Laserfiche WebLink
1 <br />EXHIBIT A <br />DATA SECURITY REQUIREM ENTS <br />ORGANIZATION OF DATA SECURITY REQUIREMENTS <br />1. Definitions <br />2. Authority <br />3. Scope of Protection <br />4. Compliance with Laws, Rules, Regulations, and Policy5. Administrative Controls <br />6. Authorization, Authentication, and Access7. Protection of Data <br />B. Method of TransferL System Protection <br />10. Data Segregation <br />'1 1. Confidentiality Protection <br />12. Dala Disposition <br />13. Data shared with Subcontractors <br />14. Notification of Compromise or Potential Compromise <br />15. Breach of Data <br />'16. Public Disclosure <br />Definitions. The words and phrases listed below, as used in this Exhibit, shall each have the following <br />definitions: <br />a. 'AES' means the Advanced Encryption Standard, a specification of Federal lnformation processin g <br />standards Publications for the encryption of electronic data issued by the National lnstitute of <br />Standards and Technology (htto://nv ubs.nist.oov/n IPS/NIST FIP .197.odf) <br />b. "Authorized Users(s)" means an individual or individuals with a business need to access DCYFconfidential lnformation and who has been authorized to do so. <br />c' "Business Associate Agreement" means an agreement between DCYF and a contractor who isreceiving Data covered under the Privacy and Security Rules of the Health lnsurance portability <br />and Accountability Act of 1996. The agreement establishes permitted and required uses anddisclosures of protected health information (PHl) in accordance with HIpAA requirements andprovides obligations for business associates to safeguard the information. <br />d. "Category 4 Data" is data that is confidential and requires special handling due to statutes orregulations that require especially strict protection of the data and from whictr especially seriousconseq uences may arise in the event of any compromise of such data. Data classified as Category4 includes but is not limited to data protected by: the Health lnsurance Portability and Accounta[if ityAct (HIPAA), Pub' L. 104-19'1 as amended by t'he Health lnformation Tech;;tdi for Economic andClinical Health Aclof 2009 (HITECH), 45 CFR Parts 160 and 104; the Famity E?ucationat Rightsand Privacy Act (FERPA), 20 U.S.C. $12329; 34 CFR Part 99; lnternal Revenue ServicePublication 1075 (.ff!p-q,l]:t:t:ty..uL*rs-.gp:Jp^&In.:.p*d!J-pL-g]_5.p_d0; substance Abuse and Mentat HeatthServices Administration regulations on confiA;nt6n;6 oi"AiConol and Drug Abuse patient Records,42 CFR Parl'2; and/or Criminal Justice lnformation Services, 28 CFR pai ZO. <br />Department of Children, youth & Famijies <br />2017CF County Program Agreement 6-24_20 <br />Page B