Laserfiche WebLink
Security Policies and Procedures <br />2) The password will be changed by the ISO on the account after each <br />use of the account to a value not known to the vendor. <br />D. Vendors, contractors and other outsiders <br />Any outside organization that wishes to gain access to our or our client's <br />Private/Internal, Confidential or Protected information must: <br />1. Sign a Business Associate Subcontractor Agreement; AND <br />2. Be willing and able to show that their privacy and security controls are at least <br />as stringent as Virtru's controls. <br />See Business Associate Subcontractor Agreement for details of Agreement. <br />A written history of incidents reported by Business Associate Subcontractors (BAS) will <br />be maintained. If the ISO becomes aware of a pattern of activity in which the BAS is not <br />carrying out the contractually required safeguards, then the ISO will do one of the <br />following: <br />1. Attempt to remedy this failure <br />2. Terminate the contract, if attempt to remedy is not feasible <br />3. Report the situation to the U.S. Secretary of Health and Human Services, if <br />terminating the contract is not feasible. <br />If any given security incident involves a breach of Personally Identifiable Information, <br />the ISO will follow our privacy policies and incident management plan for handling <br />such a breach. <br />If a security incident reported by a BAS includes the potential that personal information <br />may have been obtained by unauthorized individuals, the ISO will work with the BAS to <br />notify affected persons of this event in compliance with relevant federal and/or state <br />law. <br />See also Breaches or Impermissible Uses/Disclosures within these Security Policies and <br />Procedures. <br />E. Individuals <br />Individual persons who work for such an organization must also be bound to the <br />outside organization's controls. Such individuals must: <br />1. Have Business Associates Subcontractor Agreement with their own company; <br />OR <br />2. Have a contract with their company; AND <br />3. Have appropriate background checks and bonding in place. <br />21 <br />Rev.2015.8.6 <br />