(Insert Company Name) VA LAN Extension MOU 2017.12.11 - TEMPLATE.docx

DOCX document 93 KB Posted

Attached to
7A21--VISN 22 POC Middleware Federal contract opportunity
Solicitation number
36C26221Q0044
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 22

View the file

Other files for this federal contract opportunity

Other files attached to 7A21--VISN 22 POC Middleware, newest first.
File Type Posted
(Insert Company Name) VA MOU Appendix A POC List 2017.12.18 - TEMPLATE.docx DOCX document
VA Directive 6500.pdf PDF
OIS MOU ISA SOP Final_20191007.pdf PDF
VA MOU ISA Approved Final Template-09092020.docx DOCX document
MOU ISA Review Form-.pdf PDF
MOU ISA Intake Form Instructions.pdf PDF
MOU ISA Annual Review SharePoint User Guide.pdf PDF
(Insert Company Name) VA MOU ISA Checklist 2017.12.18.xlsx XLSX spreadsheet
36C26221Q0044 0002_1.docx DOCX document
2020 MOU ISA New Template Brown Bag.pptx PPTX presentation
lab_52_poc_hl7_spec.docx DOCX document
Appendix C Template 2018.08.08.pdf PDF
VA Handbook 6500.6 Appendix A.pdf PDF
36C26221Q0044 0002 - RFQ Amendment.docx DOCX document
Attachment B - Middleware SOW v2.docx DOCX document
RFQ - 36C26221Q0044 v2.docx DOCX document
36C26221Q0044 0001 Amendment.docx DOCX document
36C26221Q0044 0001_1.docx DOCX document
Attachment E - Past Performance References.docx DOCX document
Attachment D - VA Handbook 6500.6 Appendix C.pdf PDF
Attachment B - Middleware SOW.docx DOCX document
36C26221Q0044.docx DOCX document
Attachment C - VA Directive 6550.pdf PDF
Attachment A - Schedule.xlsx XLSX spreadsheet
Show all 24

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Basic Instructions:

1. If you did not receive this directly from the Department of Veterans Affairs (VA) recently, confirm with the VA that you have the latest version of this template for handling an LAN Extension Memorandum of Understanding (MOU). This template was last updated on 12/11/2017.

2. “Save as” with new Document Title / File Name

a. Desired Format: (Company Name) (3 Letter VA Facility Code) AG MOU (Date) – (stage of VA MOU process / other notes)

b. Example: Johns Company ABC-VHA AG MOU 2017.12.11 – Initial Draft

3. Delete this text box and work out of the “template color key” below

MEMORANDUM OF UNDERSTANDING FOR LOCAL AREA NETWORK (LAN) EXTENSION

At[Organization 2] List as it appears in the current Governance, Risk and Compliance (GRC) tool. This is the VA Organization / Facility hosting the LAN Extension.
For[VA Organization 1] VA Organization, department, or company providing services and/or hardware located at [VA Organization 1] for this LAN Extension. It should be the primary company listed from contract and/or BAA. List fully spelled out name here, list full name (abbreviation) in executive summary, then use abbreviated name for [Organization 2] in rest of document.

[December, 11 2017] – Enter date document finalized for signature in this format [Version 1.0] Fill in based on Change Log or set as 1.0 if this is a new agreement

Template color key (This Text Box to be removed from final draft)

Black text: boilerplate text that has been approved by VA management and must remain in document (flag/ comment on any areas of concern to discuss with the VA) Blue text: replace with appropriate text and change to black once done Green text: this is informational/instructional text that should be removed from final draft [VA Organization 1]: Replace with name of the VA organization (can be performed by a find and replace all (CTRL+H) [Organization 2]: Replace with name of non-VA Organization / company name (can be performed by a find and replace all (CTRL+H)

DOCUMENT CONTROL CHANGE SHEET

Date
Filename/Version #
Author
Revision Description
MM/DD/YYYY
Example: [Organization 2] ABC-VHA LAN MOU Version 1.0
POC Name (VA)

1. [VA Organization 1] i.e. COR, ISO, CIO, VA business owner New Agreement or Description of revision to existing agreement

1. Renewal or revision to existing document: include the change log history of the older MOU agreement in the format of the example in the chart above.

