|
The recent and highly publicized loss and theft of restricted data reinforces not only the importance of data security and confidentiality procedures, but emphasize the need for organizations to hire knowledgeable, qualified contractors with proven records of performance conducting compliance inspections.
HLA compliance inspections are the only reliable means for organizations that collect, use, and are responsible for safekeeping confidential and individually identifiable restricted data to verify that established privacy and security standards and procedures are consistently observed and enforced. Our restricted data compliance inspections include the following:
- Select sites for data inspections
- Review existing data licensing agreements
- Conduct unannounced onsite inspections
- Perform follow-up inspections
- Prepare evaluation/progress reports
Key Features of the Data Security Inspection Process
- Our process is non-intrusive, minimizing disruptions to daily business.
- HLA employs physical and system access protection approaches, such as fire and blast-proof, secure briefcases, password protection and encryption, to transport and store license agreements and confidential data. This prevents intrusion and safeguards data in our possession.
- We use HLA-developed automated tools using standard information technology components to ensure timely and cost effective inspections and reports while minimizing information technology security risks.
- HLA ensures that each data security investigator has a comprehensive understanding of the statutory authorities for confidential and individually identifiable data handling and licensing to minimize risk to data integrity.
- HLA data security investigators arrange visits for unannounced inspections that legitimize the inspection process and encourage cooperation and security plan compliance.
- We use sophisticated physical security devices and procedures to secure and monitor the HLA offices from which we conduct our inspection support services. This safeguards all confidential and personally identifiable data and associated license documentation.
|