2006 Spring MASFAP CONFERENCE Ginny D’Angelo Vice President of Student Loans Commerce Bank Leo Hertling Associate Director St. Louis College of Pharmacy.

Slides:



Advertisements
Similar presentations
Family Educational Rights and Privacy Act What you should know about FERPA.
Advertisements

FERPA - Sharing Student Information
Protect Our Students Protect Ourselves
FERPA: Family Educational Rights and Privacy Act
Family Educational Rights and Privacy Act (FERPA) Basics For Faculty and Staff.
FERPA: UPDATE ON THE FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Presented by Brenda V. S. Selman University Registrar-MU University of Missouri-Columbia.
Family Education Rights & Privacy Act of 1974 FERPA, You, & UC.
Maureen Cronin Associate Registrar for DARS University of Nevada, Reno.
Privacy and Information Security Training ( ) VUMC Privacy Website
FERPA Refresher Training Start. Page 2 of 11 Copyright © 2006 Arizona Board of Regents FERPA Refresher Training What is FERPA FERPA stands for Family.
Springfield Technical Community College Security Awareness Training.
Gramm-Leach-Bliley Act for Financial Aid Val Meyers Associate Director Michigan State University.
FAIR AND ACCURATE CREDIT TRANSACTIONS ACT (FACTA)- RED FLAG RULES University of Washington Red Flag Rules Protecting Against Identity Fraud.
Protecting Your Identity: What to Know, What to Do.
BEWARE! IDENTITY THEFT CARL JOHNSON FINANCIAL LITERACY JENKS HIGH CSHOOL.
FERPA: WHAT YOU SHOULD KNOW ILASFAA April 18, 2008 Amy Perrin Director of Financial Aid Elgin Community College.
Family Educational Rights and Privacy Act Training for Employees Rooker, Leroy and Falkner, Tina. AACRAO 2012 FERPA Guide FERPA.
Family Educational Rights and Privacy Act What you need to know...
Family Educational Rights and Privacy Act FERPA. The Family Educational Rights and Privacy Act of 1974, as amended, sets forth requirements regarding.
FERPA: Family Educational Rights and Privacy Act.
FERPA Skidmore College Family Education Rights & Privacy Act What is FERPA? It is the Family Educational Rights and Privacy Act of Is also referred.
1 GRAND VALLEY STATE UNIVERSITY FAMILY EDUCATIONAL RIGHTS & PRIVACY ACT (FERPA) TRAINING OFFICES OF THE REGISTRAR AND UNIVERSITY COUNSEL JANUARY 20, 2009.
What is FERPA? Family Educational Rights and Privacy Act.
2/16/2010 The Family Educational Records and Privacy Act.
FERPA The Family Educational Rights and Privacy Act.
FERPA Basics.
FERPA: Protect our Students by Protecting their Records Prepared by Rebekah D. Mathis-Stump, JD.
FERPA 2008 New regulations enact updates from over a decade of interpretations.
FERPA Family Educational Rights and Privacy Act or Buckley Amendment.
The Family Educational Rights and Privacy Act (FERPA) The Importance of Protecting Student Records This session will help you better understand the law.
FERPA REFRESHER AND UPDATE FERPA/Protecting Sensitive Information January 17, 2013 Jesh Humphrey, Senior Associate General Counsel.
FERPA Training. What is FERPA? FERPA (the Family Educational Rights and Privacy Act of 1974), also known as the Buckley Amendment, is a Federal law that.
Ten Thing IT Staff Need to Know About Education Records Privacy Ten Things IT Staff Need to Know About Education Records Privacy Jeff von Munkwitz-Smith.
8/28/2015 The Family Educational Rights and Privacy Act (FERPA)  Also known as the Buckley Amendment.  Statute: 20 U.S.C. 1232g; Regulations: 34 CFR.
FERPA The Family Educational Rights and Privacy Act (FERPA) also known as the Buckley Amendment, passed by Congress in 1974, grants four specific rights.
The Family Educational Rights and Privacy Act FERPA Tutorial online:
FERPA Family Educational Rights and Privacy Act and Rebecca Macon Registrar University of Georgia Presentation for GASFAA October.
2005 MASFAA CONFERENCE CHARLESTON, WEST VIRGINIA Ginny D’Angelo Vice President of Student Loans Commerce Bank Diane Lambart Fleming Associate Director.
1 General Awareness Training Security Awareness Module 1 Overview and Requirements.
Confidentiality and Public Information Act LISD Special Education Department Training SY
IVCC Information Security Plan Important information about the privacy of student records Adapted from SVCC Information Security Plan, 3/03. IVCC Revision.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
FERPA Refresher Training Start. Page 2 of 11 Copyright © 2006 Arizona Board of Regents FERPA Refresher Training What is FERPA FERPA stands for Family.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
 Definitions ◦ A student is any person age 18 or attending an institution of postsecondary education ◦ E ducation records are any records that are related.
Session Title: FERPA: What You Need To Know Presented By: Jeffery Loggins Institution: Mississippi Valley State University September 15, 2015.
FERPA Family Educational Rights and Privacy Act A Tutorial.
Family Educational Rights and Privacy Act.  What is FERPA?  What Information May Be Released?  Request Non-Release of Directory Information  What.
FERPA Guidelines for Cooperating Teacher and University Supervisors.
FERPA: An introduction to the Family Educational Rights and Privacy Act Presented by: Kristy Giacomelli Assistant Registrar
TASFAA 2016 Legacy of Leadership. TASFAA 2016 Legacy of Leadership Family Educational Rights and Privacy Act (FERPA) An Overview Molly Thompson Associate.
1 FERPA TUTORIAL JEFFERSON COMMUNITY & TECHNICAL COLLEGE Published by the Registrar’s Office.
The Georgia Open Records Act and ferpa
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
“Kids First, New Mexico Wins!” NMPED Data Conference Spring 2016 Dan Hill General Counsel, Public Education Department Randi Johnson General Counsel, State.
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT (FERPA) What Faculty and Staff Should Know.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Protect Our Students Protect Ourselves
Lake Land College FERPA.
FERPA (Oops, can I say that?)
FERPA (Oops, can I say that?)
Family Education Rights and Privacy Act
Red Flags Rule An Introduction County College of Morris
Family Education Rights and Privacy Act
FERPA for Colleges & Universities
Welcome to the FERPA training for Faculty and Staff.
UCA Gramm-Leach Bliley Act (GLBA) Safeguards Rule Compliance Training Effective June 12, 2018 Adapted from materials published by the Federal Trade Commission.
Family Educational Rights and Privacy Act of 1974
Presentation transcript:

