![]() |
![]() |
|||||||||||
|
| ||||||||||||
________________________________________________________________________________________________________________
Section VIII: |
Privacy and Security |
Title: |
Security Manual |
Chapter: |
Data Protection Policy |
Current Effective Date: |
6/15/05 |
Revision History: |
|
Original Effective Date: |
________________________________________________________________________________________________________________
The Department of Health and Human Services (DHHS) collects and processes a significant volume of data and information required to provide services to the residents of North Carolina. DHHS data includes sensitive individually-identifiable health information, personal, financial and operational information that must be protected in accordance with state and federal law. This policy establishes a comprehensive data protection process within all DHHS Divisions/Offices that includes data stewardship, data management, data transmission and data encryption as appropriate.
DHHS data shall be protected from unauthorized or accidental disclosure, misuse, modification or loss. This comprehensive policy is comprised of four (4) components:
Data Stewardship - Promotes data security, by designating roles and responsibilities for the appropriate control and stewardship of DHHS data. To effectively implement information security, there must be an assignment of responsibility to protect information and as well as provide accountability within an organization.
Data Management – Ensures the safe storage and handling of sensitive information. Data security is provided through the implementation of physical, technical and administrative security controls.
Data Transmissions – Ensures that sensitive data are protected during transmission. Security controls are needed to both prevent unauthorized access as well as protect the data from being read if accessed.
Data Protection Controls – Provides a broad set of requirements on protecting sensitive/critical data for the DHHS Divisions/Offices.
DHHS Privacy & Security Office - The DHHS Privacy & Security Office (PSO) shall develop standards and implementation guidelines that will include the following: Data Stewardship, Desktop Security, Data Access and Control, Data Protection Controls, Laptop/PDA Security, Records Management, Data Storage and Archiving, Email Security, Property Control, Application/Database security, and Network Security. Enterprise-wide procedures will be developed through a joint effort of the PSO and the DHHS Security Work Group (SWG) to ensure they meet the needs of the DHHS Divisions/Offices. The procedures established shall, to the extent possible, control, reduce or eliminate the risk of breaches of data protection.
Office of Information Technology Services - The Office of Information Technology Services (ITS) shall be responsible for ensuring adequate security on the North Carolina Integrated Information Network (NCIIN). In addition, to providing Internet access and email security, ITS is responsible for maintaining the security of DHHS mainframe applications. The ITS Security Office publishes IT Security policies and standards that DHHS is required to implement.
The Division of Information Resources Management – The Division of Information Resources Management (DIRM) shall be responsible for implementing and providing adequate security for the DHHS applications/systems maintained for divisions/offices. The security requirements will be implemented in accordance with DHHS security procedures and standards as developed by ITS and DHHS PSO.
DHHS Divisions/Offices - DHHS Divisions/Offices shall be responsible for implementing and providing adequate security for any application/system not maintained by DIRM. In this context, the DHHS Divisions/Offices shall be responsible for the classification of all data (see DHHS Data Classification Policy for details) and for evaluating and ensuring the adequacy of all security controls at the DHHS Divisions/Offices. For those applications/systems maintained by DIRM as an affiliate of a Division/Office, DIRM shall be responsible for ensuring the adequacy of the security controls.
If a DHHS Division/Office has outsourced work to a contractor, they are responsible for providing oversight to ensure the contractor is providing adequate security.
Policy implementation shall comply with the referenced standards and management approved best practices.
For enforcement questions or clarification on any of the information contained in this policy, please contact DHHS Security Officer. For general questions about department-wide policies and procedures, contact the DHHS Policy Coordinator.
Any exceptions to this policy will require written authorization. Exceptions granted will be issued a policy waiver for a defined period of time. Requests for exceptions to this policy should be addressed to the Director of the Division of Information Resource Management (DIRM). The waiver request will be processed in accordance with the DHHS ITS Waiver and Appeals Policy.
|
|