Privacy & Information Security Awareness Training Transcript

Privacy & Information Security Awareness Training - Text Version

Training Objectives

Upon completion of this course, you should be able to do the following.

  • Understand information security responsibilities and the consequences of any breach.
  • Become familiar with the requirements of the federal HIPAA regulations, state privacy laws, and CDA policies and procedures that protect the privacy and security of confidential data and what information must be protected.
  • Integrate information security practices into daily work.
  • Take responsibility for complying with CDA information security policies and procedures.

Your job may require you to routinely work with personal information, or you may only occasionally come into contact with it on the job. In either case, you have the ability and the duty to handle it properly. Protecting personal information is essential to protecting the privacy of your fellow Californians.

This training is required pursuant to state administrative manual (SAM) Chapter 5300, and is intended for all CDA employees, including Retired Annuitants, Student Assistants, Youth Aides, volunteers, and interns, and authorized users (CDA contractors and its subcontractors, vendors, or other business associates performing work for CDA on or off CDA's work site.)

Why protect privacy?

Not only is it our responsibility, but it's the law. Our state constitution includes a specific privacy right among the inalienable rights of all Californians. There are also other laws that require state departments to protect personal information that you will learn about in this presentation.

Stealing personal information has become a popular way for dishonest people to make money. Law enforcement calls identity theft the crime of our times. The growth of this crime in recent years puts an increased burden on all organizations to protect the personal information in their care. People entrust their most sensitive personal information to state agencies.

In most cases, they have no choice. Consumers can choose another bank or store if they're not happy about how their personal information is handled, but they can't go to another Department of Motor Vehicles to get a driver's license, or to another franchise tax board to pay their state taxes. This places a special obligation on government employees, contractors, and other individuals. If we fail to protect personal information or to use it properly, we can undermine our citizens' faith in government. Protecting personal information means protecting people. It's a matter of public trust.

Knowledge Check

Which of the following are good reasons for a state department to protect privacy?

  • A. The Information Practices Act and other state laws require it.
  • B. Identity thieves want to steal personal information collected by state agencies.
  • C. Privacy breaches cost money and hurt the state's reputation.
  • D. All of the above. (Correct Answer)

What does law enforcement call the crime of our times?

  • A. Bank robberies
  • B. Identity theft (Correct Answer)
  • C. Mail fraud
  • D. Car theft

Protecting personal information is something that only banks and other companies have to be concerned about.

  • A. True.
  • B. False. (Correct Answer)

What is Identity Theft?

Identity theft is taking someone else's personal information and using it for an unlawful purpose. It is a crime with serious consequences. In this section, you will learn about the different types of identity theft and what they cost victims and businesses.

Types of Identity Theft

There are several types of identity theft. The most common type of reported identity theft is government documents or benefits fraud. Government documents fraud, also known as identity fraud, is the manufacture, sale or use of counterfeit identity documents for immigration fraud or other criminal activity. Government benefits fraud is the misrepresentation or omission of facts on an application to obtain government benefits one is not entitled to.

Another common type of identity theft is the fraudulent use of an existing credit account. Recovering from this type of identity theft has become fairly easy. If you discover a purchase you didn't make, you simply call your bank. Your dispute generally leads to the charge being removed.

New account identity theft is when a thief uses information like your name and social security number to open new credit accounts. This type of identity theft can be much more difficult to deal with. The victim often doesn't find out for many months, sometimes only after being contacted by a debt collector. It takes many phone calls, letters, and hours of work to clear up this type of identity theft.

An identity thief may use a victim's social security number when applying for work. This can lead to increased tax obligations for the victim. A thief may also get medical treatment in the victim's name. Medical identity theft not only means unauthorized payments, but it can also pollute the victim's medical records with inaccurate information.

Criminal identity theft is often the most difficult type to resolve. All identity theft is a crime. But the term criminal here means using someone else's identifying information when arrested or charged with a crime, thereby creating a criminal record for the victim. The victim may be arrested and not released until after a fingerprint check. The victim may be unable to find work because of inaccurate information in a background report.

Identity Theft Facts

According to the Javelin Strategy and Research's 2015 identity fraud report, in 2014, 12.7 million US adults were victims of identity theft. According to law enforcement, identity theft is a low-risk, high-reward crime.