2. New Document list only one entry above. Complete all 4 columns.

Table of Contents

EXECUTIVE SUMMARY1
1.INTRODUCTION2
1.1Overview and Purpose2
1.2Authority2
1.3Background3
1.4Communications4
1.4.1Security4
1.4.2Security Incidents4
1.4.3Disasters and Other Contingencies4
1.4.4Material Changes to System Configuration4
1.4.5Access to Physical Environment5
1.4.6Personnel Changes5
1.4.7Cost Considerations5
2.Duration5
3.SIGNATORY AUTHORITY6
Appendix A: Points of Contact8
Appendix B: Questionnaire – Use, Storage, and Transmission of VA Owned Sensitive Information Utilizing an LAN Extension9
Appendix C: VA Annual Review Documentation10
Appendix D: Definitions of Sensitive Information Types11
Appendix E: Location and Inventory of [VA Organization 1]’s LAN Extension at [Organization 2]16

FOR OFFICIAL USE ONLY

OFFICE OF INFORMATION SECURITY

5 OFFICE OF INFORMATION SECURITY

EXECUTIVE SUMMARY

[Insert description, purpose and scope of the LAN Extension for [VA Organization 1] at [Organization 2]. Describe the basic purpose of the requested network and provide a high level overview of this LAN Extension system. The description should specify what hardware and applications are involved and what kind of information is transmitted on the LAN Extension. The data flows and data transfers described in this agreement should pertain to the actual LAN Extension and not the data flows/transfers that are only internal to the Department of Veterans Affairs (VA). I.e. only include things relevant to the LAN Extension, not what occurs within the VA or the company. Limit to a paragraph or two, specifics / details will be included in the body of the document.

Note: The first use of all acronyms must be spelled out.

[VA Organization 1] utilizes a Memorandum of Understanding (MOU) to document the terms and conditions for the development, management, operation, and security of a Local Area Network (LAN) Extension owned by [VA Organization 1] but located at [Organization 2]. The following supporting information within the MOU will define the purpose, identify relative authorities, specify the responsibilities of both organizations, and define the terms of the agreement between the Department of Veterans Affairs (VA) Office of Information Technology (OIT) System Owner and the VA Business Owner. Additionally, the MOU provides details pertaining to apportionment of cost and timeline for terminating or reauthorizing the LAN Extension.

INTRODUCTION

Overview and Purpose The MOU defines the responsibilities of the participating organizations.

Choose the appropriate text and delete the other one.

Renewals / Updates to Existing LAN Extension Agreements: This MOU between the organizations listed below was first authorized on [date]. This publication supersedes all previously published MOUs pertaining to the LAN Extension described below.

New LAN Extension Agreements: This MOU between the organizations listed below is a new MOU and does not supersede any previous MOUs. The authorization date for this MOU is the last signature date in the Signatory Section (Section 3).

The purpose of this document is to establish an agreement between the VA OIT System Owner and the VA Business Owner regarding the development, management, operation, use, and security of an external LAN Extension owned and operated by [Organization 1] and any attached equipment owned by either [VA Organization 1] or [Organization 2] located in the physical environment of [Organization 2] but not connected to any network systems owned or operated by [Organization 2]. This agreement will cover the relationship between [VA Organization 1] and [Organization 2] including designated managerial and technical staff, in the absence of an existing agreement that addresses and documents VA requirements pertaining to the LAN Extension.

This document does not replace the existing contract(s) between [VA Organization 1] and [Organization 2]. Key VA Personnel have reviewed the contract and determined it meets the necessary VA Requirements. This fully executed agreement supports the following NIST security controls: CA-3, AC-20, and SA-9.

Authority The authority for this LAN Extension is based on: [[VA Organization 1] Information Security Officer is responsible for listing list all relevant legislative, regulatory, or policy authorities; EXAMPLES provided below.]

· Federal Information Security Management Act (FISMA)

· VA Directive 6500, Managing Information Security Risk: VA Information Security Program, and Handbook 6500, Risk Management Framework for VA Information Systems: Tier 3 – VA Information Security Program

· Health Insurance Portability and Accountability Act (HIPAA) Security Rule, 45 C.F.R. Part 160

· 38 United States Code (U.S.C.) §§ 5721-5728, Veteran’s Benefits, Information Security

· Office of Management and Budget (OMB) Circular A-130, Appendix III, Security of Federal Automated Information Systems

· 18 U.S.C. 641 Criminal Code: Public Money, Property or Records

· 18 U.S.C. 1905 Criminal Code: Disclosure of Confidential Information Authority for [VA Organization 1] to share data for the purpose outlined under this Agreement with the recipient is as follows: [VA Organization 1] Privacy Officer is responsible for listing all relevant legislative, regulatory, or policy authorities where applicable; EXAMPLES provided below. Note: If applicable the Privacy Officer may choose to use one bullet point with the language “N/A: No VA Sensitive, PHI, or PII information is shared or transmitted on this network.”

