Laserfiche WebLink
Attachment 2: Data Security Requirements <br />1. Definitions <br />In addition to the definitions set out in the Data Use, Security, and Confidentiality Schedule, the <br />definitions below apply to this Attachment. <br />a. "Hardened Password" means a string of characters containing at least three of the following <br />character classes: upper case letters; lower case letters; numerals; and special characters, such <br />as an asterisk, ampersand or exclamation point. <br />Passwords for external authentication must be a minimum of 10 characters long. <br />Passwords for internal authentication must be a minimum of 8 characters long. <br />ii. Passwords used for system service or service accounts must be a minimum of 20 <br />characters long. <br />b. "Portable/Removable Media" means any data storage device that can be detached or removed <br />from a computer and transported, including but not limited to: optical media (e.g. CDs, DVDs); <br />USB drives; or flash media (e.g. CompactFlash, SD, MMC). <br />c. "Portable/Removable Devices" means any small computing device that can be transported, <br />including but not limited to: handhelds/PDAs/Smartphones; Ultramobile PCs, flash memory <br />devices (e.g. USB flash drives, personal media players); and laptop/notebook/tablet computers. If <br />used to store Confidential Information, devices should be Federal Information Processing <br />Standards (FIPS) Level 2 compliant. <br />d. "Secured Area" means an area to which only Authorized Users have access. Secured Areas may <br />include buildings, rooms, or locked storage containers (such as a filing cabinet) within a room, as <br />long as access to the Confidential Information is not available to unauthorized personnel. <br />e. "Transmitting" means the transferring of data electronically, such as via email, SFTP, <br />webservices, AWS Snowball, etc. <br />"Trusted System(s)" means the following methods of physical delivery: (1) hand -delivery by a <br />person authorized to have access to the Confidential Information with written acknowledgement <br />of receipt; (2) United States Postal Service ("USPS") first class mail, or USPS delivery services <br />that include Tracking, such as Certified Mail, Express Mail, or Registered Mail; (3) commercial <br />delivery services (e.g. FedEx, UPS, DHL) which offer tracking and receipt confirmation; and (4) <br />the Washington State Campus mail system. For electronic transmission, the Washington State <br />Governmental Network (SGN) is a Trusted System for communications within that Network. <br />g. "Unique User ID" means a string of characters that identifies a specific user and which, in <br />conjunction with a password, passphrase, or other mechanism, authenticates a user to an <br />information system. <br />2. Data Transmission <br />a. When transmitting HCA's Confidential Information electronically, including via email, the Data <br />must be encrypted using NIST 800 -series approved algorithms <br />(http:Hcsrc.nist.gov/publications/PubsSPs.html). This includes transmission over the public <br />internet. <br />Washington State <br />Health Care Authority Page 17 HCA Contract No. K5885-1 <br />