All Policies › Information Technology › Data Breach Notification
Data Breach Notification
Responsible Office
Vice President for Strategic Operations & Human Resources
Policy Owner
Executive Director of Innovation & Technology
Policy Contact
Executive Director of Innovation & Technology
Issued
2021-04-21
Last Revised
2026-10-01
On this page: Policy Statement · Reason for Policy · Policy Scope · Procedures · Frequently Asked Questions · Forms · Appendices · Additional Contacts · Definitions · Responsibilities · Related Information · History
Policy Statement
The university will disclose any breach of its data to any person whose sensitive, personal information was, or is reasonably believed to have been, acquired by an unauthorized person. This disclosure will be made in the timeliest manner possible. It is the university’s sole discretion to determine the scope of the breach. The university will provide information about data breaches as required by federal and state laws, and regulations and/or policies.
The disclosure may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation.
The university will make every reasonable effort to contact individuals impacted. Contact may be made in person, by mail, and/or by e-mail. If the university does not have sufficient contact information, a general disclosure will be posted on a North Central University web site and appropriate news media outlets will be notified.
University employees and students, or other individuals, must report incidents where a breach of university data is suspected to university Information Security (cybersecurity@northcentral.edu), by following university procedure: Reporting Information Security Incidents.
The Information Security Program Administrator (Program Administrator), in consultation with the university counsel and appropriate university administrators, is responsible for determining whether a breach of information security or university private data has occurred and whether notification to affected individuals is required. The Program Administrator may also seek advice from other key administrators responsible for security and privacy at the university and consult with responsible administrators in the affected area, department, or other university stakeholders.
The Program Administrator and university Information Security work with the responsible departments to send any required notifications in accordance with university procedure: Notification of a Data Security Breach. All notifications must be reviewed and approved by university Information Security prior to making notification.
Third-Party Incidents Involving University Data
When a vendor, contractor, cloud service provider, business associate, or other third party reports an incident involving university data, the Program Administrator, in consultation with university counsel, determines whether the incident meets the threshold of a breach for purposes of the university’s notification obligations. The Program Administrator makes this determination independent of the third party’s own characterization of the incident.
The third party retains responsibility for investigating the incident, containing and remediating the cause, conducting forensic analysis, and bearing the costs associated with its own response. The third party also retains responsibility for fulfilling its own notification obligations under applicable contracts, federal and state laws, and industry standards. The university’s role focuses on protecting the interests of the affected community, fulfilling the university’s independent notification obligations, and coordinating with the third party to ensure accurate and timely information.
University Information Security requests sufficient information from the third party to make a notification determination, including the categories and volume of university data involved, the individuals affected, the timeline of the incident, the third party’s findings, and any notifications the third party has issued or plans to issue.
Education Records Under FERPA. The university remains the educational agency responsible for education records under the Family Educational Rights and Privacy Act (FERPA), regardless of where a breach occurs. The university’s FERPA obligations operate independently of, and in addition to, any notification duties the third party owes under its contracts or under other laws. When a third party held education records under the school official exception or another permitted disclosure, and an incident results in unauthorized access to or disclosure of those records, the university retains responsibility for notification to affected students and, where applicable, parents of dependent or minor students. The Program Administrator, in consultation with university counsel and the Registrar, evaluates whether the incident constitutes an unauthorized disclosure of education records under FERPA, documents the disclosure in accordance with 34 CFR §99.32, and determines whether the third party’s actions warrant the five-year prohibition on access to education records described at 34 CFR §99.33(e). The university also evaluates whether to report the incident to the U.S. Department of Education’s Student Privacy Policy Office.
The Program Administrator decides how affected individuals receive notification from the university. Options include notification by the university, authorization for the third party to notify on the university’s behalf, or coordinated joint notification. The Program Administrator selects the approach that best serves clarity for affected individuals and consistency with the university’s contractual and regulatory obligations. The university’s notification decision does not relieve the third party of any separate notification obligations the third party owes under its contracts or under other laws. For incidents involving education records, the university issues or directly oversees notification to students and parents, given the university’s non-delegable obligations under FERPA.
