Information eSecurity
In following the acceptable use agreement, you agree to:
1.1 General Use
1.1.1 Exercise good judgment regarding the protection and security of the Hospital and the Graduate School information assets. Failure to follow security policies and standards could place the Hospital and the Graduate School in violation of laws and regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and Protection of Student Data.
1.1.2 Exercise good judgment when communicating as a member of the Graduate School over email, social media or other technology. Members of the Graduate School should not use language that may be offensive, obscene, sexually explicit, threatening, intimidating, discriminatory, retaliatory, or harassing.
1.1.3 Promptly report the theft, loss, or unauthorized disclosure of the Graduate School Confidential or Protected information (e.g., grades, student information, proprietary information) to the Graduate School and Information Security Office at information.security@stjude.org..
1.1.4 Use of Hospital or Graduate School technologies (network, Internet, email, computers, files shares and applications) is done so with the understanding that they are monitored for security purposes and there is no right to or expectation of privacy when using Hospital or Graduate School owned technology. The Hospital or the Graduate School reserves the right to access, monitor and disclose contents of the Internet, email, and voice mail messages or other communications made through the Hospital or Graduate School owned systems.
1.1.5 Use of Hospital or Graduate School information systems with the understanding that occasional personal use is allowed provided it is not associated with a personal business, does not interfere with productivity, and does not preempt legitimate Hospital or Graduate School business activity.
1.1.6 Refrain from attempting to test, circumvent, or defeat any security system or monitoring capability.
1.1.7 Refrain from using Hospital or the Graduate School information systems to engage in any unlawful or obscene activities that could put Hospital and/or the Graduate School at risk. Examples include, but are not limited to, the following:
- Gaining unauthorized access to any information system or network.
- Damaging, altering, or disrupting the operations of any information system or network.
- Making any inappropriate or discriminatory statements based on race, religion, national origin, sex, sexual orientation, transgender status, gender identity or expression, disability or veteran status.
- Accessing, reading, copying, storing or forwarding inappropriate or sexually explicit messages or materials.
- Engaging in illegal, fraudulent, or malicious conduct.
1.2 Asset Usage
1.2.1 Physically secure all Hospital and the Graduate School assets taken off-site at all times. Mobile devices should not be left in unattended bags, luggage, or vehicles.
1.2.2 Return all Hospital and the Graduate School issued assets upon termination of enrollment, employment, contract, or agreement. Access to Hospital and Graduate School systems, networks, and facilities will be disabled upon termination.
1.2.3 Use personal devices to store or access Hospital and Graduate School information only when authorized to do so and in accordance with defined policies and standards for personal devices.
1.3 Clear Desk/Clear Screen
1.3.1 Log off from applications or network services when they are no longer needed and lock workstations when leaving your workspace unattended.
1.3.2 Control physical access to confidential or protected information at all times to prevent unauthorized access, e.g. lock doors to offices and file cabinets, do not leave confidential or protected documents in view, stay with visitors in areas with confidential or protected information, and do not leave confidential or protected information on and immediately remove from fax machines and printers.
1.4 Data Protection
1.4.1 Refrain from transferring or storing electronic protected health information (ePHI) or student protected data to a cloud-based service that has not been approved by Information Services and the Office of Legal Services. Using an unauthorized cloud-based service for ePHI and student data may be a violation of HIPAA and the Hospital’s requirement to perform due diligence on all third-parties that process or store ePHI and the Graduate School’s requirement to safeguard student records. The Graduate School has a policy and procedure to protect the security of its student records and back up all data. Individuals should refer to the policies listed as reference documents for more information on record retention and protection of student data.
1.4.2 Use only authorized technologies, applications, and/or services verified to meet Hospital and Graduate School security requirements. If an alternative application or cloud-based service must be used, you agree not to transfer or store sensitive or confidential information on such applications or services.
1.4.3 Do not forward Hospital or Graduate School business related emails containing confidential or protected information to a personal account.
1.5 Information System Access
1.5.1 Maintain the confidentiality of authentication credentials you have been entrusted with (e.g. passwords, PINS, badges, etc.). Your authentication credentials must not be shared.
1.5.2 Create and change your passwords in accordance with Hospital Information Services password requirements (e.g. password length, password composition).
1.5.3 Be responsible for all activities that use your credentials.
1.6 Physical Security
1.6.1 Dispose of any electronic media containing confidential or protected information in accordance with Hospital and Graduate School disposal policies and standards.
1.6.2 Dispose of any paper containing confidential or protected Information securely using a locked disposal container or cross-cut paper shredder.
1.6.3 Refrain from using photographic, video, audio or other recording equipment, such as cameras in mobile devices, unless authorized.
1.7 Removable Media
1.7.1 Encrypt all removable media used to store confidential or protected information.
1.7.2 Refrain from connecting a removable media device from an unknown origin to a Hospital or Graduate School computer or information system as it may contain malware.
PROCEDURE
2.1 The Graduate School has internal procedures for addressing security breaches to protect Graduate School information (including student records).