Information Security Laws and Regulations Related to Handling Sensitive Data

From: University of Michigan/Safe Computing

Law/Regulation/ Standard Definition Examples Data Steward/ Manager Resources
Electronic Protected health Information (ePHI) or HIPAA
ePHI is regulated by the Health Insurance Portability and Accountability Act (HIPAA)
The Privacy and Security Rules apply only to covered entities in their role as a Health Care Provider, Health Plan, or Health Care Clearinghouse.Protected health information excludes individually identifiable health information in:

  • Education records covered by the Family Educational Rights and Privacy Act (FERPA), as amended, 20 U.S.C. 1232g(a)(4)(B)(iv)
  • Employment records held by a covered entity in its role as an employer
The following individually identifiable data elements, when combined with health information about that individual, make such information protected health information (PHI):

  • Names
  • All geographic subdivisions smaller than a State
  • All elements of dates (except year) for dates directly related to an individual including birth date, admission date, discharge date, date of death
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/License numbers
  • Vehicle identifiers and serial numbers, including license plate numbers
  • Device identifiers and serial numbers
  • URLs
  • IP addresses
  • Biometric identifiers
  • Full face photographic images and any comparable images
  • and any other unique identifying number, characteristic, code, or combination that allows identification of an individual.

See the Sensitive Data Guide: Protected Health Information (HIPAA) for more examples.

Health System Compliance Officer
compliance-Group@med.umich.edu
Export Control Research or ITAR, EAR
International Traffic in Arms Regulation (ITAR); Export Administration Regulations (EAR)
Export controlled research includes information that is regulated for reasons of national security, foreign policy, anti-terrorism or non-proliferation.
  • Chemical and biological agents
  • Scientific satellite information
  • Certain software or technical data sent to foreign persons
  • Military electronics….
  • Nuclear Physics
  • Work on new formula for explosives – this kind of data cannot be stored on systems outside the United States nor can non-U.S. citizens work on this type of project.

See the Sensitive Data Guide: Export Control Research (ITAR or EAR) for more examples.

Export Controls Compliance
Office of the Vice President for Research
umresearch@umich.edu
FISMA
Federal Information Security Management Act
FISMA requires federal agencies, and those providing services on their behalf to develop, document, and implement security programs for IT systems and store the data on U.S. soil. FISMA applies generally to federal “contracts” as opposed to grants. If you work with data provided by the federal government under contract and exchange data with government systems, then you may be subject to FISMA compliance regulations to protect the data.See the Sensitive Data Guide: FISMA Data for more examples.

Read Complete Post

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *