Laserfiche WebLink
Governmental Network (SGN) is a Trusted System for communications within that <br />Network. <br />g. "Unique User ID" means a string of characters that identifies a specific user and which, <br />in conjunction with a password, passphrase, or other mechanism , authenticates a user <br />to an information system . <br />2. Confidential Information Transmitting <br />a. When transmitting HCA's Confidential Information electronically, including via email, <br />the Data must be encrypted using NIST 800-series approved algorithms <br />(htlp://csrc .nist:gov/publiqations/PubsSP..s .html ). This includes transmission over the <br />public internet. <br />b. When transmitting HCA's Confidential Information via paper documents, the Receiving <br />Party must use a Trusted System . <br />3. Protection of Confidential Information <br />The Contractor agrees to store Confidential Information as described : <br />a. Data at Rest: <br />i. Data will be encrypted with NIST 800-series approved algorithms. Encryption keys <br />will be stored and protected independently of the data. Access to the Data will be <br />restricted to Authorized Users through the use of access control lists, a Unique User <br />ID, and a Hardened Password, or other authentication mechanisms which provide <br />equal or greater security, such as biometrics or smart cards. Systems which contain <br />or provide access to Confidential Information must be located in an area that is <br />accessible only to authorized personnel, with access controlled through use of a key, <br />card key, combination lock, or comparable mechanism. <br />ii. Data stored on Portable/Removable Media or Devices; <br />• Confidential Information provided by HCA on Removable Media will be encrypted <br />with NIST 800-series approved algorithms. Encryption keys will be stored and <br />protected independently of the Data. <br />• HCA's data must not be stored by the Receiving Party on Portable Devices or Media <br />unless specifically authorized within the Data Share Agreement. If so authorized, <br />the Receiving Party must protect the Data by: <br />1. Encrypting with NIST 800-series approved algorithms. Encryption keys will be <br />stored and protected independently of the data; <br />Washington State <br />Health Care Authority Page 39 of 90 HCA Contract No . K3924