minimum_required_data_policy
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
minimum_required_data_policy [2019/03/27 18:59] – tonyromero | minimum_required_data_policy [2019/03/28 16:21] (current) – removed tonyromero | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ===== Data Privacy Policies ===== | ||
- | |||
- | - [[: | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Identification of a Privacy and Security Board and Officer|]] Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Management Oversight of Privacy and Security Programs|]] Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Sanctions for Violations of Policies and Procedures|]] User/SEHD Server/OIT | ||
- | - University HIPAA Policy [[http:// | ||
- | - APS-6005 [[https:// | ||
- | - [[Reporting Potential Problems in Privacy and Security|]] User/SEHD Server/OIT | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Incident Response and Incident Response Mitigation|]] User/SEHD Server/ | ||
- | - University HIPAA Policy [[http:// | ||
- | - See attached Incident Response Process Flow Diagram for unit/ | ||
- | - [[Privacy and Security Training|]] User/SEHD | ||
- | - [[Access Control, Minimum Necessary Access and Verification for Access to Data|]] User/SEHD Database Server/OIT | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - APS-6001 [[https:// | ||
- | - [[Password Management|]] User/SEHD Database Server/OIT – complying with university policy | ||
- | - University Password Policy [[http:// | ||
- | - [[Transmitting Sensitive Information Securely including Faxing and Email|]] User/ | ||
- | - Email and Webmail Stay Secure [[https:// | ||
- | - HIPAA Policy 7.1 Safeguards [[https:// | ||
- | - [[Log-in Monitoring|]] Database Server/OIT | ||
- | - Needs to be implemented and documented | ||
- | - OIT has an internal standard for logging, monitoring and auditing that applies to all servers managed by CU Denver OIT. | ||
- | - HIPAA Policy 9.3 Auditing [[http:// | ||
- | - [[Workstation Security Configuration|]] User/SEHD, Server/OIT – duplicative with #1 | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Device and Media Control Database|]] Server/OIT – duplicative with #1 | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Securing Materials with Data|]] User/ | ||
- | - Security and Compliance Hard Drive Disposal [[https:// | ||
- | - [[Encryption|]] Database Server/OIT | ||
- | - Encrypt Your Laptop Guidance [[https:// | ||
- | - Guide to Secure Devices [[https:// | ||
- | - APS-6005 [[https:// | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Authorizations for Personal Health Information|]], | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Permitted Uses and Disclosures of PHI|]], if applicable User/ | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[HIPAA Status|]], if applicable Server/OIT | ||
- | - UC Denver’s File servers are HIPAA compliant. | ||
- | - Units/ | ||
- | - Business Associate Status, if applicable | ||
- | - NA | ||
- | - [[Designating Sensitive Information|]] User/SEHD – may be duplicative | ||
- | - University Data Classifications and Impact [[https:// | ||
- | - [[Risk Assessments and Management|]] User/SEHD – duplicative | ||
- | - University HIPAA Policy [[http:// | ||
- | - [[Change Control Procedures|]] User/SEHD – user access/ | ||
- | - OIT is also working on a process flow diagram to guide units/ | ||
- | - [[Audit and Evaluation Procedures|]] User/SEHD Server/OIT – designated liaison and form for auditors | ||
- | - Units/ | ||
- | |||
- | Sample Local Education Agency Policy Links: [[http:// | ||
- | |||
minimum_required_data_policy.1553713150.txt.gz · Last modified: 2019/03/27 18:59 by tonyromero