Laserfiche WebLink
Docusign Envelope 1D: 72A!J1 B3B-BEAT-46FE-ACDD-146571 B87804 <br />EXHIBIT 2 <br />a. Supervision of Data. The PII in paper form shall not be left unattended at anytime, unless <br />it is locked in a file cabinet, file room, desk or office. Unattended means that information <br />may be observed by an individual not authorized to access the information. <br />b. Data in Vehicles. The Contractor shall have policies that include, based on applicable risk <br />factors, a description of the circumstances under which the Contractor Staff can transport <br />PII, as well as the physical security requirements during transport. A Contractor that <br />chooses to permit its staff to leave records unattended in vehicles must include <br />provisions in its policies to ensure the PH is stored in a non -visible area such as a trunk, <br />that the vehicle is locked, and under no circumstances permit PII be left unattended in a <br />vehicle overnight or for other extended periods of time. <br />c. Public Modes of Transportation. The PH in paper form shall not be left unattended at any <br />time in airplanes, buses, trains, etc., including baggage areas. This should be included in <br />training due to the nature of the risk. <br />d. Escorting Visitors. Visitors to areas where PII is contained shall be escorted, and PII shall <br />be kept out of sight while visitors are in the area. <br />e. Confidential Destruction. PII must be disposed of through confidential means, such as <br />cross -cut shredding or pulverizing. <br />f. Removal of Data. The PH must not be removed from the premises of Contractor except <br />for identified routine business purposes or with express written permission of HHS. <br />g. Faxing. <br />i. Faxes containing PII shall not be left unattended and fax machines shall be in <br />secure areas. <br />ii. Faxes shall contain a confidentiality statement notifying persons receiving faxes <br />in error to destroy them and notify the sender. <br />iii. Fax numbers shall be verified with the intended recipient before sending the fax <br />h. Mailing. <br />i. Mailings containing PII shall be sealed and secured from damage or inappropriate <br />viewing of PII to the extent possible. <br />ii. Mailings that include five hundred (500) or more individually identifiable records <br />containing PII in a single package shall be sent using a tracked mailing method <br />10 <br />City Council 7 — 126 7/15/2025 <br />