· HIPAA Privacy Rule, 45 Code of Federal Regulations (C.F.R.) Part 164, Standards for Privacy of Individually Identifiable Health Information [Add specific HIPAA provisions where applicable]

· Privacy Act of 1974, 5 U.S.C. § 552a, as amended

· [Add System Of Records Notice (SORN) Name, Routine Use, or other Privacy Act authority if applicable]

· VA Claims Confidentiality Statute, 38 U.S.C § 5701 [Add specific citation (e.g., (b)(3) or (e)) if applicable]

· Confidentiality of Certain Medical Records, 38 U.S.C. § 7332 [Add specific citation if applicable] Background The paragraph below can be modified freely to best describe the LAN Extension. Remove this instructional paragraph from the final document. Only details applicable to the LAN Extension between [VA Organization 1] and [Organization 2]” need be included. Data that may be accidentally or incidentally exposed should be part of the Business Associate Agreement (BAA) and does not need to be included here.

[Organization 2] agrees to provide physical space for the installation of [VA Organization 1]’s LAN Extension and associated equipment, and [VA Organization 1] requires the use of [Organization 2]’s physical environment as approved in this agreement by the VA OIT System Owner. The business purpose for the LAN Extension is [describe the business purpose of the LAN Extension]. [Organization 2] acknowledges that the use of [VA Organization 1]’s LAN Extension will be limited to the business purpose stated in this MOU.

For the purposes of this document, the term “LAN Extension” is defined in VA Handbook 6513 Secure External Connections dated October 12, 2017.

The LAN Extension system is described below:

· [VA Organization 1]’s LAN Extension

– Name [Add full name of [VA Organization 1]’s LAN Extension here]

– Function [Add function of [VA Organization 1]’s LAN Extension here]

– Location Enter physical address of [VA Organization 1]

See Appendix E for [VA Organization 1]’s LAN Extension equipment at [Organization 2].

– Description of information/data to be transmitted on [VA Organization 1]’s LAN Extension hosted at [Organization 2] including Federal Information Processing Standard (FIPS) 199 sensitivity categorization level

· Information Type Transmitted: Describe what information/data types will be transmitted from the Air-Gapped network at [VA Organization 1]. Example answers include, PII, PHI, VA owned sensitive information, and financial data. See Appendix D for definitions of sensitive information types. If sensitive data is transmitted, complete Appendix B.

If you are not transmitting anything sensitive, include a statement to the effect of “No Personally Identifiable Information (PII), Protected Health Information (PHI), or VA Sensitive Information is transmitted.” Additionally, describe the non-sensitive information transmitted (for example, configuration files, system logs, metering, usage reports, etc.).

· Data Flow Description: Describe how information/data will be transmitted by the Air-Gapped network located at [VA Organization 1] by [Organization 2]. Describe if it is collected, transmitted and/or stored. Is it physically moved between networks by humans?

· The FIPS 199 Sensitivity Categorization Level is [Low/Moderate/High]. The FIPS Level is to be filled out by the sponsoring facility’s VA staff (ISO/ Contracting Officer’s Representative (COR)/etc.). Please review definitions of low, moderate, and high in the publically available FIPS 199 document (once open, search for “Potential Impact on Organizations and Individuals”). This cannot be listed as N/A.

· Confidentiality – [Low/Moderate/High]

· Integrity - [Low/Moderate/High]

· Availability - [Low/Moderate/High]

Communications Frequent formal communications are essential to ensure the successful management and operation of the LAN Extension. The parties agree to maintain open lines of communication between designated staff at both the managerial and technical levels. Communications described herein must be conducted in writing (mail or email, excluding any sensitive VA information) unless otherwise noted.