2006 Spring MASFAP CONFERENCE Ginny D’Angelo Vice President of Student Loans Commerce Bank Leo Hertling Associate Director St. Louis College of Pharmacy

GRAMM-LEACH-BLILEY GLB ACT Financial Modernization Act of 1999

Gramm-Leach-Bliley Act GLB is a federal law, which includes provisions in requiring financial institutions to take steps ensuring the security and confidentiality of a consumers/customers personal information. In 2003, the Federal Trade Commission (FTC) confirmed that higher education institutions are considered financial institutions under this law.

Gramm-Leach-Bliley Act  Colleges and universities must be in compliance with provisions of the GLB Act that relate to the Safeguards Rule.  Colleges and universities that already comply with FERPA will be deemed to be in compliance with FTC privacy rules under the GLB Act.

Gramm-Leach-Bliley Act The law requires that institutions must protect information collected about individuals:  Names  Addresses and phone numbers  Bank and credit card accounts  Social Security numbers  Income and credit histories

Gramm-Leach-Bliley Act According to the Safeguards Rule, financial institutions must develop a written information security plan that describes their program to protect customer information. Privacy notices explaining an institution’s information-sharing practices must also be provided to each customer.

Gramm-Leach-Bliley Act Experts suggest that three areas of operation present special challenges and risks to information security:  Employee training and management  Information systems (network and software),storage,transmissions and retrievals  Security management, including prevention, detection and response to attacks, intrusions or other system failures

Gramm-Leach-Bliley Act Quick Tips for Safeguarding information:  Identify what is considered sensitive information  Protect all sensitive information from unauthorized access or use  Put safeguarding into practice  Report suspicious activity

How does this apply to you? Privacy of Information – FERPA Safety of Information

Which Units are Most Affected by GLB? Registrar Financial Aid Office Bursar Development Office IT Academic Departments

Privacy of Information FERPA – Family Educational Rights & Privacy Act (1974) If you are FERPA-compliant, you are meeting GLB criteria to protect information privacy FERPA protects privacy of all student educational records and financial information

FERPA Policies Written policy – College Catalogue Staff training; i.e., memos from Registrar’s Office to faculty & staff regarding FERPA policy Information is shared on a “need to know” basis, i.e.: Audits Law enforcement officials (must have proper documentation and credentials) Contracted services (loan, collection agencies) Development Office