To repair the damage done by an identity thief, a victim incurs costs such as unreimbursed monetary losses, lost wages and any related legal and credit monitoring costs. The total cost of identity theft in 2014 was $16 billion. Because consumers ultimately pay the business costs through higher prices for goods and services, we all pay for identity theft.

The time a victim must spend to clear up an identity theft situation can range from a few hours to many days. New account or criminal identity theft can require hundreds of hours of phone calls, letter writing, and even court appearances spread over many months or years.

Knowledge Check

Identity theft is stealing someone's personal information and using it for what type of purposes?

  • A. Lawful.
  • B. Unlawful. (Correct Answer)

When an identity thief opens new credit accounts in the victim's name, the victim usually learns about it within a month.

  • A. True.
  • B. False. (Correct Answer)

The use of someone's personal information when charged with a crime can be the most difficult type of identity theft for a victim to deal with.

  • A. True. (Correct Answer)
  • B. False.

CDA Information Assets

Information assets are, information collected and or accessed in the administration of CDA programs and services, including but not limited to the following:

  • Hard copy information assets
    • For example, reports, notes, and forms
  • Electronic information assets which include but are not limited to the following:
    • Computers, laptops, cell phones, printers, and scanners
    • Network servers, switches, and routers
    • Storage media, hard drives, flash drives, and cloud storage
    • Data, applications, and databases.

It is everyone's responsibility to protect CDA information assets by:

  • Complying with operational policies and procedures
  • Integrating security practices into daily routines
  • Reporting security incidents immediately.

Information Practices Act

The basic privacy law that applies to all state agencies is the Information Practices Act of 1977. This law sets the requirements for agencies on the management of personal information. The Information Practices Act defines personal information as any information that is maintained by a department that identifies or describes an individual.

The broad definition includes information such as the following:

  • Name
  • Social security number
  • Physical description
  • Home address
  • Home telephone number
  • Education
  • Financial matters
  • Medical or employment history

The Information Practices Act allows agencies to collect only the personal information they are legally authorized to collect. It gives individuals the right to see their own records and to request that any errors be corrected. It also requires agencies to establish appropriate and reasonable administrative, technical and physical safeguards to protect personal information from a wide spectrum of threats and risks such as unauthorized access, use, disclosure, modification, or destruction.

The Information Practices Act interacts with the Public Records Act. The Public Records Act makes most state records open to the public with certain exceptions. The Information Practices Act requires protecting personal information, even when it is part of a record that is open to the public. That's why state agencies routinely redact or otherwise delete personal information before releasing public records. Check with your public information officer or legal office when responding to requests for information pursuant to the Public Records Act.

Consequences

There are penalties for violating the Information Practices Act, both for a department, which may be sued, and for an employee, who may be disciplined. An individual may bring a civil action against a department that violates the Information Practices Act if the violation results in an adverse impact on the individual. An employee who intentionally violates the act may be subject to disciplinary action, including termination. An employee who willfully obtains a record containing personal information under false pretenses may be guilty of a misdemeanor with a penalty of up to a $5,000 fine and up to one year in prison.

Social Security Number Confidentiality Act

The Social Security Number Confidentiality Act seeks to protect against identity theft using Social Security numbers with a name and a Social Security number. An identity thief can open new credit accounts and commit other financial crimes in the victim's name. Therefore, this law applies to state agencies and to other entities in California by prohibiting the public posting or display of social security numbers.

It also specifically prohibits a person or entity from doing any of the following:

  • Printing a social security number on identification membership cards
  • Requiring an individual to transmit his or her social security number over the internet unless the connection is secure or the number is encrypted
  • Mailing documents with social security numbers to an individual unless required by law
  • Requiring an individual to use his or her social security number to access a website, unless a password is also required

Knowledge Check

Which of the following are possible penalties for violating the Information Practices Act?

  • A. A state department could be sued.
  • B. A state employee could be disciplined or fired.
  • C. A state employee who steals a department's personal information could be fined $5,000 and sentenced to a year in prison.
  • D. All of the above. (Correct Answer)

A State Department can collect personal information for any reasonable purpose.

  • A. True.
  • B. False. (Correct Answer)

What Does HIPAA Do?

