Laserfiche WebLink
1. Encrypting with NIST 800 -series approved algorithms. Encryption <br />keys will be stored and protected independently of the data; <br />2. Control access to the devices with a Unique User ID and Hardened <br />Password or stronger authentication method such as a physical token <br />or biometrics; <br />3. Keeping devices in locked storage when not in use; <br />4. Using check-in/check-out procedures when devices are shared; <br />5. Maintain an inventory of devices; and <br />6. Ensure that when being transported outside of a Secured Area, all <br />devices with Data are under the physical control of an Authorized <br />User. <br />b. Paper documents. Any paper records containing Confidential Information must be <br />protected by storing the records in a Secured Area that is accessible only toauthorized <br />personnel. When not in use, such records must be stored in a locked container, such <br />as a file cabinet, locking drawer, or safe, to which only authorized persons have <br />access. <br />4. Confidential Information Segregation <br />HCA Confidential Information received under this Contract must be segregated or <br />otherwise distinguishable from non -HCA data. This is to ensure that when no longer <br />needed by the Contractor, all HCA Confidential Information can be identified for return or <br />destruction. It also aids in determining whether HCA Confidential Information has or may <br />have been compromised in the event of a security Breach. <br />a. The HCA Confidential Information must be kept in one of the following ways: <br />i. on media (e.g. hard disk, optical disc, tape, etc.) which will contain only HCA <br />Data; or <br />ii, in a logical container on electronic media, such as a partition or folder <br />dedicated to HCA's Data; or <br />iii. in a database that will contain only HCA Data; or <br />V. within a database and will be distinguishable from non -HCA Data by the <br />value of a specific field or fields within database records; or <br />V. when stored as physical paper documents, physically segregated from non - <br />HCA Data in a drawer, folder, or other container. <br />Washington State Page 40 HCA Contract No. K3924 <br />Health Care Authority <br />