Laserfiche WebLink
b. The second infraction of either type within 3 years <br />The sanction will include a written letter of reprimand that is given to the person at <br />fault, placement of a copy of the letter in the employee file, and one week's <br />suspension without pay. The letter will notify the person of the nature of this <br />infraction and of sanctions for future potential infractions. <br />Third security infraction or second serious infraction <br />If the infraction is: <br />a. A second serious infraction within 3 years, or <br />b. A third infraction of any type within 3 years. <br />The sanction will be dismissal from the workforce. <br />Virtru makes exceptions for disclosures made by employees who qualify as <br />whistleblowers or certain crime victims. <br />6. Mitigation efforts required: Virtru, to the extent practicable, shall mitigate any <br />harmful effects of unauthorized uses or disclosures of Personally -Identifiable <br />Information by the Company or any of its Business Associate Subcontractors. <br />7. Prohibition on intimidating or retaliatory acts: Neither Virtru nor any employee <br />shall intimidate, threaten, coerce, discriminate against, or take other retaliatory <br />action against any individual for the exercise of their rights or participation in any <br />process relating to HIPAA compliance, or against any person for filing a complaint <br />with the Secretary of the U.S. Department of Health and Human Services, <br />participating in an investigation, compliance review, proceeding or hearing, or <br />engaging in reasonable opposition to any act or practice that the person in good faith <br />believes to be unlawful under the Privacy Rules as long as the action does not <br />involve disclosure of Personally -Identifiable Information in violation of the <br />regulations. <br />Virtru shall document the following actions relating to its policies and procedures: <br />a. Required policies and procedures: Virtru shall implement policies and <br />procedures to assure appropriate safeguarding of <br />Personally -Identifiable Information in its operations. <br />b. Changes to policies and procedures: Virtru shall change its policies and <br />procedures as necessary and appropriate to conform to changes in law <br />or regulation. Virtru may also make changes to policies and procedures <br />at other times as long as the policies and procedures are still in <br />compliance with applicable law. Where necessary, Virtru shall make <br />correlative changes in its Privacy Notice. <br />10 <br />Rev.2015.8.25 <br />