Laserfiche WebLink
DocuSign Envelope ID: 262ABA18-5354-4F41-9508-9B13C8ACBA6D <br />Governmental Network (SGN) is a Trusted System for communications within that <br />Network. <br />g. "Unique User ID" means a string of characters that identifies a specific user and which, <br />in conjunction with a password, passphrase, or other mechanism, authenticates a user <br />to an information system. <br />2. Confidential Information Transmitting <br />a. When transmitting HCA's Confidential Information electronically, including via email, <br />the Data must be encrypted using NIST 800 -series approved algorithms <br />(htl ://csrc.nist. ovl uhiicationslPubsSPs.htii�1). This includes transmission over the <br />public internet. <br />b. When transmitting HCA's Confidential Information via paper documents, the Receiving <br />Party must use a Trusted System. <br />3. Protection of Confidential Information <br />The Contractor agrees to store Confidential Information as described <br />a. Data at Rest: <br />Data will be encrypted with NIST 800 -series approved algorithms. Encryption <br />keys will be stored and protected independently of the data. Access to the Data <br />will be restricted to Authorized Users through the use of access control lists, a <br />Unique User ID, and a Hardened Password, or other authentication mechanisms <br />which provide equal or greater security, such as biometrics or smart cards. <br />Systems which contain or provide access to Confidential Information must be <br />located in an area that is accessible only to authorized personnel, with access <br />controlled through use of a key, card key, combination lock, or comparable <br />mechanism. <br />Data stored on Portable/Removable Media or Devices: <br />Confidential Information provided by HCA on Removable Media will be <br />encrypted with NIST 800 -series approved algorithms. Encryption keys will <br />be stored and protected independently of the Data. <br />HCA's data must not be stored by the Receiving Party on Portable Devices <br />or Media unless specifically authorized within the Data Share Agreement. If <br />so authorized, the Receiving Party must protect the Data by: <br />1. Encrypting with NIST 800 -series approved algorithms. Encryption <br />keys will be stored and protected independently of the data; <br />Washington State Page 23 of 53 HCA IAA K4649 <br />Health Care Authority Revised 10/2020 <br />