Laserfiche WebLink
b. When transmitting HCA's Confidential Information via paper documents, the Contractor must use <br />a Trusted System and must be physically kept in possession of an authorized person <br />3. Protection of Data <br />The Contractor agrees to store and protect Confidential Information as described: <br />a. Data at Rest: <br />Data will be encrypted with NIST 800 -series approved algorithms. Encryption keys will be <br />stored and protected independently of the data. Access to the Data will be restricted to <br />Authorized Users through the use of access control lists, a Unique User ID, and a <br />Hardened Password, or other authentication mechanisms which provide equal or greater <br />security, such as biometrics or smart cards. Systems which contain or provide access to <br />Confidential Information must be located in an area that is accessible only to authorized <br />personnel, with access controlled through use of a key, card key, combination lock, or <br />comparable mechanism. <br />Data stored on Portable/Removable Media or Devices: <br />(A) Confidential Information provided by HCA on Removable Media will be <br />encrypted with NIST 800 -series approved algorithms. Encryption keys will be <br />stored and protected independently of the Data. <br />(B) HCA's data must not be stored by the Contractor on Portable Devices or Media <br />unless specifically authorized within the DSA. If so authorized, the Contractor <br />must protect the Data by: <br />(1) Encrypting with NIST 800 -series approved algorithms. Encryption <br />keys will be stored and protected independently of the data; <br />(2) Control access to the devices with a Unique User ID and Hardened <br />Password or stronger authentication method such as a physical <br />token or biometrics; <br />(3) Keeping devices in locked storage when not in use; <br />(4) Using check-in/check-out procedures when devices are shared; <br />(5) Maintain an inventory of devices; and <br />(6) Ensure that when being transported outside of a Secured Area, all <br />devices with Data are under the physical control of an Authorized <br />User. <br />b. Paper documents. Any paper records containing Confidential Information must be protected by <br />storing the records in a Secured Area that is accessible only to authorized personnel. When not in <br />use, such records must be stored in a locked container, such as a file cabinet, locking drawer, or <br />safe, to which only authorized persons have access. <br />Washington State <br />Health Care Authority Page 18 HCA Contract No. K5885-1 <br />