The Program Administrator, in consultation with university counsel, identifies which party holds responsibility for required notifications to federal and state regulators, payment card brands, and accrediting bodies. Some notifications fall to the third party, some fall to the university, and some require both parties to file separately. The university does not assume regulatory notification responsibilities that contractually or legally belong to the third party, and the university’s notifications do not satisfy obligations the third party owes in its own right. The university retains direct responsibility for FERPA-related notifications and for any communications with the U.S. Department of Education concerning education records.
Following a third-party incident, the Program Administrator coordinates with the contract owner and the responsible department to refer the vendor relationship for reassessment under the Vendor Risk Management Policy. For incidents involving education records, the reassessment includes a review of whether continued access to education records remains appropriate under FERPA.
Reason for Policy
This policy defines the steps that personnel must use to ensure that information security incidents are identified, contained, investigated, and remedied. It also provides a process for documentation, appropriate reporting internally and externally, and communication so that organizational learning occurs. Finally, it establishes responsibility and accountability for all steps in the process of addressing information security incidents.
Policy Scope
This policy applies to all users of all university data, whether faculty, staff, student, contractor, consultant, or agent thereof. This policy further applies to any computing or data storing devices owned or leased by the university that experience a security incident, as well as any computing or data storing device, regardless of ownership, which is used to store university data, or which, if lost, stolen, or compromised, and based on its privileged access, could lead to the unauthorized disclosure of protected data.
Procedures
Reporting Information Security Incidents
Report actual or suspected IT security incidents as soon as possible so that work can begin to investigate and resolve them. If the incident poses any immediate danger, call 911 to contact law enforcement authorities immediately.
Reporting an IT Security Incident
If you suspect a potential security issue involving any private information—whether the information is on a computer, on paper, on the web, etc.—immediately report the details to IT by clicking the Report Incident button on the incident reporting page. You should also alert your supervisor.
If you are unable to use this form, email incident@northcentral.edu.
Do not use the device or system that may be involved in a suspected security incident or data breach. Instead use alternative communication methods (e.g., different device, call the service desk 612.343.4170) to report the incident to University Information Security and wait for further instructions prior to turning the device or system off. Be prepared to include:
- A general description of the type of information at issue.
- Your contact information.
- The department involved.
- A brief description of what happened.
Do not include sensitive information in the initial report. IT staff will contact you for more details.
Notification of a Data Security Breach
The Program Administrator or delegate works with the affected department, responsible administrators, university communications, and others as appropriate to deliver timely and effective notification to individuals.
Determine if other actions are required – The Program Administrator determines whether other requirements apply, depending on the nature of the information that is the subject of the breach, as well as the scope of the breach. Notification regarding protected health information must comply with the notification provisions within HIPAA regulations. 45 C.F.R. Part 164, Subpart D.
Draft the content of notification.
While the content may vary, notification must always include these elements, to the extent possible:
- A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known
- A description of the types of private data that were involved in the breach (e.g., full name, social security number, date of birth, home address, bank account number, personal financial information, grades, diagnosis, etc.)
- Any steps individuals should take to protect themselves from possible harm resulting from the breach (e.g., identity theft)
- A brief description of what the University is doing to investigate the breach, to mitigate harm to individuals, and to protect against further breaches
- Contact information for further questions and assistance, including a toll-free telephone number, an email address, website address, or postal address as appropriate
Determine the manner of notification – The Executive Director of Innovation & Technology determines the appropriate manner of notification—whether first-class mail, email, or substitute notice—as required under the law.
Review the notification – University Information Security reviews and approves all notifications prior to making notification.
Frequently Asked Questions
Q: What counts as a data breach?
A: A breach means unauthorized access to, acquisition, use, or disclosure of university data that compromises its security and privacy. Good-faith access by an employee who does not share the data with an unauthorized person, encrypted data, and properly de-identified data do not count as a breach.
Q: I think someone accessed university data without authorization. What should I do?
