Laserfiche WebLink
DocuSign Envelope ID: 262ABAl8-5354-4F41-9508-91313C8ACBA6D <br />Attachment 1 <br />Confidential Information Security Requirements <br />1. Definitions <br />In addition to the definitions set out in Section 1, Definitions, of this Contract for Medicaid <br />Administrative Claiming (MAC) Services, the definitions below apply to this attachment. <br />a. "Hardened Password" means a string of characters containing at least three of the <br />following character classes: upper case letters; lower case letters; numerals; and <br />special characters, such as an asterisk, ampersand or exclamation point. <br />Passwords for external authentication must be a minimum of ten (10) <br />characters long. <br />Passwords for internal authentication must be a minimum of eight (8) <br />characters long. <br />iii. Passwords used for system service or service accounts must be a minimum <br />of twenty (20) characters long. <br />b. "Portable/Removable Media" means any Data storage device that can be detached or <br />removed from a computer and transported, including but not limited to: optical media <br />(e.g. CDs, DVDs); USB drives; or flash media (e.g. CompactFlash, SD, MMC). <br />c. "Portable/Removable Devices" means any small computing device that can be <br />transported, including but not limited to: handhelds/PDAs/Smartphones; Ultramobile <br />PC's, flash memory devices (e.g. USB flash drives, personal media players); and <br />laptops/notebook/tablet computers. If used to store Confidential Information, devices <br />should be Federal Information Processing Standards (FIPS) Level 2 compliant. <br />d. "Secured Area" means an area to which only Authorized Users have access. Secured <br />Areas may include buildings, rooms, or locked storage containers (such as a filing <br />cabinet) within a room, as long as access to the Confidential Information is not <br />available to unauthorized personnel. <br />e. "Transmitting" means the transferring of data electronically, such as via email, SFTP, <br />webservices, AWS Snowball, etc. <br />f. "Trusted System(s)" means the following methods of physical delivery: (1) hand - <br />delivery by a person authorized to have access to the Confidential Information with <br />written acknowledgement of receipt; (2) United States Postal Service ("USPS") first <br />class mail, or USPS delivery services that include Tracking, such as Certified Mail, <br />Express Mail or Registered Mail; (3) commercial delivery services (e.g. FedEx, UPS, <br />DHL) which offer tracking and receipt confirmation; and (4) the Washington State <br />Campus mail system. For electronic transmission, the Washington State <br />Washington State Page 22 of 53 HCA IAA K4649 <br />Health Care Authority Revised 10/2020 <br />