NOTIFICATION OF A DATA SECURITY BREACH
Related Policy – Data Breach Notification
About This Procedure
Responsible Officer
Vice President of Business & Operations
Policy Owner
Executive Director of Information Technology
Policy Contact
Executive Director of Information Technology
Issued
2021-04-21
University Procedure
The Program Administrator or delegate works with the affected department, responsible administrators, university communications, and others as appropriate to deliver timely and effective notification to individuals.
- Draft the content of notification.
- While the content may vary, notification must always include these elements, to the extent possible:
- A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known
- A description of the types of private data that were involved in the breach (e.g., full name, social security number, date of birth, home address, bank account number, personal financial information, grades, diagnosis, etc.)
- Any steps individuals should take to protect themselves from possible harm resulting from the breach (e.g., identity theft)
- A brief description of what the University is doing to investigate the breach, to mitigate harm to individuals, and to protect against further breaches
- Contact information for further questions and assistance, including a toll-free telephone number, an email address, website address, or postal address as appropriate
- Determine the manner of notification – The Director of Information Technology determines the appropriate manner of notification—whether first-class mail, email, or substitute notice—as required under the law.
- Review the notification – University Information Security reviews and approves all notifications prior to making notification.
- Determine if other actions are required – The Program Administrator determines whether other requirements apply, depending on the nature of the information that is the subject of the breach, as well as the scope of the breach. Notification regarding protected health information must comply with the notification provisions within HIPAA regulations. 45 C.F.R. Part 164, Subpart D.