13.07.2015 Views

HS 9453-D Remote Access - Office of Compliance Services - UCLA ...

HS 9453-D Remote Access - Office of Compliance Services - UCLA ...

HS 9453-D Remote Access - Office of Compliance Services - UCLA ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Remote</strong> <strong>Access</strong> Policy<strong>HS</strong> <strong>9453</strong>-Dinformation and health insurance information for patients are also considered to be PHI.“Restricted Information” (as defined by UC Policy IS-3, Electronic InformationSecurity) describes any confidential or Personal Information that is protected by law orpolicy and that requires the highest level <strong>of</strong> access control and security protection,whether in storage or in transit. This includes Personal Information, PHI and ePHI asdefined in this section but could also include other types <strong>of</strong> information such as researchdata.“Authorized Personnel” means the designated IT support person or group for an area.For hospital areas, this would be Medical Information Technology <strong>Services</strong> (MITS); fordepartments within the David Geffen School <strong>of</strong> Medicine at <strong>UCLA</strong> (“School <strong>of</strong>Medicine”), it would be the departmental Computer Support Coordinator (CSC); forareas supported by the School <strong>of</strong> Medicine IT <strong>Services</strong> (SOMITS), it would be SOMITS.“Device” refers to a networked device (e.g., PC, server, medical equipment).“MedNet” is the data network connecting the <strong>UCLA</strong> Medical Centers, the School <strong>of</strong>Medicine and the <strong>UCLA</strong> Community Physician Network.“Virtual Private Network” or “VPN” is a method to allow secure remote access acrossthe Internet by using encryption and other security mechanisms to ensure that onlyauthorized users can access the network and that data cannot be intercepted.“Workforce” means employees, volunteers, and other persons whose conduct, in theperformance <strong>of</strong> their work for <strong>UCLA</strong> Health, is under the direct control <strong>of</strong> <strong>UCLA</strong> Healthor the Regents <strong>of</strong> the University <strong>of</strong> California, whether or not <strong>UCLA</strong> Health pays them.The Workforce includes employees, medical staff, and other health care pr<strong>of</strong>essionals,agency, temporary and registry personnel, and trainees, housestaff, students andinterns, regardless <strong>of</strong> whether they are <strong>UCLA</strong> trainees or rotating through <strong>UCLA</strong> Healthfacilities from another institution.POLICYI. All remote access into <strong>UCLA</strong> Health networks across the Internet must useapproved VPN technology, and the remote access must be approved in advanceby the Department Authorizer.II.Devices that will be used for remote access that are not <strong>UCLA</strong> Health ownedequipment must be configured to comply with the provisions <strong>of</strong> this policy.2 <strong>of</strong> 5 <strong>UCLA</strong> Health<strong>Compliance</strong> Policies and ProceduresPrivacy and Information Security Policies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!