SEHD Wiki

A source for policies, procedures, handbooks and other resources from the School of Education and Human Development

User Tools

Site Tools


policy:data_privacy

This is an old revision of the document!


Data Privacy Policies

    1. See attached Incident Response Process Flow Diagram for unit/department responsibility.
  1. Password Management User/SEHD Database Server/OIT – complying with university policy
  2. Log-in Monitoring Database Server/OIT
    1. Needs to be implemented and documented
    2. OIT has an internal standard for logging, monitoring and auditing that applies to all servers managed by CU Denver OIT.
  3. Workstation Security Configuration User/SEHD, Server/OIT – duplicative with #1
  4. Device and Media Control Database Server/OIT – duplicative with #1
  5. Securing Materials with Data User/SEHD-duplicative with #1
  6. Encryption Database Server/OIT
  7. Authorizations for Personal Health Information, if applicable User/SEHD –NA
  8. Permitted Uses and Disclosures of PHI, if applicable User/SEHD—NA
  9. HIPAA Status, if applicable Server/OIT
    1. UC Denver’s File servers are HIPAA compliant.
    2. Units/Departments can request assistance from the RAC team on the security of data usage. https://www1.ucdenver.edu/offices/office-of-information-technology/services/security-and-compliance
  10. Business Associate Status, if applicable
    1. NA
  11. Designating Sensitive Information User/SEHD – may be duplicative
    1. University Data Classifications and Impact https://www.cu.edu/ois/data-classifications-impact
  12. Risk Assessments and Management User/SEHD – duplicative
  13. Change Control Procedures User/SEHD – user access/retiring users
    1. OIT is also working on a process flow diagram to guide units/departments on their role in this process and how the OIT CAB process fits into the process.
  14. Audit and Evaluation Procedures User/SEHD Server/OIT – designated liaison and form for auditors
    1. Units/Departments can request assistance from the RAC team on the security of data usage, but we are not auditors, nor do we have a specific form.

Sample Local Education Agency Policy Links: http://www.cde.state.co.us/dataprivacyandsecurity/sampleitpolicies

policy/data_privacy.1553794907.txt.gz · Last modified: 2019/03/28 17:41 by tonyromero