The purpose of the Health Insurance Portability and Accountability Act, HIPAA, of 1996 is to:

  • Guarantee the security and privacy of protected health information
  • Mandate industry-wide standards for healthcare information.

Understanding provider responsibilities under HIPAA

The HIPAA rules provide federal protections for patient health information held by covered entities and business associates and gives patients an array of rights with respect to that information.

This suite of regulations includes the Privacy Rule, which protects the privacy of individually identifiable health information; the Security Rule, which sets national standards for the security of electronic protected health information (ePHI); and the Breach Notification Rule, which requires covered entities (CEs) and business associates (BAs) to provide notification following a breach of protected health information (PHI).

Whether patient health information is on a computer, in an electronic health record, on paper, or in other media, providers have responsibilities for safeguarding the information.

HIPAA protects most individually identifiable health information in any form or media, whether electronic, paper, or oral. Individually identifiable health information is information, including demographic information, that relates to:

  • The individual's past, present, or future physical or mental health or condition
  • The provision of health care to the individual
  • The past, present, or future payment for the provision of health care to the individual.

Who Must Comply with the HIPAA Rules?

Covered entities and business associates must comply with the HIPAA rules.

Covered entities include:

  • Healthcare providers
    • Who conduct certain standard administrative and financial transactions in electronic form, including doctors, clinics, hospitals, nursing homes, and pharmacies
    • Health plans
    • Health care clearing houses

A business associate (BA) is a person or entity, other than a workforce member (e.g., a member of your office staff) who performs certain functions or activities on your behalf, or provides certain services to or for you, when the services involve access to, or disclosure of personal health information (PHI).

Business associate functions or activities include:

  • Claims processing
  • Data analysis
  • Quality assurance
  • Certain patient safety activities
  • Utilization review
  • Billing

The HIPAA Privacy Rule

The HIPAA Privacy Rule establishes national standards for the protection of certain health information.

The Privacy Rule standards address the use and disclosure of personal health information as well as standards for individuals' privacy rights to understand and control how their health information is used and shared, including rights to examine and obtain a copy of their health records as well as to request corrections.

The imposition of civil and criminal penalties is possible for violations of HIPAA and the HIPAA Privacy Rule.

For more information on the HIPAA Privacy Rule, visit U.S. Department of Health and Human Services at https://www.hhs.gov/hipaa/for-professionals/privacy/index.html

The HIPAA Security Rule

The HIPAA Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) establish a national set of security standards for protecting certain health information that is held or transferred in electronic form.

The Security Rule operationalized the protections contained in the Privacy Rule by addressing the technical and non-technical safeguards that organizations called "covered entities" must put in place to secure individuals "electronic protected health information" (e-PHI).

A major goal of the Security Rule is to protect the privacy of individuals' health information while allowing covered entities to adopt new technologies to improve the quality and efficiency of patient care. Given that the healthcare marketplace is diverse, the Security Rule is designed to be flexible and scalable so a covered entity can implement policies, procedures, and technologies that are appropriate for the entity's particular size, organizational structure, and risks to consumers' electronic protected health information.

General Rules

The Security Rule requires covered entities to maintain reasonable and appropriate administrative, technical, and physical safeguards for protecting electronic protected health information (e-PHI).

Specifically, covered entities must:

  • Ensure the confidentiality, integrity, and availability of all electronic protected health information (e-PHI) they create, receive, maintain or transmit
  • Identify and protect against reasonably anticipated threats to the security or integrity of the information
  • Protect against reasonably anticipated, impermissible uses or disclosures
  • Ensure compliance by their workforce

The Security Rule also promotes the two additional goals of maintaining the integrity and availability of electronic protected health information. Under the Security Rule, integrity means that electronic protected health information is not altered or destroyed in an unauthorized manner.

Availability means that electronic protected health information is accessible and usable on demand by an authorized person.

Breach Notification Rule

The HIPAA Breach Notification Rule, 45 CFR §§ 164.400-414, requires HIPAA-covered entities and their business associates to provide notification following a breach of unsecured protected health information.

Similar breach notification provisions implemented and enforced by the Federal Trade Commission apply to vendors of personal health records and their third-party service providers.

