The following risk assessment provides you with a series of questions to help you prioritize the development and implementation

More information

Retention & Destruction

Retention & Destruction Last Updated: March 28, 2014 This document sets forth the security policies and procedures for WealthEngine, Inc. ( WealthEngine or the Company ). A. Retention & Destruction Retention & Destruction of

More information

CITY OF MARQUETTE, MICHIGAN CITY COMMISSION POLICY

CITY OF MARQUETTE, MICHIGAN CITY COMMISSION POLICY CITY OF MARQUETTE, MICHIGAN CITY COMMISSION POLICY Policy Number: 2008-02 Date Adopted: October 27, 2008 Department: Administrative SUBJECT: IDENTITY THEFT PREVENTION PROGRAM I. OBJECTIVE: A. To protect

More information

How To Protect The Time System From Being Hacked

How To Protect The Time System From Being Hacked WISCONSIN TIME SYSTEM Training Materials TIME SYSTEM SECURITY AWARENESS HANDOUT Revised 11/21/13 2014 Security Awareness Handout All System Security The TIME/NCIC Systems are criminal justice computer

More information

Personal Safety Tips For Public Information Technology

Personal Safety Tips For Public Information Technology IDENTITY THEFT Practical Tips to Do Your Best David L. Haase November 21, 2015 OPCUG / PATACS 1 Today s Agenda Who is This Guy? Are You a Target? I.D. Theft vs. Stalking What Do Thieves Target? Have a

More information

IT Security Compliance Monitoring: Dealing with Increasing Demands

IT Security Compliance Monitoring: Dealing with Increasing Demands IT Security Compliance Monitoring: Dealing with Increasing Demands Duke TechExpo 2011 January 6, 2011 Mark Phillips, Director - IT Audit, Office of Internal Audits Brian Lowinger, JD, Institutional Ethics

More information

Central Oregon Community College. Identity Theft Prevention Program

Central Oregon Community College. Identity Theft Prevention Program Central Oregon Community College Identity Theft Prevention Program Effective beginning May 1, 2009 I. PROGRAM ADOPTION This program has been created to put COCC in compliance with Section 41.90 under the

More information

Acceptable Use of Computing and Information Technology Resources

Acceptable Use of Computing and Information Technology Resources Acceptable Use of Computing and Information Technology Resources Version 1.0, February2, 2010 General Statement As part of its educational mission, Hocking College acquires, develops, and maintains computers,

More information

The United States Office Of Personnel Management eopf Human Resources Specialist Training Manual for eopf Version 4.0.

The United States Office Of Personnel Management eopf Human Resources Specialist Training Manual for eopf Version 4.0. The United States Office Of Personnel Management eopf Human Resources Specialist Training Manual for eopf Version 4.0. Copyright 1994-2007 by Northrop Grumman. All rights reserved. Northrop Grumman, the

More information

Statement of Policy. Reason for Policy

Statement of Policy. Reason for Policy Table of Contents Statement of Policy 2 Reason for Policy 2 HIPAA Liaison 2 Individuals and Entities Affected by Policy 2 Who Should Know Policy 3 Exclusions 3 Website Address for Policy 3 Definitions

More information

PII Personally Identifiable Information Training and Fraud Prevention

PII Personally Identifiable Information Training and Fraud Prevention PII Personally Identifiable Information Training and Fraud Prevention Topics What is Personally Identifiable Information (PII)? Why are we committed to protecting PII? What laws govern us? How do we comply?

More information

New ehealth Computer Account User Information. July 2014

New ehealth Computer Account User Information. July 2014 New ehealth Computer Account User Information July 2014 Security and Identification Manitoba ehealth takes very seriously the need to protect your computer account along with the confidential data and

More information

IDENTITY THEFT PREVENTION PROGRAM

IDENTITY THEFT PREVENTION PROGRAM IDENTITY THEFT PREVENTION PROGRAM Implemented October 2009 Page 1 Table of Contents Background... 3 Purpose... 3 Definitions... 3 Pretext Calling... 4 Receiving Telephone Calls... 5 Change of Address...

