Watech.wa.gov Records Management In a nutshell. watech.wa.gov What’s a record? A record is anything you create in the course of doing your work – Everything.

Slides:



Advertisements
Similar presentations
Protect Our Students Protect Ourselves
Advertisements

University Data Classification Table* Level 5Level 4 Information that would cause severe harm to individuals or the University if disclosed. Level 5 information.
Gaucho Round-Up FAQ’s This presentation covers some of the FAQ’s about campus clean-up day. Presentation #4 2/3/
INTRODUCTION TO PUBLIC DISCLOSURE RESPONSE Paula Adams, King County Public Disclosure Officer.
National Health Information Privacy and Security Week Understanding the HIPAA Privacy and Security Rule.
Voice over the Internet Protocol (VoIP) Technologies… How to Select a Videoconferencing System for Your Agency Based on the Work of Watzlaf, V.M., Fahima,
FERPA 102 Helpful Guide for Administrators, Security Contacts and Support Staff Prepared by the Office of the Registrar Student Records: Institutional.
Data Protection.
WASHINGTON STATE DEPARTMENT OF REVENUE PROTECTING CONFIDENTIAL TAX INFORMATION.
INDIANA UNIVERSITY OFFICE OF THE VICE PRESIDENT AND GENERAL COUNSEL Indiana Access to Public Records Act (APRA) Training.
MINNESOTA GOVERNMENT DATA PRACTICES ACT How the law affects University employees and recordkeeping Susan McKinney Records & Information Management.
1 GRAND VALLEY STATE UNIVERSITY FAMILY EDUCATIONAL RIGHTS & PRIVACY ACT (FERPA) TRAINING OFFICES OF THE REGISTRAR AND UNIVERSITY COUNSEL JANUARY 20, 2009.
HEAVEN’S HANDS COMMUNITY SERVICE H.I.P.A.A. What is HIPAA? HIPAA stands for the Health Insurance Portability and Accountability Act, which was passed.
Data Protection & Freedom of Information The Practical Implications of Data Protection and Freedom of Information Caroline Dominey Data Protection Officer.
Data Classification & Privacy Inventory Workshop
Developing a Records & Information Retention & Disposition Program:
FERPA: Protect our Students by Protecting their Records Prepared by Rebekah D. Mathis-Stump, JD.
1 Disclosing Student Personal Information to the Queensland Police Service 1-2 July 2008 RED/EDS Business Meeting.
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
Confidentiality… important facts to know and critical things to do!
Created May 2, Division of Public Health Managing Records What is a Record? What is a Records Retention & Disposition Schedule? Why is this Important?
Data Protection Overview
CSP Annual Security Training Miranda Gregory, CSP Analyst Carroll County Department of Citizen Services.
SECURITY: Personal Health Information Protection Act, 2004 this 5 min. course covers: changing landscape of electronic health records security threats.
Information Security Decision- Making Tool What kind of data do I have and how do I protect it appropriately? Continue Information Security decision making.
Practical Information Management
Handling information 14 Standard.
FERPA Family Educational Rights and Privacy Act and Rebecca Macon Registrar University of Georgia Presentation for GASFAA October.
Introduction to the West Virginia Executive Branch Privacy Policies Executive Branch Privacy Program Education & the Arts Presented by Heather Butler,
Privacy and Security of Protected Health Information NorthPoint Health & Wellness Center 2011.
Privacy and Information Management ICT Guidelines.
HIPAA (health insurance portability and accountability act)
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
PRIVACY, SECURITY & ID THEFT PREVENTION - TIPS FOR THE VIGILANT BUSINESS - SMALL BUSINESS & ECONOMIC DEVELOPMENT FORUM October 21, WITH THANKS TO.
Watech.wa.gov Records Management In a nutshell. watech.wa.gov What’s a record? A record is anything you create in the course of doing your work – Everything.
What are the rules? Information technology is available to every student, faculty and staff member in support of the essential mission of the University.
Building a Privacy Foundation. Setting the Standard for Privacy Health Insurance Portability and Accountability Act (HIPAA) Patient Bill of Rights Federal.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
FERPA Family Educational Rights and Privacy Act A Tutorial.
HIPAA THE PRIVACY RULE. 2 HISTORY In 2000, many patients that were newly diagnosed with depression received free samples of anti- depressant medications.
Confidentiality A Training Without the Video. Laws FERPA (1976) or the Buckley Amendment (1994) IDEA (1991) KY Safe Schools (1998)
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Joel Rosenblatt Director, Computer and Network Security September 10, 2013.
Family Educational Rights and Privacy Act.  What is FERPA?  What Information May Be Released?  Request Non-Release of Directory Information  What.
Indiana’s Public Access Laws Heather Willis Neal Indiana Public Access Counselor Columbus Police Department August 18, 2009.
Elected Officials and Health Department Records Indiana Public Health Foundation February 27, 2008.
All Employee Basic Records Management Training. Training Overview 1.Training Objectives 2.Clark County RIM Program 3.Key Concepts 4.Employee Responsibilities.
Unit 3 Seminar.  Used to predict acceptable or unacceptable behavior  Helps to assess level of skills/knowledge/ characteristics applicants have  Reduce.
TASFAA 2016 Legacy of Leadership. TASFAA 2016 Legacy of Leadership Family Educational Rights and Privacy Act (FERPA) An Overview Molly Thompson Associate.
Business Ethics and Social Responsibility GCSE Business and Communication Systems Business and Communication Systems.
CITY OF PHOENIX RECORDS MANAGEMENT AND E-PRIVACY Margie Pleggenkuhle City Clerk Department March 18, 2004.
Scientific data storage: How are computers involved in the following?
The Health Insurance Portability and Accountability Act (HIPAA) requires Plumas County to train all employees in covered departments about the County’s.
UNIT 7 seminar! All about HIPAA, confidentiality and PHI!
Susan McKinney, CRM. RECORDS MANAGEMENT AT THE U Policy: Managing University Records and Information Procedures: Retention of University Records Destruction.
UW-Madison Guidelines for Managing the Records of Departing Employees*
Indiana Access to Public Records Act (APRA) Training
Protection of CONSUMER information
Chapter 3: IRS and FTC Data Security Rules
An Introduction to Public Records Office of the General Counsel
Managing Student Records Legally and Effectively
Welcome to the FERPA training for Faculty and Staff.
IT & Security Training Skills.
Privileged Communications
INTRODUCTION TO PUBLIC DISCLOSURE RESPONSE
Lesson 1: Introduction to HIPAA
Good Spirit School Division
Confidentiality Training 2014
Presentation transcript:

watech.wa.gov Records Management In a nutshell

watech.wa.gov What’s a record? A record is anything you create in the course of doing your work – Everything from a scribble on a post-it note to a document – Paper and electronic – Personal computer and work computer – Everything Only work related stuff are records if you use your personal computer or mobile devices The hard question is: how long are we suppose to keep them

watech.wa.gov What about retention? Depends on the content of the record… no, not whether it’s electronic or not. That’s irrelevant Records are to be kept according to the official “record retention schedule” schedules.aspx schedules.aspx It’s your job to know the schedule & keep records accordingly There is also such a thing as “transitory records” which you only have to keep for as long as they’re useful

watech.wa.gov Retention common sense Be consistent Obviously important stuff has a retention period like: – Plans, project plans, roadmaps – QA reports, records that document, assess, or summarizes something – things supporting key decisions Stupid stuff doesn’t (transitory value) If it’s a transitory record you can dump it whenever The clock start may not be obvious for some things – Project documents retention start at the end of the project…not when the records were created

watech.wa.gov Where are records stored? Key value: store records so that the agency (not just you) can find it when responding to a public disclosure request Records (especially those with a retention period) need to be stored in a “system of record” – A recognized system that people are able to search – So that we can be responsive to public record requests Systems of record: s, file shares, etc Not systems of record: some random web service we’re using Records created outside of the systems of record must be copied to the system of record Systems of record are documented in the GlassFrog notes for the role that has accountability for e-gov recordsnotes

watech.wa.gov Experimenting vs records management You can totally be innovative and experimental even with all the rules around records Just ask yourself (and answer) these questions: – What is the record retention of the records I’ll be creating? – How will I get those records copied out? – Similarly, how will I get records out of the system if I get a records request? – Is there a way to automate the copying of records out into a system of record? If yes, the sweet! – Of course, is the data category 3 or 4? If yes then you have work to do. Public URLs to the records counts as disclosed. Check. Done!!

watech.wa.gov Category 3 and 4 Category 1 - Public Information Public information is information that can be or currently is released to the public. Category 2 - Sensitive Information Sensitive information may not be specifically protected from disclosure by law and is for official use only. Category 3 - Confidential Information Confidential information is information that is specifically protected from disclosure by law. It may include but is not limited to: – a. Personal information about individuals, regardless of how that information is obtained. – b. Information concerning employee personnel records. – c. Information regarding IT infrastructure and security of computer and telecommunications systems. Category 4 - Confidential Information Requiring Special Handling Confidential information requiring special handling is information that is specifically protected from disclosure by law and for which: – a. Especially strict handling requirements are dictated, such as by statutes, regulations, or agreements. – b. Serious consequences could arise from unauthorized disclosure, such as threats to health and safety, or legal sanctions.

watech.wa.gov Public Disclosure Everything is publically disclosable Unless it’s specifically excluded: – The ATG has a great summary and list of exclusions: – Some relevant examples: – Personnel records – Taxpayer info – Banking info – Investigative records – Test and exam questions and answers – Public employee personal contact information – Security info like passwords, risk assessments, etc – Several others

watech.wa.gov Handling Public Record requests Anyone can make a request – Can be in any form like phone, , in person WaTech must respond within five days If you think you may have receive a request, or You’re not sure if it’s really a request Then, contact the agency Public Records Officer