Protecting Student Data

Slides:



Advertisements
Similar presentations
Family Educational Rights and Privacy Act What you should know about FERPA.
Advertisements

FERPA - Sharing Student Information
Protect Our Students Protect Ourselves
FERPA: Family Educational Rights and Privacy Act
HIPAA: An Overview of Transaction, Privacy and Security Regulations Training for Providers and Staff.
Protection of privacy for all Students!
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
HIPAA Basic Training for Privacy & Information Security Vanderbilt University Medical Center VUMC HIPAA Website:
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
NAU HIPAA Awareness Training
FERPA: WHAT YOU SHOULD KNOW ILASFAA April 18, 2008 Amy Perrin Director of Financial Aid Elgin Community College.
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
FERPA: Family Educational Rights and Privacy Act.
FERPA Skidmore College Family Education Rights & Privacy Act What is FERPA? It is the Family Educational Rights and Privacy Act of Is also referred.
FERPA The Family Educational Rights and Privacy Act.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
Data Privacy: Third Parties, Vendors, & Nonprofits Baron Rodriguez (PTAC), Michael Hawes (DoED), & Mike Tassey (PTAC)
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
Confidentiality… important facts to know and critical things to do!
Practical Information Management
Confidentiality Training Electra ISD School Year.
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Confidentiality and Public Information Act LISD Special Education Department Training SY
707 KAR 1:360 Confidentiality of Information. Section 1: Access Rights 1) An LEA shall permit a parent to inspect and review any education records relating.
CONFIDENTIALITY This workshop on confidentiality is designed to meet federal requirements for staff training while increasing staff awareness of their.
 CONFIDENTIALITY ASD Special Education Watch what you say Where you say it To whom you say it.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
HOOVER CITY SCHOOLS In-Service Training: Annual Review of.
Prepared by The Office of the Registrar Youngstown State University February, 2009.
F.E.R.P.A.. What is F.E.R.P.A. ? The Family Educational Rights and Privacy Act of 1974,
Privacy Act United States Army (Managerial Training)
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
FERPA & HIPAA: Maintaining Student Confidentiality.
Student Data Privacy FERPA. What governs Student Data Privacy at SCC? FERPA- Family Educational Rights and Privacy Act of 1974 (aka the Buckley Amendment)
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Denise Chrysler, JD Director, Mid-States Region
Nassau Association of School Technologists
Overview to Student Data Privacy in Illinois
Confidentiality Training
Protect Our Students Protect Ourselves
What is FERPA?? How does it affect my course?
FERPA Fundamentals The Family Educational Rights and Privacy Act (FERPA) sets out the rights and responsibilities associated with student education records.
Tomball Independent School District Annual Confidentiality Training
Student Privacy in an Ever-Changing Digital World
Student Data Privacy and Security
Russellville Independent School District
And the finer details of patient privacy
Confidentiality Training
Student Confidentiality: The FERPA/HIPAA Facts
Obligations of Educational Agencies: Parents’ Bill of Rights
SPECIAL EDUCATION A REVIEW OF: CHILD FIND/ SPED PROCESS
WHAT IS HIPAA AND HOW TO COMPLY WITH IT?
Overview to Student Data Privacy in Illinois
COMPLYING WITH FERPA WHILE USING ONLINE EDUCATIONAL SERVICES
Disability Services Agencies Briefing On HIPAA
SPECIAL EDUCATION REQUIRED TRAINING
Spencer County Public Schools Responsible Use Policy for Technology and Related Devices Spencer County Public Schools has access to and use of the Internet.
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
Family Educational Rights & Privacy Act (FERPA)
Confidentiality Training
The Issues with Technology in education
CONTRACTS PRIVILEGED COMMUNICATION PRIVACY ACT
What does that have to do with me?
The family educational rights and privacy act of 1974
Confidentiality Training 2014
Student Confidentiality: The FERPA/HIPAA Facts
Presentation transcript:

Protecting Student Data

Data breaches at schools can happen... … they can be avoided Schools will experience loss of goodwill with parents and the community, and incur significant media coverage if a data breach occurs. While incidents have been few, districts are authorized in most Acceptance Use Policy (AUP) to consider disciplinary action when a data breach occurs. Most breaches are caused by agency personnel. Data breaches can be avoided by training

Commitment to protecting student data The Kern County Data Warehouse Agreement states “[districts participating in KIDS] are committed to sharing and using student records all while maintaining data security, confidentiality, and privacy, and in compliance with laws and regulations for access, storage, management, and deletion of shared student records.”

