Laserfiche WebLink
purpose that is not directly connected with the performance of the services <br />contemplated hereunder, except: <br />25.1.1 As provided by law; or <br />25.1.2 In the case of Personal Information as defined by personal and <br />sensitive information that if improperly used or released may do <br />significant harm to a patient's interests in privacy, health care, other <br />interests, or as provided by law or with the prior written consent of the <br />person or personal representative of the person who is the subject of <br />the Personal information. <br />25.2 The Contractor shall protect and maintain all Confidential Information gained <br />by reason of this Agreement against unauthorized use, access, disclosure, <br />modification or loss. This duty requires the Contractor to employ reasonable <br />security measures, which include restricting access to the Confidential <br />Information by: <br />25.2.1 Allowing access only to staff that have an authorized business <br />requirement to view the confidential information. <br />25.2.2 Physically securing any computers, documents, or other media <br />containing the Confidential Information. <br />25.2.3 Ensure the security of Confidential Information transmitted via fax <br />(facsimile) by verifying the recipient phone number to prevent <br />accidental transmittal of Confidential Information to unauthorized <br />persons. <br />25.2.4 When transporting six (6) to one hundred forty nine (149) records <br />containing Confidential Information outside a Secure Area, do one or <br />more of the following as appropriate: <br />25.2.4(1) Use a Trusted System <br />25.2.4(2) Encrypt the Confidential Information, including: <br />25.2.4(2)(i) Email and/or email attachments. <br />25.2.4(2)(ii) Confidential Information when it is stored on <br />portable devices or media, including but not limited to <br />laptop computers and flash memory devices. <br />Professional Services Agreement <br />Page 11 <br />