[Organization 2] and [VA Organization 1] agree to designate and provide contact information for the technical lead(s) for their respective system, and to facilitate direct contact between technical leads to support the management and operation of the LAN Extension (See Appendix A). To safeguard the confidentiality, integrity, and availability of the LAN Extension systems and the data stored, processed, and transmitted, the parties agree to provide notice of specific events within the timeframes indicated below.

Security The parties agree to work together to ensure the security of [VA Organization 1]’s LAN Extension.

Security Incidents Technical Points of Contact (POC(s)), and/or the Information Security Officer (ISO) listed in Appendix A, will notify their designated counterparts by telephone or email within one hour when a security incident is detected so that the other party may take steps to determine whether the system has been compromised and to take appropriate security precautions.

Disasters and Other Contingencies Technical POC(s), listed in Appendix A, will immediately notify their designated counterparts by telephone or email in the event of a disaster or other contingency that disrupts the normal operation of the LAN Extension.

Material Changes to System Configuration Planned physical changes to the locations of equipment or the equipment itself will be communicated and coordinated with the established points of contact before such changes are implemented. Any change made to the LAN Extension by [VA Organization 1] will not result in a connection to a system owned by [Organization 2]. Any change made to the LAN Extension will be made by [VA Organization 1] Office of Information and Technology staff in coordination with [Organization 2]’s technical POC(s).

Access to Physical Environment [VA Organization 1] POCs will coordinate all visits with [Organization 2]’s technical POC(s), listed in Appendix A and only [VA Organization 1] staff listed in Appendix A will be granted access to those secure locations housing [VA Organization 1] equipment. [VA Organization 1]’s LAN Extension will be kept in a secure location that is protected from unauthorized access, interference, or damage. [Organization 2] will ensure that environmental controls are in place to protect against hazards such as fire, water, excessive heat and humidity. Additional considerations are to place LAN Extensions in secure areas to protect them from damage, loss, theft, or unauthorized physical access (per NIST 800-47). Physical Security Controls will be reviewed during the annual LAN Extension MOU review.

Personnel Changes The parties agree to provide timely notification of the separation or long-term absence of the respective technical POCs and will provide notification of any changes in point of contact information. With respect to the technical POCs, both parties also will provide notification of changes to user profiles, including users who resign or change job responsibilities.

The responsible parties for each system are listed in Appendix A of this MOU. The appendix will be updated whenever necessary. Updating the appendix does not require the re-signing of this MOU by either party. It is the responsibility of each respective approving authority to ensure the timely updating of this appendix and for the notification of such changes to the alternate party within thirty (30) days of any personnel change.

Cost Considerations The parties agree to identify responsibility for the costs of the LAN Extension / media and use of space and no such expenditures or financial commitments shall be made without the written concurrence of both parties.

Duration This agreement will expire when one or both parties determine that the LAN Extension is no longer necessary or if there is no longer a business or contractual justification. If there is no longer a business justification and/or one or both parties determine that the LAN Extension is no longer necessary, then the LAN Extension will be decommissioned.

Annually the VA ISO, along with the VA Business Owner, will review the agreement to ascertain 1) if the LAN Extension is deemed still necessary and 2) if there are any significant changes to the LAN Extension. The outcome of the review will be documented in the review section, Appendix C: VA Annual Review. If there are significant changes to the LAN Extension at any time or if major changes were noted during the annual review, the agreement must be updated and re-signed.

If one or both of the parties wish to terminate this agreement prematurely, they may do so upon thirty (30) days advanced notice or in the event of a security incident that necessitates an immediate response. Approval to decommission must come from the VA Business Owner.

SIGNATORY AUTHORITY

We, the undersigned, mutually agree to the terms of this MOU Agreement.

Note: ensure signatories have the necessary authority to sign for the organization(s) listed below. Ex. a VISN level agreement must be signed by a VISN Level ISO.

[VA Organization 1] System Owner: The system owner is the individual who is responsible for authorizing the VA General Support System as described in GRC.

[Name of [VA Organization 1]’s OIT System Owner] [Job Title of [VA Organization 1]’s System Owner]

X__________________________ Date __________

[VA Organization 1] Business Owner: The service that entered into an agreement with [Organization 2] for the LAN Extension.