Laws that protect student data FERPA: Family Educational Rights and Privacy Act FERPA is the federal law that protects the privacy of student education records. SOPIPA: Student Online Personal Information Protection Act SOPIPA ensures educators use student data for educational purposes and nothing else. CA Education Code 49073.1 This law protects the privacy of student records when an LEA enters a contract with a third party.

Complying with student data privacy laws Districts are required to impose security procedures by which unauthorized personnel cannot access data contained in the system. ...and Districts are required to secure confidential data from unauthorized disclosure.

Understanding the type of data you are responsible for protecting Personally Identifiable Information (PII) De-identified Information Personally identifiable information includes the student’s name, address, social security, date of birth, parent information, health records, grades, disciplinary records, and any information that can be linked to a specific student. Nothing prohibits aggregated de-identified data to be shared. Aggregated data prevents a student’s identity from being linked to a specific student. Can only be shared for legitimate educational interests, otherwise PII cannot be shared Can be shared with other appropriate school officials

When sharing personally identifiable student information, ask yourself…. Can this information personally identify a specific student? Is there a legitimate educational reason for sharing the information? Is there an unauthorized person around who can hear the information? Can an unauthorized person get hold of this information? Is this information being shared to the internet? Are you using a personal device to view and/or communicate student information? If you can answer “yes” to any of these questions, you are at risk of a

Types of Data Scenarios Type of Data Shared Was it OK to share? A general education teacher and a special education teacher are discussing the academic progress of a student with special needs around teachers who do not share the student. Personally identifiable information - academic information Other individuals, who do not share the student, cannot be present while PII is discussed. No. How can a data breach be prevented? The general ed. and special ed. teachers discuss the information without other individuals present. A teacher displays on the board the class roster with the final quarter grades of all students. Personally identifiable information - grades Student should not be able to see the grades of other students in the class besides their own. No. How can a data breach be prevented? Each student receives their individual grade.

Types of Data Scenarios Type of Data Shared Was it OK to share? During a PLC, teachers are discussing grade level assessment results by student group. A teacher shares out the following information: 85% of all students met Standard A 70% of English Learners met Standard A 65% of Students with Disabilities met Standard A Aggregated information - assessment results by student group Yes. By reporting student group information, a single student was not identified. A principal is meeting with the attendance clerks in her office. The principal pulls up a list of chronically absent students. The door to the office is closed, but the office has windows facing a student walkway, and the computer screen is clearly visible. Personally identifiable information - attendance information No. Anyone walking who looks inside the principal’s office can see the information. How can a data breach be prevented? Face the monitors away from the windows and/or place a privacy screen on your monitor.

Best practices for protecting student information Make every effort to prevent unauthorized people from viewing your screen while you are accessing student information. Be aware of those around you when discussing personally identifiable information regarding students. Avoid writing down username and password information where an unauthorized person can get ahold of the information When training or creating presentations, use demo data for screenshots. If you must use live data, make sure to obscure the student information using a graphical editing tool (such as a blurring tool) Ensure that you successfully log out of KIDS and/or computer before leaving your computer unattended Secure digital documents using password protected folders and secure paper documents in locked cabinets

Things to Avoid To avoid violating student data privacy laws, DON’T leave student data lying around DON’T send any personally identifiable information via email DON’T publicly post students’ personal information online DON’T display or post students’ grades in the classroom that includes names or student IDs DON’T discuss student records with others unless they have legitimate educational interest in the information DON’T share your login username and password with others

Golden Rule for Protecting Student Data Treat others’ personally identifiable information as if it is your own.

Title Insert