Laserfiche WebLink
Physically Secure the portable device(s) and/or media by <br />(d) Keeping them in locked storage when not in use <br />(e) Using check-in/check-out procedures when they are shared, and <br />(f) Taking frequent inventories <br />(2) When being transported outside of a Secured Area, portable devices and media <br />with HCA Confidential Information must be under the physical control of <br />Contractor staff with authorization to access the Data. <br />(3) Portable devices include, but are not limited to; smart phones, tablets, flash <br />memory devices (e.g. USB flash drives, personal media players), portable hard <br />disks, and laptop/notebook/netbook computers if those computers may be <br />transported outside of a Secured Area. <br />(4) Portable media includes, but is not limited to; optical media (e.g. CDs, DVDs), <br />magnetic media (e.g. floppy disks, tape), or flash media (e.g. CompactFlash, SD, <br />MMC). <br />h. Data stored for backup purposes. <br />(1) HCA data may be stored on portable media as part of Contractor's existing, <br />documented backup process for business continuity or disaster recovery <br />purposes. Such storage is authorized until such time as that media would be <br />reused during the course of normal backup operations. If backup media is retired <br />while HCA Confidential Information still exists upon it, such media will be <br />destroyed at that time in accordance with the disposition requirements in Section <br />5. Data Disposition <br />(2) HCA Data may be stored on non-portable media (e.g. Storage Area Network <br />drives, virtual media, etc.) as part of Contractor's existing, documented backup <br />process for business continuity or disaster recovery purposes. If so, such media <br />will be protected as otherwise described in this exhibit. If this media is retired <br />while HCA Confidential Information still exists upon it, the data will be destroyed <br />at that time in accordance with the disposition requirements in Section 5. Data <br />Disposition. <br />4. Data Segregation. <br />a. HCA Data must be segregated or otherwise distinguishable from non-HCA data. <br />This is to ensure that when no longer needed by Contractor, all HCA Data can be <br />identified for return or destruction. It also aids in determining whether HCA Data has <br />or may have been compromised in the event of a security breach. As such, one or <br />more of the following methods will be used for data segregation. <br />b. HCA Data will be kept on media (e.g. hard disk, optical disc, tape, etc .) which will <br />contain no non-HCA data. And/or, <br />Washington State <br />Health Care Authority Page 87 of90 HCA Contract No. K3924