minimum_required_data_policy
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
minimum_required_data_policy [2019/03/27 18:22] – tonyromero | minimum_required_data_policy [2019/03/28 16:21] (current) – removed tonyromero | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ===== Data Privacy Policies ===== | ||
- | |||
- | - [[Privacy and Security Policies and Procedures User/SEHD Server/ | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - Identification of a Privacy and Security Board and Officer Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - Management Oversight of Privacy and Security Programs Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - Sanctions for Violations of Policies and Procedures User/SEHD Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - APS-6005 [[https:// | ||
- | - Reporting Potential Problems in Privacy and Security User/SEHD Server/OIT | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - Incident Response and Incident Response Mitigation User/SEHD Server/ | ||
- | - University HIPAA Policy [[http:// | ||
- | - See attached Incident Response Process Flow Diagram for unit/ | ||
- | - Privacy and Security Training User/SEHD | ||
- | - Access Control, Minimum Necessary Access and Verification for Access to Data User/SEHD Database Server/OIT | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - APS-6001 [[https:// | ||
- | - Password Management User/SEHD Database Server/OIT – complying with university policy | ||
- | - University Password Policy [[http:// | ||
- | - Transmitting Sensitive Information Securely including Faxing and Email User/ | ||
- | - Email and Webmail Stay Secure [[https:// | ||
- | - HIPAA Policy 7.1 Safeguards [[https:// | ||
- | - Log-in Monitoring Database Server/OIT | ||
- | - Needs to be implemented and documented | ||
- | - OIT has an internal standard for logging, monitoring and auditing that applies to all servers managed by CU Denver OIT. | ||
- | - HIPAA Policy 9.3 Auditing [[http:// | ||
- | - Workstation Security Configuration User/SEHD, Server/OIT – duplicative with #1 | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - Device and Media Control Database Server/OIT – duplicative with #1 | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - Securing Materials with Data User/ | ||
- | - Security and Compliance Hard Drive Disposal [[https:// | ||
- | - Encryption Database Server/OIT | ||
- | - Encrypt Your Laptop Guidance [[https:// | ||
- | - Guide to Secure Devices [[https:// | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - Authorizations for Personal Health Information, | ||
- | - University HIPAA Policy [[http:// | ||
- | - Permitted Uses and Disclosures of PHI, if applicable User/ | ||
- | - University HIPAA Policy [[http:// | ||
- | - HIPAA Status, if applicable Server/OIT | ||
- | - UC Denver’s File servers are HIPAA compliant. | ||
- | - Units/ | ||
- | - Business Associate Status, if applicable | ||
- | - NA | ||
- | - Designating Sensitive Information User/SEHD – may be duplicative | ||
- | - University Data Classifications and Impact [[https:// | ||
- | - Risk Assessments and Management User/SEHD – duplicative | ||
- | - University HIPAA Policy [[http:// | ||
- | - Change Control Procedures User/SEHD – user access/ | ||
- | - OIT is also working on a process flow diagram to guide units/ | ||
- | - Audit and Evaluation Procedures User/SEHD Server/OIT – designated liaison and form for auditors | ||
- | - Units/ | ||
- | |||
- | Sample Local Education Agency Policy Links: [[http:// | ||
- | |||
minimum_required_data_policy.1553710974.txt.gz · Last modified: 2019/03/27 18:22 by tonyromero