My WebLink
|
Help
|
About
|
Sign Out
Home
Browse
Search
Fully Executed Contract
>
Meetings
>
2026
>
07. July
>
2026-07-21 10:00 AM - Commissioners' Agenda
>
Fully Executed Contract
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
7/27/2026 10:19:22 AM
Creation date
7/27/2026 10:19:06 AM
Metadata
Fields
Template:
Meeting
Date
7/21/2026
Meeting title
Commissioners' Agenda
Location
Commissioners' Auditorium
Address
205 West 5th Room 109 - Ellensburg
Meeting type
Regular
Meeting document type
Fully Executed Version
Supplemental fields
Item
Request to Approve a Resolution Authorizing Execution of the Agreement between the Washington State Department of Corrections and Kittitas County
Order
9
Placement
Consent Agenda
Row ID
146685
Type
Contract
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
31
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
ATTACHMENT A <br />HIPAA AND DATA SECURITY REOUIREMENTS <br />g. When accessing the Data from within the Contractor's network (the Data stays within <br />the Contractor's network at all times), enforce password and logon requirements for <br />users within the Conhactor's neiwork, including: <br />(1) A minimum length of B characters, and containing at least three of the followlng <br />character classes: uppercase letters, lowercase letters, numerals, and special <br />characters such as an asterisk, ampersand, or exclamation point. <br />(2) That a password does not contain a user's name, logon lD, or any form of their full <br />name. <br />(3) That a password does not consist of a single dictionary word. A password may be <br />formed as a passphrase which consists of multiple dictionary words- <br />(4) That passwords are significantly different from the previous four passwords. <br />Passwords that increment by simply adding a number are not considered <br />significantly different. <br />h. When accessing Confidential lnformation from an external location (the Data will <br />traverse the lnternet or othenruise travel outside the Contractor's network), mitigate risk <br />and enforce password and logon requirements for users by employing measures <br />including: <br />(1) Ensuring mitigations applied to the system don't allow end-user modification. <br />(2) Not allowing the use of dial-up connections. <br />(3) Using industry standard protocols and solutions for remote access. Examples <br />would include RADIUS and Citrix. <br />(4) Encrypting all remote access traffic from the external workstation to Trusted <br />Network or to a component within the Trusted Network networks (using key lengths <br />of 128 bits or greater) Algorithm modules validated by the National lnstitute of <br />Standards and Technology (NIST) Crvptoqraohic Module Validation Proqram <br />(CMVP) are required. The tratfic must be encrypted at alltimes while traversing <br />any network, including the lnternet, which is not a Trusted Network. <br />(5) Ensuring that the remote access system prompts for re-authentication or performs <br />automated session termination after no more than 20 minutes of inactivity. <br />(6) Ensuring use of Multi-factor Authentication to connect from the external end point <br />to the internal end point. Authentication mechanisms must meet or exceed those <br />described in the most recent version of NIST SP 800-63 for information requiring <br />assurance level 3 or higher. One of the authentication factors should be provided <br />by a device separate from the computer gaining access. <br />(7) Ensuring all system and service accounts use Enterprise Active Directory or a <br />similar centralized authentication and authorization mechanism. lf authentication <br />methods such as SQL authentication are required by the system, Contractor uses <br />credentials secured during transmission through encrypted sessions such as <br />TLS1.2 (or greater) or lPSec, and in storage using a secure hash method validated <br />!Vashington State <br />Department of Corrections <br />K14078 <br />Attachment A <br />Page 12 of 19 <br />26RAD
The URL can be used to link to this page
Your browser does not support the video tag.