Laserfiche WebLink
DocuSign Envelope ID: 62955F1D-7A37-4CB0-A8D8-2BA7ADB5515E <br />d. HBE Data will be stored in a database which will contain no non-HBE Data. Or, <br />HBE Data will be stored within a database and will be distinguishable from non-HBE Data by <br />the value of a specific field or fields within database records. Or, <br />f. When stored as physical paper documents, HBE Data will be physically segregated from non- <br />HBE Data in a drawer, folder, or other container. <br />g. When it is not feasible or practical to segregate HBE Data from non-HBE Data, then both the <br />HBE Data and the non-HBE Data with which it is commingled must be protected as <br />described in this exhibit. <br />Data Disposition. When the contracted work has been completed or when no longer needed, <br />except as noted in 2.b above, Data shall be returned to the HBE or destroyed. Media on which <br />Data may be stored and associated acceptable methods of destruction are as follows: <br />Data stored on: <br />Will be destroyed by: <br />Server or workstation hard disks, or <br />Using a "wipe" utility which will overwrite <br />the Data at least three (3) times using either <br />Removable media (e.g. floppies, USB flash <br />random or single character Data, or <br />drives, portable hard disks, Zip or similar <br />disks) <br />Degaussing sufficiently to ensure that the <br />Data cannot be reconstructed, or <br />Physically destroying the disk <br />Paper documents with sensitive or <br />Recycling through a contracted firm provided <br />confidential Data <br />the contract with the recycler assures that <br />the confidentiality of Data will be protected. <br />Paper documents containing confidential <br />On-site shredding by a method that renders <br />information requiring special handling (e.g. <br />the Data unreadable, pulping, or incineration <br />protected health information) <br />Optical discs (e.g. CDs or DVDs) <br />Incineration, shredding, or cutting/breaking <br />into small pieces. <br />Magnetic tape <br />Degaussing, incinerating or crosscut <br />shredding <br />6. Notification of Compromise or Potential Compromise. The Contractor shall have an established <br />and documented policy to deal with the compromise or potential compromise of Data that <br />complies with the HITECH Act of ARRA 209. The Contractor shall provide HBE staff of such policy <br />upon request. The compromise or potential compromise of HBE shared Data must be reported <br />to the HBE Contact designated on this Contract within one (1) business day of discovery. <br />7. Data shared with Sub -contractors. If HBE Data provided under this Contract is to be shared with <br />a sub -contractor, the contract with the sub -contractor must include all of the Data security <br />provisions within this Contract and within any amendments, attachments, or exhibits within this <br />Contract. If the subcontractor cannot protect the Data as stated within this Contract, then the <br />contract with the sub -contractor must be submitted to the HBE Contact Services for review and <br />approval. <br />HBE-349 YNHS Exhibit D — Data Security Requirements Page 27 of 41 <br />