Security breach laws are not just for HIPAA

The Information Practices Act requires departments to notify people promptly if an unauthorized person acquires certain personal information.

The personal information that triggers the notice requirement is the kind that identity thieves want. It is a name, plus one or more of the following:

  • Social security number
  • Driver's license or California identification card number
  • Financial account number
  • Medical information
  • Health insurance information

Such a breach might be the loss or theft of a laptop containing personal information, and intrusion into a state computer system by a hacker, or the mailing of a disk or letter containing information to the wrong person.

The law was passed to alert people when their personal information may have fallen into the wrong hands, thus putting them at risk of identity theft. People who receive a notice of a breach can take steps to protect themselves against the possibility of identity theft.

For example, if your social security number is involved in a breach, you can place a fraud alert or a security freeze on your credit files, which will protect you from new accounts being opened using your information.

Breach Notification

Covered entities must notify affected individuals following the discovery of a breach of unsecured protected health information.

If you discover or suspect a breach:

  • Report it to your supervisor immediately
  • Complete a Security Incident Report (CDA 1025A) and submit to your Program Manager
  • Follow CDA's security incident reporting procedure located at: https://aging.ca.gov/Information_Security/

Knowledge Check

Examples of protected health information (PHI) include:

  • A. Name, address, birthday, social security number, and e-mail address.
  • B. Medical records, diagnosis, treatment, and test results.
  • C. Billing records, research records, and referral authorizations.
  • D. All of the above. (Correct Answer)

What is the purpose of HIPAA?

  • A. To protect the privacy and security of patients' health information.
  • B. To provide for electronic and physical security of a patient's health information.
  • C. To prevent health care fraud and abuse.
  • D. All of the above. (Correct Answer)

HIPAA penalties and sanctions can include

  • A. Monetary fines
  • B. Loss of job
  • C. Jail time for willful criminal offenses
  • D. All of the above. (Correct Answer)

Recommended Privacy Practices

Protecting personal information from unauthorized access, use, disclosure, modification, or destruction is one way to protect individuals' privacy.

In this section, you will learn about good and bad practices for protecting personal, confidential, sensitive and security-related information, such as:

  • Department computer network configuration
  • Financial information
  • Drafts of policy documents

Know Where Personal Information, PI, Is

The first step to protecting personal information is to know where it is. Take a look around your workstation. Remember to look for information on employees, as well as consumers, licensees, and others.

Personal information can be on different types of media, for example, electronic or paper. Places to look include, but are not limited to, the following:

  • Desk or countertop
  • Computer
  • File drawers
  • Cabinets, shelves, and bookcases
  • Tablet and smartphone
  • Discs, CDs, DVDs, and USB flash drives
  • Printers, and scanners

Physical Security

The physical security where confidential, personal, or sensitive information is created, stored, used or viewed includes the following physical safeguards.

  • Access to PI (personal information) or PHI (personal health information) is limited to authorized individuals, based upon their job duties
  • Access authorization controls including properly coded badges, key cards, and other access authorization methods
  • Visitor controls, which includes signing into the facility and being escorted by an authorized employee within locations where confidential, personal, or sensitive information is not physically secured
  • Employees and authorized users' access to the facility or system shall be revoked or modified as appropriate in case of: Employment termination, Change of duties, or Contract termination
  • Sufficient locked storage spaces for hard copy records with confidential, personal, or sensitive information

Keep Personal Information Only As Long As Necessary

Once you've located where you keep personal information in your workstation, consider whether you really need to keep it at all. There are some kinds of records that we are required to keep for legal and policy reasons. But, there are probably lots of other files, paper and digital, that we don't need to keep beyond the period when we are working on them.

Refer to your records retention schedules for specific periods.

Develop the habit of regularly purging documents with personal information from individual file folders.

Dispose of Records Safely

One way that identity thieves steal personal information is by going through trash. Shred documents with personal and other confidential information before throwing them away. Always use a cross-cut or confetti-cut shredder to destroy documents containing personal, confidential, or sensitive information. Don't throw documents containing personal information into your wastebasket or recycling bin. Shred them.

Use confidential destruct bins and an on-site shredding service. Approved vendor shreds the documents at your work site for large quantities of documents containing personal, confidential, or sensitive information.

