2,654
edits
No edit summary |
No edit summary |
||
Line 27: | Line 27: | ||
Policy No.: '''6045'''<br /> | Policy No.: '''6045'''<br /> | ||
Effective Date: '''11/21/03'''<br /> | Effective Date: '''11/21/03'''<br /> | ||
Revised Date: ''' | Revised Date: '''07/30/18 DRAFT'''<br /> | ||
Reviewed Date: '''07/ | Reviewed Date: '''07/30/18'''<br /> | ||
<br /> | <br /> | ||
<big>'''Privacy, Confidentiality and Security of Patient and Proprietary Information Policy'''</big><br /><br /> | <big>'''Privacy, Confidentiality and Security of Patient and Proprietary Information Policy'''</big><br /><br /> | ||
== Basis for Policy == | == Basis for Policy == | ||
To maintain the privacy, confidentiality and security of patient | To maintain the privacy, confidentiality and security of patient information in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and other proprietary, confidential or regulated information. | ||
== Policy == | == Policy == | ||
It is the policy of UNMC to maintain | It is the policy of UNMC to maintain the confidentiality of all regulated information, including but not limited to protected health information, controlled unclassified information and other regulated information, and all confidential proprietary information classified in accordance with UNMC's [https://info.unmc.edu/its-security/policies/procedures/data-classification.html Data Classification Procedure]. | ||
== Definitions (as defined by HIPAA 45 CFR 164.501) == | == Definitions (as defined by HIPAA 45 CFR 164.501) == | ||
*'''Affiliated Covered Entity (ACE)''' means University of Nebraska Medical Center, The Nebraska Medical Center, UNMC Physicians, University Dental Associates, Bellevue Medical Center and The Nebraska Pediatric Practice Plan as one covered entity for the purpose of sharing PHI under HIPAA. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members. | *'''Affiliated Covered Entity (ACE)''' means University of Nebraska Medical Center, The Nebraska Medical Center, UNMC Physicians, University Dental Associates, Bellevue Medical Center and The Nebraska Pediatric Practice Plan as one covered entity for the purpose of sharing PHI under HIPAA. ACE membership may change from time to time. The Notice of Privacy Practices lists current ACE members. | ||
*'''Business Associate''' means a third party who performs services on behalf of UNMC and has access to protected health information (PHI) when performing services; or provides one of the following services for UNMC involving access to PHI: claims processing, data analysis, data processing, practice management, utilization review, quality assurance, billing, benefit management, and repricing. | *'''Business Associate''' means a third party who performs services on behalf of UNMC and has access to protected health information (PHI) when performing services; or provides one of the following services for UNMC involving access to PHI: claims processing, data analysis, data processing, practice management, utilization review, quality assurance, billing, benefit management, and repricing. | ||
*'''Designated Record Set''' is the medical record and billing record. | *'''Designated Record Set''' is the medical record and billing record. | ||
*'''Individual''' means the person who is the subject of the protected health information (including ACE workforce who are patients) | *'''Individual'''means the person who is the subject of the protected health information (including ACE workforce who are patients). | ||
*'''Protected Health Information (PHI)''' is individually identifiable health information. Health information means any information, whether oral or recorded in any medium that: | |||
*'''Protected Health Information (PHI)''' is individually identifiable health information. Health information means any information, whether oral or recorded in any medium that: | |||
:*is created or received by ACE; and | :*is created or received by ACE; and | ||
:*relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual. | :*relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual. | ||
==Definitions== | |||
'''Controlled Unclassified Information (CUI)''' is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government wide policies but is not classified under Executive Order 13526 or the Atomic Energy Act, as amended. | |||
*'''Employee Records''' refers to all information, records and documents pertaining to any person who is an applicant or nominee for any University personnel position described in the Board of Regents Bylaws, § 3.1, regardless of whether any such person is ever actually employed by the University, and all information, records and documents pertaining to any person employed by the University. | |||
*'''Information Security''' is the ability to control access and protect information from unauthorized alteration, destruction, loss or accidental or intentional disclosure to unauthorized persons. | |||
*'''Proprietary Information''' is information relating to business practices, including but not limited to financial statements, contracts, and business plans; employee records; student records; and meeting minutes. | *'''Proprietary Information''' is information relating to business practices, including but not limited to financial statements, contracts, and business plans; employee records; student records; and meeting minutes. | ||
