Laserfiche WebLink
Security Policies and Procedures <br />The granting of access to Business Associate Subcontractors will be done in the same <br />way as it is done for workforce members. <br />C. Granting access <br />The ISO will provide accounts with the matching technical privileges and give the <br />workforce member the account information including a one -time -use password that <br />the user must change to a private password upon first use of the account. <br />1. Only the person assigned to an account will be allowed to use that account. <br />2. Each time a user logs in to a system, a log will be maintained by that specific <br />program with the following information <br />a) When the user accessed the system <br />b) What information the user accessed while in the program <br />c) Tracking will be done by using the User ID and IP Address <br />d) The ISO will maintain this log for a period of 1 year <br />3. The ISO and AISO will each have a special account that allows them to create new <br />accounts. The accounts will be used: <br />a) In an emergency when all other accounts have been disabled or locked out; <br />b) To either reset the passwords on locked accounts; or <br />c) To create new accounts that provide needed access. <br />4. When a change in the role of a workforce member requires a change in access <br />privileges, the ISO will reassess the needs and provide new access privileges based <br />on the policy in Access Levels in this section. <br />a) If a workforce member leaves Virtru, the ISO will remove that member's <br />access as soon as the access is no longer needed. <br />b) If a workforce member takes a leave of absence and is not expected to <br />require access, the ISO will disable the workforce member's account when <br />he/she leaves and re -enable it upon his/her return to work. <br />c) For other people who work around protected electronic information but <br />are not qualified to access it, the ISO will decide which of the following two <br />steps to take: <br />1) Train the person to understand his/her responsibilities <br />2) Supervise while he/she is exposed to the data <br />d) For cases in which the provision of individual accounts is not feasible {e.g. <br />access by any one person of a large help desk staff of a vendor}, the ISO will <br />make: <br />1) A serially reusable account and provide a one -time -use password <br />to the vendor's representative for each time that access is needed; <br />and <br />Rev.2015.8.6 <br />20 <br />