[Name of [VA Organization 1]’s Business Owner] [Job Title of [VA Organization 1]’s Business Owner]

[VA Organization 1] Local Information Security Officer:

[Name of [VA Organization 1]’s Local Information Security Officer] Information Security Officer

As the Privacy Officer (PO) for this VA LAN Extension MOU I have determined that the legal authorities for the data covered by this agreement exist and are appropriately addressed and the uses and disclosures of the data covered by this agreement are in accordance with VA and Veterans Health Administration (VHA) directives. I concur with the privacy practices outlined in this VA LAN Extension MOU.

[VA Organization 1] Local Privacy Officer [Name of [VA Organization 1]’s Local Privacy Officer] Privacy Officer

[Organization 2] System Owner:

[Name of [Organization 2]’s OIT System Owner] [Job Title of [Organization 2]’s System Owner]

[Organization 2] Local Information Security Officer:

[Name of [Organization 2]’s Local Information Security Officer] Information Security Officer

Appendix A: Points of Contact List of Responsible Parties for Each System:

(Include all [VA Organization 1] and [Organization 2] POCs including System Owner, Business Owner, ISO, and Privacy Officer. Also include any key Technical staff and current version authors from Document Control Change Sheet)

Name
Company
Title
Office Phone
Email
John Example123
VA
System Owner
111-222-3333
John.example123@va.gov

List of Responsible Parties to Contact during a Security Incident:

(E.g. Primary ISO, Backup ISO, 24/7 Support Desk, and any key Technical staff)

Name
Company
Title
Office Phone
Email

Appendix B: Questionnaire – Use, Storage, and Transmission of VA Owned Sensitive Information Utilizing an LAN Extension Complete as many Questionnaires as needed where VA sensitive information is transmitted.

If no VA Owned sensitive information is used, list “N/A: No VA Owned sensitive information/data is transmitted via the LAN Extension” above question 1 and remove all blue instructions from remaining fields in this section.

Note: This does not have to be signed if this is listed as N/A.

1. Description of Data: [Specify the data elements / fields of data being transmitted and provide a description of the sensitive information to be transferred: such as financial information, configuration file, system logs, name, Date of Birth (DOB), and/or Social Security Number (SSN). e.g., clinical images with protected health information; financial information with names and social security numbers; individually identifiable data collected for research].

This information should align with the details in Section 1.3 “Description of data and network classification level.”

2. Purpose of the Data Use, Storage, and/or Transfer: [e.g., transfer of clinical images; financial information used to generate billing information; subject data to be analyzed under a VA or a non-VA research protocol] This information should align with the details in Section 1.3 “Function.”

3. Description of the Security Controls in Place to Protect the VA Sensitive Data in Accordance with VA Policies. [Username/Password, PIV, encryption, Physical Security] Fill in by ISO / Technical POCs

4. Non-VA Storage Location of the VA Information, if applicable:

Provide [Organization 2]’s Address (street, city, state, zip code), to include building and closet number if applicable.

5. Supporting Document(s) Describing the Use, Storage, and/or Transmission of the Data: [E.g., Contract#, Protocol name and #, MOU, HIPAA authorization, Data Use Agreement, etc.] You will need to get from the sponsoring COR or business owner

6. Provisions for the return and/or retention of the VA Data (if applicable): [Describe the provisions for the return and/or retention of the sensitive information to VA at the completion of the contract, project, clinical application/evaluation, etc., if applicable, and in accordance with records retention policies]

VA Point of Contact: [Name and Title if applicable] ] i.e. VA COR (if network has a contract) and if not, insert the VA Business Owner Signature: [insert signature] Date: [insert date]

VA Information Security Officer: [insert VA ISO name and title if applicable] Signature: [insert signature] Date: [insert date]

Appendix C: VA Annual Review Documentation VA ISO signature is required for each annual review. During the annual review of this document, the ISO should consult key stakeholders.

Fill in Change Status Column with following (Select all that apply)

1. No Change Required

2. Minor Change Required

3. Major Change Required

4. New Agreement

5. Change in POC

6. Other (please specify)

When a page is full, the ISO should add another page.

Date of Review
Change Status

(Select all that apply)

Additional Comments
Signature(s)

Appendix D: Definitions of Sensitive Information Types The following discussion defines the various types of personal information collected, maintained, and used within VA and provides an overview of how they inter-relate. Every type is subject to VA security statutes (38 U.S.C. §§ 5721-28), as long as it identifies or could reasonably be used to identify an individual. Depending on the type of information, it may also be protected by the Privacy Act (5 U.S.C. § 552a), the VA confidentiality statutes (38 U.S.C. §§ 5701, 5705, and 7332), and the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160, 164).