More information

Acceptable Use Policy

Acceptable Use Policy Acceptable Use Policy I. Introduction Each employee, student or non-student user of Greenville County Schools (GCS) information system is expected to be familiar with and follow the expectations and requirements

More information

INFORMATION SECURITY GUIDE. Employee Teleworking. Information Security Unit. Information Technology Services (ITS) July 2013

INFORMATION SECURITY GUIDE. Employee Teleworking. Information Security Unit. Information Technology Services (ITS) July 2013 INFORMATION SECURITY GUIDE Employee Teleworking Information Security Unit Information Technology Services (ITS) July 2013 CONTENTS 1. Introduction... 2 2. Teleworking Risks... 3 3. Safeguards for College

More information

Information Security

Information Security Information Security A staff guide to the University's Information Systems Security Policy Issued by the IT Security Group on behalf of the University. Information Systems Security Guidelines for Staff

More information

Using Network Attached Storage with Linux. by Andy Pepperdine

Using Network Attached Storage with Linux. by Andy Pepperdine Using Network Attached Storage with Linux by Andy Pepperdine I acquired a WD My Cloud device to act as a demonstration, and decide whether to use it myself later. This paper is my experience of how to

More information

County Identity Theft Prevention Program

County Identity Theft Prevention Program INTRODUCTION CHAPTER OSCEOLA COUNTY IDENTITY THEFT PREVENTION PROGRAM The Osceola County Board of County Commissioners is committed to protecting consumers who do business with Osceola County, and as such

More information

PRIVACY POLICY. I. Introduction. II. Information We Collect

PRIVACY POLICY. I. Introduction. II. Information We Collect PRIVACY POLICY school2life, Inc. ( school2life ) Privacy Policy is designed to provide clarity about the information we collect and how we use it to provide a better social gaming experience. By accepting

More information

State HIPAA Security Policy State of Connecticut

State HIPAA Security Policy State of Connecticut Health Insurance Portability and Accountability Act State HIPAA Security Policy State of Connecticut Release 2.0 November 30 th, 2004 Table of Contents Executive Summary... 1 Policy Definitions... 3 1.

More information

MUSC Information Security Policy Compliance Checklist for System Owners Instructions

MUSC Information Security Policy Compliance Checklist for System Owners Instructions Instructions This checklist can be used to identify gaps in compliance with MUSC's information security policies and standards, which are published on the Web at http://www.musc.edu/security. Each of the

More information

AUBURN WATER SYSTEM. Identity Theft Prevention Program. Effective October 20, 2008

AUBURN WATER SYSTEM. Identity Theft Prevention Program. Effective October 20, 2008 AUBURN WATER SYSTEM Identity Theft Prevention Program Effective October 20, 2008 I. PROGRAM ADOPTION Auburn Water System developed this Identity Theft Prevention Program ("Program") pursuant to the Federal

More information

AESDIRECT ACCOUNT ADMINISTRATION USER GUIDE

AESDIRECT ACCOUNT ADMINISTRATION USER GUIDE AESDIRECT ACCOUNT ADMINISTRATION USER GUIDE Updated June 24, 2014 Table of Contents OVERVIEW... 3 AESDirect Roles Defined... 3 Account Administrator... 3 User Managers... 3 Users... 4 AESDIRECT RULES...

More information

CLIENT PORTAL USER GUIDE

CLIENT PORTAL USER GUIDE CLIENT PORTAL USER GUIDE JULY 28, 2011 At Gelman, Rosenberg & Freedman, CPAs we take the privacy and security of your information seriously. That's why we've introduced the Client Portal for sharing your

More information

HIPAA Security. assistance with implementation of the. security standards. This series aims to

HIPAA Security. assistance with implementation of the. security standards. This series aims to HIPAA Security SERIES Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical

More information

FTA Computer Security Workshop. Security Awareness Training

FTA Computer Security Workshop. Security Awareness Training FTA Computer Security Workshop March 8,2007 Stan Wiechert, KDOR IS Security Officer Historical Background Organization of KDOR Delivery of Training Specific Contents 2 1 Historical Background 1998-Internal

More information

Data Access Request Service

Data Access Request Service Data Access Request Service Guidance Notes on Security Version: 4.0 Date: 01/04/2015 1 Copyright 2014, Health and Social Care Information Centre. Introduction This security guidance is for organisations

More information

Executive Summary Program Highlights for FY2009/2010 Mission Statement Authority State Law: University Policy:

Executive Summary Program Highlights for FY2009/2010 Mission Statement Authority State Law: University Policy: Executive Summary Texas state law requires that each state agency, including Institutions of Higher Education, have in place an Program (ISP) that is approved by the head of the institution. 1 Governance

More information

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance Date: 07/19/2011 The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance PCI and HIPAA Compliance Defined Understand

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in InCommon Federation ( Federation ) enables the participant to use Shibboleth identity attribute sharing technologies to manage access

More information

Deltek Touch Time & Expense for GovCon. User Guide for Triumph

Deltek Touch Time & Expense for GovCon. User Guide for Triumph Deltek Touch Time & Expense for GovCon User Guide for Triumph November 25, 2014 While Deltek has attempted to verify that the information in this document is accurate and complete, some typographical or

More information

Learn to protect yourself from Identity Theft. First National Bank can help.