*'''Student Education Records''' means any information recorded in any way which directly relates to a student and is maintained by or on behalf of UNMC (education agency/institution). Student education record does not include a (i) sole possession record, (ii) law enforcement record, (iii) employee record of a person other than a student who is employed by UNMC by virtue of his or her status as a student at UNMC, (iv) alumni record and (v) medical record that is part of the common medical record shared by the Affiliated Covered Entity. Student education records are covered by the Family Educational Rights and Privacy Act (FERPA). | |||
*'''Workforce''' means employees, the medical staff, volunteers, trainees, and other persons whose conduct, in the performance of work for UNMC is under the direct control of UNMC, whether or not they are paid by UNMC. | *'''Workforce''' means employees, the medical staff, volunteers, trainees, and other persons whose conduct, in the performance of work for UNMC is under the direct control of UNMC, whether or not they are paid by UNMC. | ||
==Procedures== | ==Procedures== | ||
===Patient Information=== | ===Patient Information=== | ||
Line 59: | Line 61: | ||
*Individuals shall not be asked to waive these rights as a condition of receiving treatment. | *Individuals shall not be asked to waive these rights as a condition of receiving treatment. | ||
*The ACE is responsible for safeguarding and protecting confidential information against loss, tampering, and disclosure to unauthorized individuals. The safeguarding of confidential information in any form includes when the information is stored and/or being transferred outside the facility (see UNMC Policy No. 6073, [[Transporting Protected Health Information]]). | *The ACE is responsible for safeguarding and protecting confidential information against loss, tampering, and disclosure to unauthorized individuals. The safeguarding of confidential information in any form includes when the information is stored and/or being transferred outside the facility (see UNMC Policy No. 6073, [[Transporting Protected Health Information]]). | ||
*ACE workforce have a duty to protect | *ACE workforce have a duty to protect PHI. Breach of this duty includes the following: | ||
:*Accessing | :*Accessing PHI, in any form, without a "need to know" to perform assigned duties. Workforce members with medical information system access may view their own individual medical records. Workforce members may not print copies of their own records nor access records of family members (including children), relatives, friends and others, unless access is necessary to perform assigned duties. Workforce members may obtain a copy of their medical records from the Health Information Management Department. Workforce may not alter their own medical record. | ||
:*Discussing or disclosing patient care events to individuals who do not have a “need to know” to perform assigned duties, even if the patient’s name is not mentioned. The facts surrounding patient care are confidential and can lead to the identity of the patient. | :*Discussing or disclosing patient care events to individuals who do not have a “need to know” to perform assigned duties, even if the patient’s name is not mentioned. The facts surrounding patient care are confidential and can lead to the identity of the patient. | ||
:*Disclosing | :*Disclosing PHI without proper authorization (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]); | ||
:*Accessing patient information via Health Information Exchange in a manner or for a purpose not permitted (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]); | :*Accessing patient information via Health Information Exchange in a manner or for a purpose not permitted (see UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]); | ||
:*Discussing | :*Discussing PHI in the presence of individuals who do not have the "need to know" to perform assigned duties; | ||
:*Disclosing that a patient is receiving care (except for authorized directory purposes); | :*Disclosing that a patient is receiving care (except for authorized directory purposes); | ||
:*Leaving | :*Leaving PHI unattended in a non-secure area; | ||
:*Improper disposal of | :*Improper disposal of PHI; | ||
:*Using another person's user ID, password, or other security codes; | :*Using another person's user ID, password, or other security codes; | ||
:*Assisting an unauthorized user to gain access to a secured information system; | :*Assisting an unauthorized user to gain access to a secured information system; | ||
:*Transferring | :*Transferring PHI in any form without both parties having a need to know. | ||
*The ACE shall reasonably mitigate or reduce any harmful effects that may result from privacy breaches. | *The ACE shall reasonably mitigate or reduce any harmful effects that may result from privacy breaches. | ||
*All employees, medical staff, allied health practitioners and members of the workforce with access to | *All employees, medical staff, allied health practitioners and members of the workforce with access to PHI shall sign UNMC [https://www.unmc.edu/hipaa/policies/6045-exhibit-a-statement-of-understanding.pdf Statement of Understanding (Exhibit A)] upon initial employment/work/appointment/credentialing. | ||
