Laserfiche WebLink
ATTACHMENT A <br />HIPAA AND DATA SECURITY REOUIREMENTS <br />Authorized Users through the use of access control lists which will grant access only <br />after the Authorized User has authenticated to the network using a Unique User lD <br />and Hardened Password or other authentioation mechanisms which provide equal or <br />greater security, such as biometrics or smart cards. Data on disks mounted to such <br />servers must be located in an area which is accessible only to authorized personnel, <br />wlth access controlled through use of a key, card key, combination lock, or comparable <br />rnechanism. <br />For DOC Confidential lnformation stored on these disks, deleting unneeded Data is <br />sufficient as long as the disks remain in a Secure Area and otherwise rneet the <br />requirements listed in the above paragraph. Destruction of the Data, as outlined below <br />in Section B Data Disposition, may be deferred untilthe disks are retired, replaced, or <br />otherwise taken out of the Secure Area. <br />c, Optlcal discs (CDs or DVDs) In local workstation optical disc drives. Data <br />provided by DOC on optical discs which will be used in local workstation optical disc <br />drives and which will not be transported out of a Secure Area. When not in use for the <br />contracted purpose, such discs must be $tored in a Secure Area. Workstations which <br />access DOC Data on optical discs must be located in an area which is accessible only <br />to authorized personnel, with access controlled through use of a key, card key, <br />combination lock, or comparable rnechanism, <br />d. Optical discs (CDs or DVDs) in drives or jukeboxes attached to servers, Data <br />provided by DOC on optical discs which will be attached to networkservers and which <br />will not be transported out of a Secure Area. Access to Data on these discs will be <br />restricted to Authorized Users through the use of access control lists which will grant <br />access only afterthe Authorized User has authenticated to the network using a Unique <br />User lD and Hardened Password or other authentication mechanisms which provide <br />equal or greater security, such as biometrics or smart cards. Data on discs attached <br />to such servers must be located in an area which is accessible only to authorized <br />personnel, with access controlled through use of a key, card key, combination lock, or <br />comparable mechanism. <br />e. Paper documents. Any paper records must be protected by storing the records in a <br />Secure Area which is only accessible to authorized personnel. When not in use, such <br />records must be stored in a Secure Area. <br />f, Remote Access. Access to and use of the Dala over the State Governmental <br />Network (SGN) or Secure Access Washington (SAW will be controlled by DOC staff <br />who will issue authentication credentials (e,9. a Unique User lD and Hardened <br />Password) to Authorized Users on Contractor's staff, Contractor will notifu DOC statf <br />immediately whenever an Authorized User in possession of such credentials is <br />terminated or otheruvise leaves the employ of the Contractor, and whenever an <br />Authorlzed User'$ duties change such that the Authorized User no longer requires <br />access to perform work for this Contract. <br />g, Data storage on portable devices or media. <br />(1) Except where otherwise specified herein, DOC Data shall not be stored by the <br />Contractor on portable devices or media unless specificatly authorized within the <br />Washington $taLe <br />Department of Corre ctions <br />Kl4078 <br />Attachment A <br />Page1,4of 19 <br />26RAD