Learn to protect yourself from Identity Theft. First National Bank can help. Learn to protect yourself from Identity Theft. First National Bank can help. Your identity is one of the most valuable things you own. It s important to keep your identity from being stolen by someone

More information

DHHS Information Technology (IT) Access Control Standard

DHHS Information Technology (IT) Access Control Standard DHHS Information Technology (IT) Access Control Standard Issue Date: October 1, 2013 Effective Date: October 1,2013 Revised Date: Number: DHHS-2013-001-B 1.0 Purpose and Objectives With the diversity of

More information

R345, Information Technology Resource Security 1

R345, Information Technology Resource Security 1 R345, Information Technology Resource Security 1 R345-1. Purpose: To provide policy to secure the private sensitive information of faculty, staff, patients, students, and others affiliated with USHE institutions,

More information

Network and Workstation Acceptable Use Policy

Network and Workstation Acceptable Use Policy CONTENT: Introduction Purpose Policy / Procedure References INTRODUCTION Information Technology services including, staff, workstations, peripherals and network infrastructures are an integral part of

More information

LANDER UNIVERSITY STUDENT INFORMATION SECURITY AND PRIVACY PROCEDURE

LANDER UNIVERSITY STUDENT INFORMATION SECURITY AND PRIVACY PROCEDURE founded in 1872 LANDER UNIVERSITY Office of Information Technology Services LANDER UNIVERSITY STUDENT INFORMATION SECURITY AND PRIVACY PROCEDURE 2012 REVISION TABLE OF CONTENTS I. PRIVACY.....................................................

More information

HIPAA ephi Security Guidance for Researchers

HIPAA ephi Security Guidance for Researchers What is ephi? ephi stands for Electronic Protected Health Information (PHI). It is any PHI that is stored, accessed, transmitted or received electronically. 1 PHI under HIPAA means any information that

More information

PHI- Protected Health Information

PHI- Protected Health Information HIPAA Policy 2014 The Health Insurance Portability and Accountability Act is a federal law that protects the privacy and security of patients health information and grants certain rights to patients. Clarkson

More information

Good Practice in Records Management and Information Security

Good Practice in Records Management and Information Security Good Practice in Records Management and Information Security BELB LJ Schools 2013 How Valuable are Records & Documents? Valuable only because of the information they contain. Usable if they can be accessed

More information

Protecting the Information of Clients, Donors, the Organization, Oh MY! Stacey Keegan November 14, 2012

Protecting the Information of Clients, Donors, the Organization, Oh MY! Stacey Keegan November 14, 2012 Protecting the Information of Clients, Donors, the Organization, Oh MY! Stacey Keegan November 14, 2012 Mission of Pro Bono Partnership of Atlanta: To maximize the impact of pro bono engagement by connecting

More information

HIPAA Security COMPLIANCE Checklist For Employers

HIPAA Security COMPLIANCE Checklist For Employers Compliance HIPAA Security COMPLIANCE Checklist For Employers All of the following steps must be completed by April 20, 2006 (April 14, 2005 for Large Health Plans) Broadly speaking, there are three major

More information

Tenth Judicial Circuit of Florida Information Systems Acceptable Use Guidelines Polk, Hardee and Highlands Counties as of January 2014

Tenth Judicial Circuit of Florida Information Systems Acceptable Use Guidelines Polk, Hardee and Highlands Counties as of January 2014 Tenth Judicial Circuit of Florida Information Systems Acceptable Use s Polk, Hardee and Highlands Counties as of January 2014 The following guidelines define the acceptable use of information technology

More information

HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals

HIPAA. New Breach Notification Risk Assessment and Sanctions Policy. Incident Management Policy. Focus on: For breaches affecting 1 3 individuals HIPAA New Breach Notification Risk Assessment and Sanctions Policy Incident Management Policy For breaches affecting 1 3 individuals +25 individuals + 500 individuals Focus on: analysis documentation PHI

More information

Frequently Asked Questions

Frequently Asked Questions Barclaycard Spend Management Frequently Asked Questions Access/Login 1. Is the user name case-sensitive? The user name is not case-sensitive. It must be a minimum of 6 characters and up to 100 characters.