*Workforce members who suspect a privacy or information security violation must report it immediately to their respective manager and the Privacy and/or Information Security Office. A full investigation of the suspected violation shall be conducted. Staff who wish to remain anonymous may report the suspected violation to the Compliance Hotline at | *Workforce members who suspect a privacy or information security violation must report it immediately to their respective manager and the Privacy and/or Information Security Office. A full investigation of the suspected violation shall be conducted. Staff who wish to remain anonymous may report the suspected violation to the Compliance Hotline at 844-348-9548. Sanctions shall be imposed for substantiated breaches or failure to report suspected violations. The Medical Staff and allied health practitioners shall report suspected violations to the System Chief Medical Officer. | ||
*Sanctions for violations of privacy or information security may include revocation of medical staff privileges, allied health credentials, or employee corrective action up to and including termination of employment (see UNMC Policy No. 1098, [https://wiki.unmc.edu/index.php/Corrective/Disciplinary_Action Corrective and Disciplinary Action]). Civil and criminal fines and penalties can also be levied under HIPAA. | *Sanctions for violations of privacy or information security may include revocation of medical staff privileges, allied health credentials, or employee corrective action up to and including termination of employment (see UNMC Policy No. 1098, [https://wiki.unmc.edu/index.php/Corrective/Disciplinary_Action Corrective and Disciplinary Action]). Civil and criminal fines and penalties can also be levied under HIPAA. | ||
*Workforce members may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for reporting a suspected privacy or information security violation, or for filing of a complaint within the organization or to the Office for Civil Rights. | *Workforce members may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against any individual for reporting a suspected privacy or information security violation, or for filing of a complaint within the organization or to the Office for Civil Rights. | ||
*Access to patient information via Health Information Exchange shall be conducted in accordance with | *Access to patient information via Health Information Exchange shall be conducted in accordance with UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]. | ||
*Paper medical records shall be maintained in the Health Information Management Department. | *Paper medical records shall be maintained in the Health Information Management Department. | ||
:*Records sent to clinic areas shall be returned to the Health Information Management Department within one working day. | :*Records sent to clinic areas shall be returned to the Health Information Management Department within one working day. | ||
Line 82: | Line 84: | ||
:*Records signed out to the attending physician's office or other authorized areas shall be returned to the Health Information Management Department as soon as possible (preferably by 5:00 pm each working day). | :*Records signed out to the attending physician's office or other authorized areas shall be returned to the Health Information Management Department as soon as possible (preferably by 5:00 pm each working day). | ||
*Editing, authenticating and correcting the medical record. | *Editing, authenticating and correcting the medical record. | ||
:*Please | :*Please contact the One Chart Resource team. | ||
*Business Associate agreements/addenda shall be established with any individual or corporation who performs a function on behalf of UNMC involving the use or disclosure of PHI, other than as a member of the workforce or a healthcare provider providing treatment (see UNMC Policy No. 8009, [[Contracts]]). | *Business Associate agreements/addenda shall be established with any individual or corporation who performs a function on behalf of UNMC involving the use or disclosure of PHI, other than as a member of the workforce or a healthcare provider providing treatment (see UNMC Policy No. 8009, [[Contracts]]). | ||
*Human Subjects Research shall be conducted in accordance with Human Research Protection Program (HRPP) Policies and Procedures, including HRPP Policy 3.4, Use of Protected Health Information in Research and Registries and Use and Disclosure of Protected Health Information | *Human Subjects Research shall be conducted in accordance with UNMC Human Research Protection Program (HRPP) Policies and Procedures, including [https://net.unmc.edu/rss/ HRPP Policy 3.4, Use of Protected Health Information in Research and Registries] and with UNMC Policy No. 6057, [[Use and Disclosure of Protected Health Information]]. | ||
*Retention of the designated record set and other protected health information shall be in accordance with federal, state, and local laws, and regulatory association guidelines. Documents required to demonstrate HIPAA compliance shall be retained for a period of six years. | *Retention of the designated record set and other protected health information shall be in accordance with federal, state, and local laws, and regulatory association guidelines. Documents required to demonstrate HIPAA compliance shall be retained for a period of six years. | ||
