Laserfiche WebLink
Security Policies and Procedures <br />Android Devices <br />All Android devices that store Protected Information (PHI, CJIS, etc) will have <br />encryption turned on and will be password protected at all times. The encryption <br />key will be maintained in a secure location by both the user and the ISO. <br />Windows Phone <br />All Windows Phones that store Protected Information (PHI, CJIS, etc) will have <br />encryption turned on and will be password protected at all times. The encryption <br />key will be maintained in a secure location by both the user and the ISO. <br />iPhone <br />iPhones are natively encrypted. These devices are required to be password <br />protected and/or biometrically protected at all times. <br />E. Wi-Fi network encryption <br />All wireless access points owned by Virtru are required to be protected using Wi-Fi <br />Protected Access 2 with Advanced Encryption Standard (WPA2-AES). This password <br />will be changed quarterly and will not be shared with users that are not employees or <br />authorized Business Associates. Any outside users are required to use guest access <br />points. <br />Employees that access Virtru resources from home are required to use Wi-Fi Protected <br />Access 2 with Advanced Encryption Standard (WPA2-AES) to protect their devices. <br />This password should be changed quarterly. <br />F. Email encryption <br />Virtru requires the use of its secure, encrypted email service to communicate with our <br />employees about their Personally Identifiable Information, and to communicate any <br />sensitive data. All email communication that includes personally identifiable data, and <br />potentially sensitive data will be encrypted. <br />Virtru uses only its secure, encrypted email service to communicate with clients about <br />their Personally Identifiable Information. <br />Virtru forbids the use of chat, texting or instant messaging programs by devices that <br />store PHI. <br />G. Enforcement <br />Any workforce member found to have violated this policy may be subject to <br />disciplinary action, up to and including termination of employment. <br />See Sanction Policy. <br />42 <br />Rev.2015.8.6 <br />