More information

Using YSU Password Self-Service

Using YSU Password Self-Service Using YSU Password Self-Service Using YSU Password Self-Service Password Self-Service Web Interface Required Items: YSU (MyYSU) Directory account, Web browser This guide will assist you with using the

More information

Identity theft. A fraud committed or attempted using the identifying information of another person without authority.

Identity theft. A fraud committed or attempted using the identifying information of another person without authority. SUBJECT: Effective Date: Policy Number: Identity Theft Prevention 08-24-11 2-105.1 Supersedes: Page Of 2-105 1 8 Responsible Authority: Vice President and General Counsel DATE OF INITIAL ADOPTION AND EFFECTIVE

More information

HIPAA Security Alert

HIPAA Security Alert Shipman & Goodwin LLP HIPAA Security Alert July 2008 EXECUTIVE GUIDANCE HIPAA SECURITY COMPLIANCE How would your organization s senior management respond to CMS or OIG inquiries about health information

More information

Procedure Title: TennDent HIPAA Security Awareness and Training

Procedure Title: TennDent HIPAA Security Awareness and Training Procedure Title: TennDent HIPAA Security Awareness and Training Number: TD-QMP-P-7011 Subject: Security Awareness and Training Primary Department: TennDent Effective Date of Procedure: 9/23/2011 Secondary

More information

Community First Health Plans Breach Notification for Unsecured PHI

Community First Health Plans Breach Notification for Unsecured PHI Community First Health Plans Breach Notification for Unsecured PHI The presentation is for informational purposes only. It is the responsibility of the Business Associate to ensure awareness and compliance

More information

Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721

Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721 Sierra College ADMINISTRATIVE PROCEDURE No. AP 3721 Electronic Information Security and Data Backup Procedures Date Adopted: 4/13/2012 Date Revised: Date Reviewed: References: Health Insurance Portability

More information

White Paper: NCBI Database of Genotypes and Phenotypes (dbgap) Security Best Practices Compliance Overview for the New DNAnexus Platform

White Paper: NCBI Database of Genotypes and Phenotypes (dbgap) Security Best Practices Compliance Overview for the New DNAnexus Platform White Paper: NCBI Database of Genotypes and Phenotypes (dbgap) Security Best Practices Compliance Overview for the New DNAnexus Platform April 18, 2013 Overview This White Paper summarizes how the new

More information

HIPAA 101. March 18, 2015 Webinar

HIPAA 101. March 18, 2015 Webinar HIPAA 101 March 18, 2015 Webinar Agenda Acronyms to Know HIPAA Basics What is HIPAA and to whom does it apply? What is protected by HIPAA? Privacy Rule Security Rule HITECH Basics Breaches and Responses

More information

Information Security Policy and Handbook Overview. ITSS Information Security June 2015

Information Security Policy and Handbook Overview. ITSS Information Security June 2015 Information Security Policy and Handbook Overview ITSS Information Security June 2015 Information Security Policy Control Hierarchy System and Campus Information Security Policies UNT System Information

More information

The University of North Carolina at Charlotte Identity Theft Prevention Program

The University of North Carolina at Charlotte Identity Theft Prevention Program The University of North Carolina at Charlotte Identity Theft Prevention Program Program Adoption As a best practice and using as a guide the Federal Trade Commission s ( FTC ) Red Flags Rule ( Rule ),

More information

Internet Access Gateway Logon Instructions IAG Platform, XP

Internet Access Gateway Logon Instructions IAG Platform, XP Business Services Network (BSN) Internet Access Gateway Logon Instructions IAG Platform, XP Welcome to the Business Services Network a secure, private network for authorized users within which one may

More information

HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY

HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY HFS DATA SECURITY TRAINING WITH TECHNOLOGY COMES RESPONSIBILITY Illinois Department of Healthcare and Family Services Training Outline: Training Goals What is the HIPAA Security Rule? What is the HFS Identity