Deleting files from your computing devices, for example, computers, tablets, smartphones, doesn't completely remove them. To protect personal information, computing devices must be sanitized using an approved destruction method before disposal, surveying, repairing, returning, replacing, upgrading, or other activities services involving individuals not authorized to access the personal information.

  • Sanitization is the process of wiping, overwriting, or destroying data and information in a special manner so that the data and information cannot be restored or recovered.
  • Portable electronic storage media, for example, USB flash drives, hard drives, CDs, DVDs, disks, SD cards, and other electronic devices, for example, servers, printers, routers, copiers, fax machines, scanners, digital voice recorders, must also be sanitized using an approved destruction method.

Protect Personal Information From Unauthorized Access

Not everyone in an office needs to have access to all files and databases containing personal information. Access to personal information, like social security numbers, driver's license numbers, and medical information, should be limited to only those who need to use it to perform their duties.

  • Don't give access to coworkers who are not authorized
  • Don't share your user IDs, passwords, keys, or key cards with others
  • When in doubt about someone's access privileges, check with your supervisor or manager
  • Lock your device screen when not actively using your computer, smartphone, or tablet. For computers, a good way to remember this is to think "Control-Alt-Delete," before you leave your seat

Password Management

Password requirement recommendations (your system requirements may differ):

  • Minimum of eight characters
  • Should contain at least three of the following:
    • Numbers 0 to 9
    • Alphabet Lowercase and/or Uppercase A to Z
    • Special characters !@#$%^&*()_+=<>?/
    • Spaces

Password duration recommendations:

  • Passwords can be changed after two days
  • Passwords must be changed within 90 days

Malicious Software

  • Malicious software (malware) is any software that gives partial to full control of your computer to do whatever the malware creator wants
    • Malware can be a virus, worm, trojan, adware, spyware, rootkit, etc.
    • The damage done can vary from something slight, like changing the author's name on documents to full control of your machine
  • Most malware requires the user to initiate its operation
  • Some vectors of attack include attachments in emails, browsing a malicious website that installs software after the user clicks OK on a pop-up, and from vulnerabilities in the operating system or programs

Protect Personal Information on Portable Devices

In cases where use of portable devices or removable storage media has been determined to be absolutely necessary to access and/or store PI and/or PHI and secure electronic transfer is not feasible, the following precautions shall be strictly followed:

  • Only the minimum amount of PI and or PHI necessary to the authorized task shall be downloaded or stored
  • The information shall be encrypted

In addition to protecting the information on a device, employees should take care to protect the devices themselves.

Don't leave a laptop, smartphone, or other portable devices visible in:

  • Empty vehicle
  • Locker at the gym
  • A public location

It only takes a few seconds for a thief to smash a window or break a lock and take what they want.

Protect Personal Information in Transit

Email

Think of e-mail as a postcard. It isn't private. It's also very easy to mistype e-mail addresses and send the message to the wrong person.

  • Don't use e-mail to send or receive personal information.
  • Before sending emails check:
    • The e-mail addresses to ensure that the message is being sent to the correct individuals
    • These individuals are authorized to have access to any personal information contained in the message

Voicemail

Don't leave personal information in a voicemail message. You don't know who will pick up that message. Instead, simply leave a message to call you back. This precautionary measure also applies to leaving messages with an individual who may not be authorized to have access to the personal information. This individual may also put the message where it is visible or readable by other individuals who may not be authorized to have access to the personal information.

Regular Mail

Use secure procedures for regular mail, which often contains personal information. Mail thieves are after personal information to commit identity theft.

  • Don't leave incoming or outgoing mail in unlocked or unattended receptacles.
  • Be sure to include the name of the intended recipient in the address rather than just the name of a business organization.
    • Without a name, mail room staff must open and read mail to determine the appropriate recipient.

Delivery Services

Track packages and large envelopes when authorized to send a large amount of personal information, for example, paper files for one or more individuals. Provide the estimated date of delivery to the recipient and request independent confirmation of the delivery from the recipient once the item has been actually received.

Fax

Don't send personal information by fax, unless you use security procedures. You don't know how long a fax will remain on a machine or who might see it or pick it up. If you need to fax personal information, make special arrangements with the recipient. Arrange for and confirm prompt pickup of the fax and always check the accuracy of the fax number when keying it in.

