Laserfiche WebLink
5. Maintain an inventory of devices; and <br />6. Ensure that when being transported outside of a Secured Area, all devices <br />with Data are under the physical control of an Authorized User. <br />b. Paper documents. Any paper records containing Confidential Information must be protected <br />by storing the records in a Secured Area that is accessible only to authorized personnel. <br />When not in use, such records must be stored in a locked container, such as a file cabinet, <br />locking drawer, or safe, to which only authorized persons have access. <br />4. CONFIDENTIAL INFORMATION SEGREGATION <br />HCA Confidential Information received under this Contract must be segregated or otherwise <br />distinguishable from non -HCA data. This is to ensure that when no longer needed by the <br />Contractor, all HCA Confidential Information can be identified for return or destruction. It also <br />aids in determining whether HCA Confidential Information has or may have been compromised <br />in the event of a security Breach. <br />a. The HCA Confidential Information must be kept in one of the following ways: <br />on media (e.g., hard disk, optical disc, tape, etc.) which will contain only HCA Data; <br />or <br />ii. in a logical container on electronic media, such as a partition or folder dedicated to <br />HCA's Data; or <br />iii. in a database that will contain only HCA Data; or <br />iv. within a database and will be distinguishable from non -HCA Data by the value of a <br />specific field or fields within database records; or <br />V. when stored as physical paper documents, physically segregated from non -HCA <br />Data in a drawer, folder, or other container. <br />b. When it is not feasible or practical to segregate HCA Confidential Information from non - <br />HCA data, then both the HCA Confidential Information and the non -HCA data with which it <br />is commingled must be protected as described in this Attachment. <br />5. CONFIDENTIAL INFORMATION SHARED WITH SUBCONTRACTORS <br />If HCA Confidential Information provided under this Contract is to be shared with a <br />Subcontractor, the contract with the Subcontractor must include all of the Confidential <br />Information Security Requirements. <br />6. CONFIDENTIAL INFORMATION DISPOSITION <br />When the Confidential Information is no longer needed, except as noted below, the Confidential <br />Information must be returned to HCA or destroyed. Media are to be destroyed using a method <br />documented within NIST 800-88 (httpa/csrc.nist.gov/publications/PubsSPs.html). <br />Washington State 31 Description of Services <br />Health Care Authority HCA Contract #K5885 <br />