From: University of Michigan/Safe Computing
| Law/Regulation/ Standard | Definition | Examples | Data Steward/ Manager | Resources |
|---|---|---|---|---|
| Electronic Protected health Information (ePHI) or HIPAA ePHI is regulated by the Health Insurance Portability and Accountability Act (HIPAA) |
The Privacy and Security Rules apply only to covered entities in their role as a Health Care Provider, Health Plan, or Health Care Clearinghouse.Protected health information excludes individually identifiable health information in:
|
The following individually identifiable data elements, when combined with health information about that individual, make such information protected health information (PHI):
See the Sensitive Data Guide: Protected Health Information (HIPAA) for more examples. |
Health System Compliance Officer compliance-Group@med.umich.edu |
|
| Export Control Research or ITAR, EAR International Traffic in Arms Regulation (ITAR); Export Administration Regulations (EAR) |
Export controlled research includes information that is regulated for reasons of national security, foreign policy, anti-terrorism or non-proliferation. |
See the Sensitive Data Guide: Export Control Research (ITAR or EAR) for more examples. |
Export Controls Compliance Office of the Vice President for Research umresearch@umich.edu |
|
| FISMA Federal Information Security Management Act |
FISMA requires federal agencies, and those providing services on their behalf to develop, document, and implement security programs for IT systems and store the data on U.S. soil. FISMA applies generally to federal “contracts” as opposed to grants. | If you work with data provided by the federal government under contract and exchange data with government systems, then you may be subject to FISMA compliance regulations to protect the data.See the Sensitive Data Guide: FISMA Data for more examples. |
— |
Leave a Reply