Laserfiche WebLink
5 . <br />c. HCA Data will be stored in a logical container on electronic media, such as a partition <br />or folder dedicated to HCA Data. And/or, <br />d . HCA Data will be stored in a database which will contain no non-HCA data. And/or, <br />e. HCA Data will be stored within a database and will be distinguishable from non-HCA <br />data by the value of a specific field or fields within database records . <br />f . When stored as physical paper documents, HCA Data will be physically segregated <br />from non-HCA data in a drawer, folder, or other container. <br />g. When it is not feasible or practical to segregate HCA Data from non-HCA data, then <br />both the HCA Data and the non-HCA data with which it is commingled must be <br />protected as described in this exhibit. <br />Data Disposition. When the contracted work has been completed or when no longer <br />needed, except as noted in Section 3. Protection of Data b. Network Server Disks <br />above, Data shall be returned to HCA or destroyed. Media on which Data may be stored <br />and associated acceptable methods of destruction are as follows: <br />Data stored on : Will be destroved by: <br />Server or workstation hard disks, or Using a ''wipe" utility which will overwrite the <br />Data at least three (3) times using either <br />Removable media (e.g. floppies, USB flash random or single character data, or <br />drives, portable hard disks) excluding optical <br />discs Degaussing sufficiently to ensure that the <br />Data cannot be reconstructed, or <br />Physically destrovinQ the disk <br />Paper documents with sensitive or Recycling through a contracted firm provided <br />Confidential Information the contract with the recycler assures that the <br />confidentiality of Data will be protected. <br />Paper documents containing Confidential On-site shredding, pulping, or incineration <br />Information requiring special handling (e.g. <br />protected health information) <br />Optical discs (e.g. CDs or DVDs) Incineration, shredding, or completely <br />defacing the readable surface with a coarse <br />abrasive <br />Magnetic tape Degaussing, incinerating or crosscut <br />shreddino <br />6. Notification of Compromise or Potential Compromise. The compromise or potential <br />compromise of HCA shared Data must be reported to the HCA Contact designated in <br />the Contract within one (1) business day of discovery. If no HCA Contact is designated <br />in the Contract, then the notification must be reported to the HCA Privacy Officer at <br />HCAprivacyofficer@HCAwa.gov. Contactor must also take actions to mitigate the risk <br />of loss and comply with any notification or other requirements imposed by law or HCA. <br />Washington State <br />Health Care Authority Page 88 of90 HCA Contract No. K3924