Rights Guaranteed under FERPA Right to inspect and review educational records Right to seek amendment of educational records Right to have control over the disclosure of educational records Right to file a complaint with ED for alleged failures of an institution’s compliance

What Can Be Shared? MAY SHARE Name Address telephone # Major DOB and location Photo Dates of attendance School activities Enrollment status Most recent previous school attended MAY NOT SHARE Social Security # Student ID # Race Ethnicity Nationality Gender

Dealing with Parents Major differences between FAO policies and those of the Registrar For the Registrar Parents may have access to student records if: They have obtained a SIGNED AND WRITTEN CONSENT or the student If the student is under the age of 24 and was claimed by the parent in the prior tax year, the parent may access the students records after the student has been advised of the institution’s intention to release information to the parent. You must give the student adequate time to respond. You must return the tax return to the parent. You do not have the right to keep it. Simply document that you checked it and that the student was claimed. If the student objects, the parent must obtained a signed written consent before records may be released. School must maintain records of the request and ANY disclosures

The FAO and Parents Parents of dependent students are afforded the right to access a student’s financial records. This applies for Dependent students in terms of IRS dependency. NOT TIV aid terms. FAOs may have student sign an annual waiver granting the parents access on an annual basis.

Dealing with Spouses FERPA does not recognize spouses therefore they must be treated as unrelated 3 rd parties As such, spouses have NO rights to a student’s educational or financial aid records. Period end of discussion.

GLB extends FERPA If your institution makes loans to parents and other individuals, you must also protect their privacy These loans can include: PLUS Alternative Parent Loans

Safeguard Rule Institutions must develop a written information security plan to protect customer information Institutions must send privacy notices explaining the information-sharing practices to each customer

Safeguards Rule Expanded Must include plans to safeguard information against: Natural Disaster Human Error Fraud Data corruption Theft (hardware, software, reports) Unauthorized access

Safeguards Rule (cont) Natural Disaster (Earthquake, hurricane, flood, tornado, etc.) Is your data backed up in a remote location? Do you lock your computer when you leave your work station during fire alarms – or any other time, for that matter!?

Safeguards Rule (cont) Deliberate Fraud Must maintain a separation of duties Conflict of interest policies must be observed Human Error Do you have audit trails and reports that can be used to reconstruct data

Safeguards Rule (cont) Data Corruption Protect and secure access to data, i.e., limit query vs. update capability on a “need-to-do” basis, limit student worker access as needed Anti-virus software must be maintained and applied Institution must erect firewalls and develop protection against hackers

Safeguards Rule (cont) Must secure against theft of hardware, software and reports Secure during non-business hours: offices locked, keys secured Approved shredder: eliminates guess work in how to feed in documents

More Safeguards Must protect against unauthorized access Frequent password changes should be systematically required Reports sent on a “need-to-know” basis Computer privacy shields Student ID card readers – prevents inappropriate overhearing of SIDs or SSNs

More Safeguards Communicating to students via Use student’s institutional address Respond to non-institutional that an answer has been sent to the student’s institutional address Respond to parent inquiries through student’s institutional e- mail and ask student to forward to parent Mass communication to students should take student’s to a secure web site that protects their individual information

Whose Responsible Anyway? Identify and involve all offices involved with loans or collection of data FAO Business Office IT/Computer Systems Development Academic departments (scholarship applications)

Who’s the Compliance Officer? Someone must be designated the institutional Compliance Officer This function is usually assumed by the Business and Finance Division At STLCOP our registrar is our CO FAO responsibility rests in informing potential units of GLB responsibility

FAO GLB Policies Shred all student-specific documents Policy for identifying students and parents before sharing data Refer non-student/parent requests (3 rd party) to appropriate staff Report computer problems immediately

Additional FAO Policies Don’t share passwords. Problem: What do you do when an employee is absent and you need to access information on his/her computer? Lock computers when leaving work area Computer screens shielded from other students No visitor left behind – or unattended!

Resources US Department of Education FSA Handbooks Recordkeeping and Disclosure Chapter The Blue Book Chapter 7 Record Keeping and Disclosure pp 1-93 – Ramirez, Clifford (2002) Managing the Privacy of Student Records, LRP Publications, Horsham PA

CONTACT INFORMATION Ginny D’Angelo (800) Fax: (314) Leo Hertling 314/ fax# 314/