VA Sensitive Information/Data - All Department information and/or data on any storage media or in any form or format, which requires protection due to the risk of harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the information. The term includes not only information that identifies an individual but also other information whose improper use or disclosure could adversely affect the ability of an agency to accomplish its mission, proprietary information, and records about individuals requiring protection under applicable confidentiality provisions. SOURCE: 38 U.S.C. § 5727.

Personally Identifiable Information (PII) - Any information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc. Information does not have to be retrieved by any specific individual or unique identifier (i.e., covered by the Privacy Act) to be personally identifiable information. SOURCE: Office of Management and Budget (OMB) Memorandum 07-16, Safeguarding Against and Responding to Breaches of Personally Identifiable Information (May 22, 2007)

NOTE: The term “Personally Identifiable Information” is synonymous and interchangeable with “Sensitive Personal Information.”

Sensitive Personal Information (SPI) - The term, with respect to an individual, means any information about the individual maintained by VA, including the following: (i) education, financial transactions, medical history, and criminal or employment history; and (ii) information that can be used to distinguish or trace the individual’s identity, including name, social security number, date and place of birth, mother’s maiden name, or biometric records. SPI is a subset of VA Sensitive Information/Data. SOURCE: 38 U.S.C. § 5727.

NOTE: The term “Sensitive Personal Information” is synonymous and interchangeable with “Personally Identifiable Information.”

Health Information - Health Information is any information, whether oral or recorded in any form or medium, created or received by a health care provider, health plan, public health authority, employer, life insurers, school or university, or health care clearinghouse or health plan that relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or payment for the provision of health care to an individual. This encompasses information pertaining to examination, medical history, diagnosis, and findings or treatment, including laboratory examinations, X-rays, microscopic slides, photographs, and prescriptions. SOURCE: 45 C.F.R. § 160.103

Individually Identifiable Information (III) - Individually Identifiable Information is any information pertaining to an individual that is retrieved by the individual’s name or other unique identifier, as well as Individually Identifiable Health Information regardless of how it is retrieved. Individually Identifiable Information is a subset of Personally Identifiable Information and is protected by the Privacy Act.

Individually Identifiable Health Information (IIHI) - Individually Identifiable Health Information is a subset of Health Information, including demographic information collected from an individual, that: (1) is created or received by a health care provider, health plan, or health care clearinghouse (e.g., a HIPAA-covered entity, such as VHA); (2) relates to the past, present, or future physical or mental condition of an individual, or provision of or payment for health care to an individual; and (3) identifies the individual or where a reasonable basis exists to believe the information can be used to identify the individual.

NOTE: VHA uses the term individually-identifiable health information to define information covered by the Privacy Act and the Title 38 confidentiality statutes in addition to HIPAA.

Protected Health Information (PHI) - The HIPAA Privacy Rule defines PHI as Individually Identifiable Health Information transmitted or maintained in any form or medium by a covered entity, such as VHA.

NOTE: VHA uses the term protected health information to define information that is covered by HIPAA but, unlike individually-identifiable health information, may or may not be covered by the Privacy Act or Title 38 confidentiality statutes. In addition, PHI excludes employment records held by VHA in its role as an employer.

Non-identifiable Information - Non-identifiable Information is information from which all Unique Identifiers have been removed so that the information is no longer protected under the Privacy Act, 38 U.S.C. §5701, or 38 U.S.C. § 7332. However, Non-identifiable Information has not necessarily been de-identified and may still be covered by the HIPAA Privacy Rule unless all 18 Patient Identifiers listed in the Rule’s de-identification standards are removed.

