Laserfiche WebLink
Attachment 2: Data Security Requirements <br />1. Definitions <br />ln addition to the definitions set out in the Data Use, Security, and Confidentiality Schedule, the <br />definitions below apply to this Attachment. <br />a. "Hardened Password" means a string of characters containing at least three of the foltowing <br />character classes: upper case letters; lower case letters; numerals; and special characters, such <br />as an asterisk, ampersand or exclamation point. <br />i. Passwords for external authentication must be a minimum of 10 characters long. <br />i. Passwords for internal authentication must be a minimum of 8 characters long. <br />ii. Passwords used for system service or service accounts must be a minimum of 20 <br />characters long. <br />b. "Portable/Removable Media" means any data storage device that can be detached or removed <br />from a computer and transported, including but not limited to: optical media (e.g. CDs, DVDs); <br />USB drives; or flash media (e.9. CompactFlash, SD, MMC). <br />c. "Portable/Removable Devices" means any small computing device that can be transported, <br />including but not limited to: handheldslPDAslsmartphones; Ultramobile PCs, flash memory <br />devices (e.9. USB flash drives, personal media players); and laptop/notebooUtablet computers. lf <br />used to store Confidential lnformation, devices should be Federal lnformation Processing <br />Standards (FIPS) Level 2 compliant. <br />d. "Secured Area" means an area to which only Authorized Users have access. Secured Areas may <br />include buildings, rooms, or locked storage containers (such as a filing cabinet) within a room, as <br />long as access to the Confidential lnformation is not available to unauthorized personnel. <br />e. "Transmitting" means the transferring of data electronically, such as via email, SFTP, <br />webservices, AWS Snowball, etc. <br />f. "Trusted System(s)" means the following methods of physical delivery: (1) hand-delivery by a <br />person authorized to have access to the Confidential lnformation with written acknowledgement <br />of receipt; (2) United States Postal Service ('USPS") first class mail, or USPS delivery services <br />that include Tracking, such as Certified Mail, Express Mail, or Registered Mail; (3) commercial <br />delivery services (e.9. FedEx, UPS, DHL) which offer tracking and receipt confirmation; and (4) <br />the Washington State Campus mail system. For electronic transmission, the Washington State <br />Governmental Network (SGN) is a Trusted System for communications within that Network. <br />g. "Unique User lD" means a string of characters that identifies a specitic user and which, in <br />conjunction with a password, passphrase, or other mechanism, authenticates a user to an <br />information system. <br />2. Data Transmission <br />a. When transmitting HCA's Confidential lnformation electronically, including via email, the Data <br />must be encrypted using NIST 8O0-series approved algorithms <br />(htto:llcsrc.nist.qovlpubliqationslPubsSPs.html). This includes transmission over the public <br />internet. <br />Washington State <br />Haalth Care Authoity Page 17 HCA Contract Na. K5885-1