Laserfiche WebLink
2. Control access to the devices with a Unique User ID and Hardened Password <br />or stronger authentication method such as a physical token or biometrics; <br />3. Keeping devices in locked storage when not in use; <br />4. Using check-in/check-out procedures when devices are shared; <br />5. Maintain an inventory of devices ; and <br />6. Ensure that when being transported outside of a Secured Area, all devices with <br />Data are under the physical control of an Authorized User. <br />b. Paper documents. Any paper records containing Confidential Information must be <br />protected by storing the records in a Secured Area that is accessible only to authorized <br />personnel. When not in use, such records must be stored in a locked container, such <br />as a file cabinet, locking drawer, or safe, to which only authorized persons have <br />access . <br />4. Confidential Information Segregation <br />HCA Confidential Information received under this Contract must be segregated or <br />otherwise distinguishable from non-HCA data. This is to ensure that when no longer <br />needed by the Contractor, all HCA Confidential Information can be identified for return or <br />destruction. It also aids in determining whether HCA Confidential Information has or may <br />have been compromised in the event of a security Breach. <br />a. The HCA Confidential Information must be kept in one of the following ways: <br />i. on media (e.g. hard disk, optical disc, tape, etc.) which will contain only HCA <br />Data; or <br />ii. in a logical container on electronic media, such as a partition or folder dedicated <br />to HCA's Data; or <br />iii. in a database that will contain only HCA Data; or <br />iv . within a database and will be distinguishable from non-HCA Data by the value of <br />a specific field or fields within database records; or <br />v. when stored as physical paper documents, physically segregated from non-HCA <br />Data in a drawer, folder, or other container. <br />b. When it is not feasible or practical to segregate HCA Confidential Information from non- <br />HCA data, then both the HCA Confidential Information and the non-HCA data with which <br />it is commingled must be protected as described in this Attachment. <br />Washington State <br />Health Care Authority Page 40 of90 HCA Contract No, K3924