More information

Telemedicine HIPAA/HITECH Privacy and Security

Telemedicine HIPAA/HITECH Privacy and Security Telemedicine HIPAA/HITECH Privacy and Security 1 Access Control Role Based Access The organization shall provide secure rolebased account management. Privileges granted utilizing the principle of least

More information

PDMP User s Guide. Oregon Health Authority Prescription Drug Monitoring Program

PDMP User s Guide. Oregon Health Authority Prescription Drug Monitoring Program Oregon Health Authority Prescription Drug Monitoring Program December 2015 Contents Contents 1 Document Overview... 1 Purpose and Contents... 1 RxSentry Update... 1 2 System Overview... 3 About the RxSentry

More information

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics

HIPAA Security. 4 Security Standards: Technical Safeguards. Security Topics HIPAA Security S E R I E S Security Topics 1. Security 101 for Covered Entities 2. Security Standards - Administrative Safeguards 3. Security Standards - Physical Safeguards 4. Security Standards - Technical

More information

Registrar s Office Strategic Plan 2008-2009 Results & Responses

Registrar s Office Strategic Plan 2008-2009 Results & Responses Registrar s Office 1 Registrar s Office Strategic Plan & Responses Division Mission Statement The Division of Enrollment Services will assist the College in achieving its mission of nurturing and developing

More information

Introduction. Purpose. Reference. Applicability. HIPAA Policy 7.1. Safeguards to Protect the Privacy of PHI

Introduction. Purpose. Reference. Applicability. HIPAA Policy 7.1. Safeguards to Protect the Privacy of PHI Office of Regulatory Compliance 13001 E. 17 th Place, Suite W1124 Mail Stop F497 Aurora, CO 80045 Main Office: 303-724-1010 Main Fax: 303-724-1019 HIPAA Policy 7.1 Title: Source: Prepared by: Approved

More information

Information Security Operational Procedures

Information Security Operational Procedures College Of Coastal Georgia Information Security Operational Procedures Banner Student Information System Security Policy INTRODUCTION This document provides a general framework of the policy utilized by

More information

Oregon University System Identity Theft Prevention Program Effective May 1, 2009

Oregon University System Identity Theft Prevention Program Effective May 1, 2009 Oregon University System Identity Theft Prevention Program Effective May 1, 2009 Page 2 I. PROGRAM ADOPTION The Oregon University System ( System ) developed this Identity Theft Prevention Program ("Program")

More information

HOW TO REALLY IMPLEMENT HIPAA. Presented by: Melissa Skaggs Provider Resources Group

HOW TO REALLY IMPLEMENT HIPAA. Presented by: Melissa Skaggs Provider Resources Group HOW TO REALLY IMPLEMENT HIPAA Presented by: Melissa Skaggs Provider Resources Group WHAT IS HIPAA The Health Insurance Portability and Accountability Act of 1996 (HIPAA; Pub.L. 104 191, 110 Stat. 1936,

More information

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist HIPAA Omnibus Rule Overview Presented by: Crystal Stanton MicroMD Marketing Communication Specialist 1 HIPAA Omnibus Rule - Agenda History of the Omnibus Rule What is the HIPAA Omnibus Rule and its various

More information

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH)

Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Health Insurance Portability and Accountability Act (HIPAA) and Health Information Technology for Economic and Clinical Health Act (HITECH) Table of Contents Introduction... 1 1. Administrative Safeguards...

More information

Faculty Introduction to Self-Service

Faculty Introduction to Self-Service Faculty Introduction to Self-Service This user guide focuses on how faculty members can use Self-Service to access and update their information. Using a Web browser, faculty members can enter student grades,

More information

Security Frequently Asked Questions And General Information

Security Frequently Asked Questions And General Information Security Frequently Asked Questions And General Information Here are several things to keep in mind, along with some frequently asked questions with their answers. Terminology Domain = 7-digit security

More information

Florida International University. Identity Theft Prevention Program. Effective beginning August 1, 2009

Florida International University. Identity Theft Prevention Program. Effective beginning August 1, 2009 Florida International University Identity Theft Prevention Program Effective beginning August 1, 2009 I. PROGRAM ADOPTION Florida International University developed this Identity Theft Prevention Program

More information

Portal Administration. Administrator Guide

Portal Administration. Administrator Guide Portal Administration Administrator Guide Portal Administration Guide Documentation version: 1.0 Legal Notice Legal Notice Copyright 2013 Symantec Corporation. All rights reserved. Symantec, the Symantec

More information