*The Privacy Officer shall be designated in writing and shall be responsible for developing and implementing written policies and procedures necessary to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). | *The Privacy Officer shall be designated in writing and shall be responsible for developing and implementing written policies and procedures necessary to comply with the [https://www.hhs.gov/hipaa/index.html Health Insurance Portability and Accountability Act of 1996 (HIPAA)]. | ||
*All members of the workforce shall receive training on privacy and security of confidential information upon hire, and when policies and procedures relevant to their position change. | *All members of the workforce shall receive training on privacy and security of confidential information upon hire, and when policies and procedures relevant to their position change. | ||
===Business Information=== | ===Business Information=== | ||
Line 95: | Line 97: | ||
:*Disclosure of fundraising information | :*Disclosure of fundraising information | ||
:*Disclosure of credit card information received in the course of business, whether or not such credit card information is covered by the Gramm-Leach-Bliley Act (GLBA). | :*Disclosure of credit card information received in the course of business, whether or not such credit card information is covered by the Gramm-Leach-Bliley Act (GLBA). | ||
*Workforce members who suspect a breach of confidentiality regarding proprietary | *Workforce members who suspect a breach of confidentiality regarding proprietary information shall report the breach to the Human Resources Employee Relations Department. | ||
*A full investigation of the breach shall be conducted by the Human Resources Employee Relations Department, as appropriate. | *A full investigation of the breach shall be conducted by the Human Resources Employee Relations Department, as appropriate. | ||
===Student Education Record Information=== | ===Student Education Record Information=== | ||
*Members of the workforce have a duty to maintain the confidentiality of student education records. Breach of this duty includes, but is not limited to, release of student information that is not considered “directory information” under the guidelines of the Family Educational Rights and Privacy (FERPA) listed in the Student Handbook. It also includes, but is not limited to, protection of confidential student financial information protected under the Gramm-Leach-Bliley Act (GLBA). | *Members of the workforce have a duty to maintain the confidentiality of student education records. Breach of this duty includes, but is not limited to, release of student information that is not considered “directory information” under the guidelines of the Family Educational Rights and Privacy (FERPA) listed in the Student Handbook. It also includes, but is not limited to, protection of confidential student financial information protected under the Gramm-Leach-Bliley Act (GLBA). | ||
*Employees shall verify FERPA restrictions placed on student records prior to release of student information. | *Employees shall verify FERPA restrictions placed on student records prior to release of student information. | ||
*The social security number of a student is considered confidential information and must not be used to identify a student. | *The social security number of a student is considered confidential information and must not be used to identify a student. | ||
*Information Technology Services (ITS) shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to Student Number. | *Information Technology Services (ITS) shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to Student Number. | ||
*Use of a student’s social security number in databases is prohibited. In the event that the social security number of a student must be maintained, an | *Use of a student’s social security number in databases is prohibited. In the event that the social security number of a student must be maintained, an Exhibit B - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception] must be completed and submitted to Academic Affairs for approval. If it must be used, the use of the student’s social security number must comply with [https://info.unmc.edu/its-security/policies/procedures/database-security.html ITS Database Security Procedures]. | ||
*Workforce members who suspect a breach of confidentiality regarding Student Education Records shall report the breach to the Compliance Office or the Student Affairs Office. | *Workforce members who suspect a breach of confidentiality regarding Student Education Records shall report the breach to the Compliance Office or the Student Affairs Office. | ||
*The student may file a complaint with the Family Policy Compliance Office, U.S. Department of Education, 400 Maryland Ave SW, Washington, DC 20202-4605. | *The student may file a complaint with the Family Policy Compliance Office, U.S. Department of Education, 400 Maryland Ave SW, Washington, DC 20202-4605. | ||
===Employee Information=== | ===Employee Information=== | ||