Limited Data Set - A Limited Data Set is protected health information from which certain specified direct identifiers of the individuals and their relatives, household members, and employers have been removed. These identifiers include name, address (other than town or city, state, or zip code), phone number, fax number, e-mail address, Social Security Number (SSN), medical record number, health plan number, account number, certificate and/or license numbers, vehicle identification, device identifiers, web universal resource locators (URL), internet protocol (IP) address numbers, biometric identifiers, and full-face photographic images. The two patient identifiers that can be used are dates and postal address information that is limited to town or city, State or zip code. Thus, a Limited Data Set is not De-identified Information, and it is covered by the HIPAA Privacy Rule. A Limited Data Set may be used and disclosed for research, health care operations, and public health purposes pursuant to a Data Use Agreement. SOURCE: 45 C.F.R. § 164.514(e) (2)

De-identified Information - De-identified Information is health information that is presumed not to identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual because the 18 Patient Identifiers described in the HIPAA Privacy Rule have been removed. De-identified information is no longer covered by the Privacy Act, 38 U.S.C. § 5701, 38 U.S.C. § 7332, or the HIPAA Privacy Rule. SOURCE: 45 C.F.R. § 164.514(b) (2) (i)

Patient Identifiers - Patient identifiers are the 18 data elements attributed to an individual under the HIPAA Privacy Rule that must be removed from health information for it to be de-identified and no longer covered by the HIPAA Privacy Rule. Please see VHA Handbook 1605.1, Privacy and Release of Information, Appendix B, De-identification of Data, for more detail.

Unique Identifier - A Unique Identifier is an individual’s name, address, social security number, or some other identifying number, symbol, or code assigned only to that individual (e.g., medical record number and claim number). If these identifiers are removed, then the information is no longer Individually Identifiable Information and is no longer covered by the Privacy Act, 38 U.S.C. § 5701, or 38 U.S.C. § 7332. However, if the information was originally Individually Identifiable Health Information, then it would still be covered by the HIPAA Privacy Rule unless all 18 Patient Identifiers listed in the de-identification standard have been removed.

NOTE: The VA Office of General Counsel has indicated that the first initial of last name and last four of the social security number (e.g., A2222) is not a unique identifier; therefore, inclusion of this number by itself does not make the information identifiable or sensitive.

Relations among Different Types of Information

VA Sensitive Information/Data is the broadest term and generally encompasses all of the other terms with the exception of de-identified data.

Sensitive Personal Information and Personally Identifiable Information are synonymous and encompass Individually Identifiable Information, Individually Identifiable Health Information and Protected Health Information.

Individually Identifiable Information encompasses Individually-identifiable Health Information. It may or may not be Protected Health Information.

Health Information encompasses Individually Identifiable Health Information. It may or may not be Protected Health Information.

Individually Identified Health Information is maintained by VHA and is protected by the HIPAA Privacy Rule, as well as the Privacy Act and the Title 38 confidentiality statutes.

Non-identifiable Information is no longer protected by the Privacy Act, 38 U.S.C. § 5701, or 38 U.S.C. § 7332, but is covered by the HIPAA Privacy Rule unless it has been de-identified in accordance with the Rule.

De-identified Information may include VA Sensitive Information/Data, but it will not include any of the other types of data defined herein. De-identified Information is not Protected Health Information.

Patient Identifiers encompass Unique Identifiers. Patient Identifiers are the 18 data elements attributed to an individual under the HIPAA Privacy Rule. Unique Identifiers are those Patient Identifiers that identify or could be used to identify only one individual, such as name, address, or some other number, symbol, or code assigned only to that individual. Unique Identifiers can be used to retrieve information about an individual from a Privacy Act system of records.

Protected Health Information may consist of any of the other types of data defined herein except for De-identified Information. Protected Health Information includes Limited Data Sets and Non-identifiable Information.

Sensitive VA Information/Data

Personally Identifiable Information/Sensitive Personal Information

Individually Identifiable Information

Individually Identifiable Health Information

Non-identifiable Information

Limited Data Sets

De-identified Information

Protected Health Information may be comprised on any of these types of data, except for De-identified Information.

Appendix E: Location and Inventory of [VA Organization 1]’s LAN Extension at [Organization 2] Maintain an inventory for all LAN Extension equipment both hardware and software that is covered by this MOU (type of device, serial number and owner, including the location and the responsible party). Any non-VA equipment connected to the LAN Extension must be clearly identified.

Document the physical location/closet where the LAN Extension equipment terminates at [Organization 2] and the equipment (laptops/workstations) that connect to the LAN Extension.

[Organization 2] is located at [Street, city, state, zip].

All columns below should be filled out for each listed device. Location should include address, if different than above, building number, room number, and rack/shelf number, if applicable.

Type of Device
Name of Device
Serial Number
VA Business Owner /

Department

Location
Non-VA Equipment (Y/N)

image1.gif image2.png

File details come from the government source that posted it. Updated .