A: Report it right away through the Information Security Incident Form or by emailing incident@northcentral.edu, and alert your supervisor. If the incident poses any immediate danger, call 911.
Q: Should I keep using a device that someone may have compromised?
A: No. Stop using the device or system, report the incident from a different device or by calling the service desk at 612.343.4170, and wait for instructions before turning the device off.
Q: Should I include sensitive details in my report?
A: No. Give a general description of the information involved, your contact information, the department, and what happened. IT staff will contact you for more details.
Q: Who decides whether a breach occurred?
A: The Information Security Program Administrator decides, in consultation with university counsel and appropriate university administrators.
Q: How will NCU notify people affected by a breach?
A: The university contacts affected individuals in person, by mail, or by email. When the university lacks enough contact information, it posts a general notice on a university website and notifies appropriate news media.
Q: What will a breach notice tell me?
A: A notice describes what happened and when, the types of data involved, steps you can take to protect yourself, what the university does to investigate and limit harm, and how to get more help.
Q: Can NCU delay a breach notice?
A: Yes. The university may delay notice when a law enforcement agency determines that notification would impede a criminal investigation.
Q: What happens when a vendor that holds NCU data experiences a breach?
A: The vendor investigates, fixes the cause, covers its own costs, and meets its own notification duties. The university separately decides whether its own notification duties apply, and it issues or directly oversees any notices involving student education records under FERPA.
Q: Do these requirements cover personal devices?
A: Yes, when you use a personal device to store university data, or when the device’s access could lead to unauthorized disclosure of protected data if someone loses, steals, or compromises it.
Forms
Appendices
There are no appendices associated with this policy.
Additional Contacts
| Subject | Contact | Phone | |
|---|---|---|---|
| Policy Contact & Clarification | Information Security – Program Administrator | 612.343.4754 | cybersecurity@northcentral.edu |
| Information Security – Reporting Breaches | Information Security | 612.343.4754 | incident@northcentral.edu |
Definitions
Acceptable Use
Use of IT resources that is always ethical, reflects academic honesty, and shows restraint in the consumption of shared resources. Acceptable use demonstrates respect for intellectual property, ownership of data, system security mechanisms, and individuals’ rights to privacy and to freedom from libel, slander, intimidation, discrimination, and harassment.
Authorized Use
Use that the university determines, in its sole and exclusive discretion, is consistent with the education, research, and mission of the university, consistent with effective departmental or divisional operations, and consistent with this policy.
Authorized User
Individuals or entities permitted to make use of university information technology resources, including students, staff, faculty, alumni, guests, sponsored affiliates, and other individuals who have an association with the university.
Breach of Security
For purposes of this policy this means unauthorized access to, acquisition, use, or disclosure of data maintained by the university, which compromises the security and privacy of the data. “Breach” does not include (1) good faith acquisition, access, or use of private data by an employee, contractor, or agent of the university, if the data is not provided to an unauthorized person; (2) incidents involving data that have been rendered unusable, unreadable, or undecipherable (e.g., through valid encryption) to unauthorized individuals; or (3) incidents involving data that has been de-identified in compliance with applicable legal requirements.
Business Associates
An individual (other than an employee or member of the workforce of the Covered Entity) or organization who (i) on behalf of a Covered Entity, creates, receives, maintains or transmits PHI, or (ii) provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services to a Covered Entity and where the provision of the service involves the use or disclosure of PHI.
Covered Entity
A health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with transactions covered by HIPAA, as defined in 45 CFR 160.103.
Information
Data collected, stored, transferred or reported for any purpose, whether in electronic, paper, oral, or other media.
Notification
The act of informing persons affected by a breach of university data that their information was included in the breach and the steps they can take to protect themselves and their privacy. Notification also includes required noticing to federal and state agencies. Notification to affected individuals will be overseen by Program Administrator, and depending on the data breached, may include the following components:
- A general description of the unauthorized access or acquisition.
- The type of personal information affected.
- A general description of the steps the university will take to protect the information from further unauthorized access or acquisition.