*Employment records are confidential and will not be made publicly available, except upon written authorization signed by the individual to whom the records pertain or in response to a legal mandate. In this context, employment records are those of persons who are employees of UNMC, and persons who are or have been either applicants or nominees for employment. Such records include the entire employment process beginning with application or nomination for appointment, search committee evaluation, and appointing authority evaluation, through appointment and employment, and ending with separation from employment. | *Employment records are confidential and will not be made publicly available, except upon written authorization signed by the individual to whom the records pertain or in response to a legal mandate. In this context, employment records are those of persons who are employees of UNMC, and persons who are or have been either applicants or nominees for employment. Such records include the entire employment process beginning with application or nomination for appointment, search committee evaluation, and appointing authority evaluation, through appointment and employment, and ending with separation from employment. | ||
*The social security number of an employee is considered confidential information and should not be used to identify an employee unless legally mandated, see UNMC | *The social security number of an employee is considered confidential information and should not be used to identify an employee unless legally mandated, see UNMC policy No. 6085, [[Social Security Number]]. | ||
*ITS shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to: | *ITS shall be available to assist in identifying alternatives to use of social security number. Alternatives which should be considered, include but are not limited to: | ||
:*Personnel (SAP) Number | :*Personnel (SAP) Number | ||
:*Last four digits of social security number | :*Last four digits of social security number | ||
*In the event that the social security number of an employee must be maintained, an | *In the event that the social security number of an employee must be maintained, an Exhibit C - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception] must be completed and submitted to Human Resources for approval. In cases where the employee social security number must be stored in a database, the database use must comply with [https://info.unmc.edu/its-security/policies/procedures/database-security.html ITS Database Security Procedures]. | ||
*The following are not confidential and are considered by UNMC as directory information: | *The following are not confidential and are considered by UNMC as directory information: | ||
:*Employee Name | :*Employee Name | ||
Line 121: | Line 123: | ||
:*Post-secondary education degrees earned | :*Post-secondary education degrees earned | ||
:*Awards or honors | :*Awards or honors | ||
*Employee information other than directory information is accessible only to the employee, the department administrative personnel, UNMC Human Resources, and other University offices with a need to know. Non-directory information should be released to others only with signed authorization from the employee or in response to a legal mandate. | *Employee information other than directory information is accessible only to the employee, the department administrative personnel, UNMC Human Resources, and other University offices with a need to know. Non-directory information should be released to others only with signed authorization from the employee or in response to a legal mandate. | ||
*Departments have three options for responding to requests for reference checks: | *Departments have three options for responding to requests for reference checks: | ||
:*Refer to Human Resources – Records | :*Refer to Human Resources – Records | ||
:*Provide directory information only | :*Provide directory information only | ||
:*With a signed release, respond to questions and provide information based only on what is documented in the employment file | :*With a signed release, respond to questions and provide information based only on what is documented in the employment file | ||
:*For more information about responding to reference checks, inquire at UNMC Human Resources – Records at 402 | :*For more information about responding to reference checks, inquire at UNMC Human Resources – Records at 402-559-8962. | ||
*Members of the workforce have a duty to protect employee information. Breach of this duty includes but is not limited to the following: | *Members of the workforce have a duty to protect employee information. Breach of this duty includes but is not limited to the following: | ||
:*Disclosure of social security number | :*Disclosure of social security number | ||
Line 132: | Line 134: | ||
:*Disclosure of employee corrective action | :*Disclosure of employee corrective action | ||
*Workforce members who suspect a breach of confidentiality regarding Employment Records shall report the breach to the Human Resources Employee Relations Department. | *Workforce members who suspect a breach of confidentiality regarding Employment Records shall report the breach to the Human Resources Employee Relations Department. | ||
===Controlled Unclassified Information (CUI)=== | |||
Controlled Unclassified Information as defined by Executive Order 13556 and administered by the National Archives includes several categories of information, as detailed in the CUI Registry (https://www.archives.gov/cui/registry/category-list). That list includes: | |||
