Laserfiche WebLink
Special Terms and Conditions <br />(3) lf the Data includes protected health information covered by the Health lnsurance portability andAccountability Act (HIPAA), the Cloud provider must sign a Business nssociate Agreement priorto Data being stored in their Cloud solution. <br />7 <br />6.System Protection. To prevent compromise of systems which conlain DSHS Data or through whichthat Data passes: <br />a. Systems containing DSHS Data must have all security patches or hotfixes applied within 3 monthsof being made available. <br />b. The Contractor will have a method of ensuring that the requisite patches and hotfixes have beenapplied within the required timeframes. <br />c' Systems containing DSHS Data shall have an Anti-Malware application, if available, installed. <br />d' Anti-Malware software shall be kept up to date. The product, its anti-virus engine, and any malwaredatabase the system uses, will be no more than one update behind current. <br />Data Segregation. <br />a' DSHS category 4 data must be segregated or othenruise distinguishable from non-DSHS data. Thisis to ensure that when no longer needed by the Contractor, allbSHS Data can be identified forreturn or destruction. lt also aids in determining whether DSHS Data has or may-hive beencompromised in the event of a security breach. As such, one or more of the folliwing methods willbe used for data segregation <br />(1 ) DSHS Data will be kept on media (e.g. hard disk, optical disc, tape, etc.) which will contain nonon-DSHS Data. <br />(2) DSHS Data will be^slored in a logical container on electronic media, such as a partition or folderdedicated to DSHS Data. <br />(3) DSHS Data will be stored in a database which will contain no non-DSHS data. And/or, <br />(4) DSHS Data will be stored within a database and will be distinguishable from non-DSHS data bythe value of a specific fierd or fields within database records. <br />(5) When stored as physical paper documents, DSHS Data will be physically segregated from non-DSHS data in a drawer, folder, or other container. <br />b. When it is not feasible orpraclicalto segregate DSHS Data from non-DSHS data, then both theDSHS Data and the non-DSHS data with which it is commingled must ne protecieO as described inthis exhibit. <br />Data Disposition. When the contracted work has been completed orwhen the Data is no longerneeded, except as noted above in Section 5.b, Data shall be returned to DSHS or destroyed. Media onwhich Data may be stored and associated acceptable methods of destruction are as follows: <br />8. <br />Data stored on:Will be dest ed <br />Se rver or workstation hard disks, or Using a "wipe" utility which will ovenryrite the Data at <br />least three (3) times using either random or single <br />character data, or <br />DSHS Central Contract Services <br />1 769CS County Agreement 05-1 6-2023 <br />Page 25