- Instructions and necessary information for notifying the major credit agencies of suspected or potential identity theft as needed.
Personally Identifiable Information
Any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name, or bio-metric records; and any other information that is linked or link-able to an individual, such as medical, educational, financial, and employment information.
Examples of PII include, but are not limited to:
- Name: full name, maiden name, mother’s maiden name, or alias
- Personal identification numbers: social security number (SSN), passport number, driver’s license number, taxpayer identification number, patient identification number, financial account number, or credit card number
- Personal address information: street address, or email address
- Personal telephone numbers
- Personal characteristics: photographic images (particularly of face or other identifying characteristics), fingerprints, or handwriting
- Biometric data: retina scans, voice signatures, or facial geometry
- Information identifying personally owned property: VIN number or title number
- Asset information: Internet Protocol (IP) or Media Access Control (MAC) addresses that consistently link to a particular person
The following examples on their own do not constitute PII as more than one person could share these traits. However, when linked or linkable to one of the above examples, the following could be used to identify a specific person:
- Date of birth
- Place of birth
- Business telephone number
- Business mailing or email address
- Race
- Religion
- Geographical indicators
- Employment information
- Medical information
- Education information
- Financial information
Private Data
University data protected by federal or state law (e.g., FERPA, HIPAA), regulation, or contract (e.g. PCI DSS for credit cards, some research contracts).
Program Administrator
Individual responsible for the management of the Information Security Program. Executive Director of Innovation & Technology.
Protected Health Information (“PHI”)
Information transmitted or maintained in any form or medium (electronic, paper, oral or other) that (i) is created or received by a Covered Entity, (ii) relates to the past, present or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present or future payment for the provision of health care to an individual, and (iii) is identifiable to an individual or there is reasonable basis to believe can be used to identify an individual. PHI specifically excludes information of individuals who have been deceased for more than 50 years.
The following records are exempted from the definition of PHI as defined by HIPAA:
- Student records maintained by an educational institution;
- Treatment records about post-secondary students meeting the requirements of 20 U.S.C. 1232g (4)(B)(iv); and
- Employment records held by a covered entity in its role as employer.
Unauthorized Acquisition
For the purposes of this policy, this means that a person has obtained university private data without statutory authority, authorization from an appropriate university official, or authorization of the individual who is the subject of the data, and with the intent to use the data for unauthorized or non-university purposes.
Responsibilities
All Individuals
- Report concerns regarding suspected security breaches of private data to University Information Security at cybersecurity@northcentral.edu
Program Administrator (Executive Director of Innovation & Technology)
- Accountable for making determinations, in consultation with the university counsel and appropriate privacy officers, as to whether a breach of information security or private data has occurred and whether notification is required, and direct responsible departments in complying with notification obligations.
- Delegate the authority and responsibilities for investigation of the suspected information security and data breach, and oversight of the notification process.
- Inform the appropriate officers of suspected data breaches.
- Oversight of the notification process, and breach determination.
Office of Innovation & Technology (OIT) – University Information Security
- Investigate the suspected information security or data breach.
- Report breach information and status to the Executive Director of Innovation & Technology
- Ensure that appropriate and timely action is taken on a suspected information security or data breach.
General Counsel
- Provide legal advice to the Office of Innovation & Technology and other University staff and decision makers to ensure compliance with breach determination and notification obligations under the law.
Related Information
Related Policies & Procedures
- University Policy: Acceptable Use of Information Technology Resources
- University Policy: Information Security
- University Policy: Managing Student Records
Related Legislation
- HIPAA Regulations, 45 CFR Part 164, Subpart D
- Family Educational Rights and Privacy Act (FERPA)
- Payment Card Industry Data Security Standard (PCI DSS)
- Gramm–Leach–Bliley Act (GLBA)
History
Amended
2026-10-01 – Non-substantive updates (e.g., titles and copy errors); moved procedures onto the policy page; added frequently asked questions and the Covered Entity definition.
Issued
2021-04-21