*Personally Identifiable Information (PII) | |||
*Personally Identifiable Health Information (PHI) | |||
*Defense/Technology related research and development for the US Government | |||
Guiding standards for the management and handling of CUI are: | |||
*[http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf NIST 800-171 Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations] | |||
*[http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf NIST 800-53 Security and Privacy Controls for Federal Information Systems and Organizations - Moderate Standards] | |||
All personnel, including faculty, staff, research associates and fellows, visiting scholars, students, and all other persons retained by or working at the University of Nebraska Medical Center and its affiliates will comply with all applicable U.S. laws and regulations while teaching, conducting research or providing service activities at or on behalf of the university. As such, personnel are required to comply with the U.S. laws that regulate the transfer of items, information, technology, software, and funds to destinations and persons outside of the U.S., as well as in some cases, to non-U.S. citizens at the university. | |||
*Specific CUI are referenced elsewhere in this policy, reference applicable sections for additional information. | |||
*Workforce members who suspect a breach of confidentiality regarding controlled unclassified information shall report the breach to the Privacy Office and/or Information Security Office. | |||
===Research Information=== | ===Research Information=== | ||
*Members of the workforce have a duty to protect confidential information produced while performing research. Breach of this duty includes the following: | *Members of the workforce have a duty to protect confidential information produced while performing research. Breach of this duty includes the following: | ||
Line 138: | Line 151: | ||
*Workforce members who suspect a breach of confidentiality regarding human subjects research information shall report the breach to the IRB office and/or the Privacy Office. | *Workforce members who suspect a breach of confidentiality regarding human subjects research information shall report the breach to the IRB office and/or the Privacy Office. | ||
==Additional Information== | ==Additional Information== | ||
*Contact the [mailto:debrbishop@nebraskamed.com Privacy] or [mailto: | *UNMC Policy No. 6045, Privacy, Confidentiality and Security of Patient and Proprietary Information corresponds to Nebraska Medicine Policy IM06 | ||
*Contact Human Resources – Records at 402 | *Contact the [mailto:debrbishop@nebraskamed.com Privacy] or [mailto:libazis@nebraskamed.com Information Security] Officers | ||
*Exhibit A - [https://www.unmc.edu/hipaa/policies/6045-exhibit-a-statement-of-understanding.pdf Statement of Understanding] | *Contact Human Resources – Records at 402-559-8962 or Human REsources - Employee Relations | ||
*Exhibit A - [https://www.unmc.edu/hipaa/policies/6045-exhibit-a-statement-of-understanding.pdf Statement of Understanding] | |||
*Exhibit B - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception] | *Exhibit B - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-B-SSN-Student.docx Use of Student Social Security Number Exception] | ||
*Exhibit C - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception] | *Exhibit C - [https://www.unmc.edu/hipaa/_documents/6045-Exhibit-C-SSN-Employee.docx Use of Employee Social Security Number Exception] | ||
Line 166: | Line 180: | ||
*[http://www.unmc.edu/hr/Proc/Procedures1097.pdf Human Resources Performance Management Procedures] | *[http://www.unmc.edu/hr/Proc/Procedures1097.pdf Human Resources Performance Management Procedures] | ||
*[http://info.unmc.edu/wiki/index.php/Faculty_Handbook UNMC Faculty Handbook: Operating Procedures] | *[http://info.unmc.edu/wiki/index.php/Faculty_Handbook UNMC Faculty Handbook: Operating Procedures] | ||
*[http:// | *[http://catalog.unmc.edu/general-information/ Student Handbook] | ||
*[https://aspe.hhs.gov/report/health-insurance-portability-and-accountability-act-1996 Health Insurance Portability and Accountability Act of 1996] (HIPAA) | *[https://aspe.hhs.gov/report/health-insurance-portability-and-accountability-act-1996 Health Insurance Portability and Accountability Act of 1996] (HIPAA) | ||
*[http://www.ftc.gov/privacy/privacyinitiatives/glbact.html Gramm-Leach-Bliley Act] (GLBA) | *[http://www.ftc.gov/privacy/privacyinitiatives/glbact.html Gramm-Leach-Bliley Act] (GLBA) | ||
Line 180: | Line 194: | ||
*[https://www.unmc.edu/vcr/about/research-handbook-web.pdf Research Handbook] | *[https://www.unmc.edu/vcr/about/research-handbook-web.pdf Research Handbook] | ||
*[http://www.unmc.edu/irb/ Institutional Review Board Guidelines] | *[http://www.unmc.edu/irb/ Institutional Review Board Guidelines] | ||
*[http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf NIST 800-171 Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations] | |||
*[http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf NIST 800-53 Security and Privacy Controls for Federal Information Systems and Organizations - Moderate Standards] | |||
This page maintained by [mailto:dpanowic@unmc.edu dkp]. | This page maintained by [mailto:dpanowic@unmc.edu dkp]. |