Privacy - Security - Data Breach - Originating Agency Notification, v1.0

Defines privacy requirements for organizations to notify originating organizations when sensitive information they provided has been the subject of a suspected or confirmed data breach.

Assessment Step

1
Privacy - Security - Data Breach - Originating Agency Notification (Privacy-Security-DataBreach-OriginatingAgencyNotification)
Does the organization notify originating organizations when sensitive information they provided has been the subject of a suspected or confirmed data breach?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameters
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other
Satisfied By Privacy Policyrequired
BOOLEAN : Is the organization's privacy policy the source for all supporting information for satisfying the issuance criteria of this Trustmark Definition? (TRUE=yes)

Conformance Criteria (1)

C-1
Are originating agencies notified when personal information they provided to the center has been the subject of a suspected or confirmed data breach?
Citation
FCPP
Section L.9, Security Safeguards