Wireless

Don't use wireless networks to access, communicate, or transmit personal information, unless you ensure that the wireless network is managed and secured by a known and trusted source, and that sufficient safeguards are in place. Do not trust public wireless networks.

Internet

Don't share or disclose personal information on the internet, for example, websites, unless you have obtained a signed release from the affected individual and written authorization from your supervisor or manager and information security officer.

Protecting State Information at Home and Away

  • Don't take or send state records containing personal or other confidential information out of the office unless you are authorized to do so
  • Securely store state records, laptops, smartphones, and other state information assets in your home or other authorized work location
    • Not in a vehicle during the night or extended period of time
  • Ensure individuals who use your personally owned computers or smartphones do not have access to state records, which may contain personal, confidential, or sensitive information
  • Do not use public Wi-Fi or public computers for state business
  • Implement and maintain fundamental security controls and practices when remotely accessing state information assets.
    • The fundamental security controls and practices include, but are not limited to:
      • Strong passwords
      • Two-factor authentication
      • Device and data encryption
      • Antivirus malware protection software
      • Personal firewalls
      • Automatic updates
      • Secure configurations of web browsers, operating systems, and personal networks

Beware of Social Engineering Schemes

Social engineering is stealing personal information by deception. Identity thieves try to trick people into disclosing personal information.

One common form is what's known as phishing, an e-mail that looks like it's from a bank, a government agency, or a help desk IT support. It may ask you to confirm your password, account number, or social security number. It often claims to be part of an effort to protect you from fraud. It also may ask you to open an attachment containing malware, or click on a link to a fraudulent or malicious website.

The advice to consumers on phishing, which can take place over the phone or by e-mail, is never give out any personal information unless you initiated the contact. As a state employee, you may find yourself the target of this type of identity theft attempt.

It may be part of your job to give information, including personal information, to people who call and ask for it. Social engineering schemes target government agencies, relying on workers' desire to provide good customer service.

How do you know that people who ask you for personal information are authorized to have it? Because of concerns about social engineering, it's important to verify the identity and the authority of anyone who requests personal information.

When the request is made in person, verification is usually done by asking to see a photo ID. When the request is made by phone, other procedures must be used for verification before giving out personal information.

If you're not sure how to verify someone's identity or authority to receive information, ask your supervisor or manager.

Report Information Security Incidents

In order to be able to maintain good information security, to protect the information people give to us, employees and authorized users must recognize and report promptly information security incidents.

Be alert to incidents that could expose personal, confidential, or sensitive information to unauthorized access, use, disclosure, modification, or destruction.

Incidents that must be reported to your supervisor or manager include, but are not limited to:

  • Loss or theft of a computing device (For example, computer, tablet, cell phone, or other electronic devices)
  • Loss or theft of a CD, USB flash drive, or other storage media containing personal information
  • Loss or theft of paper records containing personal information
  • Mailing, emailing, or faxing documents containing personal information to the wrong person
  • Unauthorized access into computer systems
  • Phishing emails, malware, viruses, and ransomware

When in doubt, report it!

A Matter of Respect

Protecting privacy is a matter of respect - respect for our fellow citizens and others who entrust us with their personal information, and respect for our coworkers, whose information is also in our care.

Protecting personal information is not something an information security officer or a privacy officer can do alone. We all touch some personal information in our offices and we are all responsible for protecting it.

Protecting personal information is protecting people.

Knowledge Check

Which of the following should you do before leaving your workstation?

  • A. Put documents, disks, and other records containing personal information in a drawer or otherwise out of sight
  • B. Tell your coworker to keep an eye on your desk
  • C. Press Control Alt Delete and lock your computer
  • D. Both A&C (Correct Answer)

Phishing is only done via e-mail.

  • A. True
  • B. False (Correct Answer)

Resources

  • CDA Security Incident Reporting Procedure
  • Security Incident Report Form (CDA 1025A)

These can be found at aging.ca.gov/information_security/

Congratulations!

You have completed the Privacy and Information Security Awareness Training. Enter your name below to generate and print your completion certificate.

Training Completion Attestation

Upon completing the training transcript above, please enter your information below to generate your printable completion certificate.

Completion Date: Loading date...