What is personally identifiable information (PII)? KDE Employee Training Data Security Video Series 1 of 3 October 2014.

Slides:



Advertisements
Similar presentations
National Forum on Education Statistics sponsored by the National Cooperative Education Statistics System and the National Center for Education Statistics.
Advertisements

FERPA - Sharing Student Information
Family Educational Rights and Privacy Act (FERPA) Basics For Faculty and Staff.
Information for Students MGH Institute of Health Professions Use your down arrow or click your mouse to advance through the presentation.
University Data Classification Table* Level 5Level 4 Information that would cause severe harm to individuals or the University if disclosed. Level 5 information.
FERPA Refresher Training Start. Page 2 of 11 Copyright © 2006 Arizona Board of Regents FERPA Refresher Training What is FERPA FERPA stands for Family.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
KDE Employee Training. What IS a Data Breach? Unauthorized release (loss or theft) of Sensitive or Confidential Data, such as PII, PHI, etc. On site or.
1 Office of the General Counsel FERPA  Family Educational Rights and Privacy Act (20 U.S.C § 1232g)
RVCC FACULTY FERPA WORKSHOP OCTOBER 2011 DAN PALUBNIAK REGISTRAR
FERPAFERPA Family Educational Rights and Privacy Act.
FERPA: Family Educational Rights and Privacy Act.
FERPA Skidmore College Family Education Rights & Privacy Act What is FERPA? It is the Family Educational Rights and Privacy Act of Is also referred.
2/16/2010 The Family Educational Records and Privacy Act.
FERPA 2008 New regulations enact updates from over a decade of interpretations.
FERPA Overview for CANR Business Managers Rob Kent, MSU Assistant General Counsel October 7, 2014.
Data Privacy: Third Parties, Vendors, & Nonprofits Baron Rodriguez (PTAC), Michael Hawes (DoED), & Mike Tassey (PTAC)
Office of Safe and Drug-Free Schools Advisory Committee Meeting February 21, 2007.
Data Access and Data Sharing KDE Employee Training Data Security Video Series 2 of 3 October 2014.
The Family Educational Rights and Privacy Act of 1974 February, 2014 Presented by Daniel Cordas Employee Services, Seattle Community Colleges.
707 KAR 1:360 Confidentiality of Information. Section 1: Access Rights 1) An LEA shall permit a parent to inspect and review any education records relating.
Privacy and Security Laws for Health Care Organizations Presented by Robert J. Scott Scott & Scott, LLP
THE FAMILY EDUCATION RIGHTS & PRIVACY ACT (FERPA) Presented by: Robin B. Snyder, Esquire.
{ FERPA Family Educational Rights and Privacy Act 2012 Revised May 2013.
Family Educational Rights and Privacy Act. From the moment a child enters the school system, sensitive information is collected about the child (and even.
FERPA: What you Need to Know The Family Educational Rights and Privacy Act & SEI.
FERPA Refresher Training Start. Page 2 of 11 Copyright © 2006 Arizona Board of Regents FERPA Refresher Training What is FERPA FERPA stands for Family.
CONFIDENTIALITY TRAINING FOR CALLOWAY COUNTY SCHOOLS VOLUNTEERS SCHOOL YEAR
NEW FERPA REGULATIONS: ARE YOU IN COMPLIANCE? Presented by Cristi Millard.
The Family Educational Rights and Privacy Act FERPA.
Calloway County Schools CONFIDENTIALITY TRAINING Protection of Personal Information School Year
Student Data and Confidentiality Parents Rights Schools’ Responsibilities.
FERPA Regulation Changes Effective December 2008 Presented by Karen Schultz University Registrar.
FAMIS CONFERENCE Mari M. Presley, Assistant General Counsel Florida Department of Education June 12, 2012.
1 CONFIDENTIALITY. 2 Requirement Under IDEA 34 CFR Sec (c) All staff collecting or using personally identifiable information in public education.
Special Education 101 Elementary Dept. Chair 1/27/2009 Confidentiality.
When Can You Redact Information Without Requesting an Attorney General Decision? Karen Hattaway Assistant Attorney General Open Records Division Views.
FERPA Guidelines for Cooperating Teacher and University Supervisors.
SPECIAL EDUCATION A REVIEW OF:  CHILD FIND/ SPED PROCESS  FERPA AND CONFIDENTIALITY  LENGTH OF SCHOOL DAY.
Dino Tsibouris & Mehmet Munur Privacy and Information Security Laws and Updates.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
FERPA for the Financial Aid Office NCASFAA Fall Conference November 2012.
CONFIDENTIALITY TRAINING FOR CALLOWAY COUNTY SCHOOLS VOLUNTEERS SCHOOL YEAR
Safeguarding Sensitive Information. Agenda Overview Why are we here? Roles and responsibilities Information Security Guidelines Our Obligation Has This.
FOIA Processing and Privacy Awareness at NOAA Prepared by Mark H. Graff NOAA FOIA Officer OCIO/GPD (301)
Taylor County Schools FERPA (Confidentiality) Training August 17, 2010.
FERPA Family Educational Rights and Privacy Act of 1974 (also known as the Buckley Amendment)
CCB TECHNICAL ASSISTANCE CALL July 12, :30-1:30 1.
Volunteer Training for Robertson County School Volunteers.
Laws and Regulations. Family Educational Rights and Privacy Act Children’s Online Privacy Protection Act Protection of Pupil Rights Amendment Health Insurance.
Welcome to Workforce 3 One U.S. Department of Labor Employment and Training Administration Webinar Date: Thursday, October 23, 2014 Presented by: Division.
FERPA & HIPAA: Maintaining Student Confidentiality.
Data Breach ALICAP, the District Insurance Provider, is Now Offering Data Breach Coverage as Part of Our Blanket Coverage Package 1.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Also known as the Buckley Amendment Regulations: 34 CFR Part 99.
Denise Chrysler, JD Director, Mid-States Region
Tomball Independent School District Annual Confidentiality Training
FERPA (Oops, can I say that?)
SPECIAL EDUCATION A REVIEW OF: CHILD FIND/ SPED PROCESS
FERPA Family Educational Rights and Privacy Act of 1974
FERPA (Oops, can I say that?)
SPECIAL EDUCATION REQUIRED TRAINING
Family Educational Rights & Privacy Act (FERPA)
Welcome to the FERPA training for Faculty and Staff.
Identity Theft Prevention Program Training
Colorado “Protections For Consumer Data Privacy” Law
Confidentiality Training 2014
The Health Insurance Portability and Accountability Act
Presentation transcript:

What is personally identifiable information (PII)? KDE Employee Training Data Security Video Series 1 of 3 October 2014

Protecting personal information is everybody’s job! Don’t become a headline! City Herald Dispatch [ YOUR NAME ], KDE employee accidentally placed personal data of over 600 thousand Kentucky students at risk! Whose personal information?Protecting PII – where and how? StudentsIn the office – clean house Staff and teachersOn the systems – follow protocol Your personal informationData transfers, s – Use MOVEit or don’t move it! Remote access - VPN Screenshots for publications, presentations – Create obviously fictitious person’s records i.e. Mickey Mouse Conversations – Keep private Reports – follow protocol, suppress, redact

 Family Educational Rights and Privacy Act (FERPA) gives parents protections with regard to their children’s education records and allows education agencies to disclose those records to parties under certain conditions. Family Educational Rights and Privacy Act  KRS (HB 5) addresses the safety and security of personal information held by public agencies, and requires public agencies and nonaffiliated third parties to implement, maintain, and update security procedures and practices. This includes taking any appropriate corrective action to safeguard against security breaches. KRS  KRS (HB 232) requires consumer notification when a data breach reveals personally identifiable information. It also requires cloud computing service providers contracting with educational institutions to maintain security of student data and allows the KBE to promulgate regulations as needed. KRS What defines and regulates PII?

Protects the privacy of student education records. It applies to education agencies that receive funds under programs of the U.S. Dept. of Education. FERPA defines personally identifiable information as:  the student’s name and name of the student’s parent or other family members;  address of the student or student’s family;  a personal identifier, such as social security number or student number and,  other indirect identifiers, such as student’s date of birth, place of birth, and mother’s maiden name.  Other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty. Family Educational Rights & Privacy Act (FERPA)

 Local and state education agencies may ONLY re-disclose PII if the disclosure falls under one of the permitted exceptions to the consent requirement.  The most commonly used exceptions are: 1.Directory Information (for local agencies) 2.School Official (for local agencies) 3.Studies 4.Audit/evaluation * Studies and Audit/Evaluation exceptions require written agreements. FERPA exceptions allow disclosure of PII

KRS defines personal information as a person’s (not just students’) first name or first initial and last name, personal mark, or unique biometric or genetic print or image, in combination with one or more of the following data elements:.  Account number or credit/debit card number, that in combination with any required security/access code or password would permit access to an account;  social security number; taxpayer ID number that incorporates a social security no.;  driver’s license number, state ID card number or other individual ID number;  passport number or other ID number issued by the United States government; or  individually identifiable health information, except for education records covered by FERPA. Kentucky’s data security requirements - HB 5

KRS defines personally identifiable information as an individual’s first name or first initial and last name in combination with any one of the following:  Social security number  Driver’s license number  Account number, credit or debit card number, in combination with any security code, access code, or password required to permit access to the financial account Kentucky’s data security requirements – HB 232

 Understand the confidentiality of PII  Learn to identify PII in its many forms.  Keep a “clean house.”  Read, understand and follow state and federal privacy, security and confidentiality requirements and policies.  Learn more about the best practices covered in part-two of this training series, Data Access and Data Sharing. What do I need to remember about PII?

We appreciate your feedback, questions and comments. We can be reached through the KDE Data Request mailbox.KDE Data Request mailbox Explore other resources on the KDE Data Governance Web page.KDE Data Governance Web page Thank you! Have a question? Want more information?