Laserfiche WebLink
DocuSign Envelope ID: 2A330111-63A7-4837-94A9-4126DA2ACCD4 <br />Special Terms and Conditions <br />(1). Data will not be stored in any consumer grade Cloud solution, unless all of the following <br />conditions are met: <br />(a). Contractor has written procedures in place governing use of the Cloud storage and <br />Contractor attests in writing that all such procedures will be uniformly followed; <br />(b). The Data will be Encrypted while within the Contractor network; <br />(c). The Data will remain Encrypted during transmission to the Cloud; <br />(d). The Data will remain Encrypted at all times while residing within the Cloud storage solution; <br />(e). The Contractor will possess a decryption key for the Data, and the decryption key will be <br />possessed only by the Contractor and/or DCYF; <br />(f). The Data will not be downloaded to non -authorized systems, meaning systems that are not <br />on either the DCYF or Contractor networks; <br />(g). The Data will not be decrypted until downloaded onto a computer or portable devise within <br />the control of an Authorized User and within either the DCYF or Contractor's network; and <br />(h).Access to the cloud storage requires Multi Factor Authentication or Two Step Authentication. <br />(2). Data will not be stored on an Enterprise Cloud storage solution unless either: <br />(a) The Cloud storage provider is treated as any other Sub -Contractor, and agrees in writing to <br />all of the requirements within this exhibit; or <br />(b) The Cloud storage solution used is FedRAMP certified. <br />(3) If the Data includes protected health information covered by the Health Insurance Portability and <br />Accountability Act (HIPAA), the Cloud provider must sign a Business Associate Agreement prior <br />to Data being stored in their Cloud solution. <br />8, Method of Transfer. <br />a. All Data transfers to or from the Contractor shalt only be made by using the secure data.wa.gov <br />portal provided by the state of Washington with login and hardened password security. <br />b. The Contractor shalt use an encrypted email account for electronic submissions which contain <br />Confidential, and Personal Information, as defined in the General Terms and Conditions. <br />Information regarding encrypted email accounts can be obtained at DCYF's website, located at: <br />httDsaA+�rmtw.dcy_f wa,gov/servia�slcttiid_v�,le fa�Ye_providers/encry,c�maii- <br />9. System Protection. To prevent compromise of systems which contain DCYF Data or through which <br />that Data passes: <br />a. Systems containing Data must have all security patches or hotfixes applied within three (3) months <br />of being made available; <br />b. The Contractor will have a method of ensuring that the requisite patches and hotfixes have been <br />applied within the required timeframes; <br />c. Systems containing Data shall have an Anti-Malware application; if available, installed; and <br />Department of Children, Yo(tth & Families <br />2017CF County Program Agreement (8